Comment 7 for bug 19942

Revision history for this message
Debian Bug Importer (debzilla) wrote :

Message-Id: <email address hidden>
Date: Sun, 25 Sep 2005 23:22:11 +0100
From: Edd Dumbill <email address hidden>
To: William Ballard <email address hidden>
Cc: <email address hidden>, <email address hidden>
Subject: Re: bluez-utils 2.19-1 not in Sarge security updates?

On Sun, 2005-09-25 at 18:06 -0400, William Ballard wrote:
> http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=323365
>
> Why is this grave security bugfix not in Sarge security updates, more
> than a month later? I know there's a "good reason," but in my few years
> of using Debian I have always run unstable.

It is, version 2.15-1.1, you just missed it.

We don't upload new upstream versions to stable to fix security holes.
Where we can we just backport the fix. This is so as not to cause
knock-on problems introduced in new versions.

In the case of bluez-utils, this is exactly what was done -- see
http://packages.debian.org/stable/admin/bluez-utils
http://packages.debian.org/changelogs/pool/main/b/bluez-utils/bluez-utils_2.15-1.1/changelog

I would not have closed the bug if the fix hadn't gone in.

-- Edd