Bash vulnerability CVE-2014-6271 is reported as fixed in version 4.3-11 on Debian Jessie. On a Debian Jessie server, I executed the command bash --version and it said the version is 4.3.30. Is this server vulnerable to the CVE-2014-6271? Which release came first, 4.3.30 or 4.3-11? How do I tell?
Specifically, I don't understand the release naming convention and the significance of "-" vs ".".