Bug#949711: Build-depends on sgmltools-lite, which is being removed

2020-01-23 Thread Moritz Muehlenhoff
Source: aboot Severity: serious sgmltools-lite is scheduled for removal and aboot is the last package build depending on it. There hasn't been any aboot upload since 2013 and it's RC-buggy for a long time, should we simply remove it? Cheers, Moritz

Bug#942146: koji: CVE-2019-17109

2020-01-23 Thread Moritz Muehlenhoff
On Thu, Jan 23, 2020 at 04:37:15PM +, Holger Levsen wrote: > Hi Salvatore, > > On Sun, Jan 05, 2020 at 09:02:20PM +0100, Salvatore Bonaccorso wrote: > > Any news on this issue? AFAICT, the issue is fixed as well in 1.16.3, > > so the smaller jump should be possible. Once fixed in unstable, can

Bug#946921: Project abandoned

2019-12-17 Thread Moritz Muehlenhoff
Source: rust-spin Severity: serious https://rustsec.org/advisories/RUSTSEC-2019-0031.html was issued to flag that rust-spin development stop. I suppose that means it should not enter bullseye / get removed. Cheers, Moritz

Bug#885505: bumping severity of pygtk bugs

2019-12-11 Thread Moritz Muehlenhoff
On Wed, Dec 11, 2019 at 09:52:15AM +0100, Thibaut Paumard wrote: > Le 10/12/2019 à 19:59, Moritz Mühlenhoff a écrit : > > On Mon, Oct 07, 2019 at 04:51:09PM +0200, Thibaut Paumard wrote: > >> Dear Jeremy, > >> > >> Thanks, I have warned upstream that spydr will be removed if not updated > >> to Pyt

Bug#946183: Should fusionforge be removed?

2019-12-04 Thread Moritz Muehlenhoff
Source: fusionforge Severity: serious There hasn't been an upload since two years and fusionforge missed the last two stable releases and has gathered five RC bugs at this point. Should it be removed? Cheers, Moritz

Bug#944628: Drop build dep on monotone

2019-11-12 Thread Moritz Muehlenhoff
Package: bugs-everywhere Severity: serious Hi Antoine, monotone is getting removed from Debian, can you please drop the build dep on monotone in bugs-everywhere? (It seems unused anyway, as test_usage.sh doesn't cover it). Cheers, Moritz

Bug#943985: Depends on volti, which is scheduled for removal

2019-11-01 Thread Moritz Muehlenhoff
Package: parl-desktop Severity: serious volti is scheduled for removal from the archive, the dependency needs to be removed.

Bug#943976: Should smart be removed?

2019-11-01 Thread Moritz Muehlenhoff
Source: smart Severity: serious Should smart be removed? It depends on Python 2 and pygtk, which are going away, and it's dead upstream (last release from 2011). Cheers, Moritz

Bug#943930: Should cvc3 be removed?

2019-10-31 Thread Moritz Muehlenhoff
Source: cvc3 Severity: serious Should cvc3 be removed? It's unmaintained (last maintainer upload is from 2014 and the maintainer is also one of the authors) and FTBFSes since 1.5 years. Cheers, Moritz

Bug#943899: Should ndisgtk be removed?

2019-10-31 Thread Moritz Muehlenhoff
Package: ndisgtk Severity: serious Should ndisgtk be removed? It's dead upstream (no release for 10 years) and depends on outdated stacks scheduled for removal (python 2, pygtk). Cheers, Moritz

Bug#942851: perl-modules-5.30: CPAN.pm is insecure by default, no warnings

2019-10-23 Thread Moritz Muehlenhoff
On Wed, Oct 23, 2019 at 10:20:04PM +0300, Niko Tyni wrote: > Control: reassign -1 src:perl > Control: found -1 5.20.2-3 > > On Tue, Oct 22, 2019 at 12:36:14PM +0200, Vincent Lefevre wrote: > > Package: perl-modules-5.30 > > Version: 5.30.0-8 > > Severity: grave > > Tags: security > > Justification

Bug#942895: CVE-2019-18224

2019-10-22 Thread Moritz Muehlenhoff
Source: libidn2 Severity: grave Tags: security This was assigned CVE-2019-18224: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=12420 Patch: https://github.com/libidn/libidn2/commit/e4d1558aa2c1c04a05066ee8600f37603890ba8c Cheers, Moritz

Bug#942830: CVE-2019-18218

2019-10-22 Thread Moritz Muehlenhoff
Package: file Severity: grave Tags: security This was assigned CVE-2019-18218: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=16780 https://github.com/file/file/commit/46a8443f76cec4b41ec736eca396984c74664f84 Cheers, Moritz

Bug#942831: CVE-2019-18217

2019-10-22 Thread Moritz Muehlenhoff
Source: proftpd-dfsg Severity: grave Tags: security This was assigned CVE-2019-18217: https://github.com/proftpd/proftpd/commit/13fe9462787b9a551152162f46f1641d65fe4df4 https://github.com/proftpd/proftpd/issues/846 Cheers, Moritz

Bug#942315: tcpdump: Version in oldoldstable is higher than oldstable and stable

2019-10-17 Thread Moritz Muehlenhoff
On Wed, Oct 16, 2019 at 11:59:07PM +0200, Romain Francoise wrote: > On Wed, Oct 16, 2019 at 9:48 PM Salvatore Bonaccorso > wrote: > > Ideally given the issues are denial of service issues, this would have > > been okay via a point release. But we discussed this coincidentally in > > the team conc

Bug#942270: task-spanish depends on removed manpages-es

2019-10-13 Thread Moritz Muehlenhoff
Source: tasksel Severity: grave task-spanish depends on manpages-es, which has been removed from the archive. Cheers, Moritz

Bug#942191: Depends on qt4

2019-10-11 Thread Moritz Muehlenhoff
Source: hachoir-metadata Severity: serious hachoir-metadata build-depends on python-qt4, which is being removed from the archive along with Qt4 soon. Cheers, Moritz

Bug#942165: CVE-2019-14857

2019-10-11 Thread Moritz Muehlenhoff
Package: libapache2-mod-auth-openidc Severity: grave Tags: security Please see: https://groups.google.com/forum/#!topic/mod_auth_openidc/boy1Ba3Gdk4 https://github.com/zmartzone/mod_auth_openidc/commit/5c15dfb08106c2451c2c44ce7ace6813c216ba75 https://github.com/zmartzone/mod_auth_openidc/commit/c

Bug#941527: Build-depends on Qt4

2019-10-01 Thread Moritz Muehlenhoff
Source: matplotlib Severity: serious matplotlib build-depends on python3-pyqt4 (build from src:python-qt4), which is being removed along with Qt4 itself now. Given that matplotlib only has a run-time Suggests: on python3-pyqt4, this is probably optional and simply be disabled. Cheers,

Bug#941376: Should monotone be removed?

2019-09-29 Thread Moritz Muehlenhoff
Source: monotone Severity: serious Should monotone be removed? Dead upstream, last upload three years ago and removed from testing since 1.5 years. Cheers, Moritz

Bug#875150: Should we file a removal bug?

2019-09-25 Thread Moritz Muehlenhoff
On Wed, Sep 25, 2019 at 07:57:47AM +0200, Andreas Tille wrote: > Hi, > > On Tue, Sep 24, 2019 at 10:48:24PM +0200, Moritz Mühlenhoff wrote: > > On Tue, Sep 17, 2019 at 12:05:17PM -0300, Lisandro Damián Nicanor Pérez > > Meyer wrote: > > > Hi! It seems there is no activity on this bug, should we f

Bug#875195: marked as pending in stretchplayer

2019-09-18 Thread Moritz Muehlenhoff
Control: tag -1 pending Hello, Bug #875195 in stretchplayer reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/multimedia-team/stretchplayer/commit/3e9e49170009755

Bug#875195: [stretchplayer] Future Qt4 removal from Buster

2019-09-18 Thread Moritz Muehlenhoff
On Wed, Sep 18, 2019 at 02:44:49PM -0300, Lisandro Damián Nicanor Pérez Meyer wrote: > Hi! > > El mié., 18 sep. 2019 13:18, Reiner Herrmann escribió: > > > Control: tags -1 + patch > > > > Dear maintainers, > > > > porting stretchplayer to Qt5 was straightforward. > > You can find a merge reque

Bug#851774: fixed in apt-setup 1:0.151

2019-09-09 Thread Moritz Muehlenhoff
On Fri, Aug 16, 2019 at 09:10:50AM +0200, Moritz Muehlenhoff wrote: > > Many thanks, I'll be submitting a buster-pu bug accordingly. I wouldn't > > mind an extra confirmation after it's been published in a point release > > (peace of mind and all that). > &

Bug#899241: marked as pending in mustang-plug

2019-09-04 Thread Moritz Muehlenhoff
Control: tag -1 pending Hello, Bug #899241 in mustang-plug reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/multimedia-team/mustang-plug/commit/986103d6b54147b87

Bug#874862: cppreference-doc: diff for NMU version 20170409-1.1

2019-09-02 Thread Moritz Muehlenhoff
On Mon, Sep 02, 2019 at 11:14:38PM +0300, Povilas Kanapickas wrote: > Thanks a lot! > > I was waiting for my usual sponsors to sponsor a new version of > cppreference-doc [1] that contains this fix too, but they haven't > replied yet. Ah, sorry. I wasn't aware of the package on mentors.debian.net

Bug#936025: CVE-2019-15553

2019-08-29 Thread Moritz Muehlenhoff
Source: rust-memoffset Severity: grave Tags: security Please see https://rustsec.org/advisories/RUSTSEC-2019-0011.html Cheers, Moritz

Bug#935736: Drop dependency on automoc

2019-08-25 Thread Moritz Muehlenhoff
Package: kde-sc-dev-latest Severity: serious All reverse dependencies of automoc have been dropped, but kde-sc-dev-latest still depends on it, blocking it's removal. Cheers, Moritz

Bug#935333: Should hgview be removed?

2019-08-21 Thread Moritz Muehlenhoff
Source: hgview Severity: serious Should hgview be removed? - Last maintainer upload in 2015 - Current upstream releases still depend on Python Qt4, which is scheduled for removal - Dropped from testing since almost two years, three RC bugs at this point Cheers, Moritz

Bug#934935: Should docbook2odf be removed?

2019-08-16 Thread Moritz Muehlenhoff
Package: docbook2odf Severity: serious Should docbook2odf be removed? It's unmaintained (last maintainer upload in 2007), last upload in 2010 and has been dropped from testing for three years now. Cheers, Moritz

Bug#934887: CVE-2019-9512 CVE-2019-9514 CVE-2019-9515

2019-08-16 Thread Moritz Muehlenhoff
Source: trafficserver Severity: grave Tags: security ATS is affected by three of the recently announced HTTP2 issues: https://raw.githubusercontent.com/apache/trafficserver/8.0.x/CHANGELOG-8.0.4 Cheers, Moritz

Bug#934886: CVE-2019-9512 CVE-2019-9514 CVE-2019-9515

2019-08-16 Thread Moritz Muehlenhoff
Source: h2o Severity: grave Tags: security h2o is affected by three of the recently announced HTTP2 issues: https://github.com/h2o/h2o/issues/2090 Cheers, Moritz

Bug#934885: August 2019 security release

2019-08-16 Thread Moritz Muehlenhoff
Package: nodejs Severity: grave Tags: security nodejs is affected by some of the recently announced HTTP2 issues: https://nodejs.org/en/blog/vulnerability/aug-2019-security-releases/ https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-002.md Cheers, Mori

Bug#851774: fixed in apt-setup 1:0.151

2019-08-16 Thread Moritz Muehlenhoff
On Thu, Aug 15, 2019 at 04:25:53PM +0200, Cyril Brulebois wrote: > Hi, > > Moritz Muehlenhoff (2019-07-17): > > On Fri, Jul 12, 2019 at 09:07:45AM +, Cyril Brulebois wrote: > > > apt-setup (1:0.151) unstable; urgency=medium > > > . > > >[ Mori

Bug#934319: CVE-2019-10181 CVE-2019-10182 CVE-2019-10185

2019-08-09 Thread Moritz Muehlenhoff
Source: icedtea-web Severity: grave Tags: security Please see https://www.openwall.com/lists/oss-security/2019/07/31/2 Cheers, Moritz

Bug#934248: Should this package be removed?

2019-08-08 Thread Moritz Muehlenhoff
Package: manpages-es Severity: serious The last release of manpages-es was in 2005 and the last upload in 2011. As already pointed out in #860177, the translations are consequentially very outdated, I did some random sampling and e.g - For a basic command like mkdir(1) in Spanish only documents

Bug#934026: python-django: CVE-2019-14232 CVE-2019-14233 CVE-2019-14234 CVE-2019-14235

2019-08-08 Thread Moritz Muehlenhoff
On Thu, Aug 08, 2019 at 02:16:29PM +0100, Chris Lamb wrote: > Hi Moritz, > > > > > > Security team (added to CC), would you be interested in uploads for > > > > > buster (currently 1:1.11.22-1~deb10u1) and stretch (currently > > > > > 1:1.10.7-2+deb9u5)? > […] > > I just realised that there's a 1.

Bug#934026: python-django: CVE-2019-14232 CVE-2019-14233 CVE-2019-14234 CVE-2019-14235

2019-08-08 Thread Moritz Muehlenhoff
On Thu, Aug 08, 2019 at 11:02:48AM +0100, Chris Lamb wrote: > Hi Sébastien, > > > > Security team (added to CC), would you be interested in uploads for > > > buster (currently 1:1.11.22-1~deb10u1) and stretch (currently > > > 1:1.10.7-2+deb9u5)? > […] > > yes, thank you. Can you email us debdiffs

Bug#934026: python-django: CVE-2019-14232 CVE-2019-14233 CVE-2019-14234 CVE-2019-14235

2019-08-08 Thread Moritz Muehlenhoff
On Thu, Aug 08, 2019 at 11:22:37AM +0100, Chris Lamb wrote: > Moritz Muehlenhoff wrote: > > > > I mention it specifically as I'm not 100% confident this is correct > > > and Lintian somewhat-correctly complained about a "missing" version > > &

Bug#934026: python-django: CVE-2019-14232 CVE-2019-14233 CVE-2019-14234 CVE-2019-14235

2019-08-08 Thread Moritz Muehlenhoff
On Thu, Aug 08, 2019 at 11:02:48AM +0100, Chris Lamb wrote: > Hi Sébastien, > > > > Security team (added to CC), would you be interested in uploads for > > > buster (currently 1:1.11.22-1~deb10u1) and stretch (currently > > > 1:1.10.7-2+deb9u5)? > […] > > yes, thank you. Can you email us debdiffs

Bug#933883: Should zope2.13 be removed?

2019-08-04 Thread Moritz Muehlenhoff
Source: zope2.13 Severity: serious Should zope2.13 be removed? - Unmaintained (last upload in 2014) - FTBFS for a long time, missed two stable releases Cheers, Moritz

Bug#933882: Should percona-xtrabackup be removed?

2019-08-04 Thread Moritz Muehlenhoff
Source: percona-xtrabackup Severity: serious Should percona-xtrabackup be removed? - Unmaintained (last maintainer upload in 2014) - FTBFS with GCC 6 and later (#811896) and #917583 - Missed two stable releases because of that - Broken with current Mariadb (#903043) - Replacement exists (mariabac

Bug#933035: dmtcp: Should this package be removed?

2019-07-25 Thread Moritz Muehlenhoff
Source: dmtcp Severity: serious The last upload was in 2014 and it's RC-buggy for a long time, it missed two stable releases already. Cheers, Moritz

Bug#851774: fixed in apt-setup 1:0.151

2019-07-17 Thread Moritz Muehlenhoff
On Fri, Jul 12, 2019 at 09:07:45AM +, Cyril Brulebois wrote: > apt-setup (1:0.151) unstable; urgency=medium > . >[ Moritz Mühlenhoff ] >* When preseeding a local repository via apt-setup/localX/repository, > the repository key for Secure Apt needs to be configured with > apt

Bug#931932: CVE-2019-13574

2019-07-12 Thread Moritz Muehlenhoff
Package: ruby-mini-magick Severity: grave Tags: security Please see http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-13574 Cheers, Moritz

Bug#931625: redis: CVE-2019-10192 CVE-2019-10193

2019-07-10 Thread Moritz Muehlenhoff
On Wed, Jul 10, 2019 at 10:52:11AM -0300, Chris Lamb wrote: > [Adding t...@security.debian.org to CC] > > Hi, > > > redis: CVE-2019-10192 CVE-2019-10193 > > These has been fixed everywhere apart from stretch and buster. Would > you like uploads for these distributions? Yes, please, we should fi

Bug#908678: Update on the security-tracker git discussion

2019-07-02 Thread Moritz Muehlenhoff
On Tue, Jul 02, 2019 at 01:25:43PM +0200, Salvatore Bonaccorso wrote: > p.s.: Question is if we should do a split as well for the other types of > files which are supported (DSA, TDSA, ...) while at it. We can axe out DTSA/* while we're at it. For DSA/list (and DLA/list) we can initially ke

Bug#929781: rkt: CVE-2019-10144 CVE-2019-10145 CVE-2019-10147

2019-06-18 Thread Moritz Muehlenhoff
On Tue, Jun 18, 2019 at 05:35:55PM +1000, Dmitry Smirnov wrote: > I would reclassify those vulnerabilities with lesser severity to avoid > removal from Buster. That's certainly possible, but there's still the bigger issue that the projects seems unmaintained. None of the developers even acknowled

Bug#927159: libqb: CVE-2019-12779: Insecure Temporary Files

2019-06-17 Thread Moritz Muehlenhoff
On Mon, Jun 17, 2019 at 12:52:54AM +0200, wf...@niif.hu wrote: > Dear Security Team, > > I'm ready to upload libqb-1.0.1-1+deb9u1 with the following debdiff: > > diff -Nru libqb-1.0.1/debian/changelog libqb-1.0.1/debian/changelog > --- libqb-1.0.1/debian/changelog 2016-12-07 14:55:45.000

Bug#930356: CVE-2019-12760

2019-06-11 Thread Moritz Muehlenhoff
Source: parso Severity: grave Tags: security Please see https://bugzilla.redhat.com/show_bug.cgi?id=1718212 Patch is at https://gist.github.com/dhondta/f71ae7e5c4234f8edfd2f12503a5dcc7 Cheers, Moritz

Bug#929597: CVE-2019-12211 CVE-2019-12212 CVE-2019-12213 CVE-2019-12214

2019-05-26 Thread Moritz Muehlenhoff
Source: freeimage Severity: grave Tags: security Please see http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12211 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12212 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12213 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-

Bug#915128: Dont't include in buster

2019-05-21 Thread Moritz Muehlenhoff
On Tue, May 21, 2019 at 12:08:45PM -0400, Boyuan Yang wrote: > On Fri, 30 Nov 2018 19:51:20 +0100 Moritz Muehlenhoff wrote: > > Source: swftools > > Severity: serious > > > > swftools is orphaned for a year, dead upstream and has frequent security > > issues. A

Bug#921952: [Pkg-sass-devel] Bug#921952: Don't include in buster without proper commitment to update in stable

2019-05-21 Thread Moritz Muehlenhoff
On Tue, May 21, 2019 at 10:01:55AM +0200, Aljoscha Lautenbach wrote: > Hi, > > On Mon, 20 May 2019 at 23:11, Moritz Mühlenhoff wrote: > > What's considered needed is that someone should actually look through > > https://security-tracker.debian.org/tracker/source-package/libsass and > > triage/fix

Bug#929067: Support for MDS

2019-05-16 Thread Moritz Muehlenhoff
Package: qemu-system-x86 Severity: grave Tags: security These are not upstreamed due to the embargo period, but I'm attaching the 3.1 patches from Ubuntu 19.04. Cheers, Moritz >From a57fa50701c6a0fbe5ac7dbcc314c3c970bff899 Mon Sep 17 00:00:00 2001 From: Paolo Bonzini Date: Fri, 1 Mar 201

Bug#928210: CVE-2019-11471

2019-04-29 Thread Moritz Muehlenhoff
Source: libheif Severity: grave Tags: security This was assigned CVE-2019-11471: https://github.com/strukturag/libheif/issues/123 Patch: https://github.com/strukturag/libheif/commit/995a4283d8ed2d0d2c1ceb1a577b993df2f0e014 Cheers, Moritz

Bug#928053: CVE-2019-11387 CVE-2019-11388 CVE-2019-11389 CVE-2019-11390 CVE-2019-11391

2019-04-26 Thread Moritz Muehlenhoff
Package: modsecurity-crs Severity: grave Tags: security These are still being assessed upstream ATM: CVE-2019-11391 https://github.com/SpiderLabs/owasp-modsecurity-crs/issues/1357 CVE-2019-11390 https://github.com/SpiderLabs/owasp-modsecurity-crs/issues/1358 CVE-2019-11389 https://github.com/Sp

Bug#928052: CVE-2019-11502 CVE-2019-11503

2019-04-26 Thread Moritz Muehlenhoff
Source: snapd Severity: grave Tags: security http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11502 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11503 Cheers, Moritz

Bug#927906: CVE-2019-8354 CVE-2019-8355 CVE-2019-8356 CVE-2019-8357

2019-04-24 Thread Moritz Muehlenhoff
Source: sox Severity: grave Tags: security Please see these links for descriptions and patches: https://security-tracker.debian.org/tracker/CVE-2019-8354 https://security-tracker.debian.org/tracker/CVE-2019-8355 https://security-tracker.debian.org/tracker/CVE-2019-8356 https://security-tracker.deb

Bug#927714: CVE-2019-3885 CVE-2018-16877 CVE-2018-16878

2019-04-21 Thread Moritz Muehlenhoff
Source: pacemaker Severity: grave Tags: security Please see https://www.openwall.com/lists/oss-security/2019/04/17/1 Cheers, Moritz

Bug#927711: CVE-2019-10044

2019-04-21 Thread Moritz Muehlenhoff
Package: telegram-desktop Severity: grave Tags: security This was assigned CVE-2019-10044 and is claimed to be fixed in 1.5.12: https://github.com/blazeinfosec/advisories/blob/master/telegram-advisory.txt Cheers, Moritz

Bug#927674: CVE-2019-3902

2019-04-20 Thread Moritz Muehlenhoff
Source: mercurial Version: 4.8.2-1 Severity: grave Tags: security See https://www.mercurial-scm.org/wiki/WhatsNew from 4.9: This was assigned CVE-2019-3902: It was possible to use symlinks and subrepositories to defeat Mercurial's path-checking logic and write files outside a repository. This ha

Bug#927671: CVE-2016-10542

2019-04-20 Thread Moritz Muehlenhoff
Package: node-ws Severity: grave Tags: security Please see https://nodesecurity.io/advisories/120 https://github.com/nodejs/node/issues/7388 Cheers, Moritz

Bug#899128: kdepim: Limit CVE-2017-17689 (EFAIL) even more for kmail

2019-04-09 Thread Moritz Muehlenhoff
On Tue, Apr 09, 2019 at 06:49:16PM +0200, Ivo De Decker wrote: > Hi Salvatore, > > On 4/8/19 10:59 PM, Salvatore Bonaccorso wrote: > > Control: reassign -1 src:kdepim > > On Mon, Apr 08, 2019 at 11:36:10AM +0200, Ivo De Decker wrote: > > > Hi, > > > > > > On Sat, May 19, 2018 at 07:18:06PM +0200,

Bug#926670: CVE-2019-0542

2019-04-08 Thread Moritz Muehlenhoff
Source: node-xterm Severity: grave Tags: security Please see http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-0542 Cheers, Moritz

Bug#876905: qtwebkit should not be release with buster

2019-04-02 Thread Moritz Muehlenhoff
On Tue, Apr 02, 2019 at 06:28:39PM -0300, Lisandro Damián Nicanor Pérez Meyer wrote: > El martes, 2 de abril de 2019 17:48:26 -03 Moritz Mühlenhoff escribió: > [snip] > > > Truth is we can't even agree inside the team. Some of us think we should > > > just remove it alongside whatever hasn't been

Bug#926276: Should guacamole-client be removed?

2019-04-02 Thread Moritz Muehlenhoff
Source: guacamole-client Severity: serious Should guacamole-client be removed? guacamole-client hasn't been updated since 2016, is removed from testing since 1.5 years and has four RC bugs at this point Cheers, Moritz

Bug#926275: Depends on tomcat8

2019-04-02 Thread Moritz Muehlenhoff
Package: guacamole Severity: serious guacamole depends on tomcat8, which is to be removed (#925454). Cheers, Moritz

Bug#926043: CVE-2019-0816

2019-03-30 Thread Moritz Muehlenhoff
Package: cloud-init Severity: grave Tags: security This was assigned CVE-2019-0816: https://code.launchpad.net/~jasonzio/cloud-init/+git/cloud-init/+merge/363445 https://support.microsoft.com/en-us/help/4491476/extraneous-ssh-public-keys-added-to-authorized-keys-file-on-linux-vm Is this something

Bug#925987: CVE-2019-8320 CVE-2019-8321 CVE-2019-8322 CVE-2019-8323 CVE-2019-8324 CVE-2019-8325

2019-03-29 Thread Moritz Muehlenhoff
Package: jruby Severity: grave Tags: security jruby embeds a version of rubygems, so it's affected by https://www.ruby-lang.org/en/news/2019/03/05/multiple-vulnerabilities-in-rubygems Cheers, Moritz

Bug#925986: CVE-2018-1000073

2019-03-29 Thread Moritz Muehlenhoff
Package: jruby Severity: grave Tags: security CVE-2018-173 is not fixed in the rubygems bundled in jruby, https://www.ruby-lang.org/en/news/2018/02/17/multiple-vulnerabilities-in-rubygems/ https://github.com/rubygems/rubygems/commit/1b931fc03b819b9a0214be3eaca844ef534175e2 The other 2018 ruby

Bug#923347: No sensible security support due to Oracle's policies

2019-03-29 Thread Moritz Muehlenhoff
On Thu, Mar 28, 2019 at 07:29:07PM -0400, Sandro Tosi wrote: > Hello Moritz, > could you please reply to the points made below? thanks! Sorry, missed your reply. > > what kind of security support do Debian provide to the mysql server > > packages? None at all, they're only in unstable for that

Bug#925259: Should this package be removed?

2019-03-21 Thread Moritz Muehlenhoff
Source: jquery-jplayer Severity: serious Should jquery-jplayer be removed? It's the last package blocking the removal of swftools, it hasn't seen a maintainer upload since 2014 and is thus outdated compared to current upstream and there are no reverse dep in the archive (aside from some theme pack

Bug#924616: CVE-2018-15587

2019-03-14 Thread Moritz Muehlenhoff
Source: evolution Severity: grave Tags: security https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-15587: https://bugzilla.gnome.org/show_bug.cgi?id=796424 https://gitlab.gnome.org/GNOME/evolution/commit/9c55a311325f5905d8b8403b96607e46cf343f21 https://gitlab.gnome.org/GNOME/evolution/commi

Bug#924615: CVE-2018-12178 CVE-2018-12180 CVE-2018-12181

2019-03-14 Thread Moritz Muehlenhoff
Source: edk2 Severity: grave Tags: security Please see https://security-tracker.debian.org/tracker/CVE-2018-12178 https://security-tracker.debian.org/tracker/CVE-2018-12180 https://security-tracker.debian.org/tracker/CVE-2018-12181 Cheers, Moritz

Bug#924613: CVE-2009-5155

2019-03-14 Thread Moritz Muehlenhoff
Source: gnulib Severity: grave Tags: security Please see https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-5155 Patch: http://git.savannah.gnu.org/cgit/gnulib.git/commit/?id=5513b40999149090987a0341c018d05d3eea1272 Cheers, Moritz

Bug#924610: libsdl2: Multiple security issues

2019-03-14 Thread Moritz Muehlenhoff
Source: libsdl2 Severity: grave Tags: security Hi, a number of security issues were found in SDL, please see the following links for references. https://security-tracker.debian.org/tracker/CVE-2019-7638 https://security-tracker.debian.org/tracker/CVE-2019-7637 https://security-tracker.debian.org/

Bug#924609: libsdl1.2: Multiple security issues

2019-03-14 Thread Moritz Muehlenhoff
Source: libsdl1.2 Severity: grave Tags: security Hi, a number of security issues were found in SDL, please see the following links for references. https://security-tracker.debian.org/tracker/CVE-2019-7638 https://security-tracker.debian.org/tracker/CVE-2019-7637 https://security-tracker.debian.or

Bug#924509: CVE-2016-9840 CVE-2016-9841 CVE-2016-9842 CVE-2016-9843

2019-03-13 Thread Moritz Muehlenhoff
Package: rsync Version: 3.1.3-5 Severity: grave Tags: security rsync ships a local copy of zlib, which misses the security fixes for CVE-2016-9840 CVE-2016-9841 CVE-2016-9842 CVE-2016-9843. I've attached the respective upstream patches. Also, let's revisit using the shared zlib copy for bullseye

Bug#924351: CVE-2018-16647 CVE-2018-16648

2019-03-11 Thread Moritz Muehlenhoff
Package: mupdf Version: 1.14.0+ds1-3 Severity: grave Tags: security CVE-2018-16648: https://bugs.ghostscript.com/show_bug.cgi?id=699685 http://www.ghostscript.com/cgi-bin/findgit.cgi?38f883fe129a5e89306252a4676eaaf4bc968824 CVE-2018-16647: https://bugs.ghostscript.com/show_bug.cgi?id=699686 http:

Bug#924348: CVE-2019-7629

2019-03-11 Thread Moritz Muehlenhoff
Package: tintin++ Severity: grave Tags: security Please see http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7629 Cheers, Moritz

Bug#923347: No sensible security support due to Oracle's policies

2019-02-26 Thread Moritz Muehlenhoff
Source: mysql-connector-python Severity: serious mysql-connector-python is affected by Oracle's policy of not disclosing what security fixes they fix. CVE-2019-2435 is labeled with a CVSS 8.1/10 score and only fixed in 8.x, while the version in stretch (2.1.x) is marked as vulnerable, but no 2.1.

Bug#914632: uw-imap: CVE-2018-19518

2019-02-24 Thread Moritz Muehlenhoff
On Sun, Feb 24, 2019 at 02:53:41PM +0100, Magnus Holmgren wrote: > Perhaps wanting to run imapd via remote shell is so rare that there's no need > to write a NEWS.Debian entry? I agree, I don't think this needs a NEWS.Debian. Cheers, Moritz

Bug#923008: CVE-2018-16886

2019-02-22 Thread Moritz Muehlenhoff
Source: etcd Severity: grave Tags: security Please see http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16886 and https://security-tracker.debian.org/tracker/CVE-2018-16886 Cheers, Moritz

Bug#923003: CVE-2018-19873 CVE-2018-19871 CVE-2018-19870

2019-02-22 Thread Moritz Muehlenhoff
Source: qt4-x11 Severity: grave Tags: security Three security issues fixed in QT5 also affect qt4-x11: https://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/ CVE-2018-19873: https://github.com/qt/qtbase/commit/621ab8ab59901cc3f9bd98be709929c9eac997a8 CVE-2018-19871: ht

Bug#859553: pidentd: Please migrate to openssl1.1 in buster

2019-02-21 Thread Moritz Muehlenhoff
On Thu, Feb 21, 2019 at 11:37:02PM +0100, Sebastian Andrzej Siewior wrote: > On 2019-02-21 23:18:33 [+0100], Moritz Muehlenhoff wrote: > > On Thu, Feb 21, 2019 at 08:56:14PM +0100, Sebastian Andrzej Siewior wrote: > > > Its popcon is dropping. It will not be part of Buste

Bug#859553: pidentd: Please migrate to openssl1.1 in buster

2019-02-21 Thread Moritz Muehlenhoff
On Thu, Feb 21, 2019 at 08:56:14PM +0100, Sebastian Andrzej Siewior wrote: > Its popcon is dropping. It will not be part of Buster. So either RM it > or I have no use it for, I was just looking at it because it's one of the five packages blocking the removal of src:openssl1.0, from my PoV it can b

Bug#859553: pidentd: Please migrate to openssl1.1 in buster

2019-02-19 Thread Moritz Muehlenhoff
On Wed, Feb 20, 2019 at 12:28:48AM +0100, Sebastian Andrzej Siewior wrote: > On 2017-10-12 23:44:37 [+0200], To 859...@bugs.debian.org wrote: > > this is a remainder about the openssl transition [0]. We really want to > > remove libssl1.0-dev from unstable for Buster. I will raise the severity > >

Bug#922724: Lots of security issues

2019-02-19 Thread Moritz Muehlenhoff
Source: zoneminder Severity: grave Tags: security Please see: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-8429 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-8428 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-8427 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-20

Bug#913467: nvidia-graphics-drivers: CVE‑2018‑6260: access to application data processed on the GPU through a side channel exposed by the GPU performance counters

2019-02-19 Thread Moritz Muehlenhoff
On Mon, Feb 18, 2019 at 11:15:56PM +, Luca Boccassi wrote: > On Mon, 2019-02-18 at 22:57 +0100, Moritz Mühlenhoff wrote: > > On Mon, Nov 12, 2018 at 02:36:23PM +, Luca Boccassi wrote: > > > On Mon, 2018-11-12 at 13:47 +0100, Andreas Beckmann wrote: > > > > On 2018-11-11 13:54, Luca Boccassi

Bug#922461: CVE-2018-20124

2019-02-16 Thread Moritz Muehlenhoff
Source: qemu Severity: grave Tags: security When rdma was enabled in -3, this also made a fix for CVE-2018-20124 necessary: https://lists.gnu.org/archive/html/qemu-devel/2018-12/msg02822.html https://git.qemu.org/?p=qemu.git;a=commit;h=0e68373cc2b3a063ce067bc0cc3edaf370752890 Cheers, Mor

Bug#921969: CVE-2018-20760 CVE-2018-20761 CVE-2018-20762 CVE-2018-20763

2019-02-10 Thread Moritz Muehlenhoff
Source: gpac Severity: grave Tags: security CVE-2018-20760: https://github.com/gpac/gpac/commit/4c1360818fc8948e9307059fba4dc47ba8ad255d https://github.com/gpac/gpac/issues/1177 CVE-2018-20761: https://github.com/gpac/gpac/commit/35ab4475a7df9b2a4bcab235e379c0c3ec543658 https://github.com/gpac/gp

Bug#921952: Don't include in buster without proper commitment to update in stable

2019-02-10 Thread Moritz Muehlenhoff
Source: libsass Severity: serious None of the security bugs filed in the BTS has seen any maintainer followup (dating back to 2017 in some cases), and that's just the tip of the iceberg, the security tracker lists many more. Unless someone steps forward and commits to properly maintain it during

Bug#921772: CVE-2018-1000652

2019-02-08 Thread Moritz Muehlenhoff
Package: jabref Severity: grave Tags: security This was assigned CVE-2018-1000652: https://github.com/JabRef/jabref/issues/4229 https://github.com/JabRef/jabref/commit/89f855d76713b4cd25ac0830c719cd61c511851e Cheers, Moritz

Bug#921767: CVE-2018-12029

2019-02-08 Thread Moritz Muehlenhoff
Source: passenger Severity: grave Tags: security This was assigned CVE-2018-12029: https://blog.phusion.nl/2018/06/12/passenger-5-3-2-various-security-fixes/ https://github.com/phusion/passenger/commit/207870f5b7f5cc240587ab0977d6046782ae1d86 Cheers, Moritz

Bug#921746: Should witty be removed?

2019-02-08 Thread Moritz Muehlenhoff
Package: libwt40 Severity: serious Should witty be removed from the archive? - No maintainer upload since 2016 - Remove from testing since 16 months - Multiple RC bugs (3) and other legacy issues (QT4) - Marginal popcon Cheers, Moritz

Bug#921471: Should pdf2htmlex be removed?

2019-02-05 Thread Moritz Muehlenhoff
Package: pdf2htmlex Severity: serious Should pdf2htmlex be removed? It's RC-buggy for over a year and upstream development seems to have stopped: http://pdf2htmlex.blogspot.de/2016/12/looking-for-new-maintainer.html Cheers, Moritz

Bug#921131: CVE-2018-10897

2019-02-01 Thread Moritz Muehlenhoff
Package: yum-utils Severity: grave Tags: security This was assigned CVE-2018-10897: https://bugzilla.redhat.com/show_bug.cgi?id=1600221 https://github.com/rpm-software-management/yum-utils/commit/7554c0133eb830a71dc01846037cc047d0acbc2c https://github.com/rpm-software-management/yum-utils/commit/6

Bug#921039: CVE-2018-14647

2019-01-31 Thread Moritz Muehlenhoff
Package: python2.7 Version: 2.7.15-5 Severity: grave Tags: security CVE-2018-14647 as fixed in DSA-4306-1 needs to be fixed in testing as well: https://bugs.python.org/issue34623 https://github.com/python/cpython/commit/18b20bad75b4ff0486940fba4ec680e96e70f3a2 Cheers, Moritz

Bug#920818: Should this package be removed?

2019-01-29 Thread Moritz Muehlenhoff
Source: mysql-connector-net Severity: serious Last upload three years ago and removed from testing for a year. Cheers, Moritz

Bug#920817: Should this package be removed?

2019-01-29 Thread Moritz Muehlenhoff
Package: fsgateway Severity: serious Should fsgateway be removed? Already missed stretch, seems dead upstream, dropped from testing since two years and last upload was in 2015. Cheers, Moritz

<    1   2   3   4   5   6   7   8   9   10   >