yes Debian wheezy is vulnerable, a proposed-update is queued
parent
fde1b02ba8
commit
8ad932efd5
|
@ -41,3 +41,13 @@ raghav007bisht@gmail.com
|
|||
|
||||
> Are versions `3.20120629` or `3.20130904.1~bpo70+1` vulnerable? (`wheezy` and
|
||||
> `wheezy-backports`, respectively) — [[Jon]]
|
||||
|
||||
>> 3.20120629 is vulnerable; fixed in 3.20120629.2, which is in the proposed-updates
|
||||
>> queue (the security team declined to issue a DSA). The blogspam plugin doesn't
|
||||
>> work in wheezy either; again, a fix is in the proposed-updates queue.
|
||||
>>
|
||||
>> 3.20130904.1~bpo70+1 is almost certainly vulnerable, it looks as though someone
|
||||
>> has done a drive-by backport but not kept it updated. None of ikiwiki's Debian
|
||||
>> maintainers are involved in that backport; the .deb from jessie (or even from
|
||||
>> experimental) works fine on wheezy without recompilation. I use the latest
|
||||
>> upstream release from experimental on my otherwise-Debian-7 server. --[[smcv]]
|
||||
|
|
Loading…
Reference in New Issue