Neil McGovern wrote:
> Hi all,
> 
> Could I please have the following:
> gaim - priority bump 
>       1:2.0.0+beta5-8 to 1:2.0.0+beta5-9
>       no CVE ID yet, crash when receiving an invalid UPnP response

Unblocked by Marc

> libarchive - unfreeze
>       1.2.53-2 to 1.3.1-1
>       CVE-2006-5680 - DoS (CPU consumption)

Not important according to tracker and too big diff...

> nexuiz - unfreeze/bump
>       2.1-1 to 2.2.1-1
>       CVE-2006-6609 - DoS
>       CVE-2006-6610 - remote console command injection
> nexuiz-data - unfreeze/bump
>       2.1-1 to 2.2.1-1
>       Same issues as above

Too big diff IMHO, so I'm not unblocking these...

> typo3-src - unfreeze
>       4.0.2+debian-2 to 4.0.4+debian-1
>       CVE-2006-6690 - arbitrary command execution

Fixed in 4.0.2+debian-2 according to the changelog (which I already approved).

Cheers

Luk

-- 
Luk Claes - http://people.debian.org/~luk - GPG key 1024D/9B7C328D
Fingerprint:   D5AF 25FB 316B 53BB 08E7   F999 E544 DE07 9B7C 328D

Attachment: signature.asc
Description: OpenPGP digital signature

Reply via email to