DWN 2005-47

$B:#=59f$O!"C18l$,$d$?$i$HFq$7$a$G(B ($B$=$l$OFbMF$N$;$$$+$b$7$l$^$;$s$,(B)$B!"(B
$B%X%C%@(B ($B%5%^%j$J$I(B) $B$NItJ,$K$b86J8!&%3%a%s%H$rF~$l$F$"$j$^$9!#(B
#use wml::debian::weeklynews::header PUBDATE="2005-11-22" SUMMARY="Packaging, Disclosing, Delegations, Debtags, Events, Testing, Archive, Alioth, License"
#use wml::debian::weeklynews::header PUBDATE="2005-11-22" SUMMARY="$B%Q%C%1!<%82=(B, $B3+<((B, $B0QG$(B, Debtags, $B%$%Y%s%H(B, $B%F%9%H(B, $B%"!<%+%$%V(B, Alioth, $B%i%$%;%s%9(B"
#use wml::debian::translation-check translation="1.7"

<p>Welcome to this year's 47th issue of DWN, the weekly newsletter for the
Debian community. Nathanael Nerode <a
that the new C++ libraries are not transitioning to testing due to a rash of
dependent uploads and has requested that maintainers hold off from uploading
dependent packages that will contribute to the clog. Guillem Jover <a
to <a href="http://bugs.debian.org/90989">split</a> dependency lines in the
source control files for improved readability. Andreas Tille <a
about a free <a href="http://www.klixxa.de/">Live CD</a> aiming at

<p>Debian $B%3%_%e%K%F%#$N$?$a$N=54)%K%e!<%9%l%?!<!"(BDebian
$B%&%#!<%/%j!<%K%e!<%9$N:#G/$NBh(B 47 $B9f$X$h$&$3$=!#(BNathanael Nerode $B$5$s$O!"(B
$B0MB8%Q%C%1!<%8$N%"%C%W%m!<%I%i%C%7%e$N$?$a$K?7$7$$(B C++ $B%i%$%V%i%j$,%F%9%HHG(B
(testing) $B$KF~$l$:$K$$$k>u67$r(B<a
$***@A$7$^$7$?!#(BGuillem Jover $B$5$s$O!"%=!<%9%Q%C%1!<%8$N(B control
$BDs0F$7$^$7$?(B</a>$B!#(BAndreas Tille $B$5$s$O!";R6!8~$1$N%U%j!<$N(B<a
href="http://www.klixxa.de/">$B%i%$%V(B CD</a>$B$K$D$$$F(B<a

<p><strong>Standard C++ Library Modification.</strong> Matthias Klose <a
announced</a> that the memory allocator in the standard C++
library will be changed which requires several packages to be rebuilt for
which he has appended a list. The library will be updated by new versions
of the <a href="http://packages.debian.org/gcc-3.4">gcc-3.4</a> and <a
href="http://packages.debian.org/gcc-4.0">gcc-4.0</a> packages. Maintainers
may have to <a
rename</a> the binary packages to reflect the new dependency.</p>

<p><strong>$BI8=`(B C++ $B%i%$%V%i%j$NJQ99!#(B</strong>
Matthias Klose $B$5$s$O!"I8=`(B C++ $B%i%$%V%i%jFb$N%a%b%j%"%m%1!<%?$,JQ99$5$l$k$N$G!"(B
$BH/I=$7$^$7$?(B</a>$B!#%i%$%V%i%j$O!"(B<a href="http://packages.debian.org/gcc-3.4">\
gcc-3.4</a> $B$*$h$S(B <a href="http://packages.debian.org/gcc-4.0">gcc-4.0</a>

<p><strong>Declassification of private Mails.</strong> Anthony Towns <a
a general resolution to open the archives of the debian-private list to the
public after three years. A declassification team should be delegated to
extract financial information about individuals and mails of no historical
relevance. Authors and recipients should be given a period to comment on the

<p><strong>private ($BHs8x3+(B) $B%a!<%j%s%0%j%9%H$N5!L)2r=|!#(B</strong>
Anthony Towns $B$5$s$O!"Ej9F8e(B 3 $BG/$,7P2a$7$?$i(B debian-private

<p><strong>Project Leader Delegations.</strong> Branden Robinson released a <a
document</a> explaining how project leader delegations work. The <a
href="$(HOME)/devel/constitution">constitution</a> suggests that there may be
other powers which the project leader may not directly wield, and which they
must delegate instead. If a particular decision is delegated, the project
leader cannot take back responsibility for the decision personally, but can
re-delegate it to someone else.</p>

Branden Robinson $B$5$s$O!"(B
$BJ8=q(B</a>$B$r8x3+$7$^$7$?!#(B<a href="$(HOME)/devel/constitution">$B7{>O(B</a>$B$G$O!"(B

<p><strong>Security Updates.</strong> You know the drill. Please make sure
that you update your systems if you have any of these packages installed.</p>


<li>DSA 898: <a href="$(HOME)/security/2005/dsa-898">phpgroupware</a> --
Several vulnerabilities.
<li>DSA 899: <a href="$(HOME)/security/2005/dsa-899">egroupware</a> --
Several vulnerabilities.
<li>DSA 900: <a href="$(HOME)/security/2005/dsa-900">fetchmail</a> --
Potential information leak.
<li>DSA 901: <a href="$(HOME)/security/2005/dsa-901">gnump3d</a> --
Several vulnerabilities.
<li>DSA 902: <a href="$(HOME)/security/2005/dsa-902">xmail</a> --
Arbitrary code execution.
<li>DSA 903: <a href="$(HOME)/security/2005/dsa-903">unzip</a> --
Unauthorised permissions modification.
<li>DSA 904: <a href="$(HOME)/security/2005/dsa-904">netpbm-free</a> --
Arbitrary code execution.
<li>DSA 905: <a href="$(HOME)/security/2005/dsa-905">mantis</a> --
Several vulnerabilities.
<li>DSA 906: <a href="$(HOME)/security/2005/dsa-906">sylpheed</a> --
Arbitrary code execution.
Post by Kobayashi Noritada
Nobuhiro IMAI
leader /$B%j!<%@!<(B/
reader /$B%j!<%@(B/

Security Updates $B$O$+$M$3$5$s$NLu$r;29M$K$9$l$P!$:n6H$,B.$/$9$9$`$N$G$O!)(B
Branden Robinson $B$5$s$O!"(B
$BJ8=q(B</a>$B$r8x3+$7$^$7$?!#(B<a href="$(HOME)/devel/constitution">$B7{>O(B</a>$B$G$O!"(B
$B9T;H$7$F$O$J$i$:!"(B or $B9T;H$G$-$:!"(B

$B$=$l$+$i!$(B delegatiton $B$O!V(B($B8"8B(B)$B0\>y!W$HLu$9$H%+%C%3$$$$$J$"$H;W$$$^$7$?!%(B
$B$^$:$O(B Branden $B$N%a!<%k$+$i3:EvItJ,$r0zMQ"-(B
| 5. If the DPL delegates a particular decision, he or she cannot retake
| responsibility for the decision personally, but can re-delegate it to
| someone else.[1]
| ($B!x(B5.1.1, $B!x(B8.2)
| [1] One might argue that the prohibition on rescinding delegation of
| a particular decision is tied the individual(s) to whom it is given,
| rather than the decision in question. This is important if the
| person or people to whom the decision is delegated prove unable to
| make it. This is another variant on the old "what if Linus
| (Torvalds) gets hit by a bus?" problem. One developer has told me
| that my interpretation poses a different threat, however: "It looks
| like you're going to decide this one issue in a way I don't like, so
| I'll take it away and give the decision to someone who will decide
| it the way I want to." Why a Leader would do this, or how he or she
| could expect to get away with it, is not clear to me, but this
| scenario is not impossible. If this ever proves to be a
| non-hypothetical problem, I would ask for the Project Secretary's
| interpretation of the Constitution.

rather than the decision in question $B$N(B the decision $B$,2?$HF13J$K$J$C(B
$B$F$$$k$N$+J,$+$i$J$+$C$?$N$G$9$,!$$3$l$h$jA0$G(B the $B$rA0CV$9$kL>;l$O(B
individual(s) $B$7$+$J$$$N$G!$$=$&9M$($k$H!$(B
"the individual $BN,(B, rather than the decision" $B$O!V7hDj$G$O$J$/8D?M!W(B


Linus $B$,%P%9$Km`$+$l$A$c$C$?$i$I$&$7$h$&LdBj$N?7<o$@!%(B


Post by Kobayashi Noritada
If a particular decision is delegated, the project
leader cannot take back responsibility for the decision personally, but can
re-delegate it to someone else.</p>

$B$+$C$?$H$-!$(BDPL $B8D?M$KLdBj$,La$C$F$-$F(B DPL $B$,<+J,$GBP=h$9$k$N$O%k!<%k0cH?!%(B
DPL $B$OB>$NC/$+$KLdBj=hM}$r:FEY3d$j?6$k$N$O$G$-$k!%(B


Post by Kobayashi Noritada
<li>DSA 900: <a href="$(HOME)/security/2005/dsa-900">fetchmail</a> --
Potential information leak.

$B$+$M$3$5$s$N(Bdebian-users:45220 $B$NLu$G$O!$(B
Post by Kobayashi Noritada
<li>DSA 903: <a href="$(HOME)/security/2005/dsa-903">unzip</a> --
Unauthorised permissions modification.
unauthorised $B$O(B"$B8"8B$,$J$$(B"$B$G$9!%(B

$B$G!$(Bpermission $B$NLu$G$9$,!$!V8"8B!W$@$H%U%!%$%k<+BN$N%U%i%0$G$O$J$/(B
$B$F!$(BPAM $B$H$+$N<B9T5v2D8"8B$b4^$s$G$7$^$$$=$&$K;W$($k$N$G!$(B*$B$3$3$G$O(B*

| $B967b<T$K%"%/%;%98"8B$N$"$k%G%#%l%/%H%jCf$N%U%!(B
| $B%$%k$r?-D%$9$k:]$K!"(Bunzip $B$K(B unzip $BMxMQ%f!<%6$,8"8B$r;}$DJL$N%U%!%$%k$N(B
| $B%Q!<%_%C%7%g%s$NJQ99$r$5$;$k967b$,2DG=$G$9!#(B
Nobuhiro IMAI
2005-11-30 03:54:16 UTC

Security Updates $B$O$+$M$3$5$s$NLu$r;29M$K$9$l$P!$:n6H$,B.$/$9$9$`$N$G$O!)(B
DSA $B$N(B*$BFbMF(B*$B$@$H;29M$K$G$-$k$N$G$9$,!"(BDWN $B$N(B Security Updates $B$K7G:\$5(B
$B$l$F$$$k$N$O!"(BDSA $B$N(B Vulnerability: $B$H$O0c$&$3$H$,$"$k$s$G$9$h$M!#Nc$((B
$B$P(B DSA-908 $B$@$H!"(B


[2005 $BG/(B 11 $B7n(B 23 $BF|(B] DSA-908 sylpheed-claws
buffer overflows



# DSA 908: sylpheed-claws -- Arbitrary code execution.

$B$H$J$C$F$$$^$9!#$G!"<B:]$N(B DSA $B$O!"(B


DSA-908-1 sylpheed-claws -- buffer overflows

$B$G!"(Bdebian-security-announce $B$G$O$d$C$Q$j!"(B


Vulnerability : buffer overflows

$B!D$C$F!"(BDWN $B$@$10c$&$N$O$J$<!)0JA0?y;3$5$s$,(B org $B$N(B -www $B$KLd$$9g$o$;(B
$B$F$?$h$&$J5$$,$7$^$9$,!"(BDWN $B$N(B Security Updates $B$O$I$3$+$i<h$C$F$-$F$k(B

Post by TAKEI Nobumitsu
delegation $B$K$F$3$:$j$^$7$?!%(B
Post by Nobuhiro IMAI
Post by TAKEI Nobumitsu
Security Updates $B$O$+$M$3$5$s$NLu$r;29M$K$9$l$P!$:n6H$,B.$/$9$9$`$N$G$O!)(B
$B:#0f$5$s$N$*$C$7$c$C$F$$$k$h$&$K!"K\J8$NLu$,(B DWN $BCf$N%j%9%H9`L\$NK]Lu$K$H$C$F(B
$B$=$l$+$i!"$+$M$3$5$s$NLu$G$O$J$$$N$G$9$,!"!V(BSeveral vulnerabilities.$B!W$J$I$N(B

* $B!V(Bpotential ...$B!W$O$3$l$^$G$9$Y$F!***@x:_E*$J!D!D!W$HLu$5$l$F$$$?$N$G$9$,!"(B
* $B!V(Bpermission$B!W$O!V%Q!<%_%C%7%g%s!W!&!V5v2DB0@-!W!&!V8"8B!W$H$$$C$?Lu$,(B

$***@hF|$N(B Debian $BJY6/2q$G!"!V$*$=$i$/(B Subject $B$+$i<+***@8@.$7$F$$$k$N$G$O!W(B
$B<B:]>e$N(B debian-security-announce $B$N%a!<%k$N(B Subject $B$O!"(B
[SECURITY] [DSA 908-1] New sylpheed-claws packages fix arbitrary code execution
Post by Nobuhiro IMAI
Vulnerability : buffer overflows
$B$H$N(B inconsistency $B$O!"%;%-%e%j%F%#%A!<%`$K?V$+$J$$$HJ,$+$i$J$$$h$&$J5$$,(B

Nobuhiro IMAI
2005-12-07 08:58:43 UTC

Branden Robinson $B$5$s$O!"(B
$BJ8=q(B</a>$B$r8x3+$7$^$7$?!#(B<a href="$(HOME)/devel/constitution">$B7{>O(B</a>$B$G$O!"(B
$B9T;H$7$F$O$J$i$:!"(B or $B9T;H$G$-$:!"(B
$B$=$l$+$i!$(B delegatiton $B$O!V(B($B8"8B(B)$B0\>y!W$HLu$9$H%+%C%3$$$$$J$"$H;W$$$^$7$?!%(B
Post by Kobayashi Noritada


Post by TAKEI Nobumitsu
rather than the decision in question $B$N(B the decision $B$,2?$HF13J$K$J$C(B
$B$F$$$k$N$+J,$+$i$J$+$C$?$N$G$9$,!$$3$l$h$jA0$G(B the $B$rA0CV$9$kL>;l$O(B
individual(s) $B$7$+$J$$$N$G!$$=$&9M$($k$H!$(B
"the individual $BN,(B, rather than the decision" $B$O!V7hDj$G$O$J$/8D?M!W(B
Post by TAKEI Nobumitsu
Post by Kobayashi Noritada
If a particular decision is delegated, the project
leader cannot take back responsibility for the decision personally, but can
re-delegate it to someone else.</p>
$B$+$C$?$H$-!$(BDPL $B8D?M$KLdBj$,La$C$F$-$F(B DPL $B$,<+J,$GBP=h$9$k$N$O%k!<%k0cH?!%(B
DPL $B$OB>$NC/$+$KLdBj=hM}$r:FEY3d$j?6$k$N$O$G$-$k!%(B
$B$G$9$M!#(B[1]$B$NItJ,$OCm<a$N$h$&$J$N$G!"$=$NItJ,$O(B DWN $B$N86J8$K$O=P$F$-$F(B

Nobuhiro IMAI
2005-12-16 19:48:15 UTC

Post by Nobuhiro IMAI
Post by Nobuhiro IMAI
