Bug#655960: security-tracker: DSA-2388-1 vs. tracker

2012-01-15 Thread Francesco Poli (wintermute)
Package: security-tracker Severity: normal Hi! The tracker page [1] for DSA-2388-1 [2] looks OK, but some of the referenced CVE tracker pages [3][4] claim that t1lib/5.1.2-3.3 is still vulnerable in wheezy and sid, while the DSA [2] claims that all the CVEs are fixed in wheezy and sid by

Bug#655960: security-tracker: DSA-2388-1 vs. tracker

2012-01-15 Thread Yves-Alexis Perez
On dim., 2012-01-15 at 12:53 +0100, Francesco Poli (wintermute) wrote: Package: security-tracker Severity: normal Hi! The tracker page [1] for DSA-2388-1 [2] looks OK, but some of the referenced CVE tracker pages [3][4] claim that t1lib/5.1.2-3.3 is still vulnerable in wheezy and sid,

Bug#655960: security-tracker: DSA-2388-1 vs. tracker

2012-01-15 Thread Francesco Poli
On Sun, 15 Jan 2012 13:42:50 +0100 Yves-Alexis Perez wrote: On dim., 2012-01-15 at 12:53 +0100, Francesco Poli (wintermute) wrote: [...] Assuming that the DSA is right and the tracker is wrong, please fix this inconsistency. [...] You're perfectly right, wheezy/sid doesn't have a fix for

Bug#655960: security-tracker: DSA-2388-1 vs. tracker

2012-01-15 Thread Michael Gilbert
On Sun, Jan 15, 2012 at 7:42 AM, Yves-Alexis Perez wrote: On dim., 2012-01-15 at 12:53 +0100, Francesco Poli (wintermute) wrote: Package: security-tracker Severity: normal Hi! The tracker page [1] for DSA-2388-1 [2] looks OK, but some of the referenced CVE tracker pages [3][4] claim that