Re: Python rexec and Bastion flaws

2003-01-23 Thread Bastian Kleineidam
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

On Tue, Jan 21, 2003 at 07:47:11AM +0100, Martin Schulze wrote:
> > I suggest to disable the above two modules in python2.2 (which is in
> > woody), even if existing applications can break. What do you think?
> 
> I'd rather know about the vulnerability (and maybe doko is able to
> implement a fix) than to blindly castrate software.  Theo d.R. already
> taught us that blindly releasing updates are not good.

Yup, ok. I will see if I can identify packages using rexec or Bastion
and provide patches for them instead of disabling modules.

Cheers, Bastian

- -- 
 Bastian Kleineidam

 Atombombe  Plutonium  Fat Man  Do it Yourself  Tim Taylor
-BEGIN PGP SIGNATURE-
Version: GnuPG v1.2.1 (GNU/Linux)

iD8DBQE+MBnOeBwlBDLsbz4RAvkdAKDJwrV2OBbeoaO4jkKYNlsCfPapeQCeMa/x
KjqJsBk60KpWPQ2GL/nstRI=
=DgqG
-END PGP SIGNATURE-




Mentor needed for python-opengl2

2003-01-23 Thread Thomas Wouters

Hi, my name is Thomas Wouters and I'm looking for a mentor. :)

The PyOpenGL debian package, python-opengl, is heavily outdated, being
version 1.5.7 whereas the upstream stable version is 2.0.0.44 by now. It
also has some other issues, like being built against the wrong version of
Tk. PyOpenGL 2.0 is a not-quite-compatible release though, being one of
those 'rewrite' major changes. It does improve greatly on the Python OpenGL
bindings, and fixes a bunch of bugs. Python-opengl's maintainer, Enrique
Zanardi (see Cc), doesn't have the time or inclination anymore to maintain
the package, as he explained in a seperate email to me, and offered I adopt
the package or build new binary packages. In either case, I'm in need of a
mentor.

I've debianized PyOpenGL 2.0.0.44 based on how python-opengl 1.5.7 does it,
naming it python-opengl2 to avoid the API compatibility issues. I've tested
the resulting .deb fairly thoroughly on my own system, including with
lintian. There are a few minor policy issues though, including the fact that
the software falls (partially) under the SGI Free Software License B... I'm
not sure if I should elaborate here or not. A mentor would be greatly
appreciated. :)

-- 
Thomas Wouters <[EMAIL PROTECTED]>

Hi! I'm a .signature virus! copy me into your .signature file to help me spread!