Re: [horde-vendor] [SECURITY] Kronolith H5 (4.2.4) (final)

Mathieu Parent <[email protected]>
Newsgroups gmane.comp.horde.devel
Message-ID <CAFX5sby1hFAc6F4_XK1GL5nUXV_pifvaWqKu+RpS1QPJX3-eGg@mail.gmail.com>
2014-12-03 17:24 GMT+01:00 Jan Schneider <[email protected]>:
> The Horde Team is pleased to announce the final release of the Kronolith
> Calendar Application version H5 (4.2.4).
[...]
> The major changes compared to Kronolith version H5 (4.2.3) are:
>     * Fixed disclosure of private events in daily agenda.

It seems that this change triggered the [SECURITY] tag in the subject.

Couldn't all those security fixes (at least on the stable branches)
have a CVE id assigned?

It seems easy to do [1], and will help downstream projects (i.e
distros) to follow.

[1]: http://cve.mitre.org/cve/request_id.html

Regards

-- 
Mathieu Parent
-- 
dev mailing list
Frequently Asked Questions: http://wiki.horde.org/FAQ
To unsubscribe, mail: [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.