RM: pytris -- RoM; security issues; abandoned upstream

Bug #696810 reported by Stefano Rivera
260
This bug affects 1 person
Affects Status Importance Assigned to Milestone
pytris (Debian)
Fix Released
Unknown
pytris (Ubuntu)
Fix Released
High
Dustin Kirkland 

Bug Description

Imported from Debian bug 608689:

Package: pytris
Version: 0.98+nmu1
Severity: grave
Tags: security
Justification: user security hole

The setgid wrapper for this game makes no attempt at security.

It can trivially be used to execute code as group games, which can be
used to exploit other players of the game via the score file.

It could be fixed - the security team suggests dropping the shared score
file, and thus the wrapper. However, this package has not seen a
maintainer upload in years, and is stated as being unmaintained by the
author, on his website:
http://korpus.juls.savba.sk/~garabik/software/

I believe the best solution is removal, from unstable, squeeze, and
lenny.

Radovan, are you OK with reassigning this to ftp.debian.org?

SR

-- System Information:
Debian Release: squeeze/sid
  APT prefers testing
  APT policy: (990, 'testing'), (500, 'unstable'), (1, 'experimental')
Architecture: amd64 (x86_64)

Kernel: Linux 2.6.32-5-amd64 (SMP w/8 CPU cores)
Locale: LANG=en_ZA.UTF-8, LC_CTYPE=en_ZA.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash

Versions of packages pytris depends on:
ii python 2.6.6-3+squeeze4 interactive high-level object-orie

pytris recommends no packages.

pytris suggests no packages.

-- no debconf information

security vulnerability: no → yes
Changed in pytris (Ubuntu):
importance: Undecided → High
status: New → Confirmed
Revision history for this message
Dustin Kirkland  (kirkland) wrote :

Reviewed the documentation here, and removing, per request (showing Kate how to do so, in the process...)

Changed in pytris (Ubuntu):
assignee: nobody → Dustin Kirkland (kirkland)
Revision history for this message
Dustin Kirkland  (kirkland) wrote :

lp_archive@cocoplum:~/syncs$ lp-remove-package.py -u stefanor -m "unmaintained, known security issues, being dropped from debian too" pytris
2011-01-06 21:02:55 INFO Creating lockfile: /var/lock/launchpad-lp-remove-package.lock
2011-01-06 21:03:04 INFO Removing candidates:
2011-01-06 21:03:04 INFO pytris 0.98+nmu1 in natty
2011-01-06 21:03:04 INFO pytris 0.98+nmu1 in natty amd64
2011-01-06 21:03:04 INFO pytris 0.98+nmu1 in natty armel
2011-01-06 21:03:04 INFO pytris 0.98+nmu1 in natty i386
2011-01-06 21:03:04 INFO pytris 0.98+nmu1 in natty powerpc
2011-01-06 21:03:04 INFO Removed-by: Stefano Rivera
2011-01-06 21:03:04 INFO Comment: unmaintained, known security issues, being dropped from debian too
2011-01-06 21:03:04 INFO 5 packages successfully removed.
Confirm this transaction? [yes, no] yes
2011-01-06 21:03:30 INFO Transaction committed.
2011-01-06 21:03:30 INFO The archive will be updated in the next publishing cycle.

Changed in pytris (Ubuntu):
status: Confirmed → Fix Released
Changed in pytris (Debian):
status: Unknown → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.