[MIR] gypsy

Bug #688418 reported by Ken VanDine
10
This bug affects 1 person
Affects Status Importance Assigned to Milestone
gypsy (Ubuntu)
Expired
Undecided
Unassigned

Bug Description

I have reviewed the package and it meets the requirements for main inclusion. It is a build dependency for geoclue, which is needed for indicator-datetime.

libgypsy-dev is needed to build the geoclue-gypsy backend, which is not required for indicator-datetime and there is no plans to include this by default. Of of the build depends for gypsy are already in main.

Revision history for this message
Matthias Klose (doko) wrote :

could ubuntu-security please have a final look? package starts a daemon

Changed in gypsy (Ubuntu):
assignee: nobody → Ubuntu Security Team (ubuntu-security)
Revision history for this message
Kees Cook (kees) wrote :

This daemon has unchecked string buffer copies (see nmea_gpgsv() which passes in a string with no length details), and runs as root. These kinds of potential faults should be fixed before it goes into main. I would prefer disabling the geoclue-gypsy backend or doing something to keep this daemon out of main.

Changed in gypsy (Ubuntu):
status: New → Incomplete
assignee: Ubuntu Security Team (ubuntu-security) → Ubuntu Desktop (ubuntu-desktop)
Revision history for this message
Kees Cook (kees) wrote :

I've opened bug 690323 to track security issues and emailed the upstream authors.

Revision history for this message
Laurent Bigonville (bigon) wrote :

I'm currently finishing to package gypsy in debian, I will upload it soon.

Current WIP package can be found at http://git.debian.org/?p=collab-maint/gypsy.git;a=summary
I guess it will be better to not divert to much if it goes in ubuntu main

Changed in gypsy (Ubuntu):
assignee: Ubuntu Desktop (ubuntu-desktop) → nobody
Revision history for this message
Launchpad Janitor (janitor) wrote :

[Expired for gypsy (Ubuntu) because there has been no activity for 60 days.]

Changed in gypsy (Ubuntu):
status: Incomplete → Expired
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.