libasound vulnerability

2005-02-24 Thread Geoff Crompton
http://www.securityfocus.com/bid/12575 Libasound 1.0.6 has a vulnerability. The sarge and sid versions are newer, and the woody version is much older. Anyone know if woody is affected? -- Geoff Crompton Debian System Administrator Strategic Data +61 3 9340 9000 -- To UNSUBSCRIBE, email to [EMA

2.6 kernel vulnerabilities

2005-02-24 Thread Geoff Crompton
Are the kernel team aware of http://www.securityfocus.com/bid/12555, a bunch of vulnerablities in 2.6 kernels prior to 2.6.11-rc2. Or more generally, are these being tracked? And if so, by whom, and I should I keep asking them specifically rather than posting to debian-security? -- Geoff Crompt

Re: using sarge on production machines

2005-02-24 Thread Joey Hess
Stefan Fritsch wrote: > Updates that fix security issues usually have urgency=high and change > faster to testing. However, you cannot trust this since new release > critical bugs might still keep the new package from entering testing. New release critical bugs need not keep a security update fr