Additional Security issues

Daniel Atallah daniel.atallah at gmail.com
Tue Feb 5 19:31:35 EST 2013


On Tue, Feb 5, 2013 at 6:26 PM, Mark Doliner <mark at kingant.net> wrote:
> On Tue, Feb 5, 2013 at 2:51 PM, Daniel Atallah <daniel.atallah at gmail.com> wrote:
>> Is the urgency related to the CA cert?
>
> Partially.  Other reasons:
> - I want to avoid delaying the MXit fixes much more
> - It's harder for me logistically to manage releases with large
> numbers of security problems (apply more patches, request CVEs for
> more things, email descriptions and patches to publishers, type up
> descriptions for http://www.pidgin.im/news/security/)
>
> But I guess if we have patches for these issues and we think they're
> safe then we should go ahead and release them.

I'm certainly not trying to make more work.

If we can coordinate the timing, I should be able to help with a
number of these tasks.

I'm also not strongly opposed to several releases if that makes life easier.

-D


More information about the security mailing list