Re: [Bug 227464] Re: Please roll out security fixes from PHP 5.2.6

2008-07-10 Thread Kees Cook
Sorry for the delays in getting this update published. The Ubuntu Security Team has been very busy lately. As an explaination, most of the vulnerabilities are hard to exploit, so this has been lower on the list of things to do. All that said, now that Bind and the latest cycles of kernel updates

Re: [Bug 227464] Re: Please roll out security fixes from PHP 5.2.6

2008-07-10 Thread Andrew Cholakian
Well this sounds like it meets the first criteria: "Bugs which may, under realistic circumstances, directly cause a *security vulnerability*. These are done by the security team and are documented at SecurityUpdateProcedures ." So what stage is

Re: [Bug 227464] Re: Please roll out security fixes from PHP 5.2.6

2008-07-10 Thread Dustin Kirkland
On Thu, Jul 10, 2008 at 10:14 AM, Andrew Cholakian <[EMAIL PROTECTED]> wrote: > Agreed spinkham, debian got the release out fast, what's going on here? The Stable Release Update process for an Long Term Support release such as Hardy involves a bit a work and justification on our end in order to ro