{"id":10526,"date":"2019-05-15T23:25:37","date_gmt":"2019-05-15T21:25:37","guid":{"rendered":"https:\/\/gambaru.de\/blog\/?p=10526"},"modified":"2019-05-15T23:25:37","modified_gmt":"2019-05-15T21:25:37","slug":"my-free-software-activities-in-april-2019","status":"publish","type":"post","link":"https:\/\/gambaru.de\/blog\/2019\/05\/15\/my-free-software-activities-in-april-2019\/","title":{"rendered":"My Free Software Activities in April 2019"},"content":{"rendered":"<p>Welcome to gambaru.de. Here is my monthly report that covers what I have been doing for Debian. If you're interested in Java, Games and LTS topics, this might be interesting for you.<\/p>\n<h2>Debian Games<\/h2>\n<ul>\n<li>This was a very quiet month compared to pre-freeze time. I reported three security vulnerabilities for <a href=\"https:\/\/tracker.debian.org\/pkg\/teeworlds\">Teeworlds<\/a> (<a href=\"https:\/\/bugs.debian.org\/cgi-bin\/bugreport.cgi?bug=927152\">#927152<\/a>) which were later fixed by Dylan A\u00efssi. Thank you.<\/li>\n<li>I also reviewed and sponsored a new revision of <a href=\"https:\/\/tracker.debian.org\/pkg\/openmw\">OpenMW<\/a> for Bret Curtis. I'm not sure why he didn't ask the release team for an unblock but there may be a reason.<\/li>\n<\/ul>\n<h2>Debian Java<\/h2>\n<ul>\n<li>I fixed a security vulnerability in <a href=\"https:\/\/tracker.debian.org\/pkg\/robocode\">robocode<\/a> (<a href=\"https:\/\/bugs.debian.org\/cgi-bin\/bugreport.cgi?bug=926088\">#926088<\/a>) and asked for an unblock.<\/li>\n<li>I corrected a mistake in <a href=\"https:\/\/tracker.debian.org\/pkg\/solr-tomcat\">solr-tomcat<\/a> and learned, if you want to override a service file of another package (tomcat9) the conf file has to be installed into\n<pre><code id=\"sourcecode\" class=\"no-highlight\"><span id=\"line3\" class=\"codeline \">\/etc\/systemd\/system\/tomcat9.service.d\/<\/span><\/code><\/pre>\n<p>instead of \/etc\/systemd\/system\/tomcat9.d.*sigh*<\/li>\n<\/ul>\n<h2>Misc<\/h2>\n<ul>\n<li>Last month I wrote about the challenges of the <a href=\"https:\/\/tracker.debian.org\/pkg\/ublock-origin\">ublock-origin<\/a> addon (<a href=\"https:\/\/bugs.debian.org\/cgi-bin\/bugreport.cgi?bug=926586\">#926586<\/a>). We came to the conclusion that we can no longer provide one version for Firefox and Chromium but that we don't have to create two binary packages either. Now we use symlinks\u00a0 and two different directories and hopefully this will solve all the troubles we had before. It is not a great solution but hopefully we can maintain the addon without relying on patches.\u00a0 Thanks to Michael Meskes who implemented the changes. I will probably upload a new version to experimental in May, so that people can try it out and report back.<\/li>\n<\/ul>\n<h2>Debian LTS<\/h2>\n<p>This was my\u00a0thirty-eight month as a paid contributor and I have been paid to work 17,25 hours on <a href=\"https:\/\/wiki.debian.org\/LTS\/\">Debian LTS<\/a>, a project started by <a href=\"https:\/\/raphaelhertzog.com\">Rapha\u00ebl Hertzog<\/a>. In that time I did the following:<\/p>\n<ul>\n<li>From 29.04.2019 until 05.05.2019 I was in charge of our LTS frontdesk. I investigated and triaged CVE in rebar, filezilla, lucene-solr, librecad, apparmor, phpbb3, jakarta-jmeter, jetty8, jetty, php-imagick and node-tar.<\/li>\n<li><a href=\"https:\/\/lists.debian.org\/debian-lts-announce\/2019\/05\/msg00000.html\">DLA-1753-2<\/a>. Issued a regression update for proftpd-dfsg because it became clear that neither version 1.3.5.e nor 1.3.6 was a way forward to address the memory leaks because those versions also introduced new bugs that affected sftp setups negatively (<a href=\"https:\/\/bugs.debian.org\/cgi-bin\/bugreport.cgi?bug=926719\">#926719<\/a>). I resolved these problems by backporting the patches for the memory leaks and by reverting to version 1.3.5 again.<\/li>\n<li><a href=\"https:\/\/lists.debian.org\/debian-lts-announce\/2019\/05\/msg00001.html\">DLA-1773-1<\/a>. Issued a security update for signing-party fixing 1 CVE.<\/li>\n<li><a href=\"https:\/\/lists.debian.org\/debian-lts-announce\/2019\/05\/msg00003.html\">DLA-1774-1<\/a>. Issued a security update for otrs2 fixing 1 CVE.<\/li>\n<li><a href=\"https:\/\/lists.debian.org\/debian-lts-announce\/2019\/05\/msg00004.html\">DLA-1775-1<\/a>. Issued a security update for phpbb3 fixing 1 CVE.<\/li>\n<li><a href=\"https:\/\/lists.debian.org\/debian-lts-announce\/2019\/05\/msg00005.html\">DLA-1776-1<\/a>. Issued a security update for librecad fixing 1 CVE.<\/li>\n<li><a href=\"https:\/\/lists.debian.org\/debian-lts-announce\/2019\/05\/msg00015.html\">DLA-1785-1<\/a>. Issued a security update for imagemagick together with Hugo Lefeuvre (3 CVE) fixing 50 CVE in total.<\/li>\n<\/ul>\n<h2>ELTS<\/h2>\n<p>Extended Long Term Support (<a href=\"https:\/\/wiki.debian.org\/LTS\/Extended\">ELTS<\/a>) is a project led by <a href=\"https:\/\/www.freexian.com\/\">Freexian<\/a> to further extend the lifetime of Debian releases. It is not an official Debian project but all Debian users benefit from it without cost. The current ELTS release is Debian 7 \"Wheezy\". This was my eleventh month and I have been paid to work 14,5 hours on ELTS.<\/p>\n<ul>\n<li>I was in charge of our ELTS frontdesk from 15.04.2019 until 21.04.2019 and I triaged CVE in openjdk7, php5 and libvirt.<\/li>\n<li><a href=\"https:\/\/deb.freexian.com\/extended-lts\/updates\/ela-72-2-jasper\/\">ELA-72-2<\/a>. Issued a regression update for jasper which corrected the patch for CVE-2018-19542.<\/li>\n<li><a href=\"https:\/\/deb.freexian.com\/extended-lts\/updates\/ela-109-1-jquery\/\">ELA-109-1<\/a>. Issued a security update for jquery fixing 1 CVE.<\/li>\n<li><a href=\"https:\/\/deb.freexian.com\/extended-lts\/updates\/ela-111-1-linux\/\">ELA-111-1<\/a>. Issued a security update for linux and linux-latest fixing 24 CVE.<\/li>\n<li><a href=\"https:\/\/deb.freexian.com\/extended-lts\/updates\/ela-117-1-apache2\/\">ELA-117-1<\/a>. Issued a security update for apache2 fixing 2 CVE and investigated four more CVE which I triaged as not-affected.<\/li>\n<\/ul>\n<p>Thanks for reading and see you next time.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Welcome to gambaru.de. Here is my monthly report that covers what I have been doing for Debian. If you&#8217;re interested in Java, Games and LTS topics, this might be interesting for you. Debian Games This was a very quiet month compared to pre-freeze time. I reported three security vulnerabilities for Teeworlds (#927152) which were later &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/gambaru.de\/blog\/2019\/05\/15\/my-free-software-activities-in-april-2019\/\" class=\"more-link\"><span class=\"screen-reader-text\">\u201eMy Free Software Activities in April 2019\u201c<\/span> weiterlesen<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[4],"tags":[53,68,155],"_links":{"self":[{"href":"https:\/\/gambaru.de\/blog\/wp-json\/wp\/v2\/posts\/10526"}],"collection":[{"href":"https:\/\/gambaru.de\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/gambaru.de\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/gambaru.de\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/gambaru.de\/blog\/wp-json\/wp\/v2\/comments?post=10526"}],"version-history":[{"count":0,"href":"https:\/\/gambaru.de\/blog\/wp-json\/wp\/v2\/posts\/10526\/revisions"}],"wp:attachment":[{"href":"https:\/\/gambaru.de\/blog\/wp-json\/wp\/v2\/media?parent=10526"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/gambaru.de\/blog\/wp-json\/wp\/v2\/categories?post=10526"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/gambaru.de\/blog\/wp-json\/wp\/v2\/tags?post=10526"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}