From 8324c10ec9933d0c75e0dd3749e94acf31a35bee Mon Sep 17 00:00:00 2001 From: Greg Price Date: Fri, 12 Dec 2008 06:44:43 -0500 Subject: [PATCH] factor out full bug list --- doc/LennyBugs | 133 +++---------- doc/LennyBugsAll | 485 ----------------------------------------------- 2 files changed, 23 insertions(+), 595 deletions(-) delete mode 100644 doc/LennyBugsAll diff --git a/doc/LennyBugs b/doc/LennyBugs index 08a42b1..915808c 100644 --- a/doc/LennyBugs +++ b/doc/LennyBugs @@ -31,113 +31,26 @@ Contact the SIPB Chair, Greg Price (`price@mit.edu`), or Vice-Chair, Nelson Elha == The Bugs == -Coming soon: this list formatted better and with links to the bug pages. - -{{{ -507927 acpi-support Fix suspend-resume in Thinkpad R50e (intel 855gm card) -507242 amule-daemon amule-daemon: causes OOM's by leaking lots of memory -507883 asterisk asterisk: Very frequent segfaults on startup -506961 auctex auctex: reuses old logfile on emacsen upgrades, enabling symlink attack -496954 bind9 bind9: Fails to start due to SIGSEGV -501800 bind9 bind9: bind crashes with a list for allow-update -497471 cdimage.debian.org sarge images have syslinux binaries without source -507706 cdimage.debian.org Missing sources for d-i components/kernel of etch-n-half images -502751 clamav-getfiles clamav-getfiles: piuparts test fails: eicar.com md5sum mismatch, file needs downloading -507721 cryptsetup cryptsetup: Sometimes initrd ends up missing conf/conf.d/cryptroot file in it -503532 dbus send_requested_reply="true" allows all non-reply messages -504340 djvulibre-plugin djvulibre-plugin: Iceweasel crashes when loading DjVu documents -481072 dk-filter dk-filter reliably crashes upon connection from postfix -505929 egroupware egroupware incompatible with php 5.2.6 -504283 egroupware-core CVE-2007-3215: phpmailer issue (embedded code-copy) -456037 fenix fenix: not 64 bit clean -504977 ffmpeg-debian ffmpeg-debian: Several security issues -451628 ftp.debian.org Packages might enter the archive from security without source -497823 ftp.debian.org longstanding DFSG violations in linux-2.6 package -506152 ftp.debian.org libept0 should have priority important -507675 ftp.debian.org python2.5 should have priority standard -507678 ftp.debian.org libsqlite3-0 should have priority standard -507775 ftp.debian.org libkeyutils1 should have priority standard -507778 ftp.debian.org libldap-2.4-2 should have priority standard -507779 ftp.debian.org [Priorities] libustr-1.0-1 -> standard -507780 ftp.debian.org python-sepolgen should have priority standard -507783 ftp.debian.org libxml2 should have priority standard -507784 ftp.debian.org python2.5-minimal should have priority standard -507796 ftp.debian.org libisccfg40 should have priority standard -507797 ftp.debian.org libisccc40 should have priority standard -507798 ftp.debian.org libedit2 should have priority standard -507799 ftp.debian.org libgssglue1 must have priority standard -507800 ftp.debian.org ucf must have priority standard -507801 ftp.debian.org libpci3 must have priority standard -503712 ghostscript etch->lenny upgrade left the system in broken state -504747 gnu-fdisk gnu-fdisk: wipes out MBR when used on GPT partitions -506684 guile-1.8-dev guile-1.8: includes own definition of jmp_buf type in public header -507021 helpdeco Fails to work on amd64 -507558 hibernate ignores "LockXLock yes" setting in /etc/hibernate/common.conf (e.g. does not lock the screen) -505563 icedove Mozilla Thunderbird Multiple Vulnerabilities -426465 initramfs-tools /init exports MODPROBE_OPTIONS=-qb -507059 initramfs-tools initramfs-tools: Wrong check for udevadm in functions -394963 installation-reports installation: Problems with dual booting Dell D600 with winXP pro in the first partition (hd0, 0). After installing the Dell Etch Beta 3, Windows fails to boot and I get the blue screen of death. -418972 installation-reports cdrom: Etch does not detect CD-ROM on Acer Aspire 7100 -436140 installation-reports cdrom: Most of the system's files have a future timestamp causing at least update/config problems. -494293 installation-reports installation-reports: Grub error: not a regular file... -495603 installation-reports grub-installer fails on a FSC Primergy RX300 with a level 5 RAID -501804 installation-reports installation-reports: Lenny b2 install on ThinkPad X61 - fails to detect hard disk -507072 ipsec-tools libipsec0 packaged in ipsec-tools without development headers -499078 jfsutils jfsutils: Bus Error when running fsck.jfs on sparc -506853 libgnutls26 libgnutls26: 2.4.2-3 breaks OpenLDAP access -495178 libjs-jquery libjs-jquery: Should compile jquery.min.js and jquery.pack.js from jquery.js -508133 libmad0 audacity: munmap_chunk(): invalid pointer: 0x00000000026f4eb0 -490999 libqt3-mt kicker: crashes on startup -504373 libtemplate-perl libtemplate-perl: Upgrade from etch breaks code using DBI plugins -503907 libwebkit-1.0-1 epiphany-webkit: Crashes at startup whenever I go to a site. -506353 mailscanner CVE-2008-5312/3: mailscanner might allow local users to overwrite arbitrary files via a symlink attack -496334 mdadm mdadm segfault on --assemble --force with raid10 -507889 mdadm mdadm: initramfs-tools script is broken, system with root on RAID won't boot -507818 mldonkey-server mldonkey-server: mlnet does not start, logs syntax error in downloads.ini -507947 moodle moodle: html2text.php is not DFSG-free -504918 network-manager Updating to lenny failed when NetworkManager got updated504626 nvidia-glx [nvidia-glx] Quietly drops support for several chipsets -504661 nvidia-glx-legacy-96xx-dev nvidia-glx-legacy-96xx-dev: /usr/lib/libGL.so symlink broken -507003 open-iscsi initiatorname.iscsi should maybe not be in /etc -508351 open-iscsi open-iscsi: will not install, looking for missing /sys/module/scsi_transport_iscsi/version file -507865 openoffice.org-writer openoffice.org-writer: OOo 2.4.x openinig OOo 3 files doesn't show text (2.x implements standard wrong) -500460 oss-compat oss-compat: modules are not loaded -475737 otrs2 otrs2 - makes files in /usr writable by non-root -502140 pam cannot unlock screen during etch -> lenny transition -508026 phppgadmin phpPgAdmin: Local File Inclusion Vulnerability -507915 povray Povray unusable with non-ascii filenames -476525 python-hid python-hid: hid module will not import since python policy transition -495232 quagga quagga: zebra ignores routes added via command line -507071 racoon racoon - Fails after upgrade: symbol lookup error: /usr/sbin/racoon: undefined symbol: libipsec_opt -332782 release-notes release-notes: Where's the license? -475958 release-notes document procedure to recover from "/dev/hda became /dev/sda" boot failure -506977 release.debian.org FPC: copyright infringement in pre 2.2.2 sources507239 release.debian.org RM: astrolog/stable -- RoQA; orphaned long time, non-free, contains potentially undistributable code -490171 rtorrent rtorrent: random crash -506748 rtorrent crash rtorrent by scgi-interface (function: 'fi.get_filename_last') -478717 ruby1.9 ruby1.9: FTBFS on hppa: make[1]: *** [all] Segmentation fault -507316 smarty smarty: Non-free logo included in package -505237 snmpd /etc/init.d/snmpd start reports error if already running -506057 splashy splashy: Splashy fails to install due to missing default theme -508194 sun-java5 sun-java5: New upstream release fixes several security issues -504524 sun-java6 AWT_TOOLKIT=MToolkit causes java to segfault on amd64 -508265 sysprof-module-source sysprof-module-source: doesn't compile on AMD64 arch (wrong register names) -506883 tuxguitar tuxguitar: hard-codes dependencies on libraries -508091 tuxguitar maintainer address bounces -508257 twiki CVE-2008-5305: TWiki SEARCH variable allows arbitrary shell command execution -507996 uim-tcode mazegaki conversion cannot be used -503303 upgrade-reports etch -> lenny minimal chrrot upgrade fails due to Conflicts/Pre-Depends loop -506741 wireshark wireshark: DoS caused by sending a SMTP request with large content -323473 wnpp ITA: mol-drivers-linux -- The Mac-on-Linux emulator - drivers for Linux -508322 wodim wodim: Cannot load media. Cannot init drive. -504771 wordpress wordpress can be subject of delayed attacks via cookies -476210 xbat xbat: game elements do not display properly -507576 xbattbar-acpi missing dependency: libconfig -507165 xine-lib xine-lib: CVE-2008-5242 heap-based buffer overflow -507184 xine-lib xine-lib: CVE-2008-5246 heap overflow -508313 xine-lib xine-lib: CVE-2008-5234 heap overflow in atom parsing -374644 xine-ui xine-ui: ctrl/shift key press emulation implementation broken -506652 xml2rfc Yet another boilerplate change -507944 xwhois xwhois: segfaults on start in get_servers() -507579 yocto-reader Package installation results in license violation -508124 yum Yum crashes when setting-up a CentOS chroot OS -}}} -(list as of 2008-12-10 at 2240) +See LennyBugsAll for a complete list. Attack one of the bugs that look good, or read through the unclassified ones to find the good ones. + +Below, a snapshot of the bugs identified as probable good targets. It may be out of date, so check LennyBugsAll. + +[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=374644 374644] in [http://packages.debian.org/lenny/xine-ui xine-ui] +"xine-ui: ctrl/shift key press emulation implementation broken" +[[BR]](Note: have patch but it's broken. Test? Find a fix?) + +[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=426465 426465] +in [http://packages.debian.org/lenny/initramfs-tools initramfs-tools] +"/init exports MODPROBE_OPTIONS=-qb" +[[BR]](Note: real bug report is near bottom.) + +[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=476525 476525] +in [http://packages.debian.org/lenny/python-hid python-hid] +"python-hid: hid module will not import since python policy transition" +[[BR]](Note: have patch, looks messy, looks like not-too-hard bug to fix well.) + +[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=481072 481072] +in [http://packages.debian.org/lenny/dk-filter dk-filter] +"dk-filter reliably crashes upon connection from postfix" +[[BR]](Note: bug report, little followup. Test, reproduce, debug, fix.) + diff --git a/doc/LennyBugsAll b/doc/LennyBugsAll deleted file mode 100644 index 2f80c14..0000000 --- a/doc/LennyBugsAll +++ /dev/null @@ -1,485 +0,0 @@ -Bug list dumped early 2008-12-12. The pipeline was - `$ cd /mit/debathena/debian-bts && ./get_bugs | sort | ./bugs-format-trac` - -Please sort into useful/not useful, add notes, etc. - -= Juicy? = - -Try these! - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=374644 374644] in [http://packages.debian.org/lenny/xine-ui xine-ui] -"xine-ui: ctrl/shift key press emulation implementation broken" -[[BR]](Note: have patch but it's broken. Test? Find a fix?) - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=426465 426465] -in [http://packages.debian.org/lenny/initramfs-tools initramfs-tools] -"/init exports MODPROBE_OPTIONS=-qb" -[[BR]](Note: real bug report is near bottom.) - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=476525 476525] -in [http://packages.debian.org/lenny/python-hid python-hid] -"python-hid: hid module will not import since python policy transition" -[[BR]](Note: have patch, looks messy, looks like not-too-hard bug to fix well.) - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=481072 481072] -in [http://packages.debian.org/lenny/dk-filter dk-filter] -"dk-filter reliably crashes upon connection from postfix" -[[BR]](Note: bug report, little followup. Test, reproduce, debug, fix.) - -= Flamewars = - -You might enjoy reading these, but they may not be good targets to fix. - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=475737 475737] -in [http://packages.debian.org/lenny/otrs2 otrs2] -"otrs2 - makes files in /usr writable by non-root" - - -= Specific hardware = - -If you have the relevant hardware you could help a lot. - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=394963 394963] -in [http://packages.debian.org/lenny/installation-reports installation-reports] -"installation: Problems with dual booting Dell D600 with winXP pro in the first partition (hd0, 0). After installing the Dell Etch Beta 3, Windows fails to boot and I get the blue screen of death." - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=418972 418972] -in [http://packages.debian.org/lenny/installation-reports installation-reports] -"cdrom: Etch does not detect CD-ROM on Acer Aspire 7100" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=478717 478717] -in [http://packages.debian.org/lenny/ruby1.9 ruby1.9] -"ruby1.9: FTBFS on hppa: make[1]: *** [all] Segmentation fault" - - -= Puzzling = - -Someone please explain what's going on (Debian Project-wise) in these bugs. - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=323473 323473] -in [http://packages.debian.org/lenny/wnpp wnpp] -"ITA: mol-drivers-linux -- The Mac-on-Linux emulator - drivers for Linux" -[[BR]](Note: The bug is for someone to take over maintainership. They did. Then when the bug gets automatically archived, they reply saying to keep it? I (price) don't understand.) - - -= Unclassified = - -Please read these reports and figure out what category they belong in. Or make a new category. - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=436140 436140] -in [http://packages.debian.org/lenny/installation-reports installation-reports] -"cdrom: Most of the system's files have a future timestamp causing at least update/config problems." - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=451628 451628] -in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org] -"Packages might enter the archive from security without source" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=456037 456037] -in [http://packages.debian.org/lenny/fenix fenix] -"fenix: not 64 bit clean" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=490171 490171] -in [http://packages.debian.org/lenny/rtorrent rtorrent] -"rtorrent: random crash" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=490999 490999] -in [http://packages.debian.org/lenny/libqt3-mt libqt3-mt] -"kicker: crashes on startup" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=494293 494293] -in [http://packages.debian.org/lenny/installation-reports installation-reports] -"installation-reports: Grub error: not a regular file..." - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=495178 495178] -in [http://packages.debian.org/lenny/libjs-jquery libjs-jquery] -"libjs-jquery: Should compile jquery.min.js and jquery.pack.js from jquery.js" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=495232 495232] -in [http://packages.debian.org/lenny/quagga quagga] -"quagga: zebra ignores routes added via command line" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=495603 495603] -in [http://packages.debian.org/lenny/installation-reports installation-reports] -"grub-installer fails on a FSC Primergy RX300 with a level 5 RAID" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=496334 496334] -in [http://packages.debian.org/lenny/mdadm mdadm] -"mdadm segfault on --assemble --force with raid10" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=496954 496954] -in [http://packages.debian.org/lenny/bind9 bind9] -"bind9: Fails to start due to SIGSEGV" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=497471 497471] -in [http://packages.debian.org/lenny/cdimage.debian.org cdimage.debian.org] -"sarge images have syslinux binaries without source" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=497823 497823] -in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org] -"longstanding DFSG violations in linux-2.6 package" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=499078 499078] -in [http://packages.debian.org/lenny/jfsutils jfsutils] -"jfsutils: Bus Error when running fsck.jfs on sparc" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=500460 500460] -in [http://packages.debian.org/lenny/oss-compat oss-compat] -"oss-compat: modules are not loaded" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=501800 501800] -in [http://packages.debian.org/lenny/bind9 bind9] -"bind9: bind crashes with a list for allow-update" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=501804 501804] -in [http://packages.debian.org/lenny/installation-reports installation-reports] -"installation-reports: Lenny b2 install on ThinkPad X61 - fails to detect hard disk" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=502140 502140] -in [http://packages.debian.org/lenny/pam pam] -"cannot unlock screen during etch -> lenny transition" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=502751 502751] -in [http://packages.debian.org/lenny/clamav-getfiles clamav-getfiles] -"clamav-getfiles: piuparts test fails: eicar.com md5sum mismatch, file needs downloading" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=503303 503303] -in [http://packages.debian.org/lenny/upgrade-reports upgrade-reports] -"etch -> lenny minimal chrrot upgrade fails due to Conflicts/Pre-Depends loop" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=503532 503532] -in [http://packages.debian.org/lenny/dbus dbus] -"send_requested_reply="true" allows all non-reply messages" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=503712 503712] -in [http://packages.debian.org/lenny/ghostscript ghostscript] -"etch->lenny upgrade left the system in broken state" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=503907 503907] -in [http://packages.debian.org/lenny/libwebkit-1.0-1 libwebkit-1.0-1] -"epiphany-webkit: Crashes at startup whenever I go to a site." - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504283 504283] -in [http://packages.debian.org/lenny/egroupware-core egroupware-core] -"CVE-2007-3215: phpmailer issue (embedded code-copy)" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504373 504373] -in [http://packages.debian.org/lenny/libtemplate-perl libtemplate-perl] -"libtemplate-perl: Upgrade from etch breaks code using DBI plugins" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504524 504524] -in [http://packages.debian.org/lenny/sun-java6 sun-java6] -"AWT_TOOLKIT=MToolkit causes java to segfault on amd64" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504626 504626] -in [http://packages.debian.org/lenny/nvidia-glx nvidia-glx] -"[nvidia-glx] Quietly drops support for several chipsets" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504661 504661] -in [http://packages.debian.org/lenny/nvidia-glx-legacy-96xx-dev nvidia-glx-legacy-96xx-dev] -"nvidia-glx-legacy-96xx-dev: /usr/lib/libGL.so symlink broken" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504747 504747] -in [http://packages.debian.org/lenny/gnu-fdisk gnu-fdisk] -"gnu-fdisk: wipes out MBR when used on GPT partitions" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504771 504771] -in [http://packages.debian.org/lenny/wordpress wordpress] -"wordpress can be subject of delayed attacks via cookies" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504918 504918] -in [http://packages.debian.org/lenny/network-manager network-manager] -"Updating to lenny failed when NetworkManager got updated" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504977 504977] -in [http://packages.debian.org/lenny/ffmpeg-debian ffmpeg-debian] -"ffmpeg-debian: Several security issues" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=505237 505237] -in [http://packages.debian.org/lenny/snmpd snmpd] -"/etc/init.d/snmpd start reports error if already running" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=505563 505563] -in [http://packages.debian.org/lenny/icedove icedove] -"Mozilla Thunderbird Multiple Vulnerabilities" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506057 506057] -in [http://packages.debian.org/lenny/splashy splashy] -"splashy: Splashy fails to install due to missing default theme" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506152 506152] -in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org] -"libept0 should have priority important" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506353 506353] -in [http://packages.debian.org/lenny/mailscanner mailscanner] -"CVE-2008-5312/3: mailscanner might allow local users to overwrite arbitrary files via a symlink attack" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506652 506652] -in [http://packages.debian.org/lenny/xml2rfc xml2rfc] -"Yet another boilerplate change" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506741 506741] -in [http://packages.debian.org/lenny/wireshark wireshark] -"wireshark: DoS caused by sending a SMTP request with large content" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506748 506748] -in [http://packages.debian.org/lenny/rtorrent rtorrent] -"crash rtorrent by scgi-interface (function: 'fi.get_filename_last')" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506853 506853] -in [http://packages.debian.org/lenny/libgnutls26 libgnutls26] -"libgnutls26: 2.4.2-3 breaks OpenLDAP access" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506883 506883] -in [http://packages.debian.org/lenny/tuxguitar tuxguitar] -"tuxguitar: hard-codes dependencies on libraries" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506977 506977] -in [http://packages.debian.org/lenny/release.debian.org release.debian.org] -"FPC: copyright infringement in pre 2.2.2 sources" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507003 507003] -in [http://packages.debian.org/lenny/open-iscsi open-iscsi] -"initiatorname.iscsi should maybe not be in /etc" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507021 507021] -in [http://packages.debian.org/lenny/helpdeco helpdeco] -"Fails to work on amd64" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507059 507059] -in [http://packages.debian.org/lenny/initramfs-tools initramfs-tools] -"initramfs-tools: Wrong check for udevadm in functions" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507071 507071] -in [http://packages.debian.org/lenny/racoon racoon] -"racoon - Fails after upgrade: symbol lookup error: /usr/sbin/racoon: undefined symbol: libipsec_opt" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507072 507072] -in [http://packages.debian.org/lenny/ipsec-tools ipsec-tools] -"libipsec0 packaged in ipsec-tools without development headers" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507165 507165] -in [http://packages.debian.org/lenny/xine-lib xine-lib] -"xine-lib: CVE-2008-5242 heap-based buffer overflow" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507184 507184] -in [http://packages.debian.org/lenny/xine-lib xine-lib] -"xine-lib: CVE-2008-5246 heap overflow" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507239 507239] -in [http://packages.debian.org/lenny/release.debian.org release.debian.org] -"RM: astrolog/stable -- RoQA; orphaned long time, non-free, contains potentially undistributable code" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507242 507242] -in [http://packages.debian.org/lenny/amule-daemon amule-daemon] -"amule-daemon: causes OOM's by leaking lots of memory" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507316 507316] -in [http://packages.debian.org/lenny/smarty smarty] -"smarty: Non-free logo included in package" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507558 507558] -in [http://packages.debian.org/lenny/hibernate hibernate] -"ignores "LockXLock yes" setting in /etc/hibernate/common.conf (e.g. does not lock the screen)" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507576 507576] -in [http://packages.debian.org/lenny/xbattbar-acpi xbattbar-acpi] -"missing dependency: libconfig" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507579 507579] -in [http://packages.debian.org/lenny/yocto-reader yocto-reader] -"Package installation results in license violation" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507675 507675] -in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org] -"python2.5 should have priority standard" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507678 507678] -in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org] -"libsqlite3-0 should have priority standard" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507706 507706] -in [http://packages.debian.org/lenny/cdimage.debian.org cdimage.debian.org] -"Missing sources for d-i components/kernel of etch-n-half images" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507721 507721] -in [http://packages.debian.org/lenny/cryptsetup cryptsetup] -"cryptsetup: Sometimes initrd ends up missing conf/conf.d/cryptroot file in it" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507775 507775] -in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org] -"libkeyutils1 should have priority standard" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507778 507778] -in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org] -"libldap-2.4-2 should have priority standard" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507779 507779] -in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org] -"[Priorities] libustr-1.0-1 -> standard" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507780 507780] -in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org] -"python-sepolgen should have priority standard" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507783 507783] -in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org] -"libxml2 should have priority standard" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507784 507784] -in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org] -"python2.5-minimal should have priority standard" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507796 507796] -in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org] -"libisccfg40 should have priority standard" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507797 507797] -in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org] -"libisccc40 should have priority standard" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507798 507798] -in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org] -"libedit2 should have priority standard" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507799 507799] -in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org] -"libgssglue1 must have priority standard" - -= Mostly solved? = - -These look like good progress is being made and they'll get fixed soon. - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=332782 332782] -in [http://packages.debian.org/lenny/release-notes release-notes] -"release-notes: Where's the license?" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=475958 475958] -in [http://packages.debian.org/lenny/release-notes release-notes] -"document procedure to recover from "/dev/hda became /dev/sda" boot failure" -[[BR]](Note: looks done, just not closed.) - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=476210 476210] -in [http://packages.debian.org/lenny/xbat xbat] -"xbat: game elements do not display properly" - - -= Fresh bugs = - -These are very recent and presumably will get dealt with by the package maintainers without help. - -If you're bored you might look through and see if some are interesting anyway. Also feel free to draw the line at some other time. - - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=239111 239111] -in [http://packages.debian.org/lenny/grub grub] -"Freeze when installing GRUB on XFS boot partition" -[[BR]](Note: just re-opened 2008-12-12) - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507800 507800] -in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org] -"ucf must have priority standard" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507801 507801] -in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org] -"libpci3 must have priority standard" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507818 507818] -in [http://packages.debian.org/lenny/mldonkey-server mldonkey-server] -"mldonkey-server: mlnet does not start, logs syntax error in downloads.ini" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507865 507865] -in [http://packages.debian.org/lenny/openoffice.org-writer openoffice.org-writer] -"openoffice.org-writer: OOo 2.4.x openinig OOo 3 files doesn't show text (2.x implements standard wrong)" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507883 507883] -in [http://packages.debian.org/lenny/asterisk asterisk] -"asterisk: Very frequent segfaults on startup" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507889 507889] -in [http://packages.debian.org/lenny/mdadm mdadm] -"mdadm: initramfs-tools script is broken, system with root on RAID won't boot" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507915 507915] -in [http://packages.debian.org/lenny/povray povray] -"Povray unusable with non-ascii filenames" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507927 507927] -in [http://packages.debian.org/lenny/acpi-support acpi-support] -"Fix suspend-resume in Thinkpad R50e (intel 855gm card)" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507944 507944] -in [http://packages.debian.org/lenny/xwhois xwhois] -"xwhois: segfaults on start in get_servers()" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507947 507947] -in [http://packages.debian.org/lenny/moodle moodle] -"moodle: html2text.php is not DFSG-free" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507996 507996] -in [http://packages.debian.org/lenny/uim-tcode uim-tcode] -"mazegaki conversion cannot be used" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508026 508026] -in [http://packages.debian.org/lenny/phppgadmin phppgadmin] -"phpPgAdmin: Local File Inclusion Vulnerability" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508091 508091] -in [http://packages.debian.org/lenny/tuxguitar tuxguitar] -"maintainer address bounces" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508124 508124] -in [http://packages.debian.org/lenny/python-m2crypto python-m2crypto] -"Yum crashes when setting-up a CentOS chroot OS" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508133 508133] -in [http://packages.debian.org/lenny/libmad0 libmad0] -"audacity: munmap_chunk(): invalid pointer: 0x00000000026f4eb0" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508194 508194] -in [http://packages.debian.org/lenny/sun-java5 sun-java5] -"sun-java5: New upstream release fixes several security issues" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508257 508257] -in [http://packages.debian.org/lenny/twiki twiki] -"CVE-2008-5305: TWiki SEARCH variable allows arbitrary shell command execution" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508265 508265] -in [http://packages.debian.org/lenny/sysprof-module-source sysprof-module-source] -"sysprof-module-source: doesn't compile on AMD64 arch (wrong register names)" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508272 508272] -in [http://packages.debian.org/lenny/gnome-splashscreen-manager gnome-splashscreen-manager] -"gnome-splashscreen-manager: Refuses to start, undefined symbol: gtk_file_system_error_quark" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508313 508313] -in [http://packages.debian.org/lenny/xine-lib xine-lib] -"xine-lib: CVE-2008-5234 heap overflow in atom parsing" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508322 508322] -in [http://packages.debian.org/lenny/wodim wodim] -"wodim: Cannot load media. Cannot init drive." - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508324 508324] -in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org] -"ftp.debian.org: gcc-4.2-base is not really required" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508351 508351] -in [http://packages.debian.org/lenny/open-iscsi open-iscsi] -"open-iscsi: will not install, looking for missing /sys/module/scsi_transport_iscsi/version file" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508434 508434] -in [http://packages.debian.org/lenny/ipmitool ipmitool] -"ipmitool: Several init script problems due to wrong pidfile name" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508443 508443] -in [http://packages.debian.org/lenny/imagemagick imagemagick] -"convert crash on sparc during compilation of djvulibre (work on x86-64)" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508480 508480] -in [http://packages.debian.org/lenny/iodbc iodbc] -"iodbc: Segfaults when asking for the available DSNs" - -[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508510 508510] -in [http://packages.debian.org/lenny/debget debget] -"Can't parse packages.debian.org output anymore" -- 2.44.0