[Bug 612202] [NEW] Please sync squirrelmail 2:1.4.21-1 (universe) from Debian unstable (main).

Bhavani Shankar right2bhavi at gmail.com
Sun Aug 1 06:09:08 UTC 2010


Public bug reported:

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

 affects ubuntu/squirrelmail
 status new
 importance wishlist
 subscribe ubuntu-sponsors

Please sync squirrelmail 2:1.4.21-1 (universe) from Debian unstable
(main).


Explanation of the Ubuntu delta and why it can be dropped:

We can sync the package as it fixes 2 CVE's hence the ubuntu delta can 
be dropped

Changelog since current maverick version 2:1.4.20-1ubuntu1:

squirrelmail (2:1.4.21-1) unstable; urgency=medium

  * New upstream release.
    + Addresses two low-imact security issues, bump urgency.
      [CVE-2010-1637, CVE-2010-2813]
  * Checked for policy 3.9.1, no changes necessary.

 -- Thijs Kinkhorst <thijs at debian.org>  Sat, 31 Jul 2010 13:54:45 +0200


-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFMVRDhUlfC4uPMy3QRAvQbAKCs9ag4uKoWg6wtRuxQ9rjEWoCxzwCgj/70
m+cGdjjbSWiAA0MIGeOlwuo=
=H5/h
-----END PGP SIGNATURE-----

** Affects: squirrelmail (Ubuntu)
     Importance: Wishlist
         Status: New

-- 
Please sync squirrelmail 2:1.4.21-1 (universe) from Debian unstable (main).
https://bugs.launchpad.net/bugs/612202
You received this bug notification because you are a member of Ubuntu
Sponsors Team, which is a direct subscriber.

Status in “squirrelmail” package in Ubuntu: New

Bug description:
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

 affects ubuntu/squirrelmail
 status new
 importance wishlist
 subscribe ubuntu-sponsors

Please sync squirrelmail 2:1.4.21-1 (universe) from Debian unstable (main).


Explanation of the Ubuntu delta and why it can be dropped:

We can sync the package as it fixes 2 CVE's hence the ubuntu delta can 
be dropped

Changelog since current maverick version 2:1.4.20-1ubuntu1:

squirrelmail (2:1.4.21-1) unstable; urgency=medium

  * New upstream release.
    + Addresses two low-imact security issues, bump urgency.
      [CVE-2010-1637, CVE-2010-2813]
  * Checked for policy 3.9.1, no changes necessary.

 -- Thijs Kinkhorst <thijs at debian.org>  Sat, 31 Jul 2010 13:54:45 +0200


-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFMVRDhUlfC4uPMy3QRAvQbAKCs9ag4uKoWg6wtRuxQ9rjEWoCxzwCgj/70
m+cGdjjbSWiAA0MIGeOlwuo=
=H5/h
-----END PGP SIGNATURE-----






More information about the Ubuntu-sponsors mailing list