MSN SLP Security Vulnerability

Daniel Atallah daniel.atallah at gmail.com
Wed Jun 18 14:29:37 EDT 2008


On Wed, Jun 18, 2008 at 7:55 AM, Stu Tomlinson <stu at nosnilmot.com> wrote:
> I don't know the details of the vulnerability or the proposed fix, but I
> suggest we release 2.4.3 as a security-fix only release (possibly also
> with those XML memory leaky things fixed too), branched from 2.4.2
> instead of releasing whatever happens to be in i.p.p currently.

I'm fine with this, but I'd like to backport a couple crashing fixes
from i.p.p (yahoo aliases, and something else I can't remember
offhand).

-D



More information about the Packagers mailing list