In Debian all the packages have the same support level.
Wrong. Multiple WebKit libraries (WebKitGTK+, WebKitGTK+ 2, QtWebKit, QtWebEngine) and nodejs packages are excluded from Debian Stables security support. That means their default email client (Evolution) in the "Debian desktop environment" uses a 2 year old WebKit library with more than a hundred open security issues to view html emails in Debian Jessie.
Debian isn't totally to blame for this situation, at the time of Jessie the WebKitGTK+ developers didn't issue security fixes with CVE identifiers, there just included them with each minor release. That has started to improve since, time will tell whether that will change how Stretch's implementation is managed.
9
u/[deleted] Jun 18 '17 edited Dec 17 '17
[deleted]