Bug#950372: Is radare2 suitable for stable Debian releases?

2020-02-04 Thread Moritz Mühlenhoff
On Sat, Feb 01, 2020 at 08:51:08PM +0100, Salvatore Bonaccorso wrote: > Hi Hilko, > > On Sat, Feb 01, 2020 at 12:57:27AM +0100, Hilko Bengen wrote: > > * Moritz Mühlenhoff: > > > > >> FTR, this was as well raised back in [1]. AFAIK there was no direct > > >> feedback to the question from Moritz b

Bug#950372: Is radare2 suitable for stable Debian releases?

2020-02-01 Thread Salvatore Bonaccorso
Hi Hilko, On Sat, Feb 01, 2020 at 12:57:27AM +0100, Hilko Bengen wrote: > * Moritz Mühlenhoff: > > >> FTR, this was as well raised back in [1]. AFAIK there was no direct > >> feedback to the question from Moritz back then. > > > > Yeah, we should at least remove radare2 from oldstable (IIRC for >

Bug#950372: Is radare2 suitable for stable Debian releases?

2020-01-31 Thread Hilko Bengen
* Moritz Mühlenhoff: >> FTR, this was as well raised back in [1]. AFAIK there was no direct >> feedback to the question from Moritz back then. > > Yeah, we should at least remove radare2 from oldstable (IIRC for > buster there's an rdep which prevents that) That reverse dependency is radare2-cutt

Bug#950372: Is radare2 suitable for stable Debian releases?

2020-01-31 Thread Moritz Mühlenhoff
On Fri, Jan 31, 2020 at 10:10:38PM +0100, Salvatore Bonaccorso wrote: > Hi, > > On Fri, Jan 31, 2020 at 10:59:05PM +0200, Adrian Bunk wrote: > > Source: radare2 > > Severity: grave > > Tags: security > > > > It is understandable (and normal for most software) that upstream > > is not able or will

Bug#950372: Is radare2 suitable for stable Debian releases?

2020-01-31 Thread Salvatore Bonaccorso
Hi, On Fri, Jan 31, 2020 at 10:59:05PM +0200, Adrian Bunk wrote: > Source: radare2 > Severity: grave > Tags: security > > It is understandable (and normal for most software) that upstream > is not able or willing to provide security support for the old > version shipped in stable distribution rel

Bug#950372: Is radare2 suitable for stable Debian releases?

2020-01-31 Thread Adrian Bunk
Source: radare2 Severity: grave Tags: security It is understandable (and normal for most software) that upstream is not able or willing to provide security support for the old version shipped in stable distribution releases. But below seems to be upstream actively encouraging exploiting the versi