Bug#608740: marked as done (RM: pytris -- RoM; security issues; abandoned upstream)
Your message dated Sat, 22 Jan 2011 11:51:34 +0000
with message-id <E1Pgc0E-00085o-OJ@franck.debian.org>
and subject line Bug#608740: Removed package(s) from stable
has caused the Debian Bug report #608740,
regarding RM: pytris -- RoM; security issues; abandoned upstream
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact firstname.lastname@example.org
Debian Bug Tracking System
Contact email@example.com with problems
--- Begin Message ---
- To: Debian Bug Tracking System <firstname.lastname@example.org>
- Subject: RM: pytris -- security issues; abandoned upstream
- From: Stefano Rivera <email@example.com>
- Date: Sun, 2 Jan 2011 20:14:17 +0200
- Message-id: <20110102181417.GA11207@dvorak.kardiogramm.lan>
Justification: user security hole
The setgid wrapper for this game makes no attempt at security.
It can trivially be used to execute code as group games, which can be
used to exploit other players of the game via the score file.
It could be fixed - the security team suggests dropping the shared score
file, and thus the wrapper. However, this package has not seen a
maintainer upload in years, and is stated as being unmaintained by the
author, on his website:
I believe the best solution is removal, from unstable, squeeze, and
Radovan, are you OK with reassigning this to ftp.debian.org?
-- System Information:
Debian Release: squeeze/sid
APT prefers testing
APT policy: (990, 'testing'), (500, 'unstable'), (1, 'experimental')
Architecture: amd64 (x86_64)
Kernel: Linux 2.6.32-5-amd64 (SMP w/8 CPU cores)
Locale: LANG=en_ZA.UTF-8, LC_CTYPE=en_ZA.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Versions of packages pytris depends on:
ii python 2.6.6-3+squeeze4 interactive high-level object-orie
pytris recommends no packages.
pytris suggests no packages.
-- no debconf information
--- End Message ---
--- Begin Message ---
We believe that the bug you reported is now fixed; the following
package(s) have been removed from stable:
pytris | 0.98 | source, alpha, amd64, arm, armel, hppa, i386, ia64, mips, mipsel, powerpc, s390, sparc
------------------- Reason -------------------
RoM; security issues; abandoned upstream
Note that the package(s) have simply been removed from the tag
database and may (or may not) still be in the pool; this is not a bug.
The package(s) will be physically removed automatically when no suite
references them (and in the case of source, when no binary references
it). Please also remember that the changes have been done on the
master archive (ftp-master.debian.org) and will not propagate to any
mirrors (ftp.debian.org included) until the next cron.daily run at the
Packages are usually not removed from testing by hand. Testing tracks
unstable and will automatically remove packages which were removed
from unstable when removing them from testing causes no dependency
problems. The release team can force a removal from testing if it is
really needed, please contact them if this should be the case.
Bugs which have been reported against this package are not automatically
removed from the Bug Tracking System. Please check all open bugs and
close them or re-assign them to another package if the removed package
was superseded by another one.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to firstname.lastname@example.org.
The full log for this bug can be viewed at http://bugs.debian.org/608740
This message was generated automatically; if you believe that there is
a problem with it please contact the archive administrators by mailing
Debian distribution maintenance software
Archive Administrator (the ftpmaster behind the curtain)
--- End Message ---