Re: CVE-2014-3596 insecure certificate validation

2014-10-02 Thread Markus Koschany
On 02.10.2014 13:26, Moritz Muehlenhoff wrote: [...] > Thanks for getting in touch with us! Please fix this through a point update. Hi, I have just filed https://bugs.debian.org/763815 and now I am waiting for a response from the release team. Cheers, Markus signature.asc Description: OpenPG

Re: CVE-2014-3596 insecure certificate validation

2014-10-02 Thread Moritz Muehlenhoff
On Thu, Oct 02, 2014 at 12:34:12PM +0200, Markus Koschany wrote: > On 02.10.2014 08:39, Salvatore Bonaccorso wrote: > > Hi Markus > > > > As mentioned in [1,2] we do not use anymore the RT queues (a change from > > DSA to disable them completely is pending). > > > > [1] https://wiki.debian.org/r

Re: CVE-2014-3596 insecure certificate validation

2014-10-02 Thread Markus Koschany
On 02.10.2014 08:39, Salvatore Bonaccorso wrote: > Hi Markus > > As mentioned in [1,2] we do not use anymore the RT queues (a change from > DSA to disable them completely is pending). > > [1] https://wiki.debian.org/rt.debian.org#Security_Team > [2] https://lists.debian.org/debian-devel-announc