]> sipb.mit.edu Git - wiki.git/blob - projects/lenny-bugs-all.mdwn
There is no WinAthena machine in the office at the moment.
[wiki.git] / projects / lenny-bugs-all.mdwn
1 [[!meta title="Open RC Bugs in Lenny"]]
2
3 These are bugs to consider at SIPB's [[RC-bug-squashing hackathon|lenny-bugs]] for Lenny.
4
5 Bug list dumped early 2008-12-12.  The pipeline was
6  `$ cd /mit/debathena/debian-bts && ./get_bugs | sort | ./bugs-format-trac`
7
8 Please sort into useful/not useful, add notes, etc.
9
10 ----
11
12 ## Juicy?
13
14 All acted on!  See the "Stuff we did" sections below.
15
16
17
18 ----
19
20 ## Stuff we did
21
22 ### Fixed by SIPB!
23 [436140](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=436140)
24 in [installation-reports](http://packages.debian.org/lenny/installation-reports)
25 "cdrom: Most of the system's files have a future timestamp causing at least update/config problems."
26 (closed by wdaher)
27
28 [476525](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=476525) 
29 in [python-hid](http://packages.debian.org/lenny/python-hid) 
30 "python-hid: hid module will not import since python policy transition" 
31 (tabbott)
32
33 [507071](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507071) 
34 [racoon](http://packages.debian.org/lenny/racoon) 
35 "racoon - Fails after upgrade: symbol lookup error: /usr/sbin/racoon: undefined symbol: libipsec_opt" 
36 (fixed by broder)
37
38 [507072](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507072) 
39 in [ipsec-tools](http://packages.debian.org/lenny/ipsec-tools) 
40 "libipsec0 packaged in ipsec-tools without development headers" 
41 (downgraded by hartmans)
42
43 [504626](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504626) 
44 in [nvidia-glx](http://packages.debian.org/lenny/nvidia-glx) 
45 "[nvidia-glx] Quietly drops support for several chipsets" 
46 (downgraded by nelhage)
47
48 [502845](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=502845)
49 in [open-iscsi](http://packages.debian.org/lenny/open-iscsi)
50 "open-iscsi: no login using amd64"
51 (quentin reassigned; Bastian Blank then lowered priority)
52
53 [508265](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508265)
54 in [sysprof-module-source](http://packages.debian.org/lenny/sysprof-module-source)
55 "sysprof-module-source: doesn't compile on AMD64 arch (wrong register names)"
56 (patch added by andersk)
57
58 [506057](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506057)
59 in [splashy](http://packages.debian.org/lenny/splashy)
60 "splashy: Splashy fails to install due to missing default theme"
61 (fix suggestion added by ecprice with help from tabbott and fawkes)
62
63 [506748](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506748)
64 in [rtorrent](http://packages.debian.org/lenny/rtorrent)
65 "crash rtorrent by scgi-interface (function: 'fi.get_filename_last')"
66 (submitted patch that disables broken RPC; leaving to maintainer to decide if this is what he wants to do)
67
68 [426465](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=426465)
69 in [initramfs-tools](http://packages.debian.org/lenny/initramfs-tools)
70 "/init exports MODPROBE_OPTIONS=-qb"  
71 (patch added by price)
72
73 [489501](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=489501)
74 in [zekr](http://packages.debian.org/lenny/zekr)
75 "zekr depends on libxul0d"  
76 (mako tweaked and sponsored fix by Asheesh Laroia)
77
78 ### Waiting on feedback
79
80 [502140](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=502140)
81 in [pam](http://packages.debian.org/lenny/pam)
82 "cannot unlock screen during etch -> lenny transition"
83 (hartmans added comment)
84
85 [481072](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=481072)
86 in [dk-filter](http://packages.debian.org/lenny/dk-filter)
87 "dk-filter reliably crashes upon connection from postfix"  
88 (quentin couldn't reproduce)
89
90 [507883](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507883)
91 in [asterisk](http://packages.debian.org/lenny/asterisk)
92 "asterisk: Very frequent segfaults on startup"
93 (quentin couldn't reproduce)
94
95 [456037](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=456037)
96 in [fenix](http://packages.debian.org/lenny/fenix)
97 "fenix: not 64 bit clean"  
98 (ezyang observed upstream's website looks ~dead)
99
100
101
102
103 ----
104
105 ## Fun stuff to read
106
107 ### Flamewars
108
109 You might enjoy reading these, but they may not be good targets to fix.
110
111 [475737](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=475737)
112 in [otrs2](http://packages.debian.org/lenny/otrs2)
113 "otrs2 - makes files in /usr writable by non-root"
114
115 [504771](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504771)
116 in [wordpress](http://packages.debian.org/lenny/wordpress)
117 "wordpress can be subject of delayed attacks via cookies"
118
119 For this one, the actual flamewar is off the bug report log.
120
121 [497823](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=497823)
122 in [ftp.debian.org](http://packages.debian.org/lenny/ftp.debian.org)
123 "longstanding DFSG violations in linux-2.6 package"
124
125 [504747](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504747)
126 in [gnu-fdisk](http://packages.debian.org/lenny/gnu-fdisk)
127 "gnu-fdisk: wipes out MBR when used on GPT partitions"
128
129
130 ### Would have been fun
131
132 Entertaining to read but sadly already fixed.
133
134 [506961](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506961)
135 in auctex
136 "auctex: reuses old logfile on emacsen upgrades, enabling symlink attack"
137
138
139 ### Examples to live up to
140
141 [496954](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=496954)
142 in [bind9](http://packages.debian.org/lenny/bind9)
143 "bind9: Fails to start due to SIGSEGV"  
144 This bug sat unfixed for months.  Then someone attacked it in a bug-squashing party,
145 got the first reproducible testcase, and sent that upstream, which swiftly produced a fix.
146
147
148 ### Puzzling
149
150 Someone please explain what's going on (Debian Project-wise) in these bugs.
151
152 [323473](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=323473)
153 in [wnpp](http://packages.debian.org/lenny/wnpp)
154 "ITA: mol-drivers-linux -- The Mac-on-Linux emulator - drivers for Linux"  
155 (Note: The bug is for someone to take over maintainership.  They did.  Then when the bug gets automatically archived, they reply saying to keep it?  I (price) don't understand.)
156
157
158
159
160 ----
161
162 ## Not so ripe for us to fix
163
164 ### Specific hardware
165
166 If you have the relevant hardware you could help a lot.
167
168 [394963](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=394963)
169 in [installation-reports](http://packages.debian.org/lenny/installation-reports)
170 "installation: Problems with dual booting Dell D600 with winXP pro in the first partition (hd0, 0). After installing the Dell Etch Beta 3, Windows fails to boot and I get the blue screen of death."
171
172 [418972](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=418972)
173 in [installation-reports](http://packages.debian.org/lenny/installation-reports)
174 "cdrom: Etch does not detect CD-ROM on Acer Aspire 7100"
175
176 [478717](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=478717)
177 in [ruby1.9](http://packages.debian.org/lenny/ruby1.9)
178 "ruby1.9: FTBFS on hppa: make[1]: *** [all] Segmentation fault"
179
180 [499078](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=499078)
181 in [jfsutils](http://packages.debian.org/lenny/jfsutils)
182 "jfsutils: Bus Error when running fsck.jfs on sparc"
183
184 [501804](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=501804)
185 in [installation-reports](http://packages.debian.org/lenny/installation-reports)
186 "installation-reports: Lenny b2 install on ThinkPad X61 - fails to detect hard disk"
187
188 [495603](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=495603)
189 in [installation-reports](http://packages.debian.org/lenny/installation-reports)
190 "grub-installer fails on a FSC Primergy RX300 with a level 5 RAID"
191
192
193 ### May be a lot of work
194
195 [490171](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=490171)
196 in [rtorrent](http://packages.debian.org/lenny/rtorrent)
197 "rtorrent: random crash"  
198 (Reproducing this seems to require runnin 20+ torrents for a ~day)
199
200
201 ### Unclassified
202
203 Please read these reports and figure out what category they belong in.  Or make a new category.
204
205 [504661](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504661)
206 in [nvidia-glx-legacy-96xx-dev](http://packages.debian.org/lenny/nvidia-glx-legacy-96xx-dev)
207 "nvidia-glx-legacy-96xx-dev: /usr/lib/libGL.so symlink broken"
208
209 [504918](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504918)
210 in [network-manager](http://packages.debian.org/lenny/network-manager)
211 "Updating to lenny failed when NetworkManager got updated"
212
213 ### Unclassified Security
214
215 [505563](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=505563)
216 in [icedove](http://packages.debian.org/lenny/icedove)
217 "Mozilla Thunderbird Multiple Vulnerabilities"
218
219 [507165](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507165)
220 in [xine-lib](http://packages.debian.org/lenny/xine-lib)
221 "xine-lib: CVE-2008-5242 heap-based buffer overflow"
222
223 [507184](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507184)
224 in [xine-lib](http://packages.debian.org/lenny/xine-lib)
225 "xine-lib: CVE-2008-5246 heap overflow"
226
227 [504977](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504977)
228 in [ffmpeg-debian](http://packages.debian.org/lenny/ffmpeg-debian)
229 "ffmpeg-debian: Several security issues"
230
231 ### Fresh bugs
232
233 These are very recent and presumably will get dealt with by the
234 package maintainers without help.
235
236 If you're bored you might look through and see if some are interesting
237 anyway.  Also feel free to draw the line at some other time; I (price)
238 picked December 1, arbitrarily.
239
240
241 [239111](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=239111)
242 in [grub](http://packages.debian.org/lenny/grub)
243 "Freeze when installing GRUB on XFS boot partition"  
244 (Note: just re-opened 2008-12-12)
245
246 [507558](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507558)
247 in [hibernate](http://packages.debian.org/lenny/hibernate)
248 "ignores "LockXLock yes" setting in /etc/hibernate/common.conf (e.g. does not lock the screen)"
249
250 [507579](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507579)
251 in [yocto-reader](http://packages.debian.org/lenny/yocto-reader)
252 "Package installation results in license violation"
253
254 [507706](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507706)
255 in [cdimage.debian.org](http://packages.debian.org/lenny/cdimage.debian.org)
256 "Missing sources for d-i components/kernel of etch-n-half images"
257
258 [507721](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507721)
259 in [cryptsetup](http://packages.debian.org/lenny/cryptsetup)
260 "cryptsetup: Sometimes initrd ends up missing conf/conf.d/cryptroot file in it"
261
262 [507818](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507818)
263 in [mldonkey-server](http://packages.debian.org/lenny/mldonkey-server)
264 "mldonkey-server: mlnet does not start, logs syntax error in downloads.ini"
265
266 [507865](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507865)
267 in [openoffice.org-writer](http://packages.debian.org/lenny/openoffice.org-writer)
268 "openoffice.org-writer: OOo 2.4.x openinig OOo 3 files doesn't show text (2.x implements standard wrong)"
269
270 [507889](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507889)
271 in [mdadm](http://packages.debian.org/lenny/mdadm)
272 "mdadm: initramfs-tools script is broken, system with root on RAID won't boot"
273
274 [507996](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507996)
275 in [uim-tcode](http://packages.debian.org/lenny/uim-tcode)
276 "mazegaki conversion cannot be used"
277
278 [508133](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508133)
279 in [libmad0](http://packages.debian.org/lenny/libmad0)
280 "audacity: munmap_chunk(): invalid pointer: 0x00000000026f4eb0"
281
282 [508194](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508194)
283 in [sun-java5](http://packages.debian.org/lenny/sun-java5)
284 "sun-java5: New upstream release fixes several security issues"
285
286 [508313](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508313)
287 in [xine-lib](http://packages.debian.org/lenny/xine-lib)
288 "xine-lib: CVE-2008-5234 heap overflow in atom parsing"
289
290 [508322](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508322)
291 in [wodim](http://packages.debian.org/lenny/wodim)
292 "wodim: Cannot load media.  Cannot init drive."
293
294 [508324](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508324)
295 in [ftp.debian.org](http://packages.debian.org/lenny/ftp.debian.org)
296 "ftp.debian.org: gcc-4.2-base is not really required"
297
298 [508434](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508434)
299 in [ipmitool](http://packages.debian.org/lenny/ipmitool)
300 "ipmitool: Several init script problems due to wrong pidfile name"
301
302 [508443](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508443)
303 in [imagemagick](http://packages.debian.org/lenny/imagemagick)
304 "convert crash on sparc during compilation of djvulibre (work on x86-64)"
305
306 [508480](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508480)
307 in [iodbc](http://packages.debian.org/lenny/iodbc)
308 "iodbc: Segfaults when asking for the available DSNs"
309
310 [508392](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508392)
311 in [dpkg](http://packages.debian.org/lenny/dpkg)
312 "Handling of conflicting conffiles broken"
313
314 [508565](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508565)
315 in [f2c](http://packages.debian.org/lenny/f2c)
316 "f2c: does not translate properly in EMT64 machines"
317
318 [508551](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508551)
319 in [merkaartor](http://packages.debian.org/lenny/merkaartor)
320 "merkaartor: crash on startup: QPaintEngine::setSystemClip: Should not be change
321
322 [508589](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508589)
323 in [linux-2.6](http://packages.debian.org/lenny/linux-2.6)
324 "ppp: USB Modem removal after PPP exits kills keyboard"
325
326 [508660](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508660)
327 in [autopkgtest-xenlvm](http://packages.debian.org/lenny/autopkgtest-xenlvm)
328 "adtxenlvm: initscript assumes eth0"
329
330 ### Mostly solved?
331
332 These look like good progress is being made and they'll get fixed
333 soon. Do we need a DD to do an NMU on any of these?
334
335 [504283](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504283)
336 in [egroupware-core](http://packages.debian.org/lenny/egroupware-core)
337 "CVE-2007-3215: phpmailer issue (embedded code-copy)"
338
339 [508510](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508510)
340 in [debget](http://packages.debian.org/lenny/debget)
341 "Can't parse packages.debian.org output anymore"
342
343 [332782](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=332782)
344 in [release-notes](http://packages.debian.org/lenny/release-notes)
345 "release-notes: Where's the license?"
346
347 [475958](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=475958)
348 in [release-notes](http://packages.debian.org/lenny/release-notes)
349 "document procedure to recover from "/dev/hda became /dev/sda" boot failure"  
350 (Note: looks done, just not closed.)
351
352 [506883](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506883)
353 in [tuxguitar](http://packages.debian.org/lenny/tuxguitar)
354 "tuxguitar: hard-codes dependencies on libraries"
355
356 [495178](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=495178)
357 in [libjs-jquery](http://packages.debian.org/lenny/libjs-jquery)
358 "libjs-jquery: Should compile jquery.min.js and jquery.pack.js from jquery.js"
359
360 [507059](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507059)
361 in [initramfs-tools](http://packages.debian.org/lenny/initramfs-tools)
362 "initramfs-tools: Wrong check for udevadm in functions"  
363 (No maintainer activity since it was reported 2 weeks ago; One-line patch attached.)
364
365 [496334](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=496334)
366 in [mdadm](http://packages.debian.org/lenny/mdadm)
367 "mdadm segfault on --assemble --force with raid10"  
368 Seems to be fixed and uploaded, but got reopened for some reason?
369
370 [374644](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=374644) in [xine-ui](http://packages.debian.org/lenny/xine-ui)
371 "xine-ui: ctrl/shift key press emulation implementation broken"  
372 (Note: There's a patch that may be good enough -- blocking on some guy responding)
373
374 [505237](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=505237)
375 in [snmpd](http://packages.debian.org/lenny/snmpd)
376 "/etc/init.d/snmpd start reports error if already running"
377 (Note: fixed, waiting on an upload?)
378
379 [508257](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508257)
380 in [twiki](http://packages.debian.org/lenny/twiki)
381 "CVE-2008-5305: TWiki SEARCH variable allows arbitrary shell command execution"
382
383 [508026](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508026)
384 in [phppgadmin](http://packages.debian.org/lenny/phppgadmin)
385 "phpPgAdmin: Local File Inclusion Vulnerability"
386
387 [501800](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=501800)
388 in [bind9](http://packages.debian.org/lenny/bind9)
389 "bind9: bind crashes with a list for allow-update"
390
391 [503532](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=503532)
392 in [dbus](http://packages.debian.org/lenny/dbus)
393 "send_requested_reply="true" allows all non-reply messages"
394
395 [506741](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506741)
396 in [wireshark](http://packages.debian.org/lenny/wireshark)
397 "wireshark: DoS caused by sending a SMTP request with large content"
398
399 [503303](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=503303)
400 in [upgrade-reports](http://packages.debian.org/lenny/upgrade-reports)
401 "etch -> lenny minimal chrrot upgrade fails due to Conflicts/Pre-Depends loop"
402
403 [504524](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504524)
404 in [sun-java6](http://packages.debian.org/lenny/sun-java6)
405 "AWT_TOOLKIT=MToolkit causes java to segfault on amd64"
406
407 [503712](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=503712)
408 in [ghostscript](http://packages.debian.org/lenny/ghostscript)
409 "etch->lenny upgrade left the system in broken state"
410
411 [508635](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508635)
412 in [libexif-gtk-dev](http://packages.debian.org/lenny/libexif-gtk-dev)
413 "libexif-gtk-dev: References no longer existing libXcursor.la"
414
415 [500460](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=500460)
416 in [oss-compat](http://packages.debian.org/lenny/oss-compat)
417 "oss-compat: modules are not loaded"
418
419
420 ### Not much of use one can do
421
422 (waiting on reporter to reproduce)
423
424 [494293](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=494293)
425 in [installation-reports](http://packages.debian.org/lenny/installation-reports)
426 "installation-reports: Grub error: not a regular file..."
427
428 (this one looks like it'll be removed from Lenny or have amd64 disabled)
429
430 [507021](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507021)
431 in [helpdeco](http://packages.debian.org/lenny/helpdeco)
432 "Fails to work on amd64"
433
434 (this one looks the maintainer has labeled unreproducible)
435
436 [507242](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507242)
437 in [amule-daemon](http://packages.debian.org/lenny/amule-daemon)
438 "amule-daemon: causes OOM's by leaking lots of memory"
439
440 (waiting on upstream)
441
442 [506652](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506652)
443 in [xml2rfc](http://packages.debian.org/lenny/xml2rfc)
444 "Yet another boilerplate change"
445
446 [490999](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=490999)
447 in [libqt3-mt](http://packages.debian.org/lenny/libqt3-mt)
448 "kicker: crashes on startup"
449
450 [507947](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507947)
451 in [moodle](http://packages.debian.org/lenny/moodle)
452 "moodle: html2text.php is not DFSG-free"
453
454 [495232](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=495232)
455 in [quagga](http://packages.debian.org/lenny/quagga)
456 "quagga: zebra ignores routes added via command line"
457
458 (misc)
459
460 [508091](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508091)
461 in [tuxguitar](http://packages.debian.org/lenny/tuxguitar)
462 "maintainer address bounces"
463
464 (trivial fix may cause regression, may punt)
465
466 [507003](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507003)
467 in [open-iscsi](http://packages.debian.org/lenny/open-iscsi)
468 "initiatorname.iscsi should maybe not be in /etc"
469
470 (legal issue involving non-free file)
471
472 [502751](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=502751)
473 in [clamav-getfiles](http://packages.debian.org/lenny/clamav-getfiles)
474 "clamav-getfiles: piuparts test fails: eicar.com md5sum mismatch, file needs downloading"
475
476 [506353](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506353)
477 in [mailscanner](http://packages.debian.org/lenny/mailscanner)
478 "CVE-2008-5312/3: mailscanner might allow local users to overwrite arbitrary files via a symlink attack"
479
480 [507316](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507316)
481 in [smarty](http://packages.debian.org/lenny/smarty)
482 "smarty: Non-free logo included in package"
483
484
485 ### Special team bugs
486
487 These bugs are probably not good targets because the work involved with them at this point is to be done by someone on a special Debian team.
488
489 [451628](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=451628)
490 in [ftp.debian.org](http://packages.debian.org/lenny/ftp.debian.org)
491 "Packages might enter the archive from security without source"
492
493 [506152](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506152)
494 in [ftp.debian.org](http://packages.debian.org/lenny/ftp.debian.org)
495 "libept0 should have priority important"
496
497 [507675](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507675)
498 in [ftp.debian.org](http://packages.debian.org/lenny/ftp.debian.org)
499 "python2.5 should have priority standard"
500
501 [507678](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507678)
502 in [ftp.debian.org](http://packages.debian.org/lenny/ftp.debian.org)
503 "libsqlite3-0 should have priority standard"
504
505 [507775](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507775)
506 in [ftp.debian.org](http://packages.debian.org/lenny/ftp.debian.org)
507 "libkeyutils1 should have priority standard"
508
509 [507778](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507778)
510 in [ftp.debian.org](http://packages.debian.org/lenny/ftp.debian.org)
511 "libldap-2.4-2 should have priority standard"
512
513 [507779](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507779)
514 in [ftp.debian.org](http://packages.debian.org/lenny/ftp.debian.org)
515 "[Priorities] libustr-1.0-1 -> standard"
516
517 [507780](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507780)
518 in [ftp.debian.org](http://packages.debian.org/lenny/ftp.debian.org)
519 "python-sepolgen should have priority standard"
520
521 [507783](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507783)
522 in [ftp.debian.org](http://packages.debian.org/lenny/ftp.debian.org)
523 "libxml2 should have priority standard"
524
525 [507784](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507784)
526 in [ftp.debian.org](http://packages.debian.org/lenny/ftp.debian.org)
527 "python2.5-minimal should have priority standard"
528
529 [507796](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507796)
530 in [ftp.debian.org](http://packages.debian.org/lenny/ftp.debian.org)
531 "libisccfg40 should have priority standard"
532
533 [507797](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507797)
534 in [ftp.debian.org](http://packages.debian.org/lenny/ftp.debian.org)
535 "libisccc40 should have priority standard"
536
537 [507798](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507798)
538 in [ftp.debian.org](http://packages.debian.org/lenny/ftp.debian.org)
539 "libedit2 should have priority standard"
540
541 [507799](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507799)
542 in [ftp.debian.org](http://packages.debian.org/lenny/ftp.debian.org)
543 "libgssglue1 must have priority standard"
544
545 [507800](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507800)
546 in [ftp.debian.org](http://packages.debian.org/lenny/ftp.debian.org)
547 "ucf must have priority standard"
548
549 [507801](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507801)
550 in [ftp.debian.org](http://packages.debian.org/lenny/ftp.debian.org)
551 "libpci3 must have priority standard"
552
553 [497471](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=497471)
554 in [cdimage.debian.org](http://packages.debian.org/lenny/cdimage.debian.org)
555
556 "sarge images have syslinux binaries without source"
557
558 [506977](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506977)
559 in [release.debian.org](http://packages.debian.org/lenny/release.debian.org)
560 "FPC: copyright infringement in pre 2.2.2 sources"
561
562 [507239](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507239)
563 in [release.debian.org](http://packages.debian.org/lenny/release.debian.org)
564 "RM: astrolog/stable -- RoQA; orphaned long time, non-free, contains potentially undistributable code"
565
566 This one is fixed in experimental:
567
568
569
570 [503907](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=503907)
571 in [libwebkit-1.0-1](http://packages.debian.org/lenny/libwebkit-1.0-1)
572 "epiphany-webkit: Crashes at startup whenever I go to a site."