Debian Weekly News - July 3rd, 2007

Debian Weekly News - July 3rd, 2007

Welcome to this year's 6th issue of DWN, the newsletter for the Debian
community. Ulrich Hansen created a set of nice looking CD and DVD
[1]covers for the just released [2]Debian GNU/Linux 4.0. Roland Mas
[3]announced that [4]Alioth has been upgrade to [5]etch. Kurt
Gramlich [6]announced a Skolelinux Youngster Meeting on July 20th to
26th in Chemnitz, Germany.

Call for Papers for LVEE-2007. Vlad Shakhov [7]called for papers and
speakers for the upcoming [8]Linux Vacation/Eastern Europe (LVEE)
meeting. The event takes place from June, 14th to 17th near Hrodna,
Belarus. The conference goal is to provide open exchange of ideas and
experience between developers and users, give them ability to establish
personal contacts. Participants and speakers are asked to apply not
later than 1st of June.

Interviews with Sam Hocevar. The new Debian project [9]leader was
interviewed by [10]itwire and [11]linux.com. Sam expressed that he
wants to focus on social aspects like improving the internal
communication, teamwork and motivating Ubuntu developers to contribute
to Debian. About the GPLv3 discussion he said that most GPLv2 software
in Debian is already GPLv3 compatible and that using the GPLv3 in
Debian would cause even more license incompatibilities.

Collection of Debian Art. André Luiz Rodrigues Ferreira [12]announced
the [13]Debian Art website. It aims to create an archive for high
quality artwork like wallpaper, splash screens, icons, logos,
screenshots or system sounds which can be freely used for KDE, GNOME,
Xfce or t-shirts and labels. This user contributed artwork can be
included in upcoming Debian releases.

Removing PHP4. Sean Finney [14]announced that PHP4 will be removed from
[15]unstable and thus [16]testing. Sean has setup a Wiki [17]page to
give detailed information for packages depending on PHP4 and to track
the progress. He asked the respective maintainers to fix their packages
to avoid mass bug filing.

Release Team Meeting Results. Andreas Barth [18]summarised the release
team meeting that took place in Jülich, Germany. A review of the
[19]etch release process lead to simplifying the use of release
[20]goals for the upcoming release of [21]lenny. Architecture
qualification status notes are due to be published every two months and
release updates should be sent out more regularly. The report also
contains a rough release schedule which aims at the next release in the
second half of 2008.

Boosting the Release Team. Luk Claes [22]called for new release
assistants for the lenny release cycle in order to distribute the
workload better among them. Assistants need to have done Quality
Assurance for Debian already, have loads of spare time to use for
release work, have a good understanding of several scripting languages
and acknowledge that they will be doing merely basic work without
authority over the release.

Serious Problem Reminder. Lucas Nussbaum [23]announced that he's going
to send mails to maintainers of packages with serious problems once a
month. When a release-critical bug is open for more than 30 days, or
when the package has not yet migrated into testing the maintainer will
be informed about the problems.

FrOSCon Debian Sub-Conference. Martin Zobel-Helas [24]called for papers
for a Debian sub-conference at this years' [25]FrOSCon that takes place
on August 25th and 26th in St. Augustin, Germany. In addition to the
developer room the project will also [26]run a booth in the exhibition

Format String Vulnerabilities in Debian. Karl Chen and David Wagner
will present an [27]analysis on format string vulnerabilities in the
[28]sarge distribution for the ACM SIGPLAN Workshop on [29]Programming
Languages and Analysis for Security that takes place on June 14th in
San Diego, U.S.A. Tools have marked more than 1,500 packages
potentially insecure of which 87 were determined with true format
string bugs.

Backports for Debian Etch. Alexander Wirt [30]announced the
availability of [31]backports for etch. Backported packages should be
available in the testing distribution, contain new and important
features and there has to be user demand for them. Backports for
[32]sarge are still supported and may need to be removed before the
system is upgraded to etch.

Transition to GCC 4.2. Martin Michlmayr [33]called for developers
interested in helping with the transition to GCC 4.2 by uploading
packages and inspecting build failures. Throughout the development of
GCC 4.2, the entire Debian archive has been recompiled regularly with
development snapshots of GCC to ensure a reliable compiler.

Package Build Status. Sergei Golovan [34]wondered about the meaning of
state "uploaded". Goswin von Brederlow [35]explained that it means the
[36]build daemon has received a signed changes file and has uploaded
the package into the incoming queue. When this status does not change
for a while something went wrong. The buildd admin has to upload the
package again or return it for a rebuild.

Security Updates. You know the drill. Please make sure that you update
your systems if you have any of these packages installed.

 * DSA 1280: [37]aircrack-ng -- Arbitrary code execution.
 * DSA 1281: [38]clamav -- Several vulnerabilities.
 * DSA 1282: [39]PHP4 -- Several vulnerabilities.
 * DSA 1283: [40]PHP5 -- Several vulnerabilities.
 * DSA 1284: [41]qemu -- Several vulnerabilities.
 * DSA 1285: [42]wordpress -- Several vulnerabilities.
 * DSA 1286: [43]Linux 2.6.18 -- Several vulnerabilities.
 * DSA 1287: [44]ldap-account-manager -- Arbitrary Several
 * DSA 1288: [45]pptpd -- Denial of service.
 * DSA 1289: [46]Linux 2.6.18 -- Several vulnerabilities.
 * DSA 1290: [47]squirrelmail -- Cross-site scripting.
 * DSA 1291: [48]samba -- Several vulnerabilities.
 * DSA 1292: [49]qt4-x11 -- Cross-site scripting.
 * DSA 1293: [50]quagga -- Denial of service.
 * DSA 1294: [51]XFree86 -- Several vulnerabilities.
 * DSA 1295: [52]PHP5 -- Several vulnerabilities.
 * DSA 1296: [53]PHP4 -- Privilege escalation.
 * DSA 1297: [54]gforge-plugin-scmcvs -- Arbitrary shell command
 * DSA 1298: [55]otrs2 -- Cross-site scripting.
 * DSA 1299: [56]ipsec-tools -- Denial of service.
 * DSA 1300: [57]iceape -- Several vulnerabilities.
 * DSA 1301: [58]GIMP -- Arbitrary code execution.
 * DSA 1302: [59]freetype -- Arbitrary code execution.
 * DSA 1303: [60]lighttpd -- Denial of service.
 * DSA 1304: [61]Linux 2.6.8 -- Several vulnerabilities.
 * DSA 1305: [62]icedove -- Several vulnerabilities.
 * DSA 1306: [63]xulrunner -- Several vulnerabilities.
 * DSA 1307: [64]OpenOffice.org -- Arbitrary code execution.
 * DSA 1308: [65]iceweasel -- Several vulnerabilities.
 * DSA 1309: [66]PostgreSQL 8.1 -- Privilege escalation.
 * DSA 1310: [67]libexif -- Denial of service.
 * DSA 1311: [68]PostgreSQL 7.4 -- Privilege escalation.
 * DSA 1312: [69]libapache-mod-jk -- Information disclosure.
 * DSA 1313: [70]mplayer -- Arbitrary code execution.
 * DSA 1314: [71]open-iscsi -- Several vulnerabilities.
 * DSA 1315: [72]libphp-phpmailer -- Arbitrary shell command
 * DSA 1316: [73]emacs21 -- Denial of service.
 * DSA 1317: [74]tinymux -- Arbitrary code execution.
 * DSA 1318: [75]ekg -- Denial of service.
 * DSA 1319: [76]maradns -- Denial of service.
 * DSA 1320: [77]clamav -- Several vulnerabilities.
 * DSA 1321: [78]evolution-data-server -- Arbitrary code execution.
 * DSA 1322: [79]wireshark -- Denial of service.
 * DSA 1323: [80]krb5 -- Several vulnerabilities.
 * DSA 1324: [81]hiki -- Privilege escalation.
 * DSA 1325: [82]evolution -- Arbitrary code execution.
 * DSA 1326: [83]fireflier-server -- Insecure temporary files.
 * DSA 1327: [84]gsambad -- Insecure temporary files.
 * DSA 1328: [85]unicon-imc2 -- Arbitrary code execution.

New or Noteworthy Packages. The following packages were added to the
unstable Debian archive [86]recently.

 * [87]apparix -- Console-based bookmark tool for fast file system
 * [88]apt-transport-https -- APT HTTPS transport.
 * [89]bitstormlite -- BitTorrent Client based on C++/GTK+2.0.
 * [90]ctorrent -- BitTorrent Client written in C.
 * [91]ecj -- Standalone version of the Eclipse Java compiler.
 * [92]ept-cache -- Command line tool to search the package archive.
 * [93]fdm -- Fetching, filtering and delivering emails.
 * [94]fische -- Standalone sound visualisation for Linux.
 * [95]gfa -- GTK+ fast address book.
 * [96]giggle -- GTK+ frontend for the git directory tracker.
 * [97]gozerbot -- IRC and Jabber bot written in Python.
 * [98]gpodder -- GTK+ Media aggregator and Podcast catcher.
 * [99]hgsvn -- Scripts to work locally on Subversion checkouts using
 * [100]jlgui -- Graphical music player.
 * [101]ksniffer -- Network traffic analyser for KDE.
 * [102]mtpaint -- Painting program to create pixel art and manipulate
   digital photos.
 * [103]mummer -- Efficient sequence alignment of full genomes.
 * [104]ophcrack -- Microsoft Windows password cracker using rainbow
 * [105]postpone -- Schedules commands to be executed later.
 * [106]powertop -- Linux tool to find out what is using power on a
 * [107]pybackpack -- User friendly file backup tool for GNOME.
 * [108]qgfe -- Qt based Gnuplot Frontend.
 * [109]qtemu -- Graphical user interface for QEMU.
 * [110]qtiplot -- Data analysis and scientific plotting.
 * [111]qtractor -- MIDI/Audio multi-track sequencer application.
 * [112]renpy -- Framework for developing visual-novel type games.
 * [113]rofs -- Read-Only Filesystem for FUSE.
 * [114]slim -- Desktop-independent graphical login manager for X11.
 * [115]taxbird -- First free Elster client (German Tax Declarations).
 * [116]tripod -- iPod photo uploader.
 * [117]tmw -- Mana World is a great Online Rolegame.
 * [118]wavbreaker -- Tool to split wave files into multiple chunks.
 * [119]xindy -- Index generator for structured documents like LaTeX
   or SGML.

Orphaned Packages. 58 packages were orphaned since the last issue and
require a new maintainer. Below is an excerpt of the entire list. This
makes a total of 409 orphaned packages. Many thanks to the previous
maintainers who contributed to the Free Software community. Please see
the [120]WNPP pages for the full list, and please add a note to the bug
report and retitle it to ITA: if you plan to take over a package. To
find out which orphaned packages are installed on your system the
wnpp-alert program from devscripts may be helpful.

 * [121]airsnort -- WLAN sniffer. ([122]Bug#429507)
 * [123]cfourcc -- Command line tool for changing FourCC in Microsoft
   RIFF AVI files. ([124]Bug#425242)
 * [125]datefudge -- Fake the system date. ([126]Bug#429467)
 * [127]divxcomp -- Bitrate calculator for DivX:-) movies written in
   perl. ([128]Bug#424713)
 * [129]dvi2tty -- Previewing dvi-files on text-only devices.
 * [131]ecawave -- Graphical audio file editor. ([132]Bug#431141)
 * [133]fblogo -- Converts images to framebuffer-logo header file.
 * [135]flyspray -- Lightweight Bug Tracking System (BTS) in PHP.
 * [137]gscanbus -- Scan IEEE1394 (firewire/i.link) bus.
 * [139]kforth -- Small Forth Interpreter Written in C++.
 * [141]labrea -- "Sticky" honeypot and IDS. ([142]Bug#424715)
 * [143]libc-scan-perl -- Scan C language files for easily recognised
   constructs. ([144]Bug#430977)
 * [145]medussa -- Distributed password cracking system.
 * [147]metacam -- Extract EXIF information from digital camera files.
 * [149]outguess -- Universal Steganographic tool. ([150]Bug#424718)
 * [151]pmidi -- Command line MIDI player for ALSA. ([152]Bug#429755)
 * [153]procmail-lib -- Library of useful procmail recipes.
 * [155]stegdetect -- Detect and extract steganography messages inside
   JPEG. ([156]Bug#424720)
 * [157]tcpick -- TCP stream sniffer and connection tracker.
 * [159]wmcalc -- Dockable calculator application. ([160]Bug#427132)

Want to continue reading DWN? Please help us create this newsletter. We
still need more volunteer writers who watch the Debian community and
report about what is going on. Please see the [161]contributing page to
find out how to help. We're looking forward to receiving your mail at

This issue of Debian Weekly News was edited by Sebastian Feltel,
Thomas Bliesener, Y Giridhar Appaji Nag and Martin 'Joey' Schulze.

Reply to: