Re: Security update for ‘burn’ package

2009-08-26 Thread Adam D. Barratt
On Thu, 2009-08-27 at 14:06 +1000, Ben Finney wrote: > "Adam D. Barratt" writes: > > Please could you prepare and send an updated diff which does not include > > the removal of old commented out code and the removal of functions from > > "import" lines where the code is no longer used? > > Done n

Re: Security update for ‘burn’ package

2009-08-26 Thread Ben Finney
"Adam D. Barratt" writes: > Ah, yes, I missed that on my first skim through the diff due to the > horrible indent level. :-/ Take a guess what was one of the first refactoring operations done to the code base by new upstream :-) > Looking through the diff again, there are a lot of changes which

Re: Security update for ‘burn’ package

2009-08-26 Thread Adam D. Barratt
On Wed, 2009-08-26 at 10:21 +1000, Ben Finney wrote: > "Adam D. Barratt" writes: > > > On Sun, 2009-08-23 at 15:57 +1000, Ben Finney wrote: > > In either case, the answer is yes - uploads to any Debian archive must > > be signed by a key in the Debian keyring. > > Okay. So I should seek a sponso

Re: Security update for ‘burn’ package

2009-08-25 Thread Ben Finney
"Adam D. Barratt" writes: > On Sun, 2009-08-23 at 15:57 +1000, Ben Finney wrote: > > Question: Is it correct to put changes in a stable update that > > effectively make a dead-end branch in the history? > > Does the version of the package in unstable suffer from the same > security issues

Re: Security update for ‘burn’ package

2009-08-25 Thread Adam D. Barratt
On Sun, 2009-08-23 at 15:57 +1000, Ben Finney wrote: > The package ‘burn’ has a security bug open, assigned the alert number > TEMP-0542329 “burn: Insecure escaping of file names”. I have been > advised to make a bug-fix release of this package for ‘stable’ and > send a ‘debdiff’ output to this for

Re: Security update for ‘burn’ package

2009-08-23 Thread Ben Finney
Stephen Gran writes: > What I think Ben means is that there is an issue with his package that > doesn't warrant a DSA, but that he would like to see fixed in stable. Or rather, that I've been told [0]: […] we encourage maintainers to fix such minor security issues through a point update

Re: Security update for ‘burn’ package

2009-08-23 Thread Ben Finney
Philipp Kern writes: > On Sun, Aug 23, 2009 at 03:57:34PM +1000, Ben Finney wrote: > > The package ‘burn’ has a security bug open, assigned the alert > > number TEMP-0542329 “burn: Insecure escaping of file names”. I have > > been advised to make a bug-fix release of this package for ‘stable’ > >

Security update for ‘burn ’ package

2009-08-22 Thread Ben Finney
Howdy all, The package ‘burn’ has a security bug open, assigned the alert number TEMP-0542329 “burn: Insecure escaping of file names”. I have been advised to make a bug-fix release of this package for ‘stable’ and send a ‘debdiff’ output to this forum. Please excuse my caution, since this is my f