Re: Please ensure an RC bug is open when DSA fixes are missing in testing/unstable

2012-07-26 Thread Michael Gilbert
On Thu, Jul 26, 2012 at 5:54 PM, Adrian Bunk wrote: > Many DSA's contain "For the unstable (sid) and testing (wheezy) > distribution, this problem will be fixed soon." > > When there is an unfixed version in testing and/or unstable, please > ensure an RC bug is open. Otherwise there is the possibil

Please ensure an RC bug is open when DSA fixes are missing in testing/unstable

2012-07-26 Thread Adrian Bunk
Many DSA's contain "For the unstable (sid) and testing (wheezy) distribution, this problem will be fixed soon." When there is an unfixed version in testing and/or unstable, please ensure an RC bug is open. Otherwise there is the possibility that a new Debian release might ship with vulnerabiliti

CVE-2012-1033 (bind9)

2012-07-26 Thread Mike Ashton
Hello folks, If we look here: http://security-tracker.debian.org/tracker/CVE-2012-1033 it appears as though this CVE has been written off as a DNS protocol flaw, I believe based on the original ISC announcement here: https://www.isc.org/software/bind/advisories/cve-2012-1033 (first sentence und