[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Firebird in Debian (now with security vulnerabilities!)



On Sat, May 15, 2004 at 11:08:23AM +1000, Andrew Pollock wrote:
> Hi Mark,
> 
> When the previous maintainer of the Debian Firebird packages (Grzegorz B.
> Prokopski) orphaned them, he made mention[1] that you were looking at taking
> them over. Is this correct? Are you currently a Debian Developer, or are you
> planning on becoming one, or getting a sponsor for these packages?
> 
> I'm looking at doing a QA upload soon, setting the maintainer to the QA
> group, but I don't do this if you plan on taking over active maintainence of
> the packages in the near future.

Okay, I haven't heard anything back about this, and I've just noticed that
there's a vulnerability in firebird.

http://securityfocus.com/bid/7546/info/
http://sourceforge.net/tracker/?group_id=9028&atid=109028&func=detail&aid=739480

I guess it's not huge, because it's only locally exploitable, but obviously
any vulnerability is a bad vulnerability...

According to popcon, there's only 24 installations of it, if I'm reading it
right.

Should we yoink it altogether, or prepare a QA upload? It's not in woody.

regards

Andrew

Attachment: signature.asc
Description: Digital signature


Reply to: