Bug#859122: 31 DLAs missing from the website

Brian May <[email protected]>
Newsgroups gmane.linux.debian.devel.www
Organization Debian
Message-ID <87blwq51g8.fsf__41755.9584647947$1576325862$gmane$org@silverfish.pri>
Holger Levsen <[email protected]> writes:

> ERROR: .data or .wml file missing for DLA 145-2

Hmm. Looks like that really should exist, and point to next version
5.3.3-7+squeeze25

(DLA-145-1 points to 5.3.3-7+squeeze24)


Here is the relevant information I can find:


commit f225a141ff91e4790ef74f00893cf29c2521eff6
Author: Thorsten Alteholz <[email protected]>
Date:   Mon Feb 2 16:30:14 2015 +0000

    DLA-145-1 php5 regression update
    
    git-svn-id: svn+ssh://svn.debian.org/svn/secure-testing@31913 e39458fd-73e7-0310-bf30-c45bca0a0e42

diff --git a/data/DLA/list b/data/DLA/list
index efe2117968..abf5a895cd 100644
--- a/data/DLA/list
+++ b/data/DLA/list
@@ -1,3 +1,5 @@
+[02 Feb 2015] DLA-145-2 php5 - regression update
+       [squeeze] - php5 5.3.3-7+squeeze25
 [31 Jan 2015] DLA-145-1 php5 - security update
        {CVE-2014-0237 CVE-2014-0238 CVE-2014-2270 CVE-2014-8117}
        [squeeze] - php5 5.3.3-7+squeeze24



php5 (5.3.3-7+squeeze25) squeeze-lts; urgency=high

  * Non-maintainer upload by the Squeeze LTS Team.
  * as the patch for PHP bug 68739 seems to break cURL cookie handling
    it is removed again in this version, CVE-2015-TEMP-1.patch is affected
    (bug report can be found in: 
     https://lists.debian.org/debian-lts/2015/02/msg00007.html)

 -- Thorsten Alteholz <[email protected]>  Mon, 02 Feb 2015 14:17:00 +0100


* https://bugs.php.net/bug.php?id=68739: upstream bug.

* https://lists.debian.org/debian-lts/2015/02/msg00007.html contains
technical information on the regression.


So it looks like the fix was reverted, which means in turn means that
CVE-2015-TEMP-1 was not fixed despite DLA 145-1 declaring otherwise,
however no point worrying about that now.... :-)


Where to from here? Should I invent an appropriate DLA-145-2 based on
the information above?
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.