| /[secure-testing]/hardening/subgoal-dsa.txt |
Parent Directory
|
Revision Log
| Links to HEAD: | (view) (download) (annotate) |
| Sticky Revision: |
pptpd hardened
chrony hardened
libnet-dns-perl, flex, file and freeradius hardened
uw-imap hardened suphp uploaded to sid
gdm3 hardened
smstools NMUd, libnss-ldap fixed
capi4hylafax, mutt hardened
exim4 and screen uploaded to sid after initial exp upload
rsync, pdns-recursor hardened, mediawiki now also in sid
librpcsecgss, libfishsound hardened
drbd, newt, clamav hardened
acl, netcat, spamassassin fixed
librpcsecgss hardened
pioneers and cpio hardened
opensc, ruby1.9.1, snmptrapfmt and polipo hardened
bzip hardened
tk8.4, tk8.5, lvm2 and heimdal hardened poppler now also fixed in sid
theora and netsnmp hardened
iceape hardened track spamassassin bug
note on wine hardening
wine and hplip hardened
openswan hardened
tk-img hardened
speex, amarok, kaffeine hardened koffice and kdegraphics were removed, drop it qt3 will be removed for wheezy, drop it as well track bug for kvirc
memcached and collectd hardened beid removed exim switched to dpkg-buildflags
hostapd hardened (now part of wpa source package)
socat and forked-daapd NMUd
qpid-cpp issues fixed before initial upload to archive no-dsa: krb5 fixed: krb5, drupal7, icedove
icinga hardened
ruby-gnome fixed
libxslt hardened
x11-xserver-utils and freeciv hardened
imlib2 hardened
mplayer2 fixed
nss and libcgroup hardened
iceweasel hardened
mantis bug has been split
cwidget, ruby1.8 hardened
ekg, unbound, links2 hardened
open-iscsi hardened
crossfire, id3lib3.8.3, squidguard hardened
icu hardened
ganglia fixed submitted patch for eggdrop poppler fixed in experimental
submitted patch for heimdal
hashcash NMUd
heimdal switched from cdbs to debhelper
libextractor NMUd/QA upload polipo bugnum
djbdns removed from testing and blocked with RC bug for reentering -> remove from list
ircd-hybrid fixed in NMU
kdebase replaced by kde-baseapps
submitted patches for ruby 1.8 and 1.9
kolab-cyrus-imapd now dropped from testing and blocked by RC bug
courier-authlib fixed in maintainer upload
NMUd libdumb
NMUd inotify-tools
sponsored pstotext upload
psi hardened
sort files
submitted patch for hplip
fixes from second binNMU batch, thanks jcristau
binNMU request for remaining cdbs packages
initial results of first nagging round: maintainer uploads for libmodplug and pam-pgsql
xmlsec1 NMUd couchdb, libsoup2.4, glib2.0 and libvirt fixed by uploads/current cdbs
py32 also already hardened
NMUed alsaplayer and ctorrent
py27 hardened
libexif already hardened
cscope NMUd
cgiirc removed, more cdbs triage
NMUd netrik
filed patches for lasso and drbd8
libhtml-parser-perl, libdbd-pg-perl and libimager-perl hardened, bug for libnet-dns-perl
qt4-x11 and icedove hardened, mpg123 and openssh switched to dpkg-buildflags
mono hardened more cdbs triage
libtunepimp removed, openexr hardened
unzip hardened
cairo, proftpd, linux-ftpd and texinfo hardened
mediawiki will be fixed if 1:1.18.1-1 hits sid
cdbs binnmu's verified to be fixed
gdm3 fails the binmnu
screen fixed in experimental
krb5-appl, perdition, expat, libsepol hardened
libtasn fixed through upload against current cdbs
openssl hardened
gzip hardened more cdbs triage
cdbs triage
systemtap fixed
filed bug for pmount
gtetrinet fixed by cdbs rebuild
filed bug for gzip more cdbs triage
libpwd/libreoffice fixed, more cdbs triage
webcit hardened
poppler was converted to dh in experimental, upload forthcoming
ncompress fixed, more cdbs triage
cdbs updates
libtheora uses dh, only spurious cdbs build-dep more cdbs triage
libyaml-libyaml-perl DSA more cbds triage
dovecot/gnutls26 fixed, more cdbs triage
revised multipath-tools fix
more cdbs triage
more cdbs tests
libspf2 already hardened in previous upload
more cdbs tests
lsh already fixed in previous maintainer upload new cdbs binnmu candidate
fix srcpkg name
more cdbs binnmu candidates
- cdbs is now properly fixed, start triaging pkgs. I'll try to fix a great bunch through binNMUs - pmount has migrated to debhelper
diffutils, xfont and vlc hardened
vsftpd, libav, multipath-tools, ndiswrapper, psql-9.1 switched from hardening-wrapper to dpkg-buildflags
openjdk fixed
loop-aes-utils fixed submitted patch for ifupdown
imagemagick fixed
openvpn, maildrop hardened
gnupg fixed in experimental, will be in unstable soon
nbd fixed
splitvt, hylafax fixed
filed bug for openjdk
webkit and e2fsprogs fixed
filed bug for openafs
submitted patch for open-iscsi
submitted patch for webkit
nspr, systemtap fixed
osiris removed aptitude fixed
syslog and libmikmod fixed
perl (currently only in exp), qemu, bochs hardened
submitted patch for libdumb
submitted patch for libav
maradns, rssh hardened
pound, lurker, libapache-mod-jk fixed, submitted filed bug for newt
ejabberd and nginx fixed
submitted patch for ppp, python2.7/python3.2 in preparation in exp
iscsitarget fixed
qemu-kvm/sendmail hardened, submitted patch for unicon
submitted patches for wine and mplayer
submitted patch for mplayer2, filed bug for vlc, scponly removed
submitted patches for xapian-omega and unbound
- submitted patches for freeradius, gnumeric, krb5-appl, imagemagick, inotify-tools, multipath-tools, pioneers, qemu-kvm, l2tpns and libfishsound - filed bugs for heartbeat, tk8.4, tk8.5 and perl
emacs23 and cron hardened
zabbix, gmime2.4 and opensaml hardened
submitted patch for maradns
submitted patch for lurker, filed bug for noweb
xmltooling fixed
submitted patches for ircd-hybrid and aptitude, filed bug for eglibc
filed bug for lvm2, submitted patch for ejabberd
submitted patches for net-snmp and nspr
mimetex and telepathy-gabble fixed, submitted patch for mono
submitted patch for hostapd xml-security-c and httrack fixed
submitted patch for gmime
submitted patch for nss
kazehakase was removed
submitted patch for proftpd-dfsg
exiv2 fixed, submitted patch for isakmpd
submitted patch for libtk-img, filed bug for gdbm
apt and xine-lib hardened
mlmmj, dspam, procps, tinyproxy fixed nas now fully hardened vsftpd and dmidecode not properly fixed, maintainer messed up my patches with "cleanups"
filed bug for libapache-mod-jk
submitted patches for icinga and iscsitarget
submitted patches for vnc4 and pdns
submitted patch for pdns-recursor, filed bug for incomplete nas fix
tcpreen and slurm-llnl fixed, nas partly fixed
submitted patches for slurm-llnl and snmptrapfmt
libtorrent-rasterbar fixed
submitted patches for libextractor and libmikmod
submitted patch for zabbix, suggested kazehakase for removal
vsftpd, mimetex and dmidecode fixed in maintainer uploads
pcsc-lite fixed in maintainer upload
submitted patches for texinfo and xml-security-c, ntp already hardened
submitted patches for xmlsec1 and xmltooling, filed bug for pptpd
submitted patches for mimetex and libreoffice
libcdaudio and asterisk hardened submitted patch for smstools
submitted patches for libtorrent-rasterbar and telepathy-gabble
submitted patch for webcit
submitted patches for procps, screen and imlib2
submitted patches for openexr and libcdaudio, strongswan already hardened
bsdmainutils fixed, submitted patches for exiv2 and opensc
submitted patch for qemu
submitted patches for pcsc-lite id3lib3.8.3, scponly filed for removal
submitted patch for unzip, texinfo already tracked in subgoal-dsa
submitted patches for hylafax/net-tools, filed bug for nano
submitted patches for slang2 and tgt
lftp fixed in maintainer upload
submitted patch for squidguard, filed bug for splitvt
submitted patches for loop-aes-utils and bsdmainutils
submitted patches for linux-ftpd, opensaml2 and pcre3
submitted patches for mlmmj, netrik and pam-pgsql
libxml2 and hostname fixed in maintainer uploads
submitted patches for systemtap and dmidecode
submitted patches for speex and netcat
submitted patches for hashcash and tinyproxy
krb5 fixed in maintainer upload
wget fixed in maintainer upload, filed bug for nas
submitted patches for netpbm-free
submitted patch for libxslt, firebird2.5 fixed in maintainer upload
wxwidgets2.6 removed, python3.3 not event in experimental
- citadel, zoo and sudo fixed in maintainer uploads - drop cdbs-based previous entries from the fixed list, the cdbs support for hardened build flags is a mess and needs more investigation
submitted patches for grep and x11-xserver-utils
submitted patches for zoo and base-passwd, boost1.42 removed
submitted patch for suphp
filed bug for ruby-gnome2, submitted patch for sudo
submitted patches for flex and perdition, nsd3 already hardened
libsmi and acpid fixed in maintainer uploads
mon fixed in maintainer upload, newt already tracked in subgoal dsa
submitted patch for tcpreen, mldonkey and avahi fixed in maintainer uploads
submitted patches for krb5 and ndiswrapper
- libpng fixed in maintainer upload - hybserv removed - cheesetracker removed - no-ip removed
filed bugs for avahi and dspam
couple pkgs to be removed
drop gcc-*, hybserv filed for removal
cheesetracker filed for removal
submitted patch for bzip2, drop devscripts (arch=all except for a four-line libvfork)
dia fixed in maintainer upload, filed bug for syslog-ng
mtr fixed in maintainer upload
submitted patch for xine-lib
filed bug for wzdftpd, sdl-image1.2 already hardened
submitted patches for openswan and mldonkey
submitted patch for mon, mpg123 already hardened
submitted patches for memcached and maildrop, dropped tinymux (not sec relevant)
submitted patches for cairo and openvpn
submitted patches for chrony and ganglia
submitted patch for emacs23, osiris should be removed, polipo already tracked in dsa.list
isc-dhcp and nss-pam-ldapd were fixed in maintainer uploads
submitted patches for vsftpd and pstotext
submitted patches for wget, libxml2 and sash. exiftags fixed in maintainer upload
libwmf fixed in maintainer upload
libsndfile fixed in maint upload
courier fixed in maintainer upload, submitted patch for pound
submitted patches for libsndfile and libtunepimp
submitted patches for lcms and libcgroup
submitted patch for libmodplug, libpam-heimdal removed
submitted patches for freeciv, librpcsecgss and libsmi
libarchive already hardened, submitted patch for links2
submitted patches for courier and exiftags, firebird2.5 hardening incomplete
audiofile fixed in maint upload, rm bsdgames, no sec relevance
dspam hardening, only needs a rebuild with current dpkg
submitted patch for cpio
curl, libpam-krb5 fixed kolab-cyrus-imapd doesn't need to be fixed, to be folded into standard cyrus pkg drop python2.6 and add python3.3 (candidate pythons for wheezy)
submitted patches for alsaplayer and curl drbd conversion not possible, currently broken collectd should rather be removed from the archive rdesktop fixed in maint upload
submitted patch for e2fsprogs
lynx hardened in maint upload
submitted patch for libpam-krb5
lighttpd fixed in maint upload, module-init-tools will be replaced with kmod
pimd and chmlib fixed in maint uploads
submitted patch for module-init-tools
submitted patches for socat, rssh, lighttpd and libxfont
submitted patches for libpng and mutt
submitted patches for lynx, mtr, forked-daapd and pimd
oprofile removed
remove petris, tuxpaint, typespeed: irrelevant for now
bluez-hcidump fixed in maint upload
track libexif bug remove pinball, not relevant
submitted patch for clamav
submitted patches for chmlib, nbd and beid
submitted patch for libwpd gv previously hardened by maintainer
drop abcmidi and crawl, not worth the trouble. These package can be converted later on, but no point in prioritising them
submitted patch for asterisk avahi already prepared for hardening, fixed with next upload util-linux already tracked in subgoal-important.txt
xmcd and thttpd removed
amule, enscript, xterm, findutils, iptables and inetutils hardened in maintainer uploads
made a QA upload for htdig mawk already hardened
cabextract now hardened apache2 switched to dpkg-buildflags, was already hardened
fetchmail building with hardening flags now
fontforge fixed in maintainer upload
submitted patches for capi4hylafax and fetchmail
submitted patches for fontforge, ctorrent and devil
fuse already hardened submitted patches for ekg and dovecot
submitted patches for expat and enscript
cyrus-2.2 has been removed, 2.4 uses hardening wrapper
surprisingly dpkg uses dpkg-buildflags :-)
filed patches for bochs and citadel
submitted patches for bluez-hcidump and cabextract
submitted patches for apt and barnowl wv2 fixed in maintainer upload
antiword fixed in very quick maintainer upload bug for audiofile
filed patches for acpid and amule
submitted patch for antiword kphone removed apache, apr and apr-util already hardened
reprepro already fixed submitted patches for rdesktop and cscope filed bug for openssl
fbi fixed filed patch for xterm
submitted patch for file fixed xfs in QA upload jasper already hardened
hardening updates
hardening updates
elinks fixed file bug for rsync
hardening updates
harden updates
xorg-server fixed thanks to jcristau
new sympa upload
xpdf build is now hardened
etherape fixed in sid and spu
filed bug
fixed mailman
ghostscript fixed
libmusicbrainz-2.1 NMUd
updates
remaining non candidates
filter cdbs packages more removals
mt-daapd -> forked-daapd nss-ldapd -> nss-pam-ldapd remove removals
- libcairo -> cairo - libtasn1-2 -> libtasn1-3 - libmusicbrainz-2.0 -> -libmusicbrainz-2.1 - more removed pkgs
ethereal -> wireshark belpic - beid firebird2 -> firebird2.5 gdm -> gdm3 ganglia-monitor-core -> ganglia
zgv fixed
- move removed pkgs to separate file, update list of removed pkgs - more cdbs pkgs - remove pkgs covered in subgoal important from subgoal dsa
gimp fixed
move all non-candidates to a shared file
libvirt and ncompress have been fixed more non-candidates
- change more pkgs to source pkg name - udev is the first pkg converted to dpkg-buildflags - aircrack-ng removed
also mark pkgs using hardening-includes as fixed
removed pkgs / updates nsd -> nsd3
mark pkgs already using hardening-wrapper as fixed
updates libsoup -> libsoup2.4
updates
more non-candidates gmime2.2 -> gmime2.4 glibc -> eglibc gnocatan -> pioneers
more removed pkgs isc-dhcp instead of dhcp/dhcp3 emacs23 instead of emacs21
more removed/non-candidate pkgs track cyrus-imapd-2.4 instead of cyrus-imapd
further removals / non-candidates
further removed pkgs bugzilla non-candidate track gnutls26
track removed pkgs track xen instead of xen-3.0
first filter of non-eligible packages
some more hardening info
add some instructions for hardening work
use the secure-testing repo for initial tracking/coordinating of sec hardening work. Will possibly moved elsewhere once more appropriate infrastructure has been found.
This form allows you to request diffs between any two revisions of this file. For each of the two "sides" of the diff, enter a numeric revision.
| ViewVC Help | |
| Powered by ViewVC 1.1.5 |