[Bug 2052495] Re: [MIR] wsl-pro-service

2024-03-27 Thread George-Andrei Iosif
I reviewed `wsl-pro-service` `0.1.1` as checked into Noble. This shouldn't be considered a full audit but rather a quick gauge of maintainability. For the sake of completeness, this review will also mention findings reported in previous GitHub issues and Launchpad comments. Ubuntu Pro for WSL

[Bug 2052495] Re: [MIR] wsl-pro-service

2024-03-27 Thread George-Andrei Iosif
Other patches were published in the meantime: - For the second item above, in the `347e747` commit; - Checking for a negative port number, in the `a6784f5` commit; and - Avoiding logging configuration items, in the `518a85` commit. -- You received this bug notification because you are a member

[Bug 2052495] Re: [MIR] wsl-pro-service

2024-02-29 Thread George-Andrei Iosif
The fourth item's crash has already been patched in a GitHub PR (https://github.com/canonical/ubuntu-pro-for-wsl/pull/622). -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2052495 Title: [MIR]

[Bug 2052495] Re: [MIR] wsl-pro-service

2024-02-29 Thread George-Andrei Iosif
Hi, As multiple security concerns appeared when performing the security review of this package, I had a discussion with Jean and Didier from the owning team. We concluded that reporting these issues before offering the final MIR report would be best. This is because no user is affected (as the

[Bug 2019951] Re: [MIR] libmysofa

2024-02-28 Thread George-Andrei Iosif
Thanks for the confirmation, Sebastien! -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2019951 Title: [MIR] libmysofa To manage notifications about this bug go to:

[Bug 2047149] Re: [MIR] speexdsp

2024-02-27 Thread George-Andrei Iosif
I reviewed `speexdsp` `1.2.1-1` as checked into Noble. This shouldn't be considered a full audit, but rather a quick gauge of maintainability that involves static and dynamic analysis techniques. Speex is an open-source and free audio compression codec specialised in reproducing human speech

[Bug 2031491] Re: [MIR] libemail-simple-perl ( libemail-mime-perl dependency as libmail-dmarc-perl dependency)

2024-02-26 Thread George-Andrei Iosif
** Changed in: libemail-simple-perl (Ubuntu) Assignee: Ubuntu Security Team (ubuntu-security) => (unassigned) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2031491 Title: [MIR]

[Bug 2029379] Re: [MIR] promote libdbd-sqlite3-perl (libmail-dmarc-perl dependency)

2024-02-26 Thread George-Andrei Iosif
** Changed in: libdbd-sqlite3-perl (Ubuntu) Assignee: Ubuntu Security Team (ubuntu-security) => (unassigned) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2029379 Title: [MIR] promote