Bug#639916: spread: license wackiness

2011-08-31 Thread Hendrik Weimer
Ken Arromdee arrom...@rahul.net writes: Unlike the original BSD 4 clause license this adds or software that uses this software. If I interpret this broadly (all software that uses this software must display the sentence) it's non-free, since it imposes conditions on non-derived software

Bug#423379: OpenSSL license violation

2007-05-11 Thread Hendrik Weimer
Package: kmymoney2 Version: 0.8.6-1 Severity: serious According to the copyright file kmymoney2 is being distributed under GPLv2. However, it depends on libgwenhywfar, which in turns is linked against OpenSSL. While libgwenhywfar contains an OpenSSL exception, kmymoney2 does not. So, please

Bug#403034: Deep MIME Nesting Content Filter Bypass

2006-12-14 Thread Hendrik Weimer
Package: clamav Version: 0.88.7-1 Severity: grave Tags: security While the new 0.88.7 version fixes CVE-2006-6406 and CVE-2006-6481 the update introduces another flaw that lets viruses pass undetected. If a virus is nested deeper than the --max-mail-recursion limit, the file will pass and

Bug#401873: closed by Stephen Gran [EMAIL PROTECTED] (Bug#401873: fixed in clamav 0.90~rc2-1)

2006-12-13 Thread Hendrik Weimer
The bug is still present in 0.88.7. Files nested deeper than --max-mail-recursion are not scanned and there is no error returned (exit code is 0). When using clamscan I get a warning from libclamav, but the EICAR string still passes. -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject

Bug#401873: Unusual MIME Encoding Content Filter Bypass

2006-12-06 Thread Hendrik Weimer
Package: clamav Version: 0.88.6-1 Tags: security Severity: grave As reported in http://www.quantenblog.net/security/virus-scanner-bypass ClamAV passed an EICAR test file if the following conditions are met: 1. the EICAR file is encoded in Base64 including characters not in the standard

Bug#325472: libaqhbci-qt-tools: uninstallable

2005-08-28 Thread Hendrik Weimer
Package: libaqhbci-qt-tools Severity: grave Justification: renders package unusable The following packages have unmet dependencies: libaqhbci-qt-tools: Depends: libaqbanking0 but it is not installable Depends: libaqhbci2 but it is not going to be installed