Bug#461236: boost vulnerabilities (was [pkg-boost-commits] r14144 - in boost/trunk: ...)

2008-01-21 Thread Domenico Andreoli
On Sun, Jan 20, 2008 at 05:32:03PM -0600, Steve M. Robbins wrote: Hi all, Hi, I do understand that derivative distributions such as Ubuntu do put their own release entries in there. I imagine the Ubuntu users understand that and can differentiate the Ubuntu release from the Debian one in

Bug#461236: boost vulnerabilities

2008-01-17 Thread Jamie Strandboge
Package: boost Version: 1.34.1-2.2 Severity: critical Tags: patch, security User: [EMAIL PROTECTED] Usertags: origin-ubuntu hardy ubuntu-patch boost as included in Debian is vulnerable to CVE-2008-0171 and CVE-2008-0172. Attached is a debdiff which addresses this issue (changelog entry in