summaryrefslogtreecommitdiffstats
path: root/doc/narrative_introduction
diff options
context:
space:
mode:
authorLuciano Bello <luciano@debian.org>2014-01-26 15:56:14 +0000
committerLuciano Bello <luciano@debian.org>2014-01-26 15:56:14 +0000
commit9475078b62ee29036143bace51ae502f2c25b2fd (patch)
treee34f7ae2784366284326de302c9c8b22c8a05992 /doc/narrative_introduction
parente1f43495d65e1d7478f75c76cc400010e27d5bd3 (diff)
On TODO: check
git-svn-id: svn+ssh://svn.debian.org/svn/secure-testing@25370 e39458fd-73e7-0310-bf30-c45bca0a0e42
Diffstat (limited to 'doc/narrative_introduction')
-rw-r--r--doc/narrative_introduction9
1 files changed, 9 insertions, 0 deletions
diff --git a/doc/narrative_introduction b/doc/narrative_introduction
index 248885582f..0f84e4742f 100644
--- a/doc/narrative_introduction
+++ b/doc/narrative_introduction
@@ -391,6 +391,15 @@ CVE-2005-3990 (Directory traversal vulnerability in FastJar 0.93
allows remote ...)
TODO: check, whether fastjar from the gcc source packages is affected
+If you are not sure about some decision (e.g. which package is affected) or
+classification (e.g. bug severity) you can leave a TODO note for reviewing,
+explaining which aspect have to be reviewed. For example:
+
+CVE-2013-7295 (Tor before 0.2.4.20, when OpenSSL 1.x is used in ...)
+ - tor 0.2.4.20-1 (low)
+ [wheezy] - tor <no-dsa> (Minor issue)
+ TODO: review, severity. The exploitation scenario is too complicated.
+
It is also useful to add information to issues as you find it, so that
when others go to look at an issue and want to know why you marked it
as you did, or need a reference, it will be there. The more

© 2014-2024 Faster IT GmbH | imprint | privacy policy