Control: tags -1 + confirmed On Sun, 2015-10-04 at 16:53 +0200, Andreas Beckmann wrote: > Second PU request for fixing CVE-2015-5950. > > This requires a new upstream release, too, that is two or three releases > ahead of what is currently in jessie. > > The proposed changes are all already included and tested in sid. > This includes changes from several uploads to sid (up to 340.76-4) that > are a new upstream release and several bugfixes and minor features that > I consider appropriate for jessie. > The big changes done in sid 340.76-5 onwards are excluded, instead the > changes needed for jessie were cherry-picked into 340.93-0+deb8u1.
Please go ahead. > Regarding the version number, 340.93-1 was uploaded to sid (before the > CVE was made public), so we need to use 340.93-0+deb8u1 this time (or > would 340.93-0 be ok?). (A shorter version number reduces version string > inflation when rebuilding nvidia-graphics-modules.) -0+deb8u1 would be clearer, but I wouldn't object terribly to -0. Regards, Adam

