(no commit message)
[wiki.git] / doc / LennyBugsAll
1 = Open RC Bugs in Lenny =
2
3 These are bugs to consider at SIPB's [LennyBugs RC-bug-squashing hackathon] for Lenny.
4
5 Bug list dumped early 2008-12-12.  The pipeline was
6  `$ cd /mit/debathena/debian-bts && ./get_bugs | sort | ./bugs-format-trac`
7
8 Please sort into useful/not useful, add notes, etc.
9
10 = Juicy? =
11
12 Try these!
13
14 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=374644 374644] in [http://packages.debian.org/lenny/xine-ui xine-ui]
15 "xine-ui: ctrl/shift key press emulation implementation broken"
16 [[BR]](Note: have patch but it's broken.  Test?  Find a fix?)
17
18 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=426465 426465]
19 in [http://packages.debian.org/lenny/initramfs-tools initramfs-tools]
20 "/init exports MODPROBE_OPTIONS=-qb"
21 [[BR]](Note: real bug report is near bottom.)
22
23 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=476525 476525]
24 in [http://packages.debian.org/lenny/python-hid python-hid]
25 "python-hid: hid module will not import since python policy transition"
26 [[BR]](Note: have patch, looks messy, looks like not-too-hard bug to fix well.)
27
28 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=481072 481072]
29 in [http://packages.debian.org/lenny/dk-filter dk-filter]
30 "dk-filter reliably crashes upon connection from postfix"
31 [[BR]](Note: bug report, little followup.  Test, reproduce, debug, fix.)
32
33 These ones are only about 2 weeks old:
34 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507071 507071]
35 in [http://packages.debian.org/lenny/racoon racoon]
36 "racoon - Fails after upgrade: symbol lookup error: /usr/sbin/racoon: undefined symbol: libipsec_opt"
37
38 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507072 507072]
39 in [http://packages.debian.org/lenny/ipsec-tools ipsec-tools]
40 "libipsec0 packaged in ipsec-tools without development headers"
41
42 = Specific hardware =
43
44 If you have the relevant hardware you could help a lot.
45
46 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=394963 394963]
47 in [http://packages.debian.org/lenny/installation-reports installation-reports]
48 "installation: Problems with dual booting Dell D600 with winXP pro in the first partition (hd0, 0). After installing the Dell Etch Beta 3, Windows fails to boot and I get the blue screen of death."
49
50 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=418972 418972]
51 in [http://packages.debian.org/lenny/installation-reports installation-reports]
52 "cdrom: Etch does not detect CD-ROM on Acer Aspire 7100"
53
54 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=478717 478717]
55 in [http://packages.debian.org/lenny/ruby1.9 ruby1.9]
56 "ruby1.9: FTBFS on hppa: make[1]: *** [all] Segmentation fault"
57
58 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=499078 499078]
59 in [http://packages.debian.org/lenny/jfsutils jfsutils]
60 "jfsutils: Bus Error when running fsck.jfs on sparc"
61
62 = Examples =
63
64 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=496954 496954]
65 in [http://packages.debian.org/lenny/bind9 bind9]
66 "bind9: Fails to start due to SIGSEGV"
67 [[BR]]This bug sat unfixed for months.  Then someone attacked it in a bug-squashing party,
68 got the first reproducible testcase, and sent that upstream, which swiftly produced a fix.
69
70
71 = May be a lot of work =
72
73 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=456037 456037]
74 in [http://packages.debian.org/lenny/fenix fenix]
75 "fenix: not 64 bit clean"
76
77 = Puzzling =
78
79 Someone please explain what's going on (Debian Project-wise) in these bugs.
80
81 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=323473 323473]
82 in [http://packages.debian.org/lenny/wnpp wnpp]
83 "ITA: mol-drivers-linux -- The Mac-on-Linux emulator - drivers for Linux"
84 [[BR]](Note: The bug is for someone to take over maintainership.  They did.  Then when the bug gets automatically archived, they reply saying to keep it?  I (price) don't understand.)
85
86
87 = Unclassified =
88
89 Please read these reports and figure out what category they belong in.  Or make a new category.
90
91 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=436140 436140]
92 in [http://packages.debian.org/lenny/installation-reports installation-reports]
93 "cdrom: Most of the system's files have a future timestamp causing at least update/config problems."
94
95 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=490171 490171]
96 in [http://packages.debian.org/lenny/rtorrent rtorrent]
97 "rtorrent: random crash"
98
99 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=490999 490999]
100 in [http://packages.debian.org/lenny/libqt3-mt libqt3-mt]
101 "kicker: crashes on startup"
102
103 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=494293 494293]
104 in [http://packages.debian.org/lenny/installation-reports installation-reports]
105 "installation-reports: Grub error: not a regular file..."
106
107 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=495232 495232]
108 in [http://packages.debian.org/lenny/quagga quagga]
109 "quagga: zebra ignores routes added via command line"
110
111 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=495603 495603]
112 in [http://packages.debian.org/lenny/installation-reports installation-reports]
113 "grub-installer fails on a FSC Primergy RX300 with a level 5 RAID"
114
115 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=496334 496334]
116 in [http://packages.debian.org/lenny/mdadm mdadm]
117 "mdadm segfault on --assemble --force with raid10"
118
119 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=497471 497471]
120 in [http://packages.debian.org/lenny/cdimage.debian.org cdimage.debian.org]
121 "sarge images have syslinux binaries without source"
122
123 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=500460 500460]
124 in [http://packages.debian.org/lenny/oss-compat oss-compat]
125 "oss-compat: modules are not loaded"
126
127 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=501800 501800]
128 in [http://packages.debian.org/lenny/bind9 bind9]
129 "bind9: bind crashes with a list for allow-update"
130
131 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=501804 501804]
132 in [http://packages.debian.org/lenny/installation-reports installation-reports]
133 "installation-reports: Lenny b2 install on ThinkPad X61 - fails to detect hard disk"
134
135 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=502140 502140]
136 in [http://packages.debian.org/lenny/pam pam]
137 "cannot unlock screen during etch -> lenny transition"
138
139 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=502751 502751]
140 in [http://packages.debian.org/lenny/clamav-getfiles clamav-getfiles]
141 "clamav-getfiles: piuparts test fails: eicar.com md5sum mismatch, file needs downloading"
142
143 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=503303 503303]
144 in [http://packages.debian.org/lenny/upgrade-reports upgrade-reports]
145 "etch -> lenny minimal chrrot upgrade fails due to Conflicts/Pre-Depends loop"
146
147 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=503532 503532]
148 in [http://packages.debian.org/lenny/dbus dbus]
149 "send_requested_reply="true" allows all non-reply messages"
150
151 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=503712 503712]
152 in [http://packages.debian.org/lenny/ghostscript ghostscript]
153 "etch->lenny upgrade left the system in broken state"
154
155 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=503907 503907]
156 in [http://packages.debian.org/lenny/libwebkit-1.0-1 libwebkit-1.0-1]
157 "epiphany-webkit: Crashes at startup whenever I go to a site."
158
159 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504283 504283]
160 in [http://packages.debian.org/lenny/egroupware-core egroupware-core]
161 "CVE-2007-3215: phpmailer issue (embedded code-copy)"
162
163 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504373 504373]
164 in [http://packages.debian.org/lenny/libtemplate-perl libtemplate-perl]
165 "libtemplate-perl: Upgrade from etch breaks code using DBI plugins"
166
167 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504524 504524]
168 in [http://packages.debian.org/lenny/sun-java6 sun-java6]
169 "AWT_TOOLKIT=MToolkit causes java to segfault on amd64"
170
171 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504626 504626]
172 in [http://packages.debian.org/lenny/nvidia-glx nvidia-glx]
173 "[nvidia-glx] Quietly drops support for several chipsets"
174
175 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504661 504661]
176 in [http://packages.debian.org/lenny/nvidia-glx-legacy-96xx-dev nvidia-glx-legacy-96xx-dev]
177 "nvidia-glx-legacy-96xx-dev: /usr/lib/libGL.so symlink broken"
178
179 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504747 504747]
180 in [http://packages.debian.org/lenny/gnu-fdisk gnu-fdisk]
181 "gnu-fdisk: wipes out MBR when used on GPT partitions"
182
183 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504771 504771]
184 in [http://packages.debian.org/lenny/wordpress wordpress]
185 "wordpress can be subject of delayed attacks via cookies"
186
187 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504918 504918]
188 in [http://packages.debian.org/lenny/network-manager network-manager]
189 "Updating to lenny failed when NetworkManager got updated"
190
191 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504977 504977]
192 in [http://packages.debian.org/lenny/ffmpeg-debian ffmpeg-debian]
193 "ffmpeg-debian: Several security issues"
194
195 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=505237 505237]
196 in [http://packages.debian.org/lenny/snmpd snmpd]
197 "/etc/init.d/snmpd start reports error if already running"
198
199 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=505563 505563]
200 in [http://packages.debian.org/lenny/icedove icedove]
201 "Mozilla Thunderbird Multiple Vulnerabilities"
202
203 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506057 506057]
204 in [http://packages.debian.org/lenny/splashy splashy]
205 "splashy: Splashy fails to install due to missing default theme"
206
207 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506353 506353]
208 in [http://packages.debian.org/lenny/mailscanner mailscanner]
209 "CVE-2008-5312/3: mailscanner might allow local users to overwrite arbitrary files via a symlink attack"
210
211 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506652 506652]
212 in [http://packages.debian.org/lenny/xml2rfc xml2rfc]
213 "Yet another boilerplate change"
214
215 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506741 506741]
216 in [http://packages.debian.org/lenny/wireshark wireshark]
217 "wireshark: DoS caused by sending a SMTP request with large content"
218
219 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506748 506748]
220 in [http://packages.debian.org/lenny/rtorrent rtorrent]
221 "crash rtorrent by scgi-interface (function: 'fi.get_filename_last')"
222
223 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506853 506853]
224 in [http://packages.debian.org/lenny/libgnutls26 libgnutls26]
225 "libgnutls26: 2.4.2-3 breaks OpenLDAP access"
226
227 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506977 506977]
228 in [http://packages.debian.org/lenny/release.debian.org release.debian.org]
229 "FPC: copyright infringement in pre 2.2.2 sources"
230
231 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507003 507003]
232 in [http://packages.debian.org/lenny/open-iscsi open-iscsi]
233 "initiatorname.iscsi should maybe not be in /etc"
234
235 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507059 507059]
236 in [http://packages.debian.org/lenny/initramfs-tools initramfs-tools]
237 "initramfs-tools: Wrong check for udevadm in functions"
238
239 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507165 507165]
240 in [http://packages.debian.org/lenny/xine-lib xine-lib]
241 "xine-lib: CVE-2008-5242 heap-based buffer overflow"
242
243 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507184 507184]
244 in [http://packages.debian.org/lenny/xine-lib xine-lib]
245 "xine-lib: CVE-2008-5246 heap overflow"
246
247 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507239 507239]
248 in [http://packages.debian.org/lenny/release.debian.org release.debian.org]
249 "RM: astrolog/stable -- RoQA; orphaned long time, non-free, contains potentially undistributable code"
250
251 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507242 507242]
252 in [http://packages.debian.org/lenny/amule-daemon amule-daemon]
253 "amule-daemon: causes OOM's by leaking lots of memory"
254
255 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507316 507316]
256 in [http://packages.debian.org/lenny/smarty smarty]
257 "smarty: Non-free logo included in package"
258
259
260 = Fresh bugs =
261
262 These are very recent and presumably will get dealt with by the package maintainers without help.
263
264 If you're bored you might look through and see if some are interesting anyway.  Also feel free to draw the line at some other time; I (price) picked December 1, arbitrarily.
265
266
267 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=239111 239111]
268 in [http://packages.debian.org/lenny/grub grub]
269 "Freeze when installing GRUB on XFS boot partition"
270 [[BR]](Note: just re-opened 2008-12-12)
271
272 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507558 507558]
273 in [http://packages.debian.org/lenny/hibernate hibernate]
274 "ignores "LockXLock yes" setting in /etc/hibernate/common.conf (e.g. does not lock the screen)"
275
276 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507576 507576]
277 in [http://packages.debian.org/lenny/xbattbar-acpi xbattbar-acpi]
278 "missing dependency: libconfig"
279
280 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507579 507579]
281 in [http://packages.debian.org/lenny/yocto-reader yocto-reader]
282 "Package installation results in license violation"
283
284
285 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507706 507706]
286 in [http://packages.debian.org/lenny/cdimage.debian.org cdimage.debian.org]
287 "Missing sources for d-i components/kernel of etch-n-half images"
288
289 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507721 507721]
290 in [http://packages.debian.org/lenny/cryptsetup cryptsetup]
291 "cryptsetup: Sometimes initrd ends up missing conf/conf.d/cryptroot file in it"
292
293 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507818 507818]
294 in [http://packages.debian.org/lenny/mldonkey-server mldonkey-server]
295 "mldonkey-server: mlnet does not start, logs syntax error in downloads.ini"
296
297 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507865 507865]
298 in [http://packages.debian.org/lenny/openoffice.org-writer openoffice.org-writer]
299 "openoffice.org-writer: OOo 2.4.x openinig OOo 3 files doesn't show text (2.x implements standard wrong)"
300
301 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507883 507883]
302 in [http://packages.debian.org/lenny/asterisk asterisk]
303 "asterisk: Very frequent segfaults on startup"
304
305 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507889 507889]
306 in [http://packages.debian.org/lenny/mdadm mdadm]
307 "mdadm: initramfs-tools script is broken, system with root on RAID won't boot"
308
309 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507915 507915]
310 in [http://packages.debian.org/lenny/povray povray]
311 "Povray unusable with non-ascii filenames"
312
313 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507927 507927]
314 in [http://packages.debian.org/lenny/acpi-support acpi-support]
315 "Fix suspend-resume in Thinkpad R50e (intel 855gm card)"
316
317 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507944 507944]
318 in [http://packages.debian.org/lenny/xwhois xwhois]
319 "xwhois: segfaults on start in get_servers()"
320
321 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507947 507947]
322 in [http://packages.debian.org/lenny/moodle moodle]
323 "moodle: html2text.php is not DFSG-free"
324
325 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507996 507996]
326 in [http://packages.debian.org/lenny/uim-tcode uim-tcode]
327 "mazegaki conversion cannot be used"
328
329 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508026 508026]
330 in [http://packages.debian.org/lenny/phppgadmin phppgadmin]
331 "phpPgAdmin: Local File Inclusion Vulnerability"
332
333 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508091 508091]
334 in [http://packages.debian.org/lenny/tuxguitar tuxguitar]
335 "maintainer address bounces"
336
337 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508124 508124]
338 in [http://packages.debian.org/lenny/python-m2crypto python-m2crypto]
339 "Yum crashes when setting-up a CentOS chroot OS"
340
341 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508133 508133]
342 in [http://packages.debian.org/lenny/libmad0 libmad0]
343 "audacity: munmap_chunk(): invalid pointer: 0x00000000026f4eb0"
344
345 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508194 508194]
346 in [http://packages.debian.org/lenny/sun-java5 sun-java5]
347 "sun-java5: New upstream release fixes several security issues"
348
349 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508257 508257]
350 in [http://packages.debian.org/lenny/twiki twiki]
351 "CVE-2008-5305: TWiki SEARCH variable allows arbitrary shell command execution"
352
353 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508265 508265]
354 in [http://packages.debian.org/lenny/sysprof-module-source sysprof-module-source]
355 "sysprof-module-source: doesn't compile on AMD64 arch (wrong register names)"
356
357 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508272 508272]
358 in [http://packages.debian.org/lenny/gnome-splashscreen-manager gnome-splashscreen-manager]
359 "gnome-splashscreen-manager: Refuses to start, undefined symbol: gtk_file_system_error_quark"
360
361 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508313 508313]
362 in [http://packages.debian.org/lenny/xine-lib xine-lib]
363 "xine-lib: CVE-2008-5234 heap overflow in atom parsing"
364
365 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508322 508322]
366 in [http://packages.debian.org/lenny/wodim wodim]
367 "wodim: Cannot load media.  Cannot init drive."
368
369 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508324 508324]
370 in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org]
371 "ftp.debian.org: gcc-4.2-base is not really required"
372
373 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508351 508351]
374 in [http://packages.debian.org/lenny/open-iscsi open-iscsi]
375 "open-iscsi: will not install, looking for missing /sys/module/scsi_transport_iscsi/version file"
376
377 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508434 508434]
378 in [http://packages.debian.org/lenny/ipmitool ipmitool]
379 "ipmitool: Several init script problems due to wrong pidfile name"
380
381 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508443 508443]
382 in [http://packages.debian.org/lenny/imagemagick imagemagick]
383 "convert crash on sparc during compilation of djvulibre (work on x86-64)"
384
385 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508480 508480]
386 in [http://packages.debian.org/lenny/iodbc iodbc]
387 "iodbc: Segfaults when asking for the available DSNs"
388
389 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508510 508510]
390 in [http://packages.debian.org/lenny/debget debget]
391 "Can't parse packages.debian.org output anymore"
392
393
394 = Mostly solved? =
395
396 These look like good progress is being made and they'll get fixed soon.
397
398 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=332782 332782]
399 in [http://packages.debian.org/lenny/release-notes release-notes]
400 "release-notes: Where's the license?"
401
402 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=475958 475958]
403 in [http://packages.debian.org/lenny/release-notes release-notes]
404 "document procedure to recover from "/dev/hda became /dev/sda" boot failure"
405 [[BR]](Note: looks done, just not closed.)
406
407 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=476210 476210]
408 in [http://packages.debian.org/lenny/xbat xbat]
409 "xbat: game elements do not display properly"
410
411 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506883 506883]
412 in [http://packages.debian.org/lenny/tuxguitar tuxguitar]
413 "tuxguitar: hard-codes dependencies on libraries"
414
415 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=495178 495178]
416 in [http://packages.debian.org/lenny/libjs-jquery libjs-jquery]
417 "libjs-jquery: Should compile jquery.min.js and jquery.pack.js from jquery.js"
418
419 (this one looks like it'll be removed from Lenny or have amd64 disabled)
420 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507021 507021]
421 in [http://packages.debian.org/lenny/helpdeco helpdeco]
422 "Fails to work on amd64"
423
424 = Flamewars =
425
426 You might enjoy reading these, but they may not be good targets to fix.
427
428 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=475737 475737]
429 in [http://packages.debian.org/lenny/otrs2 otrs2]
430 "otrs2 - makes files in /usr writable by non-root"
431
432 For this one, the actual flameware is off the bug report log.
433
434 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=497823 497823]
435 in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org]
436 "longstanding DFSG violations in linux-2.6 package"
437
438 = Would have been fun =
439
440 Entertaining to read but sadly already fixed.
441
442 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506961 506961]
443 in auctex
444 "auctex: reuses old logfile on emacsen upgrades, enabling symlink attack"
445
446
447 = Ftpmaster bugs =
448
449 These bugs are probably not good targets because the work involved with them is easy for either the maintainer or ftpmasters to fix.
450
451 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=451628 451628]
452 in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org]
453 "Packages might enter the archive from security without source"
454
455 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506152 506152]
456 in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org]
457 "libept0 should have priority important"
458
459 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507675 507675]
460 in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org]
461 "python2.5 should have priority standard"
462
463 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507678 507678]
464 in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org]
465 "libsqlite3-0 should have priority standard"
466 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507775 507775]
467 in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org]
468 "libkeyutils1 should have priority standard"
469
470 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507778 507778]
471 in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org]
472 "libldap-2.4-2 should have priority standard"
473
474 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507779 507779]
475 in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org]
476 "[Priorities] libustr-1.0-1 -> standard"
477
478 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507780 507780]
479 in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org]
480 "python-sepolgen should have priority standard"
481
482 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507783 507783]
483 in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org]
484 "libxml2 should have priority standard"
485
486 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507784 507784]
487 in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org]
488 "python2.5-minimal should have priority standard"
489
490 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507796 507796]
491 in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org]
492 "libisccfg40 should have priority standard"
493
494 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507797 507797]
495 in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org]
496 "libisccc40 should have priority standard"
497
498 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507798 507798]
499 in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org]
500 "libedit2 should have priority standard"
501
502 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507799 507799]
503 in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org]
504 "libgssglue1 must have priority standard"
505
506 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507800 507800]
507 in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org]
508 "ucf must have priority standard"
509
510 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507801 507801]
511 in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org]
512 "libpci3 must have priority standard"
513