Re: Quake3 security issue and non-responsive maintainer: Xavier Lamien

2010-05-20 Thread Kevin Fenzi
On Tue, 11 May 2010 11:10:39 -0800 Jeff Spaleta jspal...@gmail.com wrote: On Tue, May 11, 2010 at 10:57 AM, Jon Ciesla l...@jcomserv.net wrote: Well, no, not if there's an easy way to find the existing stuff.  Is there a way to extract this info from Bugzilla?  I'd stick that query in my

Re: Quake3 security issue and non-responsive maintainer: Xavier Lamien

2010-05-20 Thread Stanislav Ochotnicky
On 05/11/2010 10:03 PM, Thomas Spura wrote: Am Dienstag, den 11.05.2010, 17:47 +0800 schrieb Chen Lei: 2010/5/11 Rahul Sundaram methe...@gmail.com Hi https://admin.fedoraproject.org/pkgdb/acls/bugs/quake3 Quake 3 engine needs to be updated. The

Re: Quake3 security issue and non-responsive maintainer: Xavier Lamien

2010-05-20 Thread Kevin Kofler
Till Maas wrote: A current problem I see with using upstream release monitoring is that there is no easy way to query which bugs are ignored, because it is perfectly valid to not touch the bug as a maintainer but only update the package. This will avoid a new bug to be filed, but the

Re: Quake3 security issue and non-responsive maintainer: Xavier Lamien

2010-05-17 Thread Rakesh Pandit
On 15 May 2010 22:13, Till Maas wrote: On Sat, May 15, 2010 at 09:29:37PM +0530, Rakesh Pandit wrote: On 15 May 2010 21:07, Till Maas wrote: The upstream release monitoring tool (formerly fever) is not really used to identify such packages, because there is no process to identify

Re: Quake3 security issue and non-responsive maintainer: Xavier Lamien

2010-05-12 Thread Jaroslav Reznik
On Tuesday 11 May 2010 18:51:08 Kevin Fenzi wrote: On Tue, 11 May 2010 15:37:51 +0200 Jaroslav Reznik jrez...@redhat.com wrote: On Tuesday 11 May 2010 13:08:53 Rahul Sundaram wrote: On 05/11/2010 03:43 PM, Daniel P. Berrange wrote: Do we have a security team who evaluate security

Re: Quake3 security issue and non-responsive maintainer: Xavier Lamien

2010-05-12 Thread Daniel P. Berrange
On Tue, May 11, 2010 at 05:47:48PM +0800, Chen Lei wrote: 2010/5/11 Rahul Sundaram methe...@gmail.com Hi https://admin.fedoraproject.org/pkgdb/acls/bugs/quake3 Quake 3 engine needs to be updated. The current version has security issues and breaks multiplayer in a couple of Quake3

Re: Quake3 security issue and non-responsive maintainer: Xavier Lamien

2010-05-12 Thread Przemek Klosowski
On 05/11/2010 07:30 PM, Jeff Spaleta wrote: On Tue, May 11, 2010 at 3:10 PM, Przemek Klosowski przemek.klosow...@nist.gov wrote: This probably means at least a rudimentary application testing rig and a discipline that identifies and deals with distressed packages. Does the ongoing work with

Re: Quake3 security issue and non-responsive maintainer: Xavier Lamien

2010-05-11 Thread Michael Schwendt
On Tue, 11 May 2010 14:37:22 +0530, Rahul wrote: Hi https://admin.fedoraproject.org/pkgdb/acls/bugs/quake3 Quake 3 engine needs to be updated. The current version has security issues and breaks multiplayer in a couple of Quake3 based games such as OpenArena. The maintainer has not

Re: Quake3 security issue and non-responsive maintainer: Xavier Lamien

2010-05-11 Thread Chen Lei
2010/5/11 Rahul Sundaram methe...@gmail.com Hi https://admin.fedoraproject.org/pkgdb/acls/bugs/quake3 Quake 3 engine needs to be updated. The current version has security issues and breaks multiplayer in a couple of Quake3 based games such as OpenArena. The maintainer has not responded

Re: Quake3 security issue and non-responsive maintainer: Xavier Lamien

2010-05-11 Thread Mamoru Tasaka
Michael Schwendt wrote, at 05/11/2010 06:37 PM +9:00: On Tue, 11 May 2010 14:37:22 +0530, Rahul wrote: Hi https://admin.fedoraproject.org/pkgdb/acls/bugs/quake3 Quake 3 engine needs to be updated. The current version has security issues and breaks multiplayer in a couple of Quake3 based

Re: Quake3 security issue and non-responsive maintainer: Xavier Lamien

2010-05-11 Thread Rahul Sundaram
On 05/11/2010 03:26 PM, Mamoru Tasaka wrote: Xavier responsed to rubygem-json related bug recently: https://bugzilla.redhat.com/show_bug.cgi?id=589801 So I guess trying to re-contact him is better. And meanwhile leave the unaddressed security issues and prominent bugs open for more days?

Re: Quake3 security issue and non-responsive maintainer: Xavier Lamien

2010-05-11 Thread Daniel P. Berrange
On Tue, May 11, 2010 at 03:29:53PM +0530, Rahul Sundaram wrote: On 05/11/2010 03:26 PM, Mamoru Tasaka wrote: Xavier responsed to rubygem-json related bug recently: https://bugzilla.redhat.com/show_bug.cgi?id=589801 So I guess trying to re-contact him is better. And meanwhile leave

Re: Quake3 security issue and non-responsive maintainer: Xavier Lamien

2010-05-11 Thread Rahul Sundaram
On 05/11/2010 03:43 PM, Daniel P. Berrange wrote: Do we have a security team who evaluate security issues that are filed against any package, and who have the privileges to immediately fix the CVE should the maintainer not be responsive enough wrt the severity of the security problem ? We

Re: Quake3 security issue and non-responsive maintainer: Xavier Lamien

2010-05-11 Thread Xavier Lamien
On Tue, May 11, 2010 at 11:56 AM, Mamoru Tasaka mtas...@ioa.s.u-tokyo.ac.jp wrote: Michael Schwendt wrote, at 05/11/2010 06:37 PM +9:00: On Tue, 11 May 2010 14:37:22 +0530, Rahul wrote: Hi https://admin.fedoraproject.org/pkgdb/acls/bugs/quake3 Quake 3 engine needs to be updated.  The

Re: Quake3 security issue and non-responsive maintainer: Xavier Lamien

2010-05-11 Thread Daniel P. Berrange
On Tue, May 11, 2010 at 04:38:53PM +0530, Rahul Sundaram wrote: On 05/11/2010 03:43 PM, Daniel P. Berrange wrote: Do we have a security team who evaluate security issues that are filed against any package, and who have the privileges to immediately fix the CVE should the maintainer not

Re: Quake3 security issue and non-responsive maintainer: Xavier Lamien

2010-05-11 Thread Jon Ciesla
On 05/11/2010 04:07 AM, Rahul Sundaram wrote: Hi https://admin.fedoraproject.org/pkgdb/acls/bugs/quake3 Quake 3 engine needs to be updated. The current version has security issues and breaks multiplayer in a couple of Quake3 based games such as OpenArena. The maintainer has not responded

Re: Quake3 security issue and non-responsive maintainer: Xavier Lamien

2010-05-11 Thread Jaroslav Reznik
On Tuesday 11 May 2010 13:08:53 Rahul Sundaram wrote: On 05/11/2010 03:43 PM, Daniel P. Berrange wrote: Do we have a security team who evaluate security issues that are filed against any package, and who have the privileges to immediately fix the CVE should the maintainer not be responsive

Re: Quake3 security issue and non-responsive maintainer: Xavier Lamien

2010-05-11 Thread Toshio Kuratomi
On Tue, May 11, 2010 at 08:30:41AM -0500, Jon Ciesla wrote: On 05/11/2010 04:07 AM, Rahul Sundaram wrote: Hi https://admin.fedoraproject.org/pkgdb/acls/bugs/quake3 Quake 3 engine needs to be updated. The current version has security issues and breaks multiplayer in a couple of Quake3

Re: Quake3 security issue and non-responsive maintainer: Xavier Lamien

2010-05-11 Thread Richard W.M. Jones
On Tue, May 11, 2010 at 04:38:53PM +0530, Rahul Sundaram wrote: On 05/11/2010 03:43 PM, Daniel P. Berrange wrote: Do we have a security team who evaluate security issues that are filed against any package, and who have the privileges to immediately fix the CVE should the maintainer not

Re: Quake3 security issue and non-responsive maintainer: Xavier Lamien

2010-05-11 Thread Michael Schwendt
On Tue, 11 May 2010 13:10:42 +0200, Xavier wrote: https://admin.fedoraproject.org/pkgdb/acls/bugs/quake3 I definitively missed that one. Like to comment on your other packages? Are there any packages where you would appreciate co-maintainers? For example, soundconverter has 8 open tickets,

Re: Quake3 security issue and non-responsive maintainer: Xavier Lamien

2010-05-11 Thread Xavier Lamien
On Tue, May 11, 2010 at 6:37 PM, Michael Schwendt mschwe...@gmail.com wrote: On Tue, 11 May 2010 13:10:42 +0200, Xavier wrote: https://admin.fedoraproject.org/pkgdb/acls/bugs/quake3 I definitively missed that one. Like to comment on your other packages? Are there any packages where you

Re: Quake3 security issue and non-responsive maintainer: Xavier Lamien

2010-05-11 Thread Kevin Fenzi
On Tue, 11 May 2010 15:37:51 +0200 Jaroslav Reznik jrez...@redhat.com wrote: On Tuesday 11 May 2010 13:08:53 Rahul Sundaram wrote: On 05/11/2010 03:43 PM, Daniel P. Berrange wrote: Do we have a security team who evaluate security issues that are filed against any package, and who have

Re: Quake3 security issue and non-responsive maintainer: Xavier Lamien

2010-05-11 Thread Jesse Keating
On Tue, 2010-05-11 at 12:31 +0100, Daniel P. Berrange wrote: This seems like rather a major shortcoming in our processes. A security team whom can merely file bugs has no power to ensure security flaws are fixed in a timely manner is not good for Fedora. Sure would be good to have

Re: Quake3 security issue and non-responsive maintainer: Xavier Lamien

2010-05-11 Thread Jon Ciesla
On 05/11/2010 12:05 PM, Jesse Keating wrote: On Tue, 2010-05-11 at 12:31 +0100, Daniel P. Berrange wrote: This seems like rather a major shortcoming in our processes. A security team whom can merely file bugs has no power to ensure security flaws are fixed in a timely manner is not good

Re: Quake3 security issue and non-responsive maintainer: Xavier Lamien

2010-05-11 Thread Bill Nottingham
Jon Ciesla (l...@jcomserv.net) said: This seems like rather a major shortcoming in our processes. A security team whom can merely file bugs has no power to ensure security flaws are fixed in a timely manner is not good for Fedora. Sure would be good to have volunteers for

Re: Quake3 security issue and non-responsive maintainer: Xavier Lamien

2010-05-11 Thread Jon Ciesla
On 05/11/2010 01:29 PM, Bill Nottingham wrote: Jon Ciesla (l...@jcomserv.net) said: This seems like rather a major shortcoming in our processes. A security team whom can merely file bugs has no power to ensure security flaws are fixed in a timely manner is not good for Fedora.

Re: Quake3 security issue and non-responsive maintainer: Xavier Lamien

2010-05-11 Thread Rahul Sundaram
On 05/12/2010 12:27 AM, Jon Ciesla wrote: Well, no, not if there's an easy way to find the existing stuff. Is there a way to extract this info from Bugzilla? I'd stick that query in my bookmarks and peek at it every couple days. You might want to get in touch with the security team. I

Re: Quake3 security issue and non-responsive maintainer: Xavier Lamien

2010-05-11 Thread Jeff Spaleta
On Tue, May 11, 2010 at 10:57 AM, Jon Ciesla l...@jcomserv.net wrote: Well, no, not if there's an easy way to find the existing stuff.  Is there a way to extract this info from Bugzilla?  I'd stick that query in my bookmarks and peek at it every couple days. Indeed. I'd like to use my proven

Re: Quake3 security issue and non-responsive maintainer: Xavier Lamien

2010-05-11 Thread Jon Ciesla
On 05/11/2010 02:10 PM, Jeff Spaleta wrote: On Tue, May 11, 2010 at 10:57 AM, Jon Cieslal...@jcomserv.net wrote: Well, no, not if there's an easy way to find the existing stuff. Is there a way to extract this info from Bugzilla? I'd stick that query in my bookmarks and peek at it every

Re: Quake3 security issue and non-responsive maintainer: Xavier Lamien

2010-05-11 Thread Thomas Spura
Am Dienstag, den 11.05.2010, 17:47 +0800 schrieb Chen Lei: 2010/5/11 Rahul Sundaram methe...@gmail.com Hi https://admin.fedoraproject.org/pkgdb/acls/bugs/quake3 Quake 3 engine needs to be updated. The current version has security

Re: Quake3 security issue and non-responsive maintainer: Xavier Lamien

2010-05-11 Thread Jeff Spaleta
On Tue, May 11, 2010 at 1:47 AM, Chen Lei supercyp...@gmail.com wrote: It seems a lot of trivial packages in fedora are unmaintained for a long I dispute your claim that there are a lot. Yes we are going to have things fall through the cracks. But I've seen no analysis and no tools which would

Re: Quake3 security issue and non-responsive maintainer: Xavier Lamien

2010-05-11 Thread Till Maas
On Tue, May 11, 2010 at 01:26:53PM -0800, Jeff Spaleta wrote: How often does the AWOL maintainer process get used? Very rarely. If there were a lot of unmaintained packages I would expect to see the AWOL process be firing all the time as people reacted to missing maintainers. I use the

Security Bug in aircrack-ng (was: Re: Quake3 security issue and non-responsive maintainer: Xavier) Lamien

2010-05-11 Thread Till Maas
On Tue, May 11, 2010 at 11:10:39AM -0800, Jeff Spaleta wrote: On Tue, May 11, 2010 at 10:57 AM, Jon Ciesla l...@jcomserv.net wrote: Well, no, not if there's an easy way to find the existing stuff.  Is there a way to extract this info from Bugzilla?  I'd stick that query in my bookmarks and

Re: Quake3 security issue and non-responsive maintainer: Xavier Lamien

2010-05-11 Thread Jeff Spaleta
On Tue, May 11, 2010 at 2:14 PM, Till Maas opensou...@till.name wrote: I use the non-responsive process or active nagging quite a lot, since I often stumble upon such packages (it already happend twice to youtube-dl that the current maintainer did not have enough time). Thankfully the start of

Re: Quake3 security issue and non-responsive maintainer: Xavier Lamien

2010-05-11 Thread Jeff Spaleta
On Tue, May 11, 2010 at 3:10 PM, Przemek Klosowski przemek.klosow...@nist.gov wrote: This probably means at least a rudimentary application testing rig and a discipline that identifies and deals with distressed packages. Does the ongoing work with AutoQA provide the solution you are looking