tag 656815 + squeeze confirmed
thanks

On Sat, 2012-01-21 at 22:28 +0000, Jonathan Wiltshire wrote:
> Testing has shown that the fix for CVE-2011-4360 introduces a regression:
> in some situations, an error is returned instead of a login prompt. Moreover,
> the Debian package seems not to disclose information as described by the CVE.

mediawiki, how we love thee.

> For this reason I would like to get a fix into this point release rather
> than waiting for the next. I realise the window technically closes this 
> weekend
> and I'm sorry for the late notice.
> 
> Debdiff attached, it's a one line change that just disables the patch in the
> quilt series file.

Please go ahead; thanks.

Regards,

Adam




-- 
To UNSUBSCRIBE, email to debian-release-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org
Archive: 
http://lists.debian.org/1327185545.6622.25.ca...@jacala.jungle.funky-badger.org

Reply via email to