Bug#706644: untrusted input file might be harmful

2013-06-12 Thread Axel Beckert
Hi, it's too late for Wheezy, but I still have to object: John Paul Adrian Glaubitz wrote on 02-May-2013: > The package has been orphaned in Debian since 2007 Wrong. At the time you wrote this mail it was orphaned for mere 10 days. See http://bugs.debian.org/706041 -- only the last upload was fr

Bug#706644: untrusted input file might be harmful

2013-05-02 Thread Adam D. Barratt
On Fri, 2013-05-03 at 01:13 +0200, Nico Golde wrote: > * John Paul Adrian Glaubitz [2013-05-02 23:15]: > > The package has been orphaned in Debian since 2007 and abandoned by > > upstream at > > the same time since the upstream developer and Debian maintainer are the > > same > > person. > >

Bug#706644: untrusted input file might be harmful

2013-05-02 Thread Nico Golde
Hi, * John Paul Adrian Glaubitz [2013-05-02 23:15]: > The package has been orphaned in Debian since 2007 and abandoned by upstream > at > the same time since the upstream developer and Debian maintainer are the same > person. > > Popcon shows just 113 installations and there are no reverse dep

Bug#706644: untrusted input file might be harmful

2013-05-02 Thread John Paul Adrian Glaubitz
The package has been orphaned in Debian since 2007 and abandoned by upstream at the same time since the upstream developer and Debian maintainer are the same person. Popcon shows just 113 installations and there are no reverse dependencies. I therefore suggest removing the package from testing

Bug#706644: untrusted input file might be harmful

2013-05-02 Thread W. Martin Borgert
Package: tpp Version: 1.3.1-2 Severity: grave Tags: security Please feel free to downgrade the bug report or remove the security tag. It's just my point of view. Opening an untrusted input file may be harmful, because tpp supports an "exec" command, which can do bad things, e.g. sending your priv