On Tue, 18 Dec 2018 23:36:24 +0100 qmi <[email protected]> wrote: > This vulnerability seems to have been already handled. See URL: > https://security-tracker.debian.org/tracker/TEMP-0566326-9A899F
At that time, there's no info. > But no CVE assigned as this is not public yet. Yes. > Additionally, the Tencent team's page itself on the link referred by > you state that in order to apply the fix, update to 3.26.0 version. > The Debian package in unstable/sid is already at 3.26.0-3. This also > indicates that the issue is already handled. No, we should deal with it in stable release, so tracking is important. -- Hideki Yamane <[email protected]>

