Debian Package Tracker
Register | Log in
Subscribe

debian-goodies

Small toolbox-style utilities for Debian systems

Choose email to subscribe with

general
  • source: debian-goodies (main)
  • version: 0.88.1
  • maintainer: Javier Fernández-Sanguino Peña (DMD)
  • uploaders: Axel Beckert [DMD]
  • arch: all
  • std-ver: 4.6.1
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 0.84
  • oldstable: 0.87
  • stable: 0.88.1
  • testing: 0.88.1
  • unstable: 0.88.1
versioned links
  • 0.84: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 0.87: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 0.88.1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • debian-goodies (39 bugs: 0, 16, 23, 0)
action needed
1 security issue in sid high

There is 1 open security issue in sid.

1 important issue:
  • CVE-2023-27635: debmany in debian-goodies 0.88.1 allows attackers to execute arbitrary shell commands (because of an eval call) via a crafted .deb file. (The path is shown to the user before execution.)
Created: 2023-03-06 Last update: 2023-06-11 06:30
1 security issue in trixie high

There is 1 open security issue in trixie.

1 important issue:
  • CVE-2023-27635: debmany in debian-goodies 0.88.1 allows attackers to execute arbitrary shell commands (because of an eval call) via a crafted .deb file. (The path is shown to the user before execution.)
Created: 2023-06-11 Last update: 2023-06-11 06:30
4 bugs tagged patch in the BTS normal
The BTS contains patches fixing 4 bugs, consider including or untagging them.
Created: 2023-09-13 Last update: 2023-10-08 02:31
version in VCS is newer than in repository, is it time to upload? normal
vcswatch reports that this package seems to have a new changelog entry (version 0.88.2, distribution UNRELEASED) and new commits in its VCS. You should consider whether it's time to make an upload.

Here are the relevant commit messages:
commit 495eaafa94d2b4cbee4eed01cd78238e311d096b
Author: Axel Beckert <abe@deuxchevaux.org>
Date:   Sun Feb 19 05:44:35 2023 +0100

    debmany: Fix shell injection via crafted .deb
    
    Closes: #1031267
    
    Thanks to Jakub Wilk for reporting!

commit a1c248db71ea1d1725e12a329bc28b7ca0d5a214
Author: Axel Beckert <abe@deuxchevaux.org>
Date:   Sun Feb 19 04:30:49 2023 +0100

    debmany: Fix -k option, "kfmclient exec" → "kfmclient newTab"

commit dcfd28b474936e1c28a7115dc4f5e1fab6b4fd86
Author: Debian Janitor <janitor@jelmer.uk>
Date:   Sat Sep 10 17:35:34 2022 +0000

    Remove constraints unnecessary since buster (oldstable)
    
    * Remove 2 maintscript entries from 1 files.
    
    Changes-By: deb-scrub-obsolete
Created: 2022-09-11 Last update: 2023-10-07 21:08
lintian reports 3 warnings normal
Lintian reports 3 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2022-09-11 Last update: 2022-09-11 20:02
1 low-priority security issue in bullseye low

There is 1 open security issue in bullseye.

1 issue left for the package maintainer to handle:
  • CVE-2023-27635: (needs triaging) debmany in debian-goodies 0.88.1 allows attackers to execute arbitrary shell commands (because of an eval call) via a crafted .deb file. (The path is shown to the user before execution.)

You can find information about how to handle this issue in the security team's documentation.

Created: 2023-03-06 Last update: 2023-06-11 06:30
1 low-priority security issue in bookworm low

There is 1 open security issue in bookworm.

1 issue left for the package maintainer to handle:
  • CVE-2023-27635: (needs triaging) debmany in debian-goodies 0.88.1 allows attackers to execute arbitrary shell commands (because of an eval call) via a crafted .deb file. (The path is shown to the user before execution.)

You can find information about how to handle this issue in the security team's documentation.

Created: 2023-06-10 Last update: 2023-06-11 06:30
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.6.2 instead of 4.6.1).
Created: 2022-12-17 Last update: 2022-12-17 19:18
news
[rss feed]
  • [2022-09-13] debian-goodies 0.88.1 MIGRATED to testing (Debian testing watch)
  • [2022-09-10] Accepted debian-goodies 0.88.1 (source) into unstable (Axel Beckert)
  • [2022-06-30] debian-goodies 0.88 MIGRATED to testing (Debian testing watch)
  • [2022-06-19] Accepted debian-goodies 0.88 (source) into unstable (Axel Beckert)
  • [2020-12-30] debian-goodies 0.87 MIGRATED to testing (Debian testing watch)
  • [2020-12-25] Accepted debian-goodies 0.87 (source) into unstable (Axel Beckert)
  • [2020-05-27] debian-goodies 0.86 MIGRATED to testing (Debian testing watch)
  • [2020-05-22] Accepted debian-goodies 0.86 (source) into unstable (Axel Beckert)
  • [2020-04-24] debian-goodies 0.85 MIGRATED to testing (Debian testing watch)
  • [2020-04-19] Accepted debian-goodies 0.85 (source) into unstable (Axel Beckert)
  • [2018-11-24] debian-goodies 0.84 MIGRATED to testing (Debian testing watch)
  • [2018-11-18] Accepted debian-goodies 0.84 (source all) into unstable (Axel Beckert)
  • [2018-10-29] debian-goodies 0.83 MIGRATED to testing (Debian testing watch)
  • [2018-10-24] Accepted debian-goodies 0.83 (source all) into unstable (Axel Beckert)
  • [2018-09-29] debian-goodies 0.82.1 MIGRATED to testing (Debian testing watch)
  • [2018-09-24] Accepted debian-goodies 0.82.1 (source all) into unstable (Axel Beckert)
  • [2018-09-22] Accepted debian-goodies 0.82 (source all) into unstable (Axel Beckert)
  • [2018-07-26] debian-goodies 0.81 MIGRATED to testing (Debian testing watch)
  • [2018-07-21] Accepted debian-goodies 0.81 (source all) into unstable (Axel Beckert)
  • [2018-07-19] debian-goodies 0.80 MIGRATED to testing (Debian testing watch)
  • [2018-07-14] Accepted debian-goodies 0.80 (source all) into unstable (Axel Beckert)
  • [2017-12-04] debian-goodies 0.79 MIGRATED to testing (Debian testing watch)
  • [2017-11-24] debian-goodies 0.78 MIGRATED to testing (Debian testing watch)
  • [2017-11-24] Accepted debian-goodies 0.79 (source all) into unstable (Axel Beckert)
  • [2017-11-19] Accepted debian-goodies 0.78 (source all) into unstable (Axel Beckert)
  • [2017-11-15] Accepted debian-goodies 0.77 (source all) into unstable (Axel Beckert)
  • [2017-11-02] debian-goodies 0.76 MIGRATED to testing (Debian testing watch)
  • [2017-10-27] Accepted debian-goodies 0.76 (source all) into unstable (Axel Beckert)
  • [2017-09-15] debian-goodies 0.75 MIGRATED to testing (Debian testing watch)
  • [2017-09-09] Accepted debian-goodies 0.75 (source all) into unstable (Axel Beckert)
  • 1
  • 2
bugs [bug history graph]
  • all: 41
  • RC: 0
  • I&N: 17
  • M&W: 23
  • F&P: 1
  • patch: 4
links
  • lintian (0, 3)
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • screenshots
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 0.88.1ubuntu1
  • 3 bugs
  • patches for 0.88.1ubuntu1

Debian Package Tracker — Copyright 2013-2018 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing