Hi Francois I am wondering, why you didn't contact the testing-security team and prepared uploads for testing-security? If I am not mistaken, the issue is easily exploitable. If you think it is not really important, then informing us would also be a nice move, since we can add urgencies to our tracker[0]. Also I think our announce emails do not catch all updates that go via t-p-u.
By the way, did you check the two snoopy patches you are shipping? Last time I looked I didn't see a reason for not including them into the snoopy package in debian and then just depending on it (and removing another code copy :) ). Cheers Steffen [0]: http://security-tracker.debian.net/tracker/
signature.asc
Description: This is a digitally signed message part.