]> sipb.mit.edu Git - wiki.git/blob - doc/LennyBugsAll
(no commit message)
[wiki.git] / doc / LennyBugsAll
1 = Open RC Bugs in Lenny =
2
3 These are bugs to consider at SIPB's [LennyBugs RC-bug-squashing hackathon] for Lenny.
4
5 Bug list dumped early 2008-12-12.  The pipeline was
6  `$ cd /mit/debathena/debian-bts && ./get_bugs | sort | ./bugs-format-trac`
7
8 Please sort into useful/not useful, add notes, etc.
9
10 = Juicy? =
11
12 Try these!
13
14 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=374644 374644] in [http://packages.debian.org/lenny/xine-ui xine-ui]
15 "xine-ui: ctrl/shift key press emulation implementation broken"
16 [[BR]](Note: have patch but it's broken.  Test?  Find a fix?)
17
18 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=426465 426465]
19 in [http://packages.debian.org/lenny/initramfs-tools initramfs-tools]
20 "/init exports MODPROBE_OPTIONS=-qb"
21 [[BR]](Note: real bug report is near bottom.)
22
23 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=476525 476525]
24 in [http://packages.debian.org/lenny/python-hid python-hid]
25 "python-hid: hid module will not import since python policy transition"
26 [[BR]](Note: have patch, looks messy, looks like not-too-hard bug to fix well.)
27
28 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=481072 481072]
29 in [http://packages.debian.org/lenny/dk-filter dk-filter]
30 "dk-filter reliably crashes upon connection from postfix"
31 [[BR]](Note: bug report, little followup.  Test, reproduce, debug, fix.)
32
33 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506057 506057]
34 in [http://packages.debian.org/lenny/splashy splashy]
35 "splashy: Splashy fails to install due to missing default theme"
36
37 These ones are only about 2 weeks old:
38
39 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507071 507071]
40 in [http://packages.debian.org/lenny/racoon racoon]
41 "racoon - Fails after upgrade: symbol lookup error: /usr/sbin/racoon: undefined symbol: libipsec_opt"
42
43 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507072 507072]
44 in [http://packages.debian.org/lenny/ipsec-tools ipsec-tools]
45 "libipsec0 packaged in ipsec-tools without development headers"
46
47 = Specific hardware =
48
49 If you have the relevant hardware you could help a lot.
50
51 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=394963 394963]
52 in [http://packages.debian.org/lenny/installation-reports installation-reports]
53 "installation: Problems with dual booting Dell D600 with winXP pro in the first partition (hd0, 0). After installing the Dell Etch Beta 3, Windows fails to boot and I get the blue screen of death."
54
55 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=418972 418972]
56 in [http://packages.debian.org/lenny/installation-reports installation-reports]
57 "cdrom: Etch does not detect CD-ROM on Acer Aspire 7100"
58
59 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=478717 478717]
60 in [http://packages.debian.org/lenny/ruby1.9 ruby1.9]
61 "ruby1.9: FTBFS on hppa: make[1]: *** [all] Segmentation fault"
62
63 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=499078 499078]
64 in [http://packages.debian.org/lenny/jfsutils jfsutils]
65 "jfsutils: Bus Error when running fsck.jfs on sparc"
66
67 = Examples =
68
69 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=496954 496954]
70 in [http://packages.debian.org/lenny/bind9 bind9]
71 "bind9: Fails to start due to SIGSEGV"
72 [[BR]]This bug sat unfixed for months.  Then someone attacked it in a bug-squashing party,
73 got the first reproducible testcase, and sent that upstream, which swiftly produced a fix.
74
75
76 = May be a lot of work =
77
78 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=456037 456037]
79 in [http://packages.debian.org/lenny/fenix fenix]
80 "fenix: not 64 bit clean"
81
82 = Puzzling =
83
84 Someone please explain what's going on (Debian Project-wise) in these bugs.
85
86 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=323473 323473]
87 in [http://packages.debian.org/lenny/wnpp wnpp]
88 "ITA: mol-drivers-linux -- The Mac-on-Linux emulator - drivers for Linux"
89 [[BR]](Note: The bug is for someone to take over maintainership.  They did.  Then when the bug gets automatically archived, they reply saying to keep it?  I (price) don't understand.)
90
91
92 = Unclassified =
93
94 Please read these reports and figure out what category they belong in.  Or make a new category.
95
96 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=436140 436140]
97 in [http://packages.debian.org/lenny/installation-reports installation-reports]
98 "cdrom: Most of the system's files have a future timestamp causing at least update/config problems."
99
100 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=490171 490171]
101 in [http://packages.debian.org/lenny/rtorrent rtorrent]
102 "rtorrent: random crash"
103
104 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=490999 490999]
105 in [http://packages.debian.org/lenny/libqt3-mt libqt3-mt]
106 "kicker: crashes on startup"
107
108 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=494293 494293]
109 in [http://packages.debian.org/lenny/installation-reports installation-reports]
110 "installation-reports: Grub error: not a regular file..."
111
112 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=495232 495232]
113 in [http://packages.debian.org/lenny/quagga quagga]
114 "quagga: zebra ignores routes added via command line"
115
116 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=495603 495603]
117 in [http://packages.debian.org/lenny/installation-reports installation-reports]
118 "grub-installer fails on a FSC Primergy RX300 with a level 5 RAID"
119
120 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=496334 496334]
121 in [http://packages.debian.org/lenny/mdadm mdadm]
122 "mdadm segfault on --assemble --force with raid10"
123
124 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=500460 500460]
125 in [http://packages.debian.org/lenny/oss-compat oss-compat]
126 "oss-compat: modules are not loaded"
127
128 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=501800 501800]
129 in [http://packages.debian.org/lenny/bind9 bind9]
130 "bind9: bind crashes with a list for allow-update"
131
132 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=501804 501804]
133 in [http://packages.debian.org/lenny/installation-reports installation-reports]
134 "installation-reports: Lenny b2 install on ThinkPad X61 - fails to detect hard disk"
135
136 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=502140 502140]
137 in [http://packages.debian.org/lenny/pam pam]
138 "cannot unlock screen during etch -> lenny transition"
139
140 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=502751 502751]
141 in [http://packages.debian.org/lenny/clamav-getfiles clamav-getfiles]
142 "clamav-getfiles: piuparts test fails: eicar.com md5sum mismatch, file needs downloading"
143
144 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=503303 503303]
145 in [http://packages.debian.org/lenny/upgrade-reports upgrade-reports]
146 "etch -> lenny minimal chrrot upgrade fails due to Conflicts/Pre-Depends loop"
147
148 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=503532 503532]
149 in [http://packages.debian.org/lenny/dbus dbus]
150 "send_requested_reply="true" allows all non-reply messages"
151
152 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=503712 503712]
153 in [http://packages.debian.org/lenny/ghostscript ghostscript]
154 "etch->lenny upgrade left the system in broken state"
155
156 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=503907 503907]
157 in [http://packages.debian.org/lenny/libwebkit-1.0-1 libwebkit-1.0-1]
158 "epiphany-webkit: Crashes at startup whenever I go to a site."
159
160 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504373 504373]
161 in [http://packages.debian.org/lenny/libtemplate-perl libtemplate-perl]
162 "libtemplate-perl: Upgrade from etch breaks code using DBI plugins"
163
164 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504524 504524]
165 in [http://packages.debian.org/lenny/sun-java6 sun-java6]
166 "AWT_TOOLKIT=MToolkit causes java to segfault on amd64"
167
168 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504626 504626]
169 in [http://packages.debian.org/lenny/nvidia-glx nvidia-glx]
170 "[nvidia-glx] Quietly drops support for several chipsets"
171
172 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504661 504661]
173 in [http://packages.debian.org/lenny/nvidia-glx-legacy-96xx-dev nvidia-glx-legacy-96xx-dev]
174 "nvidia-glx-legacy-96xx-dev: /usr/lib/libGL.so symlink broken"
175
176 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504747 504747]
177 in [http://packages.debian.org/lenny/gnu-fdisk gnu-fdisk]
178 "gnu-fdisk: wipes out MBR when used on GPT partitions"
179
180 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504918 504918]
181 in [http://packages.debian.org/lenny/network-manager network-manager]
182 "Updating to lenny failed when NetworkManager got updated"
183
184 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=505237 505237]
185 in [http://packages.debian.org/lenny/snmpd snmpd]
186 "/etc/init.d/snmpd start reports error if already running"
187
188 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506748 506748]
189 in [http://packages.debian.org/lenny/rtorrent rtorrent]
190 "crash rtorrent by scgi-interface (function: 'fi.get_filename_last')"
191
192 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506853 506853]
193 in [http://packages.debian.org/lenny/libgnutls26 libgnutls26]
194 "libgnutls26: 2.4.2-3 breaks OpenLDAP access"
195
196 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506977 506977]
197 in [http://packages.debian.org/lenny/release.debian.org release.debian.org]
198 "FPC: copyright infringement in pre 2.2.2 sources"
199
200 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507003 507003]
201 in [http://packages.debian.org/lenny/open-iscsi open-iscsi]
202 "initiatorname.iscsi should maybe not be in /etc"
203
204 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507059 507059]
205 in [http://packages.debian.org/lenny/initramfs-tools initramfs-tools]
206 "initramfs-tools: Wrong check for udevadm in functions"
207
208 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507239 507239]
209 in [http://packages.debian.org/lenny/release.debian.org release.debian.org]
210 "RM: astrolog/stable -- RoQA; orphaned long time, non-free, contains potentially undistributable code"
211
212 = Unclassified Security =
213
214 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=505563 505563]
215 in [http://packages.debian.org/lenny/icedove icedove]
216 "Mozilla Thunderbird Multiple Vulnerabilities"
217
218 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506353 506353]
219 in [http://packages.debian.org/lenny/mailscanner mailscanner]
220 "CVE-2008-5312/3: mailscanner might allow local users to overwrite arbitrary files via a symlink attack"
221
222 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507165 507165]
223 in [http://packages.debian.org/lenny/xine-lib xine-lib]
224 "xine-lib: CVE-2008-5242 heap-based buffer overflow"
225
226 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507184 507184]
227 in [http://packages.debian.org/lenny/xine-lib xine-lib]
228 "xine-lib: CVE-2008-5246 heap overflow"
229
230 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506741 506741]
231 in [http://packages.debian.org/lenny/wireshark wireshark]
232 "wireshark: DoS caused by sending a SMTP request with large content"
233
234 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504977 504977]
235 in [http://packages.debian.org/lenny/ffmpeg-debian ffmpeg-debian]
236 "ffmpeg-debian: Several security issues"
237
238 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504771 504771]
239 in [http://packages.debian.org/lenny/wordpress wordpress]
240 "wordpress can be subject of delayed attacks via cookies"
241
242 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504283 504283]
243 in [http://packages.debian.org/lenny/egroupware-core egroupware-core]
244 "CVE-2007-3215: phpmailer issue (embedded code-copy)"
245
246 = Fresh bugs =
247
248 These are very recent and presumably will get dealt with by the package maintainers without help.
249
250 If you're bored you might look through and see if some are interesting anyway.  Also feel free to draw the line at some other time; I (price) picked December 1, arbitrarily.
251
252
253 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=239111 239111]
254 in [http://packages.debian.org/lenny/grub grub]
255 "Freeze when installing GRUB on XFS boot partition"
256 [[BR]](Note: just re-opened 2008-12-12)
257
258 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507558 507558]
259 in [http://packages.debian.org/lenny/hibernate hibernate]
260 "ignores "LockXLock yes" setting in /etc/hibernate/common.conf (e.g. does not lock the screen)"
261
262 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507576 507576]
263 in [http://packages.debian.org/lenny/xbattbar-acpi xbattbar-acpi]
264 "missing dependency: libconfig"
265
266 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507579 507579]
267 in [http://packages.debian.org/lenny/yocto-reader yocto-reader]
268 "Package installation results in license violation"
269
270
271 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507706 507706]
272 in [http://packages.debian.org/lenny/cdimage.debian.org cdimage.debian.org]
273 "Missing sources for d-i components/kernel of etch-n-half images"
274
275 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507721 507721]
276 in [http://packages.debian.org/lenny/cryptsetup cryptsetup]
277 "cryptsetup: Sometimes initrd ends up missing conf/conf.d/cryptroot file in it"
278
279 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507818 507818]
280 in [http://packages.debian.org/lenny/mldonkey-server mldonkey-server]
281 "mldonkey-server: mlnet does not start, logs syntax error in downloads.ini"
282
283 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507865 507865]
284 in [http://packages.debian.org/lenny/openoffice.org-writer openoffice.org-writer]
285 "openoffice.org-writer: OOo 2.4.x openinig OOo 3 files doesn't show text (2.x implements standard wrong)"
286
287 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507883 507883]
288 in [http://packages.debian.org/lenny/asterisk asterisk]
289 "asterisk: Very frequent segfaults on startup"
290
291 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507889 507889]
292 in [http://packages.debian.org/lenny/mdadm mdadm]
293 "mdadm: initramfs-tools script is broken, system with root on RAID won't boot"
294
295 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507915 507915]
296 in [http://packages.debian.org/lenny/povray povray]
297 "Povray unusable with non-ascii filenames"
298
299 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507927 507927]
300 in [http://packages.debian.org/lenny/acpi-support acpi-support]
301 "Fix suspend-resume in Thinkpad R50e (intel 855gm card)"
302
303 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507944 507944]
304 in [http://packages.debian.org/lenny/xwhois xwhois]
305 "xwhois: segfaults on start in get_servers()"
306
307 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507947 507947]
308 in [http://packages.debian.org/lenny/moodle moodle]
309 "moodle: html2text.php is not DFSG-free"
310
311 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507996 507996]
312 in [http://packages.debian.org/lenny/uim-tcode uim-tcode]
313 "mazegaki conversion cannot be used"
314
315 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508026 508026]
316 in [http://packages.debian.org/lenny/phppgadmin phppgadmin]
317 "phpPgAdmin: Local File Inclusion Vulnerability"
318
319 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508091 508091]
320 in [http://packages.debian.org/lenny/tuxguitar tuxguitar]
321 "maintainer address bounces"
322
323 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508124 508124]
324 in [http://packages.debian.org/lenny/python-m2crypto python-m2crypto]
325 "Yum crashes when setting-up a CentOS chroot OS"
326
327 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508133 508133]
328 in [http://packages.debian.org/lenny/libmad0 libmad0]
329 "audacity: munmap_chunk(): invalid pointer: 0x00000000026f4eb0"
330
331 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508194 508194]
332 in [http://packages.debian.org/lenny/sun-java5 sun-java5]
333 "sun-java5: New upstream release fixes several security issues"
334
335 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508257 508257]
336 in [http://packages.debian.org/lenny/twiki twiki]
337 "CVE-2008-5305: TWiki SEARCH variable allows arbitrary shell command execution"
338
339 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508265 508265]
340 in [http://packages.debian.org/lenny/sysprof-module-source sysprof-module-source]
341 "sysprof-module-source: doesn't compile on AMD64 arch (wrong register names)"
342
343 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508272 508272]
344 in [http://packages.debian.org/lenny/gnome-splashscreen-manager gnome-splashscreen-manager]
345 "gnome-splashscreen-manager: Refuses to start, undefined symbol: gtk_file_system_error_quark"
346
347 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508313 508313]
348 in [http://packages.debian.org/lenny/xine-lib xine-lib]
349 "xine-lib: CVE-2008-5234 heap overflow in atom parsing"
350
351 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508322 508322]
352 in [http://packages.debian.org/lenny/wodim wodim]
353 "wodim: Cannot load media.  Cannot init drive."
354
355 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508324 508324]
356 in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org]
357 "ftp.debian.org: gcc-4.2-base is not really required"
358
359 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508351 508351]
360 in [http://packages.debian.org/lenny/open-iscsi open-iscsi]
361 "open-iscsi: will not install, looking for missing /sys/module/scsi_transport_iscsi/version file"
362
363 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508434 508434]
364 in [http://packages.debian.org/lenny/ipmitool ipmitool]
365 "ipmitool: Several init script problems due to wrong pidfile name"
366
367 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508443 508443]
368 in [http://packages.debian.org/lenny/imagemagick imagemagick]
369 "convert crash on sparc during compilation of djvulibre (work on x86-64)"
370
371 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508480 508480]
372 in [http://packages.debian.org/lenny/iodbc iodbc]
373 "iodbc: Segfaults when asking for the available DSNs"
374
375 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508510 508510]
376 in [http://packages.debian.org/lenny/debget debget]
377 "Can't parse packages.debian.org output anymore"
378
379
380 = Mostly solved? =
381
382 These look like good progress is being made and they'll get fixed soon.
383
384 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507316 507316]
385 in [http://packages.debian.org/lenny/smarty smarty]
386 "smarty: Non-free logo included in package"
387
388 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=332782 332782]
389 in [http://packages.debian.org/lenny/release-notes release-notes]
390 "release-notes: Where's the license?"
391
392 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=475958 475958]
393 in [http://packages.debian.org/lenny/release-notes release-notes]
394 "document procedure to recover from "/dev/hda became /dev/sda" boot failure"
395 [[BR]](Note: looks done, just not closed.)
396
397 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=476210 476210]
398 in [http://packages.debian.org/lenny/xbat xbat]
399 "xbat: game elements do not display properly"
400
401 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506883 506883]
402 in [http://packages.debian.org/lenny/tuxguitar tuxguitar]
403 "tuxguitar: hard-codes dependencies on libraries"
404
405 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=495178 495178]
406 in [http://packages.debian.org/lenny/libjs-jquery libjs-jquery]
407 "libjs-jquery: Should compile jquery.min.js and jquery.pack.js from jquery.js"
408
409 = Not much of use one can do =
410
411 (this one looks like it'll be removed from Lenny or have amd64 disabled)
412
413 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507021 507021]
414 in [http://packages.debian.org/lenny/helpdeco helpdeco]
415 "Fails to work on amd64"
416
417 (this one looks the maintainer has labeled unreproducible)
418
419 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507242 507242]
420 in [http://packages.debian.org/lenny/amule-daemon amule-daemon]
421 "amule-daemon: causes OOM's by leaking lots of memory"
422
423 (waiting on upstream)
424
425 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506652 506652]
426 in [http://packages.debian.org/lenny/xml2rfc xml2rfc]
427 "Yet another boilerplate change"
428
429 = Flamewars =
430
431 You might enjoy reading these, but they may not be good targets to fix.
432
433 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=475737 475737]
434 in [http://packages.debian.org/lenny/otrs2 otrs2]
435 "otrs2 - makes files in /usr writable by non-root"
436
437 For this one, the actual flameware is off the bug report log.
438
439 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=497823 497823]
440 in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org]
441 "longstanding DFSG violations in linux-2.6 package"
442
443 = Would have been fun =
444
445 Entertaining to read but sadly already fixed.
446
447 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506961 506961]
448 in auctex
449 "auctex: reuses old logfile on emacsen upgrades, enabling symlink attack"
450
451
452 = Special team bugs =
453
454 These bugs are probably not good targets because the work involved with them is to be done by someone on a special Debian team.
455
456 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=451628 451628]
457 in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org]
458 "Packages might enter the archive from security without source"
459
460 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506152 506152]
461 in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org]
462 "libept0 should have priority important"
463
464 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507675 507675]
465 in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org]
466 "python2.5 should have priority standard"
467
468 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507678 507678]
469 in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org]
470 "libsqlite3-0 should have priority standard"
471
472 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507775 507775]
473 in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org]
474 "libkeyutils1 should have priority standard"
475
476 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507778 507778]
477 in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org]
478 "libldap-2.4-2 should have priority standard"
479
480 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507779 507779]
481 in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org]
482 "[Priorities] libustr-1.0-1 -> standard"
483
484 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507780 507780]
485 in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org]
486 "python-sepolgen should have priority standard"
487
488 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507783 507783]
489 in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org]
490 "libxml2 should have priority standard"
491
492 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507784 507784]
493 in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org]
494 "python2.5-minimal should have priority standard"
495
496 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507796 507796]
497 in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org]
498 "libisccfg40 should have priority standard"
499
500 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507797 507797]
501 in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org]
502 "libisccc40 should have priority standard"
503
504 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507798 507798]
505 in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org]
506 "libedit2 should have priority standard"
507
508 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507799 507799]
509 in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org]
510 "libgssglue1 must have priority standard"
511
512 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507800 507800]
513 in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org]
514 "ucf must have priority standard"
515
516 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507801 507801]
517 in [http://packages.debian.org/lenny/ftp.debian.org ftp.debian.org]
518 "libpci3 must have priority standard"
519
520 [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=497471 497471]
521 in [http://packages.debian.org/lenny/cdimage.debian.org cdimage.debian.org]
522 "sarge images have syslinux binaries without source"
523