[Bug 2097727] Re: [MIR] papers

2025-02-27 Thread Federico Quattrin
I reviewed papers 48~beta-3ubuntu1 as checked into plucky. This shouldn't be considered a full audit but rather a quick gauge of maintainability. papers is a document viewer for the GNOME desktop. - CVE History - Evince had a few CVEs, the last being from 2023. The list does not look concern

[Bug 2074086] Re: MIR libimobiledevice-glue

2025-02-13 Thread Federico Quattrin
** Changed in: libimobiledevice-glue (Ubuntu) Assignee: Ubuntu Security Team (ubuntu-security) => (unassigned) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2074086 Title: MIR libimobiledevice-

[Bug 2074086] Re: MIR libimobiledevice-glue

2025-02-13 Thread Federico Quattrin
I reviewed libimobiledevice-glue 1.3.1-1 as checked into plucky. This shouldn't be considered a full audit but rather a quick gauge of maintainability. libimobiledevice-glue is a library with common code used by the libraries and tools around the libimobiledevice project. The following project

[Bug 2089037] Re: [MIR] flexparser

2025-02-10 Thread Federico Quattrin
I reviewed flexparser 0.4-1 as checked into plucky. This shouldn't be considered a full audit but rather a quick gauge of maintainability. flexparser is a parser written in python. Users must write their own classes for every type of content they want to parse and implement the from_string metho

[Bug 2070025] Re: [MIR] wsdd

2024-09-17 Thread Federico Quattrin
I reviewed wsdd 2:0.8-2ubuntu3 as checked into oracular. This shouldn't be considered a full audit but rather a quick gauge of maintainability. wsdd is a deamon that enables samba hosts to be discoverable by Web Service Discovery Clients like Windows. It also contains a client that enables to dis

[Bug 2069308] Re: MIR xdg-terminal-exec

2024-09-10 Thread Federico Quattrin
I reviewed xdg-terminal-exec 0.10.1-1 as checked into oracular. This shouldn't be considered a full audit but rather a quick gauge of maintainability. xdg-terminal-exec is a proposal for XDG Default Terminal Execution Specification and reference shell-based implementation. The proposal has not b

[Bug 2073287] [NEW] [Jammy, Focal] fusiondirectory installation issue: fatal error encountered

2024-07-16 Thread Federico Quattrin
Public bug reported: When installing the package as stated in https://fusiondirectory-user- manual.readthedocs.io/en/1.3/fusiondirectory/install/debian/debian-fd- install.html, I encountered an error in the setup page: Fatal Error: "Class SetAttribute cannot extend final class Attribute" in /usr/s

[Bug 2071858] [NEW] Tomcat7 7.0.78-1 FTBFS since Bionic switched to OpenJDK-11

2024-07-03 Thread Federico Quattrin
Public bug reported: Since OpenJDK-11, java.xml.bind has been removed. See https://bugs.openjdk.org/browse/JDK-8195073. Tomcat7 FTBFS as it is importing that module in java/org/apache/catalina/util/Base64.java and test/org/apache/catalina/util/TesterBase64Performance.java. ** Affects: openjdk

[Bug 2071856] [NEW] Tomcat7 fails to build from source due to the latest OpenJDK-7 update

2024-07-03 Thread Federico Quattrin
Public bug reported: Tomcat7 in Trusty (7.0.52-1ubuntu0.16) fails to build from source because OpenJDK-7 has been updated to version 211 in Trusty (7u211-2.6.17-0ubuntu0.1), where the NULL cipher algorithm has been removed. As a result, getSupportedCipherSuites no longer returns TLS_EMPTY_RENEGOTI

[Bug 2071855] [NEW] TLS_EMPTY_RENEGOTIATION_INFO_SCSV is disabled after updating to 211

2024-07-03 Thread Federico Quattrin
Public bug reported: OpenJDK-7 has been updated to version 211 in Trusty (7u211-2.6.17-0ubuntu0.1), where the NULL cipher algorithm has been removed. As a result, getSupportedCipherSuites no longer returns TLS_EMPTY_RENEGOTIATION_INFO_SCSV as a supported cipher. See https://bugs.openjdk.org/brows