Debian Bug report logs - #451373
RM: ircii-pana -- RoQA; security issues, abandoned upstream, unmainted

Package: ftp.debian.org; Maintainer for ftp.debian.org is Debian FTP Master <ftpmaster@ftp-master.debian.org>;

Reported by: Stephan Hermann <sh@sourcecode.de>

Date: Thu, 15 Nov 2007 13:09:02 UTC

Severity: normal

Done: Debian Archive Maintenance <ftpmaster@ftp-master.debian.org>

Bug is archived. No further changes may be made.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, William Vera <billy@billy.com.mx>:
Bug#451373; Package ircii-pana. (full text, mbox, link).


Acknowledgement sent to Stephan Hermann <sh@sourcecode.de>:
New Bug report received and forwarded. Copy sent to William Vera <billy@billy.com.mx>. (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Stephan Hermann <sh@sourcecode.de>
To: submit@bugs.debian.org
Subject: removal of ircii-pana (aka bitchx)
Date: Thu, 15 Nov 2007 14:02:54 +0100
[Message part 1 (text/plain, inline)]
Package: ircii-pana
Version 1:1.1-5

Dear Colleagues,

I discussed this on #debian-security@OFTC and with other people from
the ubuntu community. 

I (or we) think it's time to get rid of this packages, just because it
has a lot of security flaws (which are not already determined) but with
3 CVEs hanging. 

Upstream seems to be (is) dead.

Regarding the alternatives for IRC clients on the console (irssi in
this case) and other alternatives on the X Window interface (xchat,
konversation etc.) it should be no deal to get rid of this package.

This removal request will be filed on Launchpad.net for Ubuntu, too.


Regards,

\sh

[signature.asc (application/pgp-signature, attachment)]

Bug reassigned from package `ircii-pana' to `ftp.debian.org'. Request was from Nico Golde <nion@debian.org> to control@bugs.debian.org. (Thu, 15 Nov 2007 13:42:05 GMT) (full text, mbox, link).


Changed Bug title to `RM: ircii-pana, security flaws, no upstream, inactive maintainer' from `removal of ircii-pana (aka bitchx)'. Request was from Nico Golde <nion@debian.org> to control@bugs.debian.org. (Thu, 15 Nov 2007 13:45:03 GMT) (full text, mbox, link).


Information forwarded to debian-bugs-dist@lists.debian.org, James Troup and others <ftpmaster@ftp-master.debian.org>:
Bug#451373; Package ftp.debian.org. (full text, mbox, link).


Acknowledgement sent to Nico Golde <nion@debian.org>:
Extra info received and forwarded to list. Copy sent to James Troup and others <ftpmaster@ftp-master.debian.org>. (full text, mbox, link).


Message #14 received at 451373@bugs.debian.org (full text, mbox, reply):

From: Nico Golde <nion@debian.org>
To: 451373@bugs.debian.org
Subject: Re: Bug#451373: removal of ircii-pana (aka bitchx)
Date: Thu, 15 Nov 2007 14:50:01 +0100
[Message part 1 (text/plain, inline)]
Hi,
* Stephan Hermann <sh@sourcecode.de> [2007-11-15 14:11]:
> Dear Colleagues,
> 
> I discussed this on #debian-security@OFTC and with other people from
> the ubuntu community. 
> 
> I (or we) think it's time to get rid of this packages, just because it
> has a lot of security flaws (which are not already determined) but with
> 3 CVEs hanging. 
> 
> Upstream seems to be (is) dead.
> 
> Regarding the alternatives for IRC clients on the console (irssi in
> this case) and other alternatives on the X Window interface (xchat,
> konversation etc.) it should be no deal to get rid of this package.
> 
> This removal request will be filed on Launchpad.net for Ubuntu, too.

I strongly agree with this.
Bitchx (ircii-pana) is currently vulnerable to 3 security 
issues, namely CVE-2007-3360, CVE-2007-4584 and CVE-2007-5839.
In my opinion CVE-2007-4584 is most important and noone 
found a solution yet. Of course this alone is no reason to 
remove it. The whole source code is a mess, everyone who 
sits down to find a security issue in bitchx will find 
another one.

The ircii-pana maintainer also seems to be MIA, I mailed him 
some time ago without an answer yet. I also mailed the 
upstream quite some time ago, also no answer.

Additionally it has an FTBFS open (patch attached to the bug 
report) but even with the patch for this FTBFS you would run 
into another I didn't file a bug for since noone seems to 
care about ircii-pana.

Sadly still a lot of people use bitchx but considering that 
there are enough good alternatives in the archive I think 
removing it would be appropriate.

Kind regards
Nico
-- 
Nico Golde - http://www.ngolde.de - nion@jabber.ccc.de - GPG: 0x73647CFF
For security reasons, all text in this mail is double-rot13 encrypted.
[Message part 2 (application/pgp-signature, inline)]

Changed Bug title to `RM: ircii-pana -- RoQA; security issues, abandoned upstream, unmainted' from `RM: ircii-pana, security flaws, no upstream, inactive maintainer'. Request was from Adam D. Barratt <debian-bts@adam-barratt.org.uk> to control@bugs.debian.org. (Thu, 15 Nov 2007 18:33:04 GMT) (full text, mbox, link).


Reply sent to Debian Archive Maintenance <ftpmaster@ftp-master.debian.org>:
You have taken responsibility. (full text, mbox, link).


Notification sent to Stephan Hermann <sh@sourcecode.de>:
Bug acknowledged by developer. (full text, mbox, link).


Message #21 received at 451373-close@bugs.debian.org (full text, mbox, reply):

From: Debian Archive Maintenance <ftpmaster@ftp-master.debian.org>
To: 451373-close@bugs.debian.org
Cc: ircii-pana@packages.debian.org, ircii-pana@packages.qa.debian.org
Subject: Bug#451373: fixed
Date: Fri, 23 Nov 2007 00:44:54 +0000
We believe that the bug you reported is now fixed; the following
package(s) have been removed from unstable:

    bitchx |    1:1.1-4 | hurd-i386
    bitchx |    1:1.1-5 | alpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390, sparc
    bitchx | 1:1.1-5+b1 | m68k
bitchx-dev |    1:1.1-4 | hurd-i386
bitchx-dev |    1:1.1-5 | alpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390, sparc
bitchx-dev | 1:1.1-5+b1 | m68k
bitchx-gtk |    1:1.1-4 | hurd-i386
bitchx-gtk |    1:1.1-5 | alpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390, sparc
bitchx-gtk | 1:1.1-5+b1 | m68k
bitchx-ssl |    1:1.1-4 | hurd-i386
bitchx-ssl |    1:1.1-5 | alpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390, sparc
bitchx-ssl | 1:1.1-5+b1 | m68k
ircii-pana |    1:1.1-5 | source

Note that the package(s) have simply been removed from the tag
database and may (or may not) still be in the pool; this is not a bug.
The package(s) will be physically removed automatically when no suite
references them (and in the case of source, when no binary references
it).  Please also remember that the changes have been done on the
master archive (ftp-master.debian.org) and will not propagate to any
mirrors (ftp.debian.org included) until the next cron.daily run at the
earliest.

Packages are never removed from testing by hand.  Testing tracks
unstable and will automatically remove packages which were removed
from unstable when removing them from testing causes no dependency
problems.

Bugs which have been reported against this package are not automatically
removed from the Bug Tracking System.  Please check all open bugs and
close them or re-assign them to another package if the removed package
was superseded by another one.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 451373@bugs.debian.org.

This message was generated automatically; if you believe that there is
a problem with it please contact the archive administrators by mailing
ftpmaster@debian.org.

Debian distribution maintenance software
pp.
Joerg Jaspert (the ftpmaster behind the curtain)




Information forwarded to debian-bugs-dist@lists.debian.org, James Troup and others <ftpmaster@ftp-master.debian.org>:
Bug#451373; Package ftp.debian.org. (full text, mbox, link).


Acknowledgement sent to Parasite <parasit3@no-log.org>:
Extra info received and forwarded to list. Copy sent to James Troup and others <ftpmaster@ftp-master.debian.org>. (full text, mbox, link).


Message #26 received at 451373@bugs.debian.org (full text, mbox, reply):

From: Parasite <parasit3@no-log.org>
To: 451373@bugs.debian.org
Subject: Re: Bug#451373: removal of ircii-pana (aka bitchx)
Date: Fri, 23 Nov 2007 12:05:36 +0100
I am still using Bitchx and don't want to use another client, really sad
news ! It has a nice design and the defaut configuration is awesome.
I'll give another chance to irssi but I'm not convinced...





Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Sat, 22 Dec 2007 07:31:31 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Thu Jan 11 18:12:18 2018; Machine Name: buxtehude

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.