]> sipb.mit.edu Git - wiki.git/blob - doc/LennyBugsAll
a242df2ec5d152756ca249a7a00b1a757387c469
[wiki.git] / doc / LennyBugsAll
1 = Open RC Bugs in Lenny =
2
3 These are bugs to consider at SIPB's [LennyBugs RC-bug-squashing hackathon] for Lenny.
4
5 Bug list dumped early 2008-12-12.  The pipeline was
6  `$ cd /mit/debathena/debian-bts && ./get_bugs | sort | ./bugs-format-trac`
7
8 Please sort into useful/not useful, add notes, etc.
9
10 = Juicy? =
11
12 Try these!
13
14 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=374644 374644] in [http://packages.debian.org/lenny/xine-ui xine-ui]
15 "xine-ui: ctrl/shift key press emulation implementation broken"
16 [[BR]](Note: have patch but it's broken.  Test?  Find a fix?)
17
18 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=426465 426465]
19 in [http://packages.debian.org/lenny/initramfs-tools initramfs-tools]
20 "/init exports MODPROBE_OPTIONS=-qb"
21 [[BR]](Note: real bug report is near bottom.)
22
23 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=476525 476525]
24 in [http://packages.debian.org/lenny/python-hid python-hid]
25 "python-hid: hid module will not import since python policy transition"
26 [[BR]](Note: have patch, looks messy, looks like not-too-hard bug to fix well.)
27
28 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=481072 481072]
29 in [http://packages.debian.org/lenny/dk-filter dk-filter]
30 "dk-filter reliably crashes upon connection from postfix"
31 [[BR]](Note: bug report, little followup.  Test, reproduce, debug, fix.)
32
33
34 = Specific hardware =
35
36 If you have the relevant hardware you could help a lot.
37
38 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=394963 394963]
39 in [http://packages.debian.org/lenny/installation-reports installation-reports]
40 "installation: Problems with dual booting Dell D600 with winXP pro in the first partition (hd0, 0). After installing the Dell Etch Beta 3, Windows fails to boot and I get the blue screen of death."
41
42 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=418972 418972]
43 in [http://packages.debian.org/lenny/installation-reports installation-reports]
44 "cdrom: Etch does not detect CD-ROM on Acer Aspire 7100"
45
46 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=478717 478717]
47 in [http://packages.debian.org/lenny/ruby1.9 ruby1.9]
48 "ruby1.9: FTBFS on hppa: make[1]: *** [all] Segmentation fault"
49
50 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=499078 499078]
51 in [http://packages.debian.org/lenny/jfsutils jfsutils]
52 "jfsutils: Bus Error when running fsck.jfs on sparc"
53
54 = Examples =
55
56 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=496954 496954]
57 in [http://packages.debian.org/lenny/bind9 bind9]
58 "bind9: Fails to start due to SIGSEGV"
59 [[BR]]This bug sat unfixed for months.  Then someone attacked it in a bug-squashing party,
60 got the first reproducible testcase, and sent that upstream, which swiftly produced a fix.
61
62
63 = Puzzling =
64
65 Someone please explain what's going on (Debian Project-wise) in these bugs.
66
67 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=323473 323473]
68 in [http://packages.debian.org/lenny/wnpp wnpp]
69 "ITA: mol-drivers-linux -- The Mac-on-Linux emulator - drivers for Linux"
70 [[BR]](Note: The bug is for someone to take over maintainership.  They did.  Then when the bug gets automatically archived, they reply saying to keep it?  I (price) don't understand.)
71
72
73 = Unclassified =
74
75 Please read these reports and figure out what category they belong in.  Or make a new category.
76
77 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=436140 436140]
78 in [http://packages.debian.org/lenny/installation-reports installation-reports]
79 "cdrom: Most of the system's files have a future timestamp causing at least update/config problems."
80
81 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=451628 451628]
82 in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org]
83 "Packages might enter the archive from security without source"
84
85 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=456037 456037]
86 in [http://packages.debian.org/lenny/fenix fenix]
87 "fenix: not 64 bit clean"
88
89 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=490171 490171]
90 in [http://packages.debian.org/lenny/rtorrent rtorrent]
91 "rtorrent: random crash"
92
93 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=490999 490999]
94 in [http://packages.debian.org/lenny/libqt3-mt libqt3-mt]
95 "kicker: crashes on startup"
96
97 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=494293 494293]
98 in [http://packages.debian.org/lenny/installation-reports installation-reports]
99 "installation-reports: Grub error: not a regular file..."
100
101 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=495178 495178]
102 in [http://packages.debian.org/lenny/libjs-jquery libjs-jquery]
103 "libjs-jquery: Should compile jquery.min.js and jquery.pack.js from jquery.js"
104
105 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=495232 495232]
106 in [http://packages.debian.org/lenny/quagga quagga]
107 "quagga: zebra ignores routes added via command line"
108
109 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=495603 495603]
110 in [http://packages.debian.org/lenny/installation-reports installation-reports]
111 "grub-installer fails on a FSC Primergy RX300 with a level 5 RAID"
112
113 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=496334 496334]
114 in [http://packages.debian.org/lenny/mdadm mdadm]
115 "mdadm segfault on --assemble --force with raid10"
116
117 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=497471 497471]
118 in [http://packages.debian.org/lenny/cdimage.debian.org cdimage.debian.org]
119 "sarge images have syslinux binaries without source"
120
121 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=497823 497823]
122 in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org]
123 "longstanding DFSG violations in linux-2.6 package"
124
125 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=500460 500460]
126 in [http://packages.debian.org/lenny/oss-compat oss-compat]
127 "oss-compat: modules are not loaded"
128
129 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=501800 501800]
130 in [http://packages.debian.org/lenny/bind9 bind9]
131 "bind9: bind crashes with a list for allow-update"
132
133 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=501804 501804]
134 in [http://packages.debian.org/lenny/installation-reports installation-reports]
135 "installation-reports: Lenny b2 install on ThinkPad X61 - fails to detect hard disk"
136
137 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=502140 502140]
138 in [http://packages.debian.org/lenny/pam pam]
139 "cannot unlock screen during etch -> lenny transition"
140
141 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=502751 502751]
142 in [http://packages.debian.org/lenny/clamav-getfiles clamav-getfiles]
143 "clamav-getfiles: piuparts test fails: eicar.com md5sum mismatch, file needs downloading"
144
145 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=503303 503303]
146 in [http://packages.debian.org/lenny/upgrade-reports upgrade-reports]
147 "etch -> lenny minimal chrrot upgrade fails due to Conflicts/Pre-Depends loop"
148
149 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=503532 503532]
150 in [http://packages.debian.org/lenny/dbus dbus]
151 "send_requested_reply="true" allows all non-reply messages"
152
153 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=503712 503712]
154 in [http://packages.debian.org/lenny/ghostscript ghostscript]
155 "etch->lenny upgrade left the system in broken state"
156
157 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=503907 503907]
158 in [http://packages.debian.org/lenny/libwebkit-1.0-1 libwebkit-1.0-1]
159 "epiphany-webkit: Crashes at startup whenever I go to a site."
160
161 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504283 504283]
162 in [http://packages.debian.org/lenny/egroupware-core egroupware-core]
163 "CVE-2007-3215: phpmailer issue (embedded code-copy)"
164
165 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504373 504373]
166 in [http://packages.debian.org/lenny/libtemplate-perl libtemplate-perl]
167 "libtemplate-perl: Upgrade from etch breaks code using DBI plugins"
168
169 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504524 504524]
170 in [http://packages.debian.org/lenny/sun-java6 sun-java6]
171 "AWT_TOOLKIT=MToolkit causes java to segfault on amd64"
172
173 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504626 504626]
174 in [http://packages.debian.org/lenny/nvidia-glx nvidia-glx]
175 "[nvidia-glx] Quietly drops support for several chipsets"
176
177 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504661 504661]
178 in [http://packages.debian.org/lenny/nvidia-glx-legacy-96xx-dev nvidia-glx-legacy-96xx-dev]
179 "nvidia-glx-legacy-96xx-dev: /usr/lib/libGL.so symlink broken"
180
181 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504747 504747]
182 in [http://packages.debian.org/lenny/gnu-fdisk gnu-fdisk]
183 "gnu-fdisk: wipes out MBR when used on GPT partitions"
184
185 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504771 504771]
186 in [http://packages.debian.org/lenny/wordpress wordpress]
187 "wordpress can be subject of delayed attacks via cookies"
188
189 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504918 504918]
190 in [http://packages.debian.org/lenny/network-manager network-manager]
191 "Updating to lenny failed when NetworkManager got updated"
192
193 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504977 504977]
194 in [http://packages.debian.org/lenny/ffmpeg-debian ffmpeg-debian]
195 "ffmpeg-debian: Several security issues"
196
197 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=505237 505237]
198 in [http://packages.debian.org/lenny/snmpd snmpd]
199 "/etc/init.d/snmpd start reports error if already running"
200
201 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=505563 505563]
202 in [http://packages.debian.org/lenny/icedove icedove]
203 "Mozilla Thunderbird Multiple Vulnerabilities"
204
205 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506057 506057]
206 in [http://packages.debian.org/lenny/splashy splashy]
207 "splashy: Splashy fails to install due to missing default theme"
208
209 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506152 506152]
210 in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org]
211 "libept0 should have priority important"
212
213 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506353 506353]
214 in [http://packages.debian.org/lenny/mailscanner mailscanner]
215 "CVE-2008-5312/3: mailscanner might allow local users to overwrite arbitrary files via a symlink attack"
216
217 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506652 506652]
218 in [http://packages.debian.org/lenny/xml2rfc xml2rfc]
219 "Yet another boilerplate change"
220
221 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506741 506741]
222 in [http://packages.debian.org/lenny/wireshark wireshark]
223 "wireshark: DoS caused by sending a SMTP request with large content"
224
225 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506748 506748]
226 in [http://packages.debian.org/lenny/rtorrent rtorrent]
227 "crash rtorrent by scgi-interface (function: 'fi.get_filename_last')"
228
229 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506853 506853]
230 in [http://packages.debian.org/lenny/libgnutls26 libgnutls26]
231 "libgnutls26: 2.4.2-3 breaks OpenLDAP access"
232
233 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506977 506977]
234 in [http://packages.debian.org/lenny/release.debian.org release.debian.org]
235 "FPC: copyright infringement in pre 2.2.2 sources"
236
237 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507003 507003]
238 in [http://packages.debian.org/lenny/open-iscsi open-iscsi]
239 "initiatorname.iscsi should maybe not be in /etc"
240
241 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507021 507021]
242 in [http://packages.debian.org/lenny/helpdeco helpdeco]
243 "Fails to work on amd64"
244
245 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507059 507059]
246 in [http://packages.debian.org/lenny/initramfs-tools initramfs-tools]
247 "initramfs-tools: Wrong check for udevadm in functions"
248
249 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507071 507071]
250 in [http://packages.debian.org/lenny/racoon racoon]
251 "racoon - Fails after upgrade: symbol lookup error: /usr/sbin/racoon: undefined symbol: libipsec_opt"
252
253 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507072 507072]
254 in [http://packages.debian.org/lenny/ipsec-tools ipsec-tools]
255 "libipsec0 packaged in ipsec-tools without development headers"
256
257 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507165 507165]
258 in [http://packages.debian.org/lenny/xine-lib xine-lib]
259 "xine-lib: CVE-2008-5242 heap-based buffer overflow"
260
261 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507184 507184]
262 in [http://packages.debian.org/lenny/xine-lib xine-lib]
263 "xine-lib: CVE-2008-5246 heap overflow"
264
265 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507239 507239]
266 in [http://packages.debian.org/lenny/release.debian.org release.debian.org]
267 "RM: astrolog/stable -- RoQA; orphaned long time, non-free, contains potentially undistributable code"
268
269 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507242 507242]
270 in [http://packages.debian.org/lenny/amule-daemon amule-daemon]
271 "amule-daemon: causes OOM's by leaking lots of memory"
272
273 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507316 507316]
274 in [http://packages.debian.org/lenny/smarty smarty]
275 "smarty: Non-free logo included in package"
276
277
278 = Fresh bugs =
279
280 These are very recent and presumably will get dealt with by the package maintainers without help.
281
282 If you're bored you might look through and see if some are interesting anyway.  Also feel free to draw the line at some other time; I (price) picked December 1, arbitrarily.
283
284
285 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=239111 239111]
286 in [http://packages.debian.org/lenny/grub grub]
287 "Freeze when installing GRUB on XFS boot partition"
288 [[BR]](Note: just re-opened 2008-12-12)
289
290 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507558 507558]
291 in [http://packages.debian.org/lenny/hibernate hibernate]
292 "ignores "LockXLock yes" setting in /etc/hibernate/common.conf (e.g. does not lock the screen)"
293
294 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507576 507576]
295 in [http://packages.debian.org/lenny/xbattbar-acpi xbattbar-acpi]
296 "missing dependency: libconfig"
297
298 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507579 507579]
299 in [http://packages.debian.org/lenny/yocto-reader yocto-reader]
300 "Package installation results in license violation"
301
302 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507675 507675]
303 in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org]
304 "python2.5 should have priority standard"
305
306 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507678 507678]
307 in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org]
308 "libsqlite3-0 should have priority standard"
309
310 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507706 507706]
311 in [http://packages.debian.org/lenny/cdimage.debian.org cdimage.debian.org]
312 "Missing sources for d-i components/kernel of etch-n-half images"
313
314 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507721 507721]
315 in [http://packages.debian.org/lenny/cryptsetup cryptsetup]
316 "cryptsetup: Sometimes initrd ends up missing conf/conf.d/cryptroot file in it"
317
318 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507775 507775]
319 in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org]
320 "libkeyutils1 should have priority standard"
321
322 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507778 507778]
323 in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org]
324 "libldap-2.4-2 should have priority standard"
325
326 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507779 507779]
327 in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org]
328 "[Priorities] libustr-1.0-1 -> standard"
329
330 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507780 507780]
331 in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org]
332 "python-sepolgen should have priority standard"
333
334 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507783 507783]
335 in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org]
336 "libxml2 should have priority standard"
337
338 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507784 507784]
339 in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org]
340 "python2.5-minimal should have priority standard"
341
342 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507796 507796]
343 in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org]
344 "libisccfg40 should have priority standard"
345
346 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507797 507797]
347 in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org]
348 "libisccc40 should have priority standard"
349
350 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507798 507798]
351 in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org]
352 "libedit2 should have priority standard"
353
354 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507799 507799]
355 in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org]
356 "libgssglue1 must have priority standard"
357
358 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507800 507800]
359 in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org]
360 "ucf must have priority standard"
361
362 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507801 507801]
363 in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org]
364 "libpci3 must have priority standard"
365
366 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507818 507818]
367 in [http://packages.debian.org/lenny/mldonkey-server mldonkey-server]
368 "mldonkey-server: mlnet does not start, logs syntax error in downloads.ini"
369
370 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507865 507865]
371 in [http://packages.debian.org/lenny/openoffice.org-writer openoffice.org-writer]
372 "openoffice.org-writer: OOo 2.4.x openinig OOo 3 files doesn't show text (2.x implements standard wrong)"
373
374 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507883 507883]
375 in [http://packages.debian.org/lenny/asterisk asterisk]
376 "asterisk: Very frequent segfaults on startup"
377
378 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507889 507889]
379 in [http://packages.debian.org/lenny/mdadm mdadm]
380 "mdadm: initramfs-tools script is broken, system with root on RAID won't boot"
381
382 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507915 507915]
383 in [http://packages.debian.org/lenny/povray povray]
384 "Povray unusable with non-ascii filenames"
385
386 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507927 507927]
387 in [http://packages.debian.org/lenny/acpi-support acpi-support]
388 "Fix suspend-resume in Thinkpad R50e (intel 855gm card)"
389
390 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507944 507944]
391 in [http://packages.debian.org/lenny/xwhois xwhois]
392 "xwhois: segfaults on start in get_servers()"
393
394 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507947 507947]
395 in [http://packages.debian.org/lenny/moodle moodle]
396 "moodle: html2text.php is not DFSG-free"
397
398 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507996 507996]
399 in [http://packages.debian.org/lenny/uim-tcode uim-tcode]
400 "mazegaki conversion cannot be used"
401
402 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508026 508026]
403 in [http://packages.debian.org/lenny/phppgadmin phppgadmin]
404 "phpPgAdmin: Local File Inclusion Vulnerability"
405
406 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508091 508091]
407 in [http://packages.debian.org/lenny/tuxguitar tuxguitar]
408 "maintainer address bounces"
409
410 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508124 508124]
411 in [http://packages.debian.org/lenny/python-m2crypto python-m2crypto]
412 "Yum crashes when setting-up a CentOS chroot OS"
413
414 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508133 508133]
415 in [http://packages.debian.org/lenny/libmad0 libmad0]
416 "audacity: munmap_chunk(): invalid pointer: 0x00000000026f4eb0"
417
418 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508194 508194]
419 in [http://packages.debian.org/lenny/sun-java5 sun-java5]
420 "sun-java5: New upstream release fixes several security issues"
421
422 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508257 508257]
423 in [http://packages.debian.org/lenny/twiki twiki]
424 "CVE-2008-5305: TWiki SEARCH variable allows arbitrary shell command execution"
425
426 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508265 508265]
427 in [http://packages.debian.org/lenny/sysprof-module-source sysprof-module-source]
428 "sysprof-module-source: doesn't compile on AMD64 arch (wrong register names)"
429
430 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508272 508272]
431 in [http://packages.debian.org/lenny/gnome-splashscreen-manager gnome-splashscreen-manager]
432 "gnome-splashscreen-manager: Refuses to start, undefined symbol: gtk_file_system_error_quark"
433
434 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508313 508313]
435 in [http://packages.debian.org/lenny/xine-lib xine-lib]
436 "xine-lib: CVE-2008-5234 heap overflow in atom parsing"
437
438 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508322 508322]
439 in [http://packages.debian.org/lenny/wodim wodim]
440 "wodim: Cannot load media.  Cannot init drive."
441
442 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508324 508324]
443 in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org]
444 "ftp.debian.org: gcc-4.2-base is not really required"
445
446 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508351 508351]
447 in [http://packages.debian.org/lenny/open-iscsi open-iscsi]
448 "open-iscsi: will not install, looking for missing /sys/module/scsi_transport_iscsi/version file"
449
450 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508434 508434]
451 in [http://packages.debian.org/lenny/ipmitool ipmitool]
452 "ipmitool: Several init script problems due to wrong pidfile name"
453
454 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508443 508443]
455 in [http://packages.debian.org/lenny/imagemagick imagemagick]
456 "convert crash on sparc during compilation of djvulibre (work on x86-64)"
457
458 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508480 508480]
459 in [http://packages.debian.org/lenny/iodbc iodbc]
460 "iodbc: Segfaults when asking for the available DSNs"
461
462 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508510 508510]
463 in [http://packages.debian.org/lenny/debget debget]
464 "Can't parse packages.debian.org output anymore"
465
466
467 = Mostly solved? =
468
469 These look like good progress is being made and they'll get fixed soon.
470
471 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=332782 332782]
472 in [http://packages.debian.org/lenny/release-notes release-notes]
473 "release-notes: Where's the license?"
474
475 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=475958 475958]
476 in [http://packages.debian.org/lenny/release-notes release-notes]
477 "document procedure to recover from "/dev/hda became /dev/sda" boot failure"
478 [[BR]](Note: looks done, just not closed.)
479
480 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=476210 476210]
481 in [http://packages.debian.org/lenny/xbat xbat]
482 "xbat: game elements do not display properly"
483
484 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506883 506883]
485 in [http://packages.debian.org/lenny/tuxguitar tuxguitar]
486 "tuxguitar: hard-codes dependencies on libraries"
487
488
489 = Flamewars =
490
491 You might enjoy reading these, but they may not be good targets to fix.
492
493 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=475737 475737]
494 in [http://packages.debian.org/lenny/otrs2 otrs2]
495 "otrs2 - makes files in /usr writable by non-root"
496
497
498 = Would have been fun =
499
500 Entertaining to read but sadly already fixed.
501
502 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506961 506961]
503 in auctex
504 "auctex: reuses old logfile on emacsen upgrades, enabling symlink attack"
505
506