tag 317967 - security thanks Presumably this bug was fixed in dpkg 1.13.11, which was released well after the fixed zlib got into the archive. Although I've not actually checked all the builds to see.
Therefore I am not tracking this bug as a security hole, and IMHO it should be closed, unless the fact that dpkg still embeds a static zlib and still will be vulnerable and need recompiles because of future holes in that library is a problem worth leaving a bug open for. -- see shy jo
signature.asc
Description: Digital signature

