It's too late to get these into 1.2.1, but these recipes will need to get upgraded for 1.2.2: openssl: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2333 libpng: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3048 xinetd: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0862 libxml2: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-1025
Please file 4 separate bugs since each pacakge is owned by different people
I've now filed separate bugs for these, so I'm closing this one. openssl - bug #2701 xinetd - bug #2702 libxml2 - bug #2703 I was mistaken about libpng, the version we ship is actually safe.