Bug#1074275: Depends on gpac

2024-06-25 Thread Moritz Muehlenhoff
Source: ogmrip Version: 1.0.1-4 Severity: serious gpac is unsupportable and thus orphaned and not in stable. It should be removed, but ogmrip depends on it. From a quick glance ogmrip also supports mencoder, so possibly that dependency could simply get removed? Cheers, Moritz

Bug#1074276: Depends on gpac

2024-06-25 Thread Moritz Muehlenhoff
Source: ccextractor Version: 0.94+ds1-3 Severity: serious gpac is unsupportable, thus orphaned and not in Bookworm. It should be removed, but ccextractor build depends on it. From a quick glance is also has some build flags for ffmpeg, so maybe that's an alternative? Cheers, Moritz

Bug#1072366: libndp: CVE-2024-5564

2024-06-16 Thread Moritz Muehlenhoff
On Fri, Jun 14, 2024 at 07:30:46AM +0200, Florian Ernst wrote: > On Thu, Jun 13, 2024 at 08:17:41PM +0200, Moritz Muehlenhoff wrote: > > Thanks, these look good! Please upload to security-master, I'll take care > > of the DSA over the weekend. > > Thanks for verify

Bug#1072366: libndp: CVE-2024-5564

2024-06-13 Thread Moritz Muehlenhoff
Hi Florian, > Please give those packages an additional check, and feel free to just > upload them when they indeed meet your requirements, or briefly ping me > back for me to upload them / possibly apply further changes, whatever > suits you best. Thanks, these look good! Please upload to securit

Bug#1072366: libndp: CVE-2024-5564

2024-06-10 Thread Moritz Muehlenhoff
Hi Florian, On Mon, Jun 10, 2024 at 08:41:27AM +0200, Florian Ernst wrote: > Dear Security Team, > > On Sat, Jun 01, 2024 at 04:57:53PM +0200, Salvatore Bonaccorso wrote: > > [...] > > [0] https://security-tracker.debian.org/tracker/CVE-2024-5564 > > https://www.cve.org/CVERecord?id=CVE-2024-

Bug#1071628: python-pymysql: CVE-2024-36039

2024-05-28 Thread Moritz Muehlenhoff
On Tue, May 28, 2024 at 09:06:51AM +0200, Thomas Goirand wrote: > On 5/22/24 17:08, Moritz Mühlenhoff wrote: > > The following vulnerability was published for python-pymysql. > > > > We should also fix this in a DSA, could you prepare debdiffs for > > bookworm-security and bullseye-security? > >

Bug#1053004: CVE-2019-10784 and CVE-2023-40619

2024-05-22 Thread Moritz Muehlenhoff
On Wed, May 22, 2024 at 02:42:58PM -0300, Leandro Cunha wrote: > Hi everyone, > > On Wed, May 22, 2024 at 12:39 PM Moritz Mühlenhoff wrote: > > > > Am Wed, Mar 06, 2024 at 06:39:01AM -0300 schrieb Leandro Cunha: > > > Hi Christoph Berg, > > > > > > On Wed, Mar 6, 2024 at 5:42 AM Christoph Berg w

Bug#1069762: pdns-recursor: CVE-2024-25583 - 4.8.8 for stable

2024-04-24 Thread Moritz Muehlenhoff
On Thu, Apr 25, 2024 at 08:37:14AM +0200, Chris Hofstaedtler wrote: > Hi Moritz, > > could we once again use the upstream release for stable? > debdiff 4.8.7-1 -> 4.8.8-1 is attached. Ack. Following the 4.8 releases has served us well. debdiff looks fine, please build with -sa and upload to secur

Bug#1068818: sngrep: CVE-2024-3119 CVE-2024-3120

2024-04-21 Thread Moritz Muehlenhoff
On Sun, Apr 21, 2024 at 07:35:43PM +, Victor Seva wrote: > Hi, > > > I've just uploaded sngrep 1.8.1-1 to sid and prepared 1.6.0-1+deb12u1 for > bookworms-security [0]. > > Attached debdiff file. > > Waiting for you reply, > Victor > > [0] > https://salsa.debian.org/pkg-voip-team/sngrep/

Bug#1068412: apache2: CVE-2024-27316 CVE-2024-24795 CVE-2023-38709

2024-04-05 Thread Moritz Muehlenhoff
On Fri, Apr 05, 2024 at 08:16:43AM +0400, Yadd wrote: > On 4/4/24 22:51, Moritz Mühlenhoff wrote: > > Source: apache2 > > X-Debbugs-CC: t...@security.debian.org > > Severity: grave > > Tags: security > > > > Hi, > > > > The following vulnerabilities were published for apache2. > > > > CVE-2024-2

Bug#1060407: gtkwave update for {bookworm,bullseye,buster}-security

2024-04-03 Thread Moritz Muehlenhoff
Hi Adrian, > >... > > > debdiffs contain only changes to debian/ > > > > The bookworm/bullseye debdiffs looks good, please upload to > > security-master, thanks! > > both are now uploaded. DSA has been released, thanks! > > Note that both need -sa, but dak needs some special attention when >

Bug#1060407: Multiple security issues

2024-01-10 Thread Moritz Muehlenhoff
Source: gtkwave Version: 3.3.116-1 Severity: grave Tags: security X-Debbugs-Cc: Debian Security Team A very thorough security audit of gtkwave unveiled a total of 82 security issues in gtkwave, all fixed in 3.3.118: CVE-2023-32650 CVE-2023-34087 CVE-2023-34436 CVE-2023-35004 CVE-2023-35057 CVE-2

Bug#1059054: nss: CVE-2023-6135

2023-12-20 Thread Moritz Muehlenhoff
On Wed, Dec 20, 2023 at 11:43:11AM +0900, Mike Hommey wrote: > Version: 2:3.95-1 > > On Tue, Dec 19, 2023 at 10:21:27PM +0100, Moritz Mühlenhoff wrote: > > Source: nss > > X-Debbugs-CC: t...@security.debian.org > > Severity: grave > > Tags: security > > > > Hi, > > > > The following vulnerabilit

Bug#1054666: open-vm-tools: CVE-2023-34059 CVE-2023-34058

2023-10-31 Thread Moritz Muehlenhoff
On Tue, Oct 31, 2023 at 10:29:55AM +0100, Bernd Zeimetz wrote: > > Both uploaded! DSA has been released, thanks! Cheers, Moritz

Bug#1054666: open-vm-tools: CVE-2023-34059 CVE-2023-34058

2023-10-30 Thread Moritz Muehlenhoff
On Mon, Oct 30, 2023 at 07:09:53PM +0100, Bernd Zeimetz wrote: > Hi Moritz, > > as usual, stable/oldstable updates prepared, diffs are attached to this > mail as salsa seems to have some issues right now. > > https://salsa.debian.org/vmware-packaging-team/pkg-open-vm-tools/ - > bookworm/bullseye

Bug#1051888: Should Kino be removed?

2023-09-13 Thread Moritz Muehlenhoff
Source: kino Version: 1.3.4+dfsg0-1.1 Severity: serious Your package came up as a candidate for removal from Debian: - Dead upstream for a decade - FTBFS with ffmpeg 5 since 1.5 years (Debian is at ffmpeg 6 by now) - Depends on various legacy libs (GTK2, Glade) If you disagree and want to continu

Bug#1050970: open-vm-tools: CVE-2023-20900

2023-09-07 Thread Moritz Muehlenhoff
On Thu, Sep 07, 2023 at 11:43:27AM +0200, Bernd Zeimetz wrote: > Hi Moritz, > > > Ack, that's perfectly fine! > > > > Thanks! > > Here are the current diffs: > > bullseye: > https://salsa.debian.org/vmware-packaging-team/pkg-open-vm-tools/-/compare/15b2b38edd7834b7ad93ae25831fc7ef2bf7ce28...bu

Bug#1037178: puppet does not sync files anymore after recent ruby2.5 security upload

2023-06-07 Thread Moritz Muehlenhoff
On Wed, Jun 07, 2023 at 01:43:26PM +0530, Utkarsh Gupta wrote: > Hi Chris, > > On Wed, Jun 7, 2023 at 12:56 PM Salvatore Bonaccorso > wrote: > > Can you please have a look, as this seems to be caused by the DLA > > issued as DLA-3447-1. > > This has been caused by the ruby2.5 update. It's defi

Bug#1035474: Don't include in Bookworm?

2023-05-30 Thread Moritz Muehlenhoff
On Wed, May 31, 2023 at 09:28:02AM +0300, Timo Aaltonen wrote: > Moritz Muehlenhoff kirjoitti 3.5.2023 klo 20.44: > > Source: libdmx > > Version: 1:1.1.4-2 > > Severity: serious > > > > The Xorg folks mentioned at > > https://www.openwall.com/lists/oss-se

Bug#1034824: tomcat9 should not be released with Bookworm

2023-05-26 Thread Moritz Muehlenhoff
On Fri, May 26, 2023 at 12:10:18AM +0200, Markus Koschany wrote: > First of all trapperkeeper-webserver-jetty9-clojure should add a build- > dependency on logback to detect such regressions in advance. > > #1036250 is mainly a logback problem, not a tomcat problem. I still would like > to hear Emm

Bug#1036279: XSS in RSS syntax

2023-05-18 Thread Moritz Muehlenhoff
Source: dokuwiki Version: 0.0.20220731.a-1 Severity: grave Tags: security X-Debbugs-Cc: Debian Security Team No CVE yet: https://huntr.dev/bounties/c6119106-1a5c-464c-94dd-ee7c5d0bece0/ https://github.com/dokuwiki/dokuwiki/pull/3967 https://www.github.com/splitbrain/dokuwiki/commit/53df38b0e44658

Bug#1035474: Don't include in Bookworm?

2023-05-03 Thread Moritz Muehlenhoff
Source: libdmx Version: 1:1.1.4-2 Severity: serious The Xorg folks mentioned at https://www.openwall.com/lists/oss-security/2023/05/02/3: | We have also announced that we plan to retire the following packages soon | and while their gitlab repos are not yet archived, we expect they will be | arch

Bug#1034732: Keep out of testing

2023-04-22 Thread Moritz Muehlenhoff
Package: gpac Version: 2.0.0+dfsg1-2+b1 Severity: serious In some discussion between Reinhard, Sebastian and the Security team we've come to the conclusion that gpac isn't suitable to be included in a stable release. The massive influx of security issues makes that untenable (and there's no suit

Bug#1033335: Don't include in Bookworm

2023-03-22 Thread Moritz Muehlenhoff
Source: rust-const-cstr Version: 0.3.0-1 Severity: serious Hi, there is https://rustsec.org/advisories/RUSTSEC-2023-0020.html which flags that rust-const-cstr is unmaintained. Since there are no reverse deps in the archive, let's exclude it from bookworm (or rather remove rightaway)? Cheers,

Bug#1033334: Don't include in Bookworm

2023-03-22 Thread Moritz Muehlenhoff
Source: rust-boxfnonce Version: 0.1.1-2 Severity: serious Per https://rustsec.org/advisories/RUSTSEC-2019-0040.html rust-boxfnonce is obsolete, let's keep it out of bookworm (and remove from the archive). Cheers, Moritz

Bug#1033333: Don't include in Bookworm

2023-03-22 Thread Moritz Muehlenhoff
Source: rust-encoding Version: 0.2.33-1 Severity: serious Hi, there is https://rustsec.org/advisories/RUSTSEC-2021-0153.html which flags that rust-encoding is unmaintained. Since there are no reverse deps in the archive, let's exclude it from bookworm (or rather remove rightaway)? Cheers,

Bug#1032476: apache2: CVE-2023-25690 CVE-2023-27522

2023-03-08 Thread Moritz Muehlenhoff
On Wed, Mar 08, 2023 at 07:09:20AM +0400, Yadd wrote: > On 3/7/23 23:46, Salvatore Bonaccorso wrote: > > Source: apache2 > > Version: 2.4.55-1 > > Severity: grave > > Tags: security upstream > > X-Debbugs-Cc: car...@debian.org, Debian Security Team > > > > > > Hi, > > > > The following vulnerab

Bug#1030669: Only include in Bookworm with commitment to stable updates

2023-03-08 Thread Moritz Muehlenhoff
On Wed, Mar 08, 2023 at 02:20:25PM +0100, Marco d'Itri wrote: 0;115;0c> On Feb 14, Moritz Muehlenhoff wrote: > > > > > Varnish should only be included in Bookworm with a reliable commitment > > > > by the maintainers to backport/test security fixes across

Bug#1032086: Don't include in Bookworm

2023-02-27 Thread Moritz Muehlenhoff
Source: golang-github-labstack-echo.v3 Version: 3.3.10-2 Severity: serious This is an older version of src:golang-github-labstack-echo. None of the reverse deps are currently in bookworm, so golang-github-labstack-echo.v3 should be dropped as well (and post freeze the reverse deps fixed and the pa

Bug#1032085: Don't include in Bookworm

2023-02-27 Thread Moritz Muehlenhoff
Source: golang-github-labstack-echo.v2 Version: 2.2.0-3 Severity: serious This is an older version of src:golang-github-labstack-echo. None of the reverse deps are currently in bookworm, so golang-github-labstack-echo.v2 should be dropped as well (and post freeze the reverse deps fixed and the pac

Bug#972146: /usr/share/applications/mono-runtime-common.desktop: should not handle MIME type by executing arbitrary code

2023-02-18 Thread Moritz Muehlenhoff
On Sat, Feb 18, 2023 at 12:04:27PM +0100, Gabriel Corona wrote: > I believe obtaining a CVE ID would be beneficial so that this issue may be > tracked by downstream projects/distributions. All those distros were notified via your post to oss-security. You can try cveform, if there's no assignment

Bug#1030669: Only include in Bookworm with commitment to stable updates

2023-02-14 Thread Moritz Muehlenhoff
On Tue, Feb 14, 2023 at 02:48:43AM +0100, Marco d'Itri wrote: > On Feb 02, Moritz Muehlenhoff wrote: > > > Varnish should only be included in Bookworm with a reliable commitment > > by the maintainers to backport/test security fixes across the typical > > three

Bug#1031046: Only include in Bookworm with commitment to stable updates

2023-02-10 Thread Moritz Muehlenhoff
Source: asterisk Version: 1:20.1.0~dfsg+~cs6.12.40431414-1 Severity: serious Asterisk should only be included in Bookworm with a reliable commitment by the maintainers to backport/test security fixes across the typical three year life cycle (two years of stable-security and one year of oldstable-s

Bug#1030669: Only include in Bookworm with commitment to stable updates

2023-02-06 Thread Moritz Muehlenhoff
Source: varnish Version: 7.1.1-1.1 Severity: serious Varnish should only be included in Bookworm with a reliable commitment by the maintainers to backport/test security fixes across the typical three year life cycle (two years of stable-security and one year of oldstable-security). Especially sin

Bug#1019230: Bug#1021276: Pending snort 2.9.20 update

2023-01-21 Thread Moritz Muehlenhoff
On Sat, Jan 21, 2023 at 10:53:24PM +0100, Markus Koschany wrote: > Hi Javier, > > Am Freitag, dem 20.01.2023 um 22:23 +0100 schrieb Javier Fernandez-Sanguino: > > Dear Markus, > > > > Thank you for preparing. Could you please share the patch you are working > > on? > > Snort is available in Sals

Bug#1028421: Only include in Bookworm with commitment to stable updates

2023-01-10 Thread Moritz Muehlenhoff
Source: salt Severity: serious salt is currently RC-buggy and not in testing, but regardless of the remaining RC bugs getting fixed it should only get re-included with a reliable commitment to backport/test security-updates across the typical three year life cycle (two years of stable-security and

Bug#1004441: unblocking chromium?

2023-01-06 Thread Moritz Muehlenhoff
On Fri, Jan 06, 2023 at 08:41:50AM +0100, Paul Gevers wrote: > Dear Chromium team, Security team, > > On 27-01-2022 17:15, Moritz Muehlenhoff wrote: > > On Wed, Jan 26, 2022 at 09:38:42PM +0100, Paul Gevers wrote: > > > > So, I'm proposing the following: we unblo

Bug#1026163: Uses Java 11

2022-12-15 Thread Moritz Muehlenhoff
Source: puppetdb Version: 7.11.2-3 Severity: grave Thanks for all the great work on Puppetdb! I was trying to setup a test environment with Puppetdb 7.11.2 from current testing and I noticed that it's using openjdk-11-jre-headless. While openjdk-11 is currently still in testing, Bookworm will on

Bug#1025011: Keep out of bookworm unless actively maintained

2022-11-28 Thread Moritz Muehlenhoff
Source: netatalk Version: 3.1.13~ds-2 Severity: serious netatalk should not enter bookworm unless it gets adopted and actively maintained. Cheers, Moritz

Bug#1024561: Unmaintained, keep out of stable

2022-11-21 Thread Moritz Muehlenhoff
Source: maradns Version: 2.0.13-1.4 Severity: serious The last maintainer upload was in 2015 and the version currently in the archive is way behind current upstream releases (which is at 3.4.07), we have plenty of maintained DNS servers, keep it out of testing ( and if noone picks it up, remove it

Bug#1023697: Keep out of testing

2022-11-08 Thread Moritz Muehlenhoff
Source: wolfssl Version: 5.2.0-2 Severity: serious wolfssl has no active maintainer, plenty of open security issues and we already have too many TLS libraries in our releases. Keep it out of testing. I'm going to file bugs against the handful of reverse deps. Cheers, Moritz

Bug#1022931: Should viewmol be removed?

2022-10-27 Thread Moritz Muehlenhoff
Source: viewmol Version: 2.4.1-26 Severity: serious Your package came up as a candidate for removal from Debian: - Still depends on Python 2 (which will soon be removed) - Dead upstream - Dropped from testing for over two years If you disagree and want to continue to maintain this package, pleas

Bug#1022932: Should fbpanel be removed?

2022-10-27 Thread Moritz Muehlenhoff
Source: fbpanel Version: 7.0-4.3 Severity: serious Your package came up as a candidate for removal from Debian: - Depends on Python 2, which will soon be removed - Last maintainer upload five years ago - Dead upstream If you disagree and want to continue to maintain this package, please just clos

Bug#1014966: onionshare: CVE-2021-41867 CVE-2021-41868 CVE-2022-21688 CVE-2022-21689 CVE-2022-21690 CVE-2022-21691 CVE-2022-21692 CVE-2022-21693 CVE-2022-21694 CVE-2022-21695 CVE-2022-21696

2022-10-25 Thread Moritz Muehlenhoff
Hi Clément, > Sadly, upstream rectified and confirms it affects 2.2 [0], and has been > tested and reproduced on Bullseye. We do need to fix it. Upstream has a few > suggestions, but I guess our choices are either uploading 2.5 to stable, if > that's possible. python-stem at least will need to be

Bug#1021737: lava: CVE-2022-42902

2022-10-19 Thread Moritz Muehlenhoff
On Tue, Oct 18, 2022 at 06:09:42PM -0300, Antonio Terceiro wrote: > Hi, > > On Thu, Oct 13, 2022 at 09:13:18PM +0200, Moritz Mühlenhoff wrote: > > Source: lava > > X-Debbugs-CC: t...@security.debian.org > > Severity: grave > > Tags: security > > > > Hi, > > > > The following vulnerability was pu

Bug#1021810: Should firefox-esr be dropped on 32bit architectures in bookworm?

2022-10-15 Thread Moritz Muehlenhoff
On Sat, Oct 15, 2022 at 09:27:33AM +0300, Adrian Bunk wrote: > Package: firefox-esr > Version: 102.3.0esr-1 > Severity: serious > Tags: bookworm sid > X-Debbugs-Cc: Carsten Schoenert , > debian-rele...@lists.debian.org, t...@security.debian.org, > debian-...@lists.debian.org > > [ various potent

Bug#1019230: Current version is EOLed

2022-09-05 Thread Moritz Muehlenhoff
Source: snort Version: 2.9.15.1-6 Severity: serious Per https://blog.snort.org/2021/07/29150-has-reached-its-end-of-life.html the version currently in sid is EOLed and no longer compatible with current rule updates. In general snort seems unsuitable for standard stable given that the engine needs

Bug#1017579: Freeciv < 2.6.7, freeciv-3.0 < 3.0.3, Modpack Installer buffer overflow

2022-08-17 Thread Moritz Muehlenhoff
Source: freeciv Version: 2.6.6-1 Severity: grave Tags: security X-Debbugs-Cc: Debian Security Team Quoting from the announcement posted to oss-security (no CVE is available): -- Just released freeciv-2.6.7 & freeciv-3.0.3 fix b

Bug#1017062: Should kross be removed?

2022-08-12 Thread Moritz Muehlenhoff
Source: kross Version: 5.96.0-1 Severity: serious See #1017061, kross isn't useful without interpreters. Cheers, Moritz

Bug#1017061: Should kross-interpreters be removed?

2022-08-12 Thread Moritz Muehlenhoff
Source: kross-interpreters Version: 4:21.12.3-1 Severity: serious Your package came up as a candidate for removal from Debian. On IRC Sune mentioned that libkross is most probably unused these days and on the KF6 removal list. And the Python bindings still depend on Python 2 (without porting activ

Bug#1016974: sofia-sip: CVE-2022-31001 CVE-2022-31002 CVE-2022-31003

2022-08-11 Thread Moritz Muehlenhoff
On Thu, Aug 11, 2022 at 11:08:49PM +0200, Evangelos Ribeiro Tzaras wrote: > Hi Moritz, > > On Wed, 2022-08-10 at 22:08 +0200, Moritz Mühlenhoff wrote: > > Source: sofia-sip > > X-Debbugs-CC: t...@security.debian.org > > Severity: grave > > Tags: security > > > > Hi, > > > > The following vulnera

Bug#1016986: Should pd-py be removed?

2022-08-10 Thread Moritz Muehlenhoff
Source: pd-py Version: 0.2.2+git20170625.1.88fc77a-2 Severity: serious Your package came up as a candidate for removal from Debian: - Still depends on Python 2, which is finally being removed in Bookworm - Last upload in 2018 If you disagree and want to continue to maintain this package, please j

Bug#1016983: Should k3d be removed?

2022-08-10 Thread Moritz Muehlenhoff
Source: k3d Version: 0.8.0.6-8 Severity: serious Your package came up as a candidate for removal from Debian: - Python 2 will finally be removed in Bookworm and there's no upstream porting activity - Last upload four years ago - Multiple other FTBFS issue If you disagree and want to continue to

Bug#1016139: For Review: Bug#1016139: (net-snmp: CVE-2022-24810 CVE-2022-24809 CVE-2022-24808 CVE-2022-24807 CVE-2022-24806 CVE-2022-24805)

2022-08-10 Thread Moritz Muehlenhoff
On Wed, Aug 10, 2022 at 05:05:12PM +1000, Craig Small wrote: > > Do you have capacity to prepare updates for bullseye? > > > Yes, see attached debdiff for review. It's just those two patches. Looks good, thanks! Please upload to security-master. Cheers, Moritz

Bug#1016667: Should this package be removed?

2022-08-04 Thread Moritz Muehlenhoff
Source: caldav-tester Version: 7.0+20190225-4 Severity: serious Your package came up as a candidate for removal from Debian: The plan is to remove Python 2 in Bookworm and there's no porting activity towards Python 3. If you disagree and want to continue to maintain this package, please just clos

Bug#1015980: Should pd-aubio be removed?

2022-07-24 Thread Moritz Muehlenhoff
Source: pd-aubio Version: 0.4-1 Severity: serious Your package came up as a candidate for removal from Debian: - Still depends on Python 2 - Last upload in 2014 If you disagree and want to continue to maintain this package, please just close this bug (and fix the open issues). If you agree with

Bug#1015981: Should grokmirror be removed?

2022-07-24 Thread Moritz Muehlenhoff
Source: grokmirror Version: 1.0.0-1.1 Severity: serious Your package came up as a candidate for removal from Debian: - Still depends on Python 2 - Last maintainer upload in 2016 If you disagree and want to continue to maintain this package, please just close this bug (and fix the open issues). I

Bug#1015979: Should python-unshare be removed?

2022-07-24 Thread Moritz Muehlenhoff
Source: python-unshare Version: 0.2-1 Severity: serious Your package came up as a candidate for removal from Debian: - Still depends on Python 2 - Last upload in 2016 If you disagree and want to continue to maintain this package, please just close this bug (and fix the open issues). If you agree

Bug#1015978: Should falcon be removed?

2022-07-24 Thread Moritz Muehlenhoff
Source: falcon Version: 1.8.8-1 Severity: serious Your package came up as a candidate for removal from Debian: - Still depends on Python 2 - Dropped from testing in 2018 - Last upload in 2017 If you disagree and want to continue to maintain this package, please just close this bug (and fix the op

Bug#1015977: Should vland be removed?

2022-07-24 Thread Moritz Muehlenhoff
Source: vland Version: 0.8-1 Severity: serious Your package came up as a candidate for removal from Debian, it's one of the few remaining packages still depending on Python 2 and there're no visible upstream activity to port it to vland? If you disagree and want to continue to maintain this packa

Bug#1015976: Should vmm be removed?

2022-07-24 Thread Moritz Muehlenhoff
Source: vmm Version: 0.6.2-2 Severity: serious Your package came up as a candidate for removal from Debian: - Still depends on Python 2 - Last upload in 2017, removed from testing since 2019 If you disagree and want to continue to maintain this package, please just close this bug (and fix the ope

Bug#1015975: Should python-neuroshare be removed?

2022-07-24 Thread Moritz Muehlenhoff
Source: python-neuroshare Version: 0.9.2-1 Severity: serious Your package came up as a candidate for removal from Debian: - Still depends on Python 2 - Last upload in 2014 - Dead upstream (last commits from 2016) If you disagree and want to continue to maintain this package, please just close thi

Bug#1015974: Should gnat-gps be removed?

2022-07-24 Thread Moritz Muehlenhoff
Source: gnat-gps Version: 19.2-3 Severity: serious Your package came up as a candidate for removal from Debian: - Still depends on Python 2 - Removed from testing since 2019 If you disagree and want to continue to maintain this package, please just close this bug (and fix the open issues). If yo

Bug#1015973: Should xdeb be removed?

2022-07-24 Thread Moritz Muehlenhoff
Source: xdeb Version: 0.6.7 Severity: serious Your package came up as a candidate for removal from Debian: - Still depends on Python 2 - No upload since five years If you disagree and want to continue to maintain this package, please just close this bug (and fix the open issues). If you agree w

Bug#1012513: apache2: CVE-2022-31813 CVE-2022-26377 CVE-2022-28614 CVE-2022-28615 CVE-2022-29404 CVE-2022-30522 CVE-2022-30556

2022-06-08 Thread Moritz Muehlenhoff
On Wed, Jun 08, 2022 at 07:51:28PM +0200, Yadd wrote: > Hi, > > those CVEs are tagged low/moderate by upstream, why did you tag this bug as > grave ? Anything moderate or above should get fixed by the next Debian release IOW RC severity. Cheers, Moritz

Bug#1012138: CVE-2021-40426

2022-05-30 Thread Moritz Muehlenhoff
Source: sox Version: 14.4.2+git20190427-3 Severity: grave Tags: security X-Debbugs-Cc: Debian Security Team https://talosintelligence.com/vulnerability_reports/TALOS-2021-1434 The report states that upstream was notified, but we need to figure out whether this was addressed by upstream already o

Bug#1009282: Should live-wrapper be removed?

2022-04-10 Thread Moritz Muehlenhoff
Source: live-wrapper Version: 0.10 Severity: serious Your package came up as a candidate for removal from Debian: - Still depends on Python 2 and thus removed from testing since 2019 - Depends on vmdebootstrap which was removed - It's not included in Bullseye, but we did release live images so

Bug#1009281: Should cinfony be removed?

2022-04-10 Thread Moritz Muehlenhoff
Source: cinfony Version: 1.2-4 Severity: serious Your package came up as a candidate for removal from Debian: - Still depends on Python 2 and thus removed from testing since 2019 - Dead upstream - No reverse dependencies If you disagree and want to continue to maintain this package, please just

Bug#1009280: Should python-passfd be removed?

2022-04-10 Thread Moritz Muehlenhoff
Source: python-passfd Version: 0.2-3 Severity: serious Your package came up as a candidate for removal from Debian: - Still depends on Python 2 and thus removed from testing since 2020 - No reverse dependencies - Last upload in 2016 If you disagree and want to continue to maintain this package,

Bug#1009276: Should fsl be removed?

2022-04-10 Thread Moritz Muehlenhoff
Source: fsl Version: 5.0.8-6 Severity: serious Your package came up as a candidate for removal from Debian: - Still depends on Python 2 and thus removed from testing since two years - Also FTBFSes with GCC 10 - Last upload in 2019 If you disagree and want to continue to maintain this package, pl

Bug#1009273: Should python-keepkey be removed?

2022-04-10 Thread Moritz Muehlenhoff
Source: python-keepkey Version: 0.7.3-1 Severity: serious Your package came up as a candidate for removal from Debian: - Still depends on Python 2 and thus removed from testing since 2019 - Last upload back in 2016 If you disagree and want to continue to maintain this package, please just close

Bug#1009269: Should sphinx-patchqueue be removed?

2022-04-10 Thread Moritz Muehlenhoff
Source: sphinx-patchqueue Version: 0.5.0-2 Severity: serious Your package came up as a candidate for removal from Debian: - Still depends on Python 2 and thus removed from testing since 2019 - No remaining reverse dependencies - Last upload in 2015 If you disagree and want to continue to maintai

Bug#1008792: Should vmtk be removed?

2022-04-01 Thread Moritz Muehlenhoff
Source: vmtk Version: 1.3+dfsg-2.3 Severity: serious Your package came up as a candidate for removal from Debian: - Depends on Python 2 and thus removed from testing since 2019 (current upstream 1.4 is fixed, though) - Last maintainer upload in 2016 If you disagree and want to continue to maint

Bug#1008791: Should googlefontdirectory-tools be removed?

2022-04-01 Thread Moritz Muehlenhoff
Source: googlefontdirectory-tools Version: 20120309.1-1.1 Severity: serious Your package came up as a candidate for removal from Debian: - Still depends on Python 2 and thus removed from testing since 2019 - Last maintainer upload in 2015 If you disagree and want to continue to maintain this pac

Bug#1008704: Sould astk be removed?

2022-03-30 Thread Moritz Muehlenhoff
Source: astk Version: 1.13.1-2.1 Severity: serious Your package came up as a candidate for removal from Debian: - Still depends on Python 2 and thus removed from testing since 2019 - Last maintainer upload in 2014 If you disagree and want to continue to maintain this package, please just close t

Bug#1008703: Should sortsmill-tools be removed?

2022-03-30 Thread Moritz Muehlenhoff
Source: sortsmill-tools Version: 0.4-2 Severity: serious Your package came up as a candidate for removal from Debian: - Still depends on Python and thus removed from testing since 2019 - Last upload in 2013 If you disagree and want to continue to maintain this package, please just close this bug

Bug#1008702: Should ketchup be removed?

2022-03-30 Thread Moritz Muehlenhoff
Source: ketchup Version: 1.0.1+git20111228+e1c62066-2 Severity: serious Your package came up as a candidate for removal from Debian: - Still depends on Python 2 and thus removed from testing since 2019 - Last upload in 2017 - Seems dead upstream (last commit from eight years ago) - Per #946203 do

Bug#1008701: Should broctl be removed?

2022-03-30 Thread Moritz Muehlenhoff
Source: broctl Version: 1.4-1 Severity: serious Your package came up as a candidate for removal from Debian: - Still uses Python 2.7 and thus removed from testing since 2019 - Last upload in 2015 If you disagree and want to continue to maintain this package, please just close this bug (and fix t

Bug#1008700: Should geda-gaf be removed?

2022-03-30 Thread Moritz Muehlenhoff
Source: geda-gaf Version: 1:1.8.2-11 Severity: serious Your package came up as a candidate for removal from Debian: - Still depends on Python 2 and thus removed from testing since 2019 - Also uses outdated Guile - Last upload in 2018 If you disagree and want to continue to maintain this package,

Bug#1008500: Should undertaker be removed?

2022-03-27 Thread Moritz Muehlenhoff
Source: undertaker Version: 1.6.1-4.2 Severity: serious Your package came up as a candidate for removal from Debian: - Still depends on Python 2 and thus removed from testing since 2019 - Last maintainer upload in 2016 If you disagree and want to continue to maintain this package, please just cl

Bug#1008499: Should neard be removed?

2022-03-27 Thread Moritz Muehlenhoff
Source: neard Version: 0.16-0.1 Severity: serious Your package came up as a candidate for removal from Debian: - Last maintainer upload in 2013 - Depends on Python 2 and thus removed from testing since 2019 If you disagree and want to continue to maintain this package, please just close this bug

Bug#1008498: Should hgsubversion be removed?

2022-03-27 Thread Moritz Muehlenhoff
Source: hgsubversion Version: 1.9.3+git20190419+6a6ce-5 Severity: serious Your package came up as a candidate for removal from Debian: - Still depends on Python 2 and removed from testing since 2020 - Dead upstream (no commits after 2019) If you disagree and want to continue to maintain this pac

Bug#1008285: Should zorp be removed?

2022-03-25 Thread Moritz Muehlenhoff
Source: zorp Version: 7.0.1~alpha2-3 Severity: serious Your package came up as a candidate for removal from Debian: - Last upload in 2019, removed from testing since 2017 - Still depends on Python 2.7 and thus RC-buggy If you disagree and want to continue to maintain this package, please just cl

Bug#1008286: Should nglister be removed?

2022-03-25 Thread Moritz Muehlenhoff
Source: nglister Version: 1.0.2 Severity: serious Your package came up as a candidate for removal from Debian: - Last upload in 2016 - Removed from testing since 2019 - Multiple RC bugs If you disagree and want to continue to maintain this package, please just close this bug (and f

Bug#1008274: Should sandsifter be removed?

2022-03-25 Thread Moritz Muehlenhoff
Source: sandsifter Version: 1.04-1 Severity: serious Your package came up as a candidate for removal from Debian: - Still uses Python 2.7 and thus RC buggy - Last upload in 2019 and not in testing since 2019 If you disagree and want to continue to maintain this package, please just close this bu

Bug#1008273: Should python-nemu be removed?

2022-03-25 Thread Moritz Muehlenhoff
Source: python-nemu Version: 0.3.1-1 Severity: serious Your package came up as a candidate for removal from Debian: - Last upload in 2016 and dropped from testing in 2019 - Still uses Python 2.7 and not fixed upstream either If you disagree and want to continue to maintain this package, please j

Bug#1008272: Should postnews be removed?

2022-03-25 Thread Moritz Muehlenhoff
Source: postnews Version: 0.7-1 Severity: serious Your package came up as a candidate for removal from Debian: - Removed from testing for ~ two years, no followup to RC bugs - Also no changes upstream since 2017 If you disagree and want to continue to maintain this package, please just close thi

Bug#1008271: Should arriero be removed?

2022-03-25 Thread Moritz Muehlenhoff
Source: arriero Version: 0.6-1 Severity: serious Your package came up as a candidate for removal from Debian: - Last upload in 2017 - Still uses Python 2.7 and thus RC buggy - Missed the last two stable releases and removed from testing since 2018 If you disagree and want to continue to maintain

Bug#1008265: CVE-2018-25032: zlib memory corruption on deflate

2022-03-25 Thread Moritz Muehlenhoff
Source: zlib Version: 1:1.2.11.dfsg-2 Severity: grave Tags: security X-Debbugs-Cc: Debian Security Team This was assigned CVE-2018-25032: https://www.openwall.com/lists/oss-security/2022/03/24/1 https://github.com/madler/zlib/commit/5c44459c3b28a9bd3283aaceab7c615f8020c531 Cheers, Moritz

Bug#1008264: Multiple security issues

2022-03-25 Thread Moritz Muehlenhoff
Source: pluxml Version: 5.6-1 Severity: grave Tags: security X-Debbugs-Cc: Debian Security Team CVE-2022-25020: https://github.com/MoritzHuppert/CVE-2022-25020/blob/main/CVE-2022-25020.pdf CVE-2022-25018: https://github.com/MoritzHuppert/CVE-2022-25018/blob/main/CVE-2022-25018.pdf CVE-2022-2458

Bug#1005981: Please migrate away from dpatch

2022-02-19 Thread Moritz Muehlenhoff
On Fri, Feb 18, 2022 at 02:41:57PM -0800, Bill Poser wrote: > I am the developer of redet. I don't understand this bug report. redet does > not use anything called dpatch so far as I know. Is this something added in > the Debianization of redet downstream from me? Yes, exactly. It's a legacy mecha

Bug#1005988: Don't release with bookworm

2022-02-18 Thread Moritz Muehlenhoff
Source: dpatch Version: 2.0.41 Severity: serious dpatch has been obsoleted by source format 3.0 (quilt), there's only 19 reverse dependencies in the archive (5 of them in testing), for which bugs have been filed. Cheers, Moritz

Bug#1005987: Please migrate away from dpatch

2022-02-18 Thread Moritz Muehlenhoff
Source: mgetty Version: 1.2.1-1.1 Severity: serious dpatch is deprecated and will be removed before the bookworm release. Please migrate to source format 3.0 (quilt) instead.

Bug#1005986: Please migrate away from dpatch

2022-02-18 Thread Moritz Muehlenhoff
Source: dvbsnoop Version: 1.4.50-5 Severity: serious dpatch is deprecated and will be removed before the bookworm release. Please migrate to source format 3.0 (quilt) instead.

Bug#1005985: Please migrate away from dpatch

2022-02-18 Thread Moritz Muehlenhoff
Source: scim-skk Version: 0.5.2-7.2 Severity: serious dpatch is deprecated and will be removed before the bookworm release. Please migrate to source format 3.0 (quilt) instead.

Bug#1005984: Please migrate away from dpatch

2022-02-18 Thread Moritz Muehlenhoff
Source: scim-canna Version: 1.0.0-4.3 Severity: serious dpatch is deprecated and will be removed before the bookworm release. Please migrate to source format 3.0 (quilt) instead.

Bug#1005983: Please migrate away from dpatch

2022-02-18 Thread Moritz Muehlenhoff
Source: myspell Version: 1:3.0+pre3.1-24.2 Severity: serious dpatch is deprecated and will be removed before the bookworm release. Please migrate to source format 3.0 (quilt) instead.

Bug#1005981: Please migrate away from dpatch

2022-02-18 Thread Moritz Muehlenhoff
Source: redet Version: 8.26-1.4 Severity: serious dpatch is deprecated and will be removed before the bookworm release. Please migrate to source format 3.0 (quilt) instead.

Bug#1005982: Please migrate away from dpatch

2022-02-18 Thread Moritz Muehlenhoff
Source: elscreen Version: 1.4.6-5.3 Severity: serious dpatch is deprecated and will be removed before the bookworm release. Please migrate to source format 3.0 (quilt) instead.

Bug#1005980: Please migrate away from dpatch

2022-02-18 Thread Moritz Muehlenhoff
Source: syrep Version: 0.9-4.3 Severity: serious dpatch is deprecated and will be removed before the bookworm release. Please migrate to source format 3.0 (quilt) instead.

  1   2   3   4   5   6   7   8   9   10   >