Re: [horde-vendor] [SECURITY] Kronolith H5 (4.2.4) (final)
Mathieu Parent <[email protected]>
| Newsgroups | gmane.comp.horde.devel |
|---|---|
| Message-ID | <CAFX5sby1hFAc6F4_XK1GL5nUXV_pifvaWqKu+RpS1QPJX3-eGg@mail.gmail.com> |
2014-12-03 17:24 GMT+01:00 Jan Schneider <[email protected]>: > The Horde Team is pleased to announce the final release of the Kronolith > Calendar Application version H5 (4.2.4). [...] > The major changes compared to Kronolith version H5 (4.2.3) are: > * Fixed disclosure of private events in daily agenda. It seems that this change triggered the [SECURITY] tag in the subject. Couldn't all those security fixes (at least on the stable branches) have a CVE id assigned? It seems easy to do [1], and will help downstream projects (i.e distros) to follow. [1]: http://cve.mitre.org/cve/request_id.html Regards -- Mathieu Parent -- dev mailing list Frequently Asked Questions: http://wiki.horde.org/FAQ To unsubscribe, mail: [email protected]