[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

testing security status (post kde)



Steve asked me to send in one of these amazingly easy to generate mails
again now that kde is in.

aduser
	goes in tomorrow
amd64-libs
	15 days old
	blocked by glibc
asterisk
	80 days old
	3 RC bugs
		- 335079: Not clear if this affects a large number of
		  users or if it is a regression from testing.
		- 330983: Affects testing version too.
		- 331318: Need to check if copyright issue affects the
		  testing version, or it is is a new thing in unstable.
	Note that the security hole allows remote code execution. Also
	note that none of the above RC bugs have received a maintainer
	response. IMHO the fix should either be forced in, or asterisk
	should be dropped from testing, and MIA notified.
chmlib
	too new
dhis-tools-dns
	missing sparc upload (build happened Oct 29th)
enigmail
	17 days old
	blocked by mozilla and mozilla-thunderbird
linux-2.6
	too young
	missing many builds for alpha, m68k, s390, hppa, etc
	ftp-master old binary removal fu needed
mozilla
	23 days old
	vorlon is forcing it, hope that works
mozilla-thunderbird
	23 days old
	vorlon is forcing it, hope that works
mozilla-firefox
	40 days old
	2 RC code bugs
	1 RC cpyright bug
	At least 7 fixed security bugs, with at least 3 involving remote
	code execution.
openldap2.2
	too young
slune
	41 days old
	blocked by soya
texinfo
	too young
uim
	scheduled for removal
uw-imap
	21 days old
	RC bug #334512 is avoided by upgrading to libssl 0.9.8a-3.
	Package needs an upload with a dependency on that version to
	close the bug.
	BTW, the security hole is remote code execution.
yiff
	too young
zope2.7
	goes in tomorrow

PS: The current number of untransitioned security fixes is lower than it
    has been at any point in the past year.
PPS: But testing/unstable also have well over 100 unfixed security bugs..

-- 
see shy jo

Attachment: signature.asc
Description: Digital signature


Reply to: