Bug#873795: calibre: Security risk and possible backdoor when fetching news

2020-08-04 Thread Norbert Preining
Hi all, On Tue, 04 Aug 2020, Nicholas D Steeves wrote: > options 3) Convince upstream to update in a more secure way. Given > that they consider our package "buggy/outdated" and advocate a "wget > -nv -O- https://foo.com/please-root-me.sh | sudo sh /dev/stdin" > installation method I'm not sure

Bug#873795: calibre: Security risk and possible backdoor when fetching news

2020-08-04 Thread Nicholas D Steeves
Control: noowner -1 Justification: lack of free time Hi, On Thu, Oct 03, 2019 at 11:52:18PM -0400, Dev Null wrote: > On Sat, 21 Sep 2019 14:06:28 -0400 Nicholas D Steeves > wrote: [snip] > > On Thu, Aug 31, 2017 at 10:07:25AM +0200, Jens Schmidt wrote: > > > Package: calibre > > > Version:

Bug#873795: calibre: Security risk and possible backdoor when fetching news

2019-10-03 Thread Dev Null
On Sat, 21 Sep 2019 14:06:28 -0400 Nicholas D Steeves wrote: > Control: tags = confirmed > Control: severity = important > > On Thu, Aug 31, 2017 at 10:07:25AM +0200, Jens Schmidt wrote: > > Package: calibre > > Version: 3.4.0+dfsg-1 > > Severity: normal > > > > Dear Maintainer, > > > > I'm using

Bug#873795: calibre: Security risk and possible backdoor when fetching news

2019-09-21 Thread Nicholas D Steeves
Control: tags = confirmed Control: severity = important On Thu, Aug 31, 2017 at 10:07:25AM +0200, Jens Schmidt wrote: > Package: calibre > Version: 3.4.0+dfsg-1 > Severity: normal > > Dear Maintainer, > > I'm using cron and /usr/bin/ebook-convert to fetch RSS news daily. Some > generated ebooks

Bug#873795: calibre: Security risk and possible backdoor when fetching news

2017-08-31 Thread Jens Schmidt
Package: calibre Version: 3.4.0+dfsg-1 Severity: normal Dear Maintainer, I'm using cron and /usr/bin/ebook-convert to fetch RSS news daily. Some generated ebooks are containing typos. The mistakes are located in a so-called "news fetching recipe" in Zip archive