Re: Vulnerabilities rated medium or low risk may not be fixed by Debian security team, is that correct?

2016-10-13 Thread Michael Stone
On Thu, Oct 13, 2016 at 02:45:29PM -, te3...@sigaint.org wrote: As you asked me for a specific case, may I bring up CVE-2016-5696. A fix to the medium-risk vulnerability was uploaded on July 10, 2016 by Eric Dumazet (cf. https://github.com/torvalds/linux/commit/75ff39ccc1bd5d3c455b6822ab09e5

Re: Vulnerabilities rated medium or low risk may not be fixed by Debian security team, is that correct?

2016-10-13 Thread te3d4q
> Of course, every distribution makes their own assessment. After > all each distro might ship an affected codebase in different > versions/configs/environments. > > Cheers, > Moritz > Hi Moritz I appreciate the time and effort that you spent on clarifying my questions. Thank you.

Re: Vulnerabilities rated medium or low risk may not be fixed by Debian security team, is that correct?

2016-10-13 Thread te3d4q
> > To have an example, you'd need specifics. This is a hypothetical without > a question. If the implicit question is "could this happen" the answer > is yes, but you'd need to discuss a specific case to find out why. > > Mike Stone As you asked me for a specific case, may I bring up CVE-2016-569