Package: release.debian.org Severity: normal User: [email protected] Usertags: unblock
Hello, We respectfully request that you unblock mosh 1.2.3-1 and include it in the wheezy release. A debdiff from mosh 1.2.2-1 is available at http://mosh.mit.edu/mosh_1.2.2-1_to_mosh-1.2.3-1.debdiff.txt . mosh 1.2.3 is an upstream microrelease that fixes several issues we learned about during the first six months of widespread use. It is well-tested and has passed the regressions tests. Most prominently, mosh now links against OpenSSL and uses OpenSSL's implementation of AES. Previously, Mosh 1.2.2 shipped its own AES reference implementation for licensing reasons. The reference implementation has been criticized for possible timing leakage, and it is preferable to avoid shipping a duplicate cipher implementation. Mosh 1.2.3 also includes several robustness fixes, including increased resilience when transiting problematic NATs and VPNs and compatibility with the KDE konsole and dual-stack IPv4/v6 sshds. More security and robustness improvements are listed in the changelog. I regret the lateness of this upstream release in the wheezy freeze cycle. But given the expected lifetime of wheezy as a stable release, upstream would much rather be supporting 1.2.3 instead of 1.2.2 for the long term. We appreciate your consideration of our request. unblock mosh/1.2.3-1 -- To UNSUBSCRIBE, email to [email protected] with a subject of "unsubscribe". Trouble? Contact [email protected] Archive: http://lists.debian.org/20121023224411.18147.98504.reportbug@trolley

