Comment 2 for bug 992618

Revision history for this message
Julian Taylor (jtaylor) wrote :

thanks for the thorough review.

> * New package versions are wrong. For example, the Oneiric version should be
> '0.14.1-1ubuntu2'. Please see the version examples at:
> https://wiki.ubuntu.com/SecurityTeam/UpdatePreparation#Update_the_packaging

they provide an upgrade path, they are just a bit longer than minimal. Does this matter?
also according to the wiki it shouldn't it be 0.14.1-1ubuntu1.1

> * The backported CVE-2012-2085.patch is in all three releases is missing
> gajim.thread_interface(p.wait) call in else block of exec_command()

> * The natty and lucid debdiffs seem to have a missing "jid_tuple = (jid_id,)"
> in the else block of CVE-2012-2086.patch in chunk @ 654.

fixed the issues and forwarded them to debian where they also exist.