Bug#993372: Bug#993378: RM: gtkpod -- RoQA; Upstream not active, orphaned & uses a vulnerable embedded library

2021-09-01 Thread Adrian Bunk
On Wed, Sep 01, 2021 at 09:32:09AM +0100, Neil Williams wrote: >... > Hi Adrian. Hi Neil, > Sorry, No. The commit linked to CVE-2021-37232 does not even fix the > problem described as being fixed by that commit in atomicparsley, at > least in my testing using the data file supplied by upstream.

Bug#993372: Bug#993378: RM: gtkpod -- RoQA; Upstream not active, orphaned & uses a vulnerable embedded library

2021-09-01 Thread Neil Williams
On Wed, 1 Sep 2021 12:08:16 +0300 Adrian Bunk wrote: > On Wed, Sep 01, 2021 at 09:32:09AM +0100, Neil Williams wrote: > >... > > Hi Adrian. > > Hi Neil, > > > Sorry, No. The commit linked to CVE-2021-37232 does not even fix the > > problem described as being fixed by that commit in

Bug#993372: Bug#993378: RM: gtkpod -- RoQA; Upstream not active, orphaned & uses a vulnerable embedded library

2021-09-01 Thread Neil Williams
On Wed, 1 Sep 2021 11:05:09 +0300 Adrian Bunk wrote: > Control: tags 993378 moreinfo > > On Tue, Aug 31, 2021 at 03:49:45PM +0100, Neil Williams wrote: > > Package: ftp.debian.org > > Severity: normal > > > > gtkpod upstream has moved but has not had any activity for over 5 > > years. > > > >

Bug#993372: Bug#993378: RM: gtkpod -- RoQA; Upstream not active, orphaned & uses a vulnerable embedded library

2021-09-01 Thread Adrian Bunk
Control: tags 993378 moreinfo On Tue, Aug 31, 2021 at 03:49:45PM +0100, Neil Williams wrote: > Package: ftp.debian.org > Severity: normal > > gtkpod upstream has moved but has not had any activity for over 5 years. > > When investigating the two CVEs against AtomicParsley, former maintainer >