Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #1069273

Bug#993372: Bug#993378: RM: gtkpod -- RoQA; Upstream not active, orphaned & uses a vulnerable embedded library

From Adrian Bunk <bunk@debian.org>
Newsgroups linux.debian.bugs.dist
Subject Bug#993372: Bug#993378: RM: gtkpod -- RoQA; Upstream not active, orphaned & uses a vulnerable embedded library
Date 2021-09-01 10:10 +0200
Message-ID <CSttL-7dc-1@gated-at.bofh.it> (permalink)
References <CSdp0-53E-15@gated-at.bofh.it> <CScCB-4N1-3@gated-at.bofh.it> <CSdp0-53E-15@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


Control: tags 993378 moreinfo

On Tue, Aug 31, 2021 at 03:49:45PM +0100, Neil Williams wrote:
> Package: ftp.debian.org
> Severity: normal
> 
> gtkpod upstream has moved but has not had any activity for over 5 years.
> 
> When investigating the two CVEs against AtomicParsley, former maintainer Matteo F. Vescovi reached
> out to me to suggest removal of gtkpod.
> 
> The use case for this package seems to be declining / absent and 4 crash bugs are currently open.
> 
> Fixes for these bugs and CVEs seem unlikely to appear, it would seem best to remove gtkpod
> from Debian at this point.

As a user I am quite unhappy when a working package I am using is out of 
the void getting am RM bug.

With software for older hardware it is normal that upstream becomes 
inactive, and anything other than declining usage would be a surprise.

I am also dismayed at the CVEs. At first sight the "two CVEs" might be 
for the same bug, with the fix for the first CVE not fixing the bug.
Does manually backporting the one-character change from CVE-2021-37232 
fix everything, even without the larger CVE-2021-37231 refactoring?

> Thanks

cu
Adrian

Back to linux.debian.bugs.dist | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

Bug#993378: RM: gtkpod -- RoQA; Upstream not active, orphaned & uses a vulnerable embedded library Neil Williams <codehelp@debian.org> - 2021-08-31 17:00 +0200
  Bug#993372: Bug#993378: RM: gtkpod -- RoQA; Upstream not active, orphaned & uses a vulnerable embedded library Adrian Bunk <bunk@debian.org> - 2021-09-01 10:10 +0200
    Bug#993372: Bug#993378: RM: gtkpod -- RoQA; Upstream not active, orphaned & uses a vulnerable embedded library Neil Williams <codehelp@debian.org> - 2021-09-01 10:40 +0200
      Bug#993372: Bug#993378: RM: gtkpod -- RoQA; Upstream not active, orphaned & uses a vulnerable embedded library Adrian Bunk <bunk@debian.org> - 2021-09-01 11:20 +0200
        Bug#993372: Bug#993378: RM: gtkpod -- RoQA; Upstream not active, orphaned & uses a vulnerable embedded library Neil Williams <codehelp@debian.org> - 2021-09-01 11:40 +0200

csiph-web