Debian Bug report logs -
#487217
libwbxml2-0: Several SyncML flaws
Reported by: Michael Bell <michael.bell@web.de>
Date: Fri, 20 Jun 2008 10:21:04 UTC
Severity: important
Found in version wbxml2/0.9.2-4
Fixed in version wbxml2/0.9.2-5
Done: Michael Banck <mbanck@debian.org>
Bug is archived. No further changes may be made.
Toggle useless messages
Report forwarded to debian-bugs-dist@lists.debian.org, Riku Voipio <riku.voipio@iki.fi>:
Bug#487217; Package libwbxml2-0.
(full text, mbox, link).
Acknowledgement sent to Michael Bell <michael.bell@web.de>:
New Bug report received and forwarded. Copy sent to Riku Voipio <riku.voipio@iki.fi>.
(full text, mbox, link).
Message #5 received at submit@bugs.debian.org (full text, mbox, reply):
[Message part 1 (text/plain, inline)]
Package: libwbxml2-0
Version: 0.9.2-4
Severity: important
I'm one of the upstream maintainers of libsyncml. I found several
flaws in the wbxml library in respect to correct handling of SyncML.
Below are short descriptions to every file which must be patched.
Patches are attached.
wbxml_encoder.c:
incomplete SyncML 1.2 detection
wbxml_tables.c:
wrong namespaces (the specifications of SyncML require big letters)
(e.g. SYNCML:SYNCML1.1 and not syncml:SYNCML1.1)
wbxml_tree.c:
missing debug statement in case of an error
missing content type (function is used by XML and WBXML callbacks)
wbxml_tree_clb_xml.c:
localName includes the namespace of a tag (syncml:devinf:DevInf)
the XML parser needs the document type to determine the code pages
Additionally I will send the patches to the upstream maintainer of the
library too (libwbxml@aymerick.com).
-- System Information:
Debian Release: lenny/sid
APT prefers unstable
APT policy: (500, 'unstable')
Architecture: i386 (i686)
Kernel: Linux 2.6.25-2-686 (SMP w/1 CPU core)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/bash
Versions of packages libwbxml2-0 depends on:
ii libc6 2.7-11 GNU C Library: Shared libraries
ii libexpat1 1.95.8-4 XML parsing C library - runtime li
ii libpopt0 1.10-3 lib for parsing cmdline parameters
ii zlib1g 1:1.2.3.3.dfsg-12 compression library - runtime
libwbxml2-0 recommends no packages.
-- no debconf information
[libwbxml_full.diff (text/x-c, attachment)]
Reply sent to Michael Banck <mbanck@debian.org>:
You have taken responsibility.
(full text, mbox, link).
Notification sent to Michael Bell <michael.bell@web.de>:
Bug acknowledged by developer.
(full text, mbox, link).
Message #10 received at 487217-close@bugs.debian.org (full text, mbox, reply):
Source: wbxml2
Source-Version: 0.9.2-5
We believe that the bug you reported is fixed in the latest version of
wbxml2, which is due to be installed in the Debian FTP archive:
libwbxml2-0-dbg_0.9.2-5_i386.deb
to pool/main/w/wbxml2/libwbxml2-0-dbg_0.9.2-5_i386.deb
libwbxml2-0_0.9.2-5_i386.deb
to pool/main/w/wbxml2/libwbxml2-0_0.9.2-5_i386.deb
libwbxml2-dev_0.9.2-5_i386.deb
to pool/main/w/wbxml2/libwbxml2-dev_0.9.2-5_i386.deb
libwbxml2-utils_0.9.2-5_i386.deb
to pool/main/w/wbxml2/libwbxml2-utils_0.9.2-5_i386.deb
wbxml2_0.9.2-5.diff.gz
to pool/main/w/wbxml2/wbxml2_0.9.2-5.diff.gz
wbxml2_0.9.2-5.dsc
to pool/main/w/wbxml2/wbxml2_0.9.2-5.dsc
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 487217@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Michael Banck <mbanck@debian.org> (supplier of updated wbxml2 package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@debian.org)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.8
Date: Wed, 06 Aug 2008 18:00:34 +0200
Source: wbxml2
Binary: libwbxml2-dev libwbxml2-0-dbg libwbxml2-0 libwbxml2-utils
Architecture: source i386
Version: 0.9.2-5
Distribution: unstable
Urgency: low
Maintainer: Michael Banck <mbanck@debian.org>
Changed-By: Michael Banck <mbanck@debian.org>
Description:
libwbxml2-0 - WBXML parsing and encoding library
libwbxml2-0-dbg - WBXML library development file
libwbxml2-dev - WBXML library development file
libwbxml2-utils - Binary XML utilities
Closes: 487217 493436
Changes:
wbxml2 (0.9.2-5) unstable; urgency=low
.
* New maintainer.
+ debian/control (Maintainer): Set to myself.
* debian/control (Standards-Version): Bumped to 3.8.0.
* debian/control (libwbxml2-utils/Description): Make the short
description a bit more readable; closes: #493436.
* debian/patches/05-syncml-fixes.patch: New patch, fixes a couple of
issues with SyncML, by Michael Bell; closes: #487217.
Checksums-Sha1:
8eab8ce8a3fb583c09308821fbebc134b87d00a9 1120 wbxml2_0.9.2-5.dsc
477d0997d1b5821a5a252a780551ee7025c33b5c 10567 wbxml2_0.9.2-5.diff.gz
b9adaa7d81e0855a1516e5b80360b9b36a64410a 90842 libwbxml2-dev_0.9.2-5_i386.deb
d3e27601161889ee9c3b2e95a059524e1e192f60 88184 libwbxml2-0-dbg_0.9.2-5_i386.deb
ecf5f5218cd4538cd433914ff015f5e8eb7d6785 66996 libwbxml2-0_0.9.2-5_i386.deb
58a573a1e3c7cd3046e7f7442f5141bbf2a978eb 21102 libwbxml2-utils_0.9.2-5_i386.deb
Checksums-Sha256:
bed047f1620af5227227a9332162b340ffbd1c91c94625fa740cb3ebcd00352c 1120 wbxml2_0.9.2-5.dsc
dc68717104be95640b7e28a97734b77bfe66ce6b4c3062d0edd8400b2ff5d3dd 10567 wbxml2_0.9.2-5.diff.gz
6c7ff8a05a266cb864222a12238c851ed5b62a19a04eb2a9faf6f481ab768cf9 90842 libwbxml2-dev_0.9.2-5_i386.deb
2efade873928ef949d5df076fecd18ac2cb2e3248d74a0bc05bbe76879a543b3 88184 libwbxml2-0-dbg_0.9.2-5_i386.deb
24222dc417f3f68978d7002070defdd2d8381c985ccdd22525c352932b0439d0 66996 libwbxml2-0_0.9.2-5_i386.deb
b5787be9e9e49a3088206322a663d53f20195ef51deae42b2a7b044b24941fb7 21102 libwbxml2-utils_0.9.2-5_i386.deb
Files:
761630f22e461a73a7e9bbc0b4c8677b 1120 libs optional wbxml2_0.9.2-5.dsc
9e99ad1caa15eafd6c8aa5b0acac30c3 10567 libs optional wbxml2_0.9.2-5.diff.gz
65666351c5b8bd5cad3091f89f768b5b 90842 libdevel optional libwbxml2-dev_0.9.2-5_i386.deb
06d672c71f5d7004db0fba0c97b3abae 88184 libdevel extra libwbxml2-0-dbg_0.9.2-5_i386.deb
27f1daaa2a90711becc8d523e2e14827 66996 libs optional libwbxml2-0_0.9.2-5_i386.deb
2a5c0b852790fe1dbd41c724e7ec8dd8 21102 text optional libwbxml2-utils_0.9.2-5_i386.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (GNU/Linux)
iD8DBQFImyR/mHaJYZ7RAb8RAgqdAKCOmuR4j5wWMlGpEYh4QjgHXi8SrwCeK6fg
BnKYp1aAK5+rmzjPHA4cMFw=
=o35g
-----END PGP SIGNATURE-----
Information forwarded to debian-bugs-dist@lists.debian.org, Riku Voipio <riku.voipio@iki.fi>:
Bug#487217; Package libwbxml2-0.
(full text, mbox, link).
Acknowledgement sent to Michael Banck <mbanck@debian.org>:
Extra info received and forwarded to list. Copy sent to Riku Voipio <riku.voipio@iki.fi>.
(full text, mbox, link).
Message #15 received at 487217@bugs.debian.org (full text, mbox, reply):
Hi Michael,
I've taken over wbxml2 maintainership in Debian and have applied your
patch. However, did you submit it upstream yet? I think this should be
integrated. I noticed a couple of hunks got already changed similarly
in upstream's subversion repository.
If you simply want to avoid creating yet another trac account, I can
submit it for you (but I'll have to create an account as well, though as
the new maintainer that's probably a good idea anyway).
Thanks,
Michael
Message sent on to Michael Bell <michael.bell@web.de>:
Bug#487217.
(full text, mbox, link).
Acknowledgement sent to Michael Bell <michael.bell@cms.hu-berlin.de>:
Extra info received and filed, but not forwarded.
(full text, mbox, link).
Message #23 received at 487217-quiet@bugs.debian.org (full text, mbox, reply):
[Message part 1 (text/plain, inline)]
Hi Michael,
sorry for the delay, I was on holidays.
Michael Banck wrote:
> I've taken over wbxml2 maintainership in Debian and have applied your
> patch. However, did you submit it upstream yet? I think this should be
> integrated. I noticed a couple of hunks got already changed similarly
> in upstream's subversion repository.
I send the changes to the author of libwbxml via email. I did not notice
that there is a trac on the webpage. Okay, I must be blind. OpenSync
uses it too and I sent an email.
> If you simply want to avoid creating yet another trac account, I can
> submit it for you (but I'll have to create an account as well, though as
> the new maintainer that's probably a good idea anyway).
I will create a trac account and open a new ticket.
Sorry for trouble and thanks for the new package
Michael
--
_______________________________________________________________
Michael Bell Humboldt-Universitaet zu Berlin
Tel.: +49 (0)30-2093 2482 ZE Computer- und Medienservice
Fax: +49 (0)30-2093 2704 Unter den Linden 6
michael.bell@cms.hu-berlin.de D-10099 Berlin
_______________________________________________________________
X.509 CA Certificates / Wurzelzertifikate
https://pki.pca.dfn.de/hu-berlin-ca/cgi-bin/pub/pki?cmd=getStaticPage;name=index;id=2&RA_ID=0
[smime.p7s (application/x-pkcs7-signature, attachment)]
Acknowledgement sent to Michael Bell <michael.bell@cms.hu-berlin.de>:
Extra info received and filed, but not forwarded.
(full text, mbox, link).
Message #28 received at 487217-quiet@bugs.debian.org (full text, mbox, reply):
[Message part 1 (text/plain, inline)]
Hi Michael,
Michael Banck wrote:
> If you simply want to avoid creating yet another trac account, I can
> submit it for you (but I'll have to create an account as well, though as
> the new maintainer that's probably a good idea anyway).
Looks like it is not possible to create a new trac account. The register
link is disabled :(
Perhaps I sent therefore only a mail to the author.
Best regards
Michael
BTW I get no reaction from the author until today.
--
_______________________________________________________________
Michael Bell Humboldt-Universitaet zu Berlin
Tel.: +49 (0)30-2093 2482 ZE Computer- und Medienservice
Fax: +49 (0)30-2093 2704 Unter den Linden 6
michael.bell@cms.hu-berlin.de D-10099 Berlin
_______________________________________________________________
X.509 CA Certificates / Wurzelzertifikate
https://pki.pca.dfn.de/hu-berlin-ca/cgi-bin/pub/pki?cmd=getStaticPage;name=index;id=2&RA_ID=0
[smime.p7s (application/x-pkcs7-signature, attachment)]
Bug archived.
Request was from Debbugs Internal Request <owner@bugs.debian.org>
to internal_control@bugs.debian.org.
(Mon, 29 Sep 2008 07:27:00 GMT) (full text, mbox, link).
Send a report that this bug log contains spam.
Debian bug tracking system administrator <owner@bugs.debian.org>.
Last modified:
Fri Jan 12 00:45:50 2018;
Machine Name:
beach
Debian Bug tracking system
Debbugs is free software and licensed under the terms of the GNU
Public License version 2. The current version can be obtained
from https://bugs.debian.org/debbugs-source/.
Copyright © 1999 Darren O. Benham,
1997,2003 nCipher Corporation Ltd,
1994-97 Ian Jackson,
2005-2017 Don Armstrong, and many other contributors.