On Tue, Jan 28, 2014 at 10:26:06PM +0100, Felix Geyer wrote: > Do you want to handle this through a security update? > According to upstream the vulnerabilities are mostly about users on the VM > being able > to crash their VM. No ways to execute code on the host are known.
I that case we don't need a DSA Could you fix this in a point release? http://www.debian.org/doc/manuals/developers-reference/pkgs.html#upload-stable Cheers, Moritz -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org