[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Wheezy update of inspircd?



On Tue, 2016-09-06 at 22:28 -0400, Antoine Beaupré wrote:
> I am a bit surprised to see this - are ircd packages sponsored now?
> There's a similar issue in Charybdis and I deliberately marked it as
> unsupported in LTS because, AFAIK, no customer expressed the need to
> support those yet.

If Freexian customers don't use it then it's low priority for those of
us paid through Freexian.  But that doesn't mean it should be marked
unsupported by the LTS team.

> I'd be glad to see if we can update charybdis in Wheezy as well, but to
> be honest, i think people running IRCs on wheezy are really looking for
> trouble, both in the case of charybdis and inspircd. I think they should
> be marked as unsupported, because they are not supported upstream.
> 
> I had an interesting conversation with the inspircd maintainers
> recently, over IRC: they are basically saying that 2.0.5 is full of
> security holes, and they do not bother with issuing CVEs, so it's really
> hard to tell what version if affected by what.

This, on the other hand, is a good reason to make it explicitly
unsupported (or, if some LTS users really do want it, to move to a
supportable upstream version).

Ben.

> It's only because I requested those CVEs that this issue propped up on
> Debian's radar at all, btw...
> 
> A.
-- 
Ben Hutchings
For every action, there is an equal and opposite criticism. - Harrison

Attachment: signature.asc
Description: This is a digitally signed message part


Reply to: