The relevant binary package needs to actually exist in the release in order for it to be of any concern. No naxsi binary packages were being produced prior to Precise and this bug is therefore Invalid in them. I'll leave the remaining bug as assigned to determine if the CVE is pertanent to Precise and Quantal.
-- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1025463 Title: 2012, July 16 - Security Advisory - CVE-2012-3380 To manage notifications about this bug go to: https://bugs.launchpad.net/nginx/+bug/1025463/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs