Bug#1035474: Don't include in Bookworm?

2023-05-03 Thread Moritz Muehlenhoff
Source: libdmx Version: 1:1.1.4-2 Severity: serious The Xorg folks mentioned at https://www.openwall.com/lists/oss-security/2023/05/02/3: | We have also announced that we plan to retire the following packages soon | and while their gitlab repos are not yet archived, we expect they will be |

Bug#1033916: libapache2-mod-auth-openidc: CVE-2023-28625: segfault DoS when OIDCStripCookies is set

2023-05-03 Thread Moritz Muehlenhoff
On Wed, May 03, 2023 at 04:55:00PM +0200, Moritz Mühlenhoff wrote: > I think we can fix this via a DSA, can you please change the distribution line > to bullseye-wikimedia and upload to security-master? (Needs an upload with -sa Sorry, this should be bullseye-security obviously :-) Cheers,

Bug#1034885: RM: golang-github-go-macaron-binding -- RoQA; Obsolete

2023-04-26 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal User: ftp.debian@packages.debian.org Usertags: remove X-Debbugs-Cc: golang-github-go-macaron-bind...@packages.debian.org Control: affects -1 + src:golang-github-go-macaron-binding Please remove golang-github-go-macaron-binding. This was originally

Bug#1034883: RM: golang-github-go-macaron-csrf -- RoQA; Obsolete, open security issues

2023-04-26 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal User: ftp.debian@packages.debian.org Usertags: remove X-Debbugs-Cc: golang-github-go-macaron-c...@packages.debian.org Control: affects -1 + src:golang-github-go-macaron-csrf Please remove golang-github-go-macaron-csrf. It was only packaged for Gitea,

Bug#1034884: RM: golang-github-go-macaron-gzip -- RoQA; Obsolete

2023-04-26 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal User: ftp.debian@packages.debian.org Usertags: remove X-Debbugs-Cc: golang-github-go-macaron-g...@packages.debian.org Control: affects -1 + src:golang-github-go-macaron-gzip Please remove golang-github-go-macaron-gzip. The version in the archive is a

Bug#1034839: RM: golang-github-go-macaron-i18n -- RoQA; obsolete, open security issue

2023-04-25 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal User: ftp.debian@packages.debian.org Usertags: remove X-Debbugs-Cc: golang-github-go-macaron-i...@packages.debian.org Control: affects -1 + src:golang-github-go-macaron-i18n Please remove golang-github-go-macaron-i18n. It was only packaged for gitea,

Bug#1034798: RM: gpac/2.0.0+dfsg1-4

2023-04-24 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: rm X-Debbugs-Cc: g...@packages.debian.org, siret...@tauware.de, sramac...@debian.org Control: affects -1 + src:gpac In priot discussion between Reinhard, Sebastian and the Security team we've

Bug#1034732: Keep out of testing

2023-04-22 Thread Moritz Muehlenhoff
Package: gpac Version: 2.0.0+dfsg1-2+b1 Severity: serious In some discussion between Reinhard, Sebastian and the Security team we've come to the conclusion that gpac isn't suitable to be included in a stable release. The massive influx of security issues makes that untenable (and there's no

Bug#1034374: RUSTSEC-2023-0031

2023-04-13 Thread Moritz Muehlenhoff
Source: rust-spin Version: 0.9.5-1 Severity: important Tags: security X-Debbugs-Cc: Debian Security Team https://rustsec.org/advisories/RUSTSEC-2023-0031.html https://github.com/mvdnes/spin-rs/issues/148 Cheers, Moritz

Bug#1033333: Don't include in Bookworm

2023-03-24 Thread Moritz Muehlenhoff
Hi Peter, On Thu, Mar 23, 2023 at 09:23:18PM +, Peter Green wrote: > severity 103 normal > retitle 103 rust-encoding is unmaintained upstream > severity 104 normal > retitle 104 rust-boxfnonce is unmaintained upstream > severity 105 normal > retitle 105 rust-const-cstr

Bug#1033337: RM: lvtk -- RoQA; unmaintained, depends on python2

2023-03-22 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal User: ftp.debian@packages.debian.org Usertags: remove X-Debbugs-Cc: l...@packages.debian.org Control: affects -1 + src:lvtk Please remove lvtk. The last maintainer upload was in 2016, still depends on Python 2 and has been removed from testing since

Bug#1033336: RM: faumachine -- RoQA; RC-buggy, depends on python 2

2023-03-22 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal User: ftp.debian@packages.debian.org Usertags: remove X-Debbugs-Cc: faumach...@packages.debian.org Control: affects -1 + src:faumachine Please remove faumachine. It FTBFSes since GCC 9 and still uses Python 2. It has been removed from testing since

Bug#1033334: Don't include in Bookworm

2023-03-22 Thread Moritz Muehlenhoff
Source: rust-boxfnonce Version: 0.1.1-2 Severity: serious Per https://rustsec.org/advisories/RUSTSEC-2019-0040.html rust-boxfnonce is obsolete, let's keep it out of bookworm (and remove from the archive). Cheers, Moritz

Bug#1033335: Don't include in Bookworm

2023-03-22 Thread Moritz Muehlenhoff
Source: rust-const-cstr Version: 0.3.0-1 Severity: serious Hi, there is https://rustsec.org/advisories/RUSTSEC-2023-0020.html which flags that rust-const-cstr is unmaintained. Since there are no reverse deps in the archive, let's exclude it from bookworm (or rather remove rightaway)? Cheers,

Bug#1033333: Don't include in Bookworm

2023-03-22 Thread Moritz Muehlenhoff
Source: rust-encoding Version: 0.2.33-1 Severity: serious Hi, there is https://rustsec.org/advisories/RUSTSEC-2021-0153.html which flags that rust-encoding is unmaintained. Since there are no reverse deps in the archive, let's exclude it from bookworm (or rather remove rightaway)? Cheers,

Bug#1033332: RM: faumachine -- RoQA; unmaintained, depends on Python 2

2023-03-22 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal User: ftp.debian@packages.debian.org Usertags: remove X-Debbugs-Cc: faumach...@packages.debian.org Control: affects -1 + src:faumachine Please remove drbdlinks. The last maintainer upload was in 2012, it's removed from testing for over three years and

Bug#1033270: RM: sqlite -- RoQA; Obsolete

2023-03-20 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal User: ftp.debian@packages.debian.org Usertags: remove X-Debbugs-Cc: sql...@packages.debian.org Control: affects -1 + src:sqlite Please remove sqlite. It's an older copy of src:sqlite3 and EOL for a long time (#607969) Cheers, Moritz

Bug#1033269: RM: kannel-sqlbox -- RoQA; Unmaintained, RC-buggy, blocks removal of src:sqlite

2023-03-20 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal User: ftp.debian@packages.debian.org Usertags: remove X-Debbugs-Cc: kannel-sql...@packages.debian.org Control: affects -1 + src:kannel-sqlbox Please remove kannel-sqlbox. The last maintainer upload was in 2018, it's removed from testing since 2020 and

Bug#1032977: unblock: apache2/2.4.56-1

2023-03-18 Thread Moritz Muehlenhoff
On Sat, Mar 18, 2023 at 09:17:25AM +0100, Sebastian Ramacher wrote: > Control: tags -1 moreinfo > > Hi security team > > On 2023-03-15 06:46:32 +0400, Yadd wrote: > > Package: release.debian.org > > Severity: normal > > User: release.debian@packages.debian.org > > Usertags: unblock > >

Bug#1033104: CVE-2023-24808

2023-03-17 Thread Moritz Muehlenhoff
Source: ippsample Version: 0.0~git20220607.72f89b3-1 Severity: normal ippsample bundles a copy of PDFio, which is affected by CVE-2023-24808. Not sure if the code is even reachable and even if it's just a crash in a CLI tool. Cheers, Moritz

Bug#1033095: Disable TIOCSTI for trixie

2023-03-17 Thread Moritz Muehlenhoff
Source: linux Severity: wishlist https://www.openwall.com/lists/oss-security/2023/03/14/2 Filing a bug (for trixie (added in 6.2), can be applied early to notice potentially affected applications early on) Cheers, Moritz

Bug#1033069: release-notes: Update release notes entry for OpenJDK security support

2023-03-16 Thread Moritz Muehlenhoff
Package: release-notes Severity: important Hi, the "5.2.1.2. OpenJDK 17" section needs to be updated for bookworm: The same applies for Java 21, so instead it should state: Debian bookworm comes with an early access version of OpenJDK 21 (the next expected OpenJDK LTS version after OpenJDK 17),

Bug#1033066: RM: sendpage -- RoQA; obsolete, unmaintained, dead upstream

2023-03-16 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal User: ftp.debian@packages.debian.org Usertags: remove X-Debbugs-Cc: sendp...@packages.debian.org Control: affects -1 + src:sendpage Please remove sendpage. It's dead upstream, obsolete and unmaintained (last maintainer upload 14 years ago and dropped

Bug#1032885: unblock: debian-security-support/1:12+2023.03.05

2023-03-13 Thread Moritz Muehlenhoff
On Mon, Mar 13, 2023 at 03:07:34PM +, Holger Levsen wrote: > On Mon, Mar 13, 2023 at 03:58:45PM +0100, Moritz Mühlenhoff wrote: > > Am Mon, Mar 13, 2023 at 01:43:11PM +0100 schrieb Holger Levsen: > > > * security-support-limited: > > > - for golang and openjdk-17, point to the bookworm

Bug#1032529: RM: rust-crossbeam-utils-0.7 -- RoQA; Obsolete, open security issue

2023-03-08 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal User: ftp.debian@packages.debian.org Usertags: remove X-Debbugs-Cc: rust-crossbeam-utils-...@packages.debian.org Control: affects -1 + src:rust-crossbeam-utils-0.7 Please remove rust-crossbeam-utils-0.7. It's an older version of src:

Bug#1032476: apache2: CVE-2023-25690 CVE-2023-27522

2023-03-08 Thread Moritz Muehlenhoff
On Wed, Mar 08, 2023 at 07:09:20AM +0400, Yadd wrote: > On 3/7/23 23:46, Salvatore Bonaccorso wrote: > > Source: apache2 > > Version: 2.4.55-1 > > Severity: grave > > Tags: security upstream > > X-Debbugs-Cc: car...@debian.org, Debian Security Team > > > > > > Hi, > > > > The following

Bug#1030669: Only include in Bookworm with commitment to stable updates

2023-03-08 Thread Moritz Muehlenhoff
On Wed, Mar 08, 2023 at 02:20:25PM +0100, Marco d'Itri wrote: 0;115;0c> On Feb 14, Moritz Muehlenhoff wrote: > > > > > Varnish should only be included in Bookworm with a reliable commitment > > > > by the maintainers to backport/test security fixes across the t

Bug#1032266: autopkgtest regression in stable with latest Java 11

2023-03-02 Thread Moritz Muehlenhoff
Source: fdroidserver Version: 2.0.3-1 Severity: important Hi, with the latest security update of openjdk-11 in stable (which updated from 11.0.6 to 11.0.8, as we're following the Java LTS releases), the autopkgtest of fdroidserver fails. This seems caused by the "Disabled SHA-1 Signed JARs

Bug#1032088: https://rustsec.org/advisories/RUSTSEC-2022-0078.html

2023-02-27 Thread Moritz Muehlenhoff
Source: rust-bumpalo Version: 3.7.0-3 Severity: important Tags: security X-Debbugs-Cc: Debian Security Team https://rustsec.org/advisories/RUSTSEC-2022-0078.html

Bug#1032086: Don't include in Bookworm

2023-02-27 Thread Moritz Muehlenhoff
Source: golang-github-labstack-echo.v3 Version: 3.3.10-2 Severity: serious This is an older version of src:golang-github-labstack-echo. None of the reverse deps are currently in bookworm, so golang-github-labstack-echo.v3 should be dropped as well (and post freeze the reverse deps fixed and the

Bug#1032085: Don't include in Bookworm

2023-02-27 Thread Moritz Muehlenhoff
Source: golang-github-labstack-echo.v2 Version: 2.2.0-3 Severity: serious This is an older version of src:golang-github-labstack-echo. None of the reverse deps are currently in bookworm, so golang-github-labstack-echo.v2 should be dropped as well (and post freeze the reverse deps fixed and the

Bug#1031635: bullseye-pu: package snakeyaml/1.28-1

2023-02-27 Thread Moritz Muehlenhoff
On Fri, Feb 24, 2023 at 10:29:07PM +0100, Markus Koschany wrote: > Hi, > > Am Freitag, dem 24.02.2023 um 16:01 +0100 schrieb Moritz Mühlenhoff: > [...] > > Could we also ship the README.Debian.security that was recently added > > in unstable to bullseye/buster? > > I've just uploaded a new

Bug#1031733: libcommons-fileupload-java: CVE-2023-24998

2023-02-22 Thread Moritz Muehlenhoff
On Tue, Feb 21, 2023 at 09:48:35PM -0800, tony mancill wrote: > On Tue, Feb 21, 2023 at 04:10:16PM +0100, Moritz Mühlenhoff wrote: > > Source: libcommons-fileupload-java > > X-Debbugs-CC: t...@security.debian.org > > Severity: important > > Tags: security > > > > Hi, > > > > The following

Bug#1031732: iortcw: CVE-2019-25104

2023-02-21 Thread Moritz Muehlenhoff
On Tue, Feb 21, 2023 at 03:32:01PM +, Simon McVittie wrote: > On Tue, 21 Feb 2023 at 16:09:30 +0100, Moritz Mühlenhoff wrote: > > CVE-2019-25104[0]: > > https://github.com/rtcwcoop/rtcwcoop/pull/45 > > This looks like a denial of service via memory exhaustion when running > a multiplayer

Bug#972146: /usr/share/applications/mono-runtime-common.desktop: should not handle MIME type by executing arbitrary code

2023-02-18 Thread Moritz Muehlenhoff
On Sat, Feb 18, 2023 at 12:04:27PM +0100, Gabriel Corona wrote: > I believe obtaining a CVE ID would be beneficial so that this issue may be > tracked by downstream projects/distributions. All those distros were notified via your post to oss-security. You can try cveform, if there's no assignment

Bug#1030669: Only include in Bookworm with commitment to stable updates

2023-02-14 Thread Moritz Muehlenhoff
On Tue, Feb 14, 2023 at 02:48:43AM +0100, Marco d'Itri wrote: > On Feb 02, Moritz Muehlenhoff wrote: > > > Varnish should only be included in Bookworm with a reliable commitment > > by the maintainers to backport/test security fixes across the typical > > three ye

Bug#1031046: Only include in Bookworm with commitment to stable updates

2023-02-10 Thread Moritz Muehlenhoff
Source: asterisk Version: 1:20.1.0~dfsg+~cs6.12.40431414-1 Severity: serious Asterisk should only be included in Bookworm with a reliable commitment by the maintainers to backport/test security fixes across the typical three year life cycle (two years of stable-security and one year of

Bug#1031044: RM: latd -- RoQA; obsolete, orphaned for a long time, dead upstream

2023-02-10 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal User: ftp.debian@packages.debian.org Usertags: remove X-Debbugs-Cc: l...@packages.debian.org Control: affects -1 + src:latd Please remove latd. It's orphaned without an adopter since 2014, dead upstream and practically unused per popcon. Cheers,

Bug#1031043: RM: xavante -- RoQA; orphaned, uses old Lua releases, alternatives exist

2023-02-10 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal User: ftp.debian@packages.debian.org Usertags: remove X-Debbugs-Cc: xava...@packages.debian.org Control: affects -1 + src:xavante Please remove xavante, the last maintainer upload was in 2013, there's plenty of web servers in the archive and it depends

Bug#1030046: Document snakeyaml security expectations

2023-02-06 Thread Moritz Muehlenhoff
On Mon, Jan 30, 2023 at 10:15:47PM +0100, Markus Koschany wrote: > Hi, > > Am Montag, dem 30.01.2023 um 18:44 +0100 schrieb Moritz Muehlenhoff: > > > > Could we please add a README.Debian.security with something like the > > following > > t

Bug#1030669: Only include in Bookworm with commitment to stable updates

2023-02-06 Thread Moritz Muehlenhoff
Source: varnish Version: 7.1.1-1.1 Severity: serious Varnish should only be included in Bookworm with a reliable commitment by the maintainers to backport/test security fixes across the typical three year life cycle (two years of stable-security and one year of oldstable-security). Especially

Bug#1030046: Document snakeyaml security expectations

2023-01-30 Thread Moritz Muehlenhoff
Source: snakeyaml Version: 1.33-1 Severity: important Google's oss-fuzz found various cases where snakeyaml triggers an exception on malformed YAML input. These end up blindly being picked by various security web sites (since CVE IDs) were assigned. This is causing lots of overhead/annoyance for

Bug#638791: marked as done (warns and wants to disable tcp4+tcp6 entries as duplicate lines)

2023-01-28 Thread Moritz Muehlenhoff
On Sat, Jan 28, 2023 at 01:37:41PM +0100, Guillem Jover wrote: > Control: reopen -1 > Control: affects -1 - leafnode > > Hi! > > This seems to still be a valid concern for update-inetd. I think this > was probably closed in error as showing up in leafnode bugs page due > to the affects. Given

Bug#1019230: Bug#1021276: Pending snort 2.9.20 update

2023-01-21 Thread Moritz Muehlenhoff
On Sat, Jan 21, 2023 at 10:53:24PM +0100, Markus Koschany wrote: > Hi Javier, > > Am Freitag, dem 20.01.2023 um 22:23 +0100 schrieb Javier Fernandez-Sanguino: > > Dear Markus, > > > > Thank you for preparing. Could you please share the patch you are working > > on? > > Snort is available in

Bug#1025695: openjdk-11-jdk: Please update to 11.0.16.1

2023-01-16 Thread Moritz Muehlenhoff
On Sun, Jan 15, 2023 at 12:28:06PM -0800, tony mancill wrote: > On Wed, Dec 07, 2022 at 04:03:17PM +0100, Carsten Pfeiffer wrote: > > Package: openjdk-11-jdk > > Version: 11.0.16+8-1~deb11u1 > > Severity: normal > > > > Dear Maintainer, > > > > openjdk 11.0.16 in Bullseye contains a severe

Bug#1028421: Only include in Bookworm with commitment to stable updates

2023-01-10 Thread Moritz Muehlenhoff
Source: salt Severity: serious salt is currently RC-buggy and not in testing, but regardless of the remaining RC bugs getting fixed it should only get re-included with a reliable commitment to backport/test security-updates across the typical three year life cycle (two years of stable-security

Bug#1028419: RM: python3.9 -- ROM; Obsoleted by python3.10 and python3.11

2023-01-10 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal User: ftp.debian@packages.debian.org Usertags: remove X-Debbugs-Cc: python...@packages.debian.org, d...@debian.org Control: affects -1 + src:python3.9 Please remove python3.9, which has been replaced by python3.10/python3.11. The removal will need to

Bug#1004441: unblocking chromium?

2023-01-06 Thread Moritz Muehlenhoff
On Fri, Jan 06, 2023 at 08:41:50AM +0100, Paul Gevers wrote: > Dear Chromium team, Security team, > > On 27-01-2022 17:15, Moritz Muehlenhoff wrote: > > On Wed, Jan 26, 2022 at 09:38:42PM +0100, Paul Gevers wrote: > > > > So, I'm proposing the following: we unblock ch

Bug#1027187: O: coco-cpp -- Coco/R Compiler Generator (C++ Version)

2022-12-28 Thread Moritz Muehlenhoff
Package: wnpp Severity: normal X-Debbugs-Cc: coco-...@packages.debian.org Control: affects -1 + src:coco-cpp The former maintainer is no longer active and per a discussion with the former sponsor, I'm orphaning the coco-cpp package. The package description is: Coco/R is a compiler generator,

Bug#1027184: RM: primesense-nite-nonfree -- RoQA; broken for a long time

2022-12-28 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal User: ftp.debian@packages.debian.org Usertags: remove X-Debbugs-Cc: primesense-nite-nonf...@packages.debian.org Control: affects -1 + src:primesense-nite-nonfree Please remove primesense-nite-nonfree. It's broken since 2014 (#771187) and hasn't seen an

Bug#1027181: RM: selfhtml -- RoQA; obsolete, RC-buggy, unmaintained

2022-12-28 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal User: ftp.debian@packages.debian.org Usertags: remove X-Debbugs-Cc: selfh...@packages.debian.org Control: affects -1 + src:selfhtml Please remove selfhtml. The last upload was in 2008, it's RC-buggy (#1002966) and these docs describe the state of

Bug#1027178: RM: loganalyzer -- RoQA; unmaintained, broken

2022-12-28 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal User: ftp.debian@packages.debian.org Usertags: remove X-Debbugs-Cc: loganaly...@packages.debian.org Control: affects -1 + src:loganalyzer Please remove loganalyzer. It's broken since PHP 7 #974586, dropped from testing since 15 months and hasn't seen a

Bug#1027108: RM: python2.7 -- RoQA; Obsolete

2022-12-27 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal User: ftp.debian@packages.debian.org Usertags: remove X-Debbugs-Cc: python...@packages.debian.org, d...@debian.org Control: affects -1 + src:python2.7 Removing the last Python 2 remnants, this will need to be forced since there are some inter

Bug#1027107: RM: python-defaults -- RoQA; Obsolete

2022-12-27 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal User: ftp.debian@packages.debian.org Usertags: remove X-Debbugs-Cc: python-defau...@packages.debian.org, d...@debian.org Control: affects -1 + src:python-defaults Removing the last Python 2 remnants, this will need to be forced since there are some

Bug#1027106: RM: python-stdlib-extensions -- RoQA; Obsolete

2022-12-27 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal User: ftp.debian@packages.debian.org Usertags: remove X-Debbugs-Cc: python-stdlib-extensi...@packages.debian.org, d...@debian.org Control: affects -1 + src:python-stdlib-extensions Removing the last Python 2 remnants. This will need to be forced since

Bug#1027042: RM: telepathy-ring -- RoQA; Depends on Python 2

2022-12-26 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal Please remove telepathy-ring. It's one of the last package still using Python 2, there hasn't been a maintainer followup on #938644 since 2019 and https://git.merproject.org/mer-core/telepathy-ring is gone.

Bug#1026163: Uses Java 11

2022-12-15 Thread Moritz Muehlenhoff
Source: puppetdb Version: 7.11.2-3 Severity: grave Thanks for all the great work on Puppetdb! I was trying to setup a test environment with Puppetdb 7.11.2 from current testing and I noticed that it's using openjdk-11-jre-headless. While openjdk-11 is currently still in testing, Bookworm will

Bug#1025817: RM: sdic -- RoQA; RC-buggy, unmaintained

2022-12-09 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal Please remove sdic. It's RC-buggy and dropped from testing since 2017. Cheers, Moritz

Bug#1025205: bullseye-pu: package mplayer/2:1.4+ds1-1+deb11u1

2022-11-30 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal Tags: bullseye User: release.debian@packages.debian.org Usertags: pu This updates fixes various minor crashes in mplayer, which don't warrant a DSA by itself. I've run the PoCs against the updated build where applicable and also tested various

Bug#1025011: Keep out of bookworm unless actively maintained

2022-11-28 Thread Moritz Muehlenhoff
Source: netatalk Version: 3.1.13~ds-2 Severity: serious netatalk should not enter bookworm unless it gets adopted and actively maintained. Cheers, Moritz

Bug#1025010: bullseye-pu: package jtreg6/6.1+2-1~deb11u1

2022-11-28 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal Tags: bullseye User: release.debian@packages.debian.org Usertags: pu X-Debbugs-Cc: d...@debian.org openjdk bumped the requirements for the test suite within their 11.x branch (which is what we ship in Bullseye), it now needs jtreg6. The debdiff is

Bug#1024561: Unmaintained, keep out of stable

2022-11-21 Thread Moritz Muehlenhoff
Source: maradns Version: 2.0.13-1.4 Severity: serious The last maintainer upload was in 2015 and the version currently in the archive is way behind current upstream releases (which is at 3.4.07), we have plenty of maintained DNS servers, keep it out of testing ( and if noone picks it up, remove

Bug#1024411: RM: gkrellm-x86info -- RoQA; unmaintained, RC-buggy, dead upstream, replacement exists

2022-11-18 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal Please remove gkrellm-x86info. The last maintainer upload was in 2011, it's RC-buggy, dead upstream and dropped from testing for almost a year. And 1002714 indicates a replacement exists.

Bug#1024410: RM: dvbsnoop -- RoQA; unmaintained, RC-buggy, dead upstream

2022-11-18 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal Please remove dvbsnoop. The last maintainer upload was in 2013, it's RC-buggy, dead upstream and dropped from testing for almost a year.

Bug#1024407: RM: scim-canna -- RoQA; unmaintained, RC-buggy, dead upstream

2022-11-18 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal Please remove scim-canna. The last maintainer upload was in 2010, it's RC-buggy, dead upstream and dropped from testing for almost a year.

Bug#1024409: RM: vsdump -- RoQA; unmaintained, RC-buggy, dead upstream

2022-11-18 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal Please remove vsdump. The last maintainer upload was in 2010, it's RC-buggy, dead upstream and dropped from testing for almost a year.

Bug#1024408: RM: ibam -- RoQA; unmaintained, RC-buggy, dead upstream

2022-11-18 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal Please remove ibam. The last maintainer upload was in 2011, it's RC-buggy, dead upstream and dropped from testing for almost a year.

Bug#1024406: RM: cryptcat -- RoQA; unmaintained, RC-buggy, dead upstream

2022-11-18 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal Please remove cryptcat. The last maintainer upload was in 2008, it's RC-buggy, dead upstream and dropped from testing for almost a year.

Bug#1024341: RM: lostirc -- RoQA; unmaintained, dead upstream, depends on obsolete libs, alternatives exist

2022-11-17 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal Please remove lostirc. The last maintainer upload was in 2008, it's orphaned without an adopter since 2016, depends on obsolete GTK2, is dead upstream and there are plenty of alternatives in the archive.

Bug#1024340: RM: kanjipad -- RoQA; unmaintained, dead upstream, depends on obsolete libs

2022-11-17 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal Please remove kanjipad. The last maintainer upload was in 2013, it's orphaned without an adopter since 2020, depends on obsolete GTK2 and is dead upstream. Popcon is practically non-existent.

Bug#1024339: RM: ion -- RoQA; unmaintained, RC-buggy

2022-11-17 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal Please remove ion. It's unmaintained (last maintainer upload in 2014 and orphaned without adopter since 1.5 years) and RC-buggy (FTBFS with GCC >= 7) since 2017.

Bug#1024338: RM: setcolortemperature -- RoQA; dead upstream, replaced by xsct

2022-11-17 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal Please remove setcolortemperature. Development has ceased and https://github.com/Tookmund/setcolortemperature (and the original O: bug) point to xsct, which is now packaged in Debian.

Bug#1024337: RM: twoftpd -- RoQA; unmaintained, dead upstream, plenty of alternatives

2022-11-17 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal Please remove twoftpd. The last maintainer upload was in 2014, it's orphaned without an adopter since 2019 and dead upstream. And there's plenty of ftpd alternatives in the archive.

Bug#1021142: fixed in cargo 0.63.1-1

2022-11-16 Thread Moritz Muehlenhoff
reopen 1021142 thanks On Wed, Nov 16, 2022 at 01:05:18PM +, Debian FTP Masters wrote: > cargo (0.63.1-1) unstable; urgency=medium > . >* fix CVE-2022-36113/CVE-2022-36114 (Closes: #1021142) Hi Fabian, These are only fixed in 0.65, reopening. Cheers, Moritz

Bug#1024113: RM: golang-libgeoip -- RoQA; unmaintained, dead upstream, no reverse deps

2022-11-14 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal Please remove golang-libgeoip. It's orphaned without a new adopter since 2016, there are no reverse deps and it's dead upstream (last commit in 2017).

Bug#1024112: RM: golang-nzaat -- RoQA; unmaintained, no reverse deps, dead upstream

2022-11-14 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal Please remove golang-nzaat. It's up for adoption since 2016 without a new maintainer, there are no reverse deps and it's dead upstream (last commit nine years ago).

Bug#1024111: RM: golang-openldap -- RoQA; RC-buggy, dead upstream, broken with openldap 2.5

2022-11-14 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal X-Debbugs-Cc: r...@tardis.ca Please remove golang-openldap. It's unmaintained (last upload in 2018), there are no reverse deps, it's broken with OpenLDAP 2.5 and it's dead upstream (no commits since 2016). An alternative exists with golang-github-go-ldap

Bug#1024110: RM: mutrace -- RoQA; unmaintained, unused, RC-buggy

2022-11-14 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal Please remove mutrace. The last maintainer upload was in 2016, it's RC-buggy (and apparently already broken since 2016 per 810638) and popcon is practically non-existent.

Bug#1024109: RM: libdispatch -- RoQA; unmaintained, obsolete, no rdeps

2022-11-14 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal Please remove libdispatch. The last maintainer upload was in 2011, it's up for adoption since 2020 (where the former maintainer suggested to remove it) and there are no reverse deps.

Bug#1024108: RM: libblkmaker -- RoQA; obsolete, unmaintained, RC-buggy

2022-11-14 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal Please remove libblkmaker. It has been up for adoption since 2018, is broken since 2017 (#858377) and there are no reverse deps.

Bug#1024107: RM: lostirc -- RoQA; unmaintained, depends on obsolete libs, dead upstream

2022-11-14 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal Please remove lostirc. The last maintainer upload was in 2008, it's orphaned without an adopter since 2016, depends on obsolete GTK2, is dead upstream and there are plenty of alternatives in the archive.

Bug#1024014: RM: gatling -- RoQA; Obsolete, unmaintained, unused

2022-11-13 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal Please remove gatling, the last maintainer upload was in 2016, the version currently in the archive is way behind current upstream releases, popcon is virtually non-existent and there's plenty of other httpds in the archive. Cheers, Moritz

Bug#1023697: Keep out of testing

2022-11-08 Thread Moritz Muehlenhoff
Source: wolfssl Version: 5.2.0-2 Severity: serious wolfssl has no active maintainer, plenty of open security issues and we already have too many TLS libraries in our releases. Keep it out of testing. I'm going to file bugs against the handful of reverse deps. Cheers, Moritz

Bug#1022932: Should fbpanel be removed?

2022-10-27 Thread Moritz Muehlenhoff
Source: fbpanel Version: 7.0-4.3 Severity: serious Your package came up as a candidate for removal from Debian: - Depends on Python 2, which will soon be removed - Last maintainer upload five years ago - Dead upstream If you disagree and want to continue to maintain this package, please just

Bug#1022931: Should viewmol be removed?

2022-10-27 Thread Moritz Muehlenhoff
Source: viewmol Version: 2.4.1-26 Severity: serious Your package came up as a candidate for removal from Debian: - Still depends on Python 2 (which will soon be removed) - Dead upstream - Dropped from testing for over two years If you disagree and want to continue to maintain this package,

Bug#1014966: onionshare: CVE-2021-41867 CVE-2021-41868 CVE-2022-21688 CVE-2022-21689 CVE-2022-21690 CVE-2022-21691 CVE-2022-21692 CVE-2022-21693 CVE-2022-21694 CVE-2022-21695 CVE-2022-21696

2022-10-25 Thread Moritz Muehlenhoff
Hi Clément, > Sadly, upstream rectified and confirms it affects 2.2 [0], and has been > tested and reproduced on Bullseye. We do need to fix it. Upstream has a few > suggestions, but I guess our choices are either uploading 2.5 to stable, if > that's possible. python-stem at least will need to be

Bug#1021737: lava: CVE-2022-42902

2022-10-19 Thread Moritz Muehlenhoff
On Tue, Oct 18, 2022 at 06:09:42PM -0300, Antonio Terceiro wrote: > Hi, > > On Thu, Oct 13, 2022 at 09:13:18PM +0200, Moritz Mühlenhoff wrote: > > Source: lava > > X-Debbugs-CC: t...@security.debian.org > > Severity: grave > > Tags: security > > > > Hi, > > > > The following vulnerability was

Bug#1021668: [Pkg-xen-devel] Bug#1021668: xen: CVE-2022-33749 CVE-2022-33748 CVE-2022-33747 CVE-2022-33746

2022-10-19 Thread Moritz Muehlenhoff
> > For the latest set of Xen issues my estimate is that we can postpone > > them until the next batch, they seem all of moderate/limited impact. > > But let me know if you think otherwise. > > I agree. Let's do them together with the new stuff that's planned for > Nov 1st,

Bug#1021668: [Pkg-xen-devel] Bug#1021668: xen: CVE-2022-33749 CVE-2022-33748 CVE-2022-33747 CVE-2022-33746

2022-10-18 Thread Moritz Muehlenhoff
On Tue, Oct 18, 2022 at 02:17:32PM +0200, Hans van Kranenburg wrote: > Does explicitly opening a BTS bug mean that, like we use to call it, > "these CVEs warrant a DSA", No, in general we aim to file bugs for any open CVEs regardless of the DSA state. This allows people to see that an issue is

Bug#1021810: Should firefox-esr be dropped on 32bit architectures in bookworm?

2022-10-15 Thread Moritz Muehlenhoff
On Sat, Oct 15, 2022 at 09:27:33AM +0300, Adrian Bunk wrote: > Package: firefox-esr > Version: 102.3.0esr-1 > Severity: serious > Tags: bookworm sid > X-Debbugs-Cc: Carsten Schoenert , > debian-rele...@lists.debian.org, t...@security.debian.org, > debian-...@lists.debian.org > > [ various

Bug#995838: [htcondor-debian] Bug#995838: Should condor be removed?

2022-09-09 Thread Moritz Muehlenhoff
reassign 995838 condor thanks On Fri, Sep 09, 2022 at 11:17:05AM -0500, Tim Theisen wrote: > I am making progress here. I have built an HTCondor 9.0 LTS version locally > back in May. I was about to upload it and then changes in sid caused it to > not build from sources again. > > The 10.0 LTS

Bug#1019456: RM: patchage -- RoQA; Unmaintained, dead upstream, depends on Python 2

2022-09-09 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal Please remove patchage. It depends on Python 2, the upstream homepage vanished from the internet and there hasn't been a maintainer upload since 2009. Cheers, Moritz

Bug#1019230: Current version is EOLed

2022-09-05 Thread Moritz Muehlenhoff
Source: snort Version: 2.9.15.1-6 Severity: serious Per https://blog.snort.org/2021/07/29150-has-reached-its-end-of-life.html the version currently in sid is EOLed and no longer compatible with current rule updates. In general snort seems unsuitable for standard stable given that the engine

Bug#1018903: RM: flowcanvas -- RoQA; unmaintained, dead upstream, depends on Python 2

2022-09-01 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal Please remove flowcanvas. Removal has already suggested back in 2018 (#888656), there are no reverse dependencies left, the package is unmaintained (last maintainer upload in 2009) and it depends on Python 2. Cheers, Moritz

Bug#1007931: buster-pu: package qemu/1:3.1+dfsg-8+deb10u9

2022-08-22 Thread Moritz Muehlenhoff
On Mon, Aug 22, 2022 at 02:50:41PM +0530, Abhijith PA wrote: > Hello Moritz, > > I've prepared a qemu build months back fixing pending CVEs then. I > have now took 2 patches (CVE-2020-35504, CVE-2020-35505) from your > diff and backported a new CVE, fixing total of ~35 CVEs. > > I've tested

Bug#1017579: Freeciv < 2.6.7, freeciv-3.0 < 3.0.3, Modpack Installer buffer overflow

2022-08-17 Thread Moritz Muehlenhoff
Source: freeciv Version: 2.6.6-1 Severity: grave Tags: security X-Debbugs-Cc: Debian Security Team Quoting from the announcement posted to oss-security (no CVE is available): -- Just released freeciv-2.6.7 & freeciv-3.0.3 fix

Bug#1017368: RM: libaio-ocaml/experimental -- RoQA; obsolete

2022-08-14 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal This was uploaded only to experimental over a decade ago. Given it was never actually uploaded to unstable let's simply remove it... Cheers, Moritz

Bug#1017103: Provide transition package for geda-gaf

2022-08-13 Thread Moritz Muehlenhoff
Source: lepton-eda Version: 1.9.18-1 Severity: wishlist geda-gaf has been removed from the archive. In #1008700 it was mentioned that lepton-eda is a sufficient replacement, so it could provide a transition package to help existing geda-gaf users. Cheers, Moritz

Bug#1017062: Should kross be removed?

2022-08-12 Thread Moritz Muehlenhoff
Source: kross Version: 5.96.0-1 Severity: serious See #1017061, kross isn't useful without interpreters. Cheers, Moritz

Bug#1017061: Should kross-interpreters be removed?

2022-08-12 Thread Moritz Muehlenhoff
Source: kross-interpreters Version: 4:21.12.3-1 Severity: serious Your package came up as a candidate for removal from Debian. On IRC Sune mentioned that libkross is most probably unused these days and on the KF6 removal list. And the Python bindings still depend on Python 2 (without porting

<    1   2   3   4   5   6   7   8   9   10   >