Bug#639916: spread: license wackiness

2011-08-31 Thread Hendrik Weimer
Ken Arromdee writes: > Unlike the original BSD 4 clause license this adds "or software that uses > this software". > > If I interpret this broadly (all software that uses this software must > display the sentence) it's non-free, since it imposes conditions on > non-derived software that happens t

Bug#423379: OpenSSL license violation

2007-05-11 Thread Hendrik Weimer
Package: kmymoney2 Version: 0.8.6-1 Severity: serious According to the copyright file kmymoney2 is being distributed under GPLv2. However, it depends on libgwenhywfar, which in turns is linked against OpenSSL. While libgwenhywfar contains an OpenSSL exception, kmymoney2 does not. So, please obtai

Bug#403034: Deep MIME Nesting Content Filter Bypass

2006-12-14 Thread Hendrik Weimer
Package: clamav Version: 0.88.7-1 Severity: grave Tags: security While the new 0.88.7 version fixes CVE-2006-6406 and CVE-2006-6481 the update introduces another flaw that lets viruses pass undetected. If a virus is nested deeper than the --max-mail-recursion limit, the file will pass and ClamAV's

Bug#401873: closed by Stephen Gran <[EMAIL PROTECTED]> (Bug#401873: fixed in clamav 0.90~rc2-1)

2006-12-13 Thread Hendrik Weimer
The bug is still present in 0.88.7. Files nested deeper than --max-mail-recursion are not scanned and there is no error returned (exit code is 0). When using clamscan I get a warning from libclamav, but the EICAR string still passes. -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject o

Bug#401873: Unusual MIME Encoding Content Filter Bypass

2006-12-06 Thread Hendrik Weimer
Package: clamav Version: 0.88.6-1 Tags: security Severity: grave As reported in http://www.quantenblog.net/security/virus-scanner-bypass ClamAV passed an EICAR test file if the following conditions are met: 1. the EICAR file is encoded in Base64 including characters not in the standard alphab

Bug#325472: libaqhbci-qt-tools: uninstallable

2005-08-28 Thread Hendrik Weimer
Package: libaqhbci-qt-tools Severity: grave Justification: renders package unusable The following packages have unmet dependencies: libaqhbci-qt-tools: Depends: libaqbanking0 but it is not installable Depends: libaqhbci2 but it is not going to be installed