Ticket #84 (new enhancement)

Opened 5 months ago

Last modified 4 months ago

Security issues with BitchX

Reported by: mspasov Owned by: saurik
Priority: trivial Component: Telesphoreo
Keywords: bitchx, security Cc:

Description

According to this debian bug, bitchx has unsolved security issues and is dropped from unstable.

http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=451373

Also there are bugs that are patched in debian/ubuntu, but are not in the upstream. I'm not sure what source is used to build bx on iphone.

Change History

follow-up: ↓ 2   Changed 5 months ago by saurik

I'm not certain what to do about this. First off, I will state that Telesphoreo uses Debian APT, but is not Debian. Not entirely relevant, but I think important anyway.

I guess I should just drop the package? Unlike Debian, Telesphoreo currently does not have any good alternatives as ircii doesn't work yet (the glib issue, which is apparently not filed as a bug).

in reply to: ↑ 1   Changed 5 months ago by mspasov

Replying to saurik:

I'm not certain what to do about this.

I don't know either..

First off, I will state that Telesphoreo uses Debian APT, but is not Debian. Not entirely relevant, but I think important anyway.

Yep, I'm aware of this. This also means that all debian fixes that are not in the upstream (which according to them is dead) are not here.

I guess I should just drop the package? Unlike Debian, Telesphoreo currently does not have any good alternatives as ircii doesn't work yet (the glib issue, which is apparently not filed as a bug).

IMHO a note/waring of some sort should be enough.. Telesphoreo has quite smaller userbase (compared to debian), no draconian policies to follow and probably people are more willing to take risks..

  Changed 4 months ago by ripskee

  • priority changed from major to trivial
  • type changed from defect to enhancement

Instead of complaining that there is no warning please provide the patch(es) which you wish to be integrated.

Btw, did you see the warning (in that nifty little box) that mobile phones can cause cancer ?

I didn't.

No joy.

Chris.

Note: See TracTickets for help on using tickets.