Bug#986701: mosquitto: CVE-2021-28166

2021-04-09 Thread Roger Light
This will be fixed soon, I would like to include an autopkgtest in the package, otherwise this would have been updated already. On Fri, 9 Apr 2021 at 20:27, Salvatore Bonaccorso wrote: > > Source: mosquitto > Version: 2.0.9-1 > Severity: grave > Tags: security upstream > Justification: user secur

Bug#754787: mosquitto: does not handle errors from authentication plugins correctly

2014-07-14 Thread Roger Light
Source: mosquitto Version: 1.2.1-1 Severity: grave Tags: security upstream Justification: user security hole If an end user uses mosquitto with an authentication plugin, and the plugin returns an application error when making an authentication check (such as if a database was unavailable), then mo

Bug#651688: [pkg-ggz-maintainers] Bug#651688: Bug#651688: Should ggz-server be orphaned or removed from Debian?

2012-01-02 Thread Roger Light
> It appears that Josef is no longer active He replied to my email fairly promptly so I'm sure he'll do so with this as well. >.  I was just the > sponsor/helper here, so I don't know the status of upstream etc. very > well.  At one point, these libraries had a reverse dependency into > GNOME, bu

Bug#651688: [pkg-ggz-maintainers] Bug#651688: Should ggz-server be orphaned or removed from Debian?

2011-12-13 Thread Roger Light
Hi Ansgar, I've spoken with Josef Spillner, the old GGZ project lead and we both agree that the best course of action is for the GGZ packages to be removed from Debian. It's not fair to leave the maintenance in the hands of the distributors. Cheers, Roger -- To UNSUBSCRIBE, email to debian-b