Debian Package Tracker
Register | Log in
Subscribe

man2html

browse man pages in your web browser

Choose email to subscribe with

general
  • source: man2html (main)
  • version: 1.6g-14
  • maintainer: Robert Luberda (DMD)
  • arch: any
  • std-ver: 4.5.1
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 1.6g-9
  • oldstable: 1.6g-11
  • stable: 1.6g-14
  • testing: 1.6g-14
  • unstable: 1.6g-14
versioned links
  • 1.6g-9: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.6g-11: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.6g-14: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • man2html (7 bugs: 0, 3, 4, 0)
  • man2html-base (1 bugs: 0, 0, 1, 0)
action needed
Problems while searching for a new upstream version high
uscan had problems while searching for a new upstream version:
In watchfile debian/watch, reading webpage
  http://primates.ximian.com/~flucifredi/man/ failed: 500 Can't connect to primates.ximian.com:80 (Name or service not known)
Created: 2020-06-29 Last update: 2023-03-25 05:32
2 security issues in sid high

There are 2 open security issues in sid.

2 important issues:
  • CVE-2021-40647: In man2html 1.6g, a specific string being read in from a file will overwrite the size parameter in the top chunk of the heap. This at least causes the program to segmentation abort if the heap size parameter isn't aligned correctly. In version before GLIBC version 2.29 and aligned correctly, it allows arbitrary write anywhere in the programs memory.
  • CVE-2021-40648: In man2html 1.6g, a filename can be created to overwrite the previous size parameter of the next chunk and the fd, bk, fd_nextsize, bk_nextsize of the current chunk. The next chunk is then freed later on, causing a freeing of an arbitrary amount of memory.
Created: 2022-09-14 Last update: 2023-03-01 19:01
2 security issues in buster high

There are 2 open security issues in buster.

2 important issues:
  • CVE-2021-40647: In man2html 1.6g, a specific string being read in from a file will overwrite the size parameter in the top chunk of the heap. This at least causes the program to segmentation abort if the heap size parameter isn't aligned correctly. In version before GLIBC version 2.29 and aligned correctly, it allows arbitrary write anywhere in the programs memory.
  • CVE-2021-40648: In man2html 1.6g, a filename can be created to overwrite the previous size parameter of the next chunk and the fd, bk, fd_nextsize, bk_nextsize of the current chunk. The next chunk is then freed later on, causing a freeing of an arbitrary amount of memory.
Created: 2022-09-14 Last update: 2023-03-01 19:01
4 bugs tagged patch in the BTS normal
The BTS contains patches fixing 4 bugs, consider including or untagging them.
Created: 2022-07-27 Last update: 2023-03-25 09:02
Depends on packages which need a new maintainer normal
The packages that man2html depends on which need a new maintainer are:
  • swish++ (#738474)
    • Suggests: swish++
Created: 2019-11-22 Last update: 2023-03-25 06:34
version in VCS is newer than in repository, is it time to upload? normal
vcswatch reports that this package seems to have a new changelog entry (version 1.6g-15, distribution UNRELEASED) and new commits in its VCS. You should consider whether it's time to make an upload.

Here are the relevant commit messages:
commit c5396f3c3f009345a99948d7ae98659c81df1875
Merge: b7f3621 c997a46
Author: Jelmer Vernooij <jelmer@debian.org>
Date:   Sun Oct 30 14:01:52 2022 +0000

    Merge branch 'lintian-fixes' into 'master'
    
    Fix some issues reported by lintian
    
    See merge request debian/man2html!2

commit c997a46e49a2457a8c53117b1479edb86dca67f8
Author: Debian Janitor <janitor@jelmer.uk>
Date:   Sun Oct 23 09:57:41 2022 +0000

    Update standards version to 4.6.1, no changes needed.
    
    Changes-By: lintian-brush
    Fixes: lintian: out-of-date-standards-version
    See-also: https://lintian.debian.org/tags/out-of-date-standards-version.html

commit 9b983cd03587bef68797971e54c0ccdcbbd14881
Author: Debian Janitor <janitor@jelmer.uk>
Date:   Sun Oct 23 09:57:09 2022 +0000

    Update lintian override info to new format on line 2.
    
    Changes-By: lintian-brush
    Fixes: lintian: mismatched-override
    See-also: https://lintian.debian.org/tags/mismatched-override.html
Created: 2022-10-30 Last update: 2023-03-21 15:06
lintian reports 3 warnings normal
Lintian reports 3 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2022-01-01 Last update: 2022-07-30 12:15
2 low-priority security issues in bullseye low

There are 2 open security issues in bullseye.

2 issues left for the package maintainer to handle:
  • CVE-2021-40647: (needs triaging) In man2html 1.6g, a specific string being read in from a file will overwrite the size parameter in the top chunk of the heap. This at least causes the program to segmentation abort if the heap size parameter isn't aligned correctly. In version before GLIBC version 2.29 and aligned correctly, it allows arbitrary write anywhere in the programs memory.
  • CVE-2021-40648: (needs triaging) In man2html 1.6g, a filename can be created to overwrite the previous size parameter of the next chunk and the fd, bk, fd_nextsize, bk_nextsize of the current chunk. The next chunk is then freed later on, causing a freeing of an arbitrary amount of memory.

You can find information about how to handle these issues in the security team's documentation.

Created: 2022-09-14 Last update: 2023-03-01 19:01
debian/patches: 35 patches to forward upstream low

Among the 35 debian patches available in version 1.6g-14 of the package, we noticed the following issues:

  • 35 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2023-02-26 15:54
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.6.2 instead of 4.5.1).
Created: 2021-08-18 Last update: 2022-12-17 19:18
news
[rss feed]
  • [2021-01-11] man2html 1.6g-14 MIGRATED to testing (Debian testing watch)
  • [2021-01-05] Accepted man2html 1.6g-14 (source) into unstable (Robert Luberda)
  • [2020-12-26] man2html 1.6g-13 MIGRATED to testing (Debian testing watch)
  • [2020-12-20] Accepted man2html 1.6g-13 (source) into unstable (Robert Luberda)
  • [2019-08-09] man2html 1.6g-12 MIGRATED to testing (Debian testing watch)
  • [2019-08-04] Accepted man2html 1.6g-12 (source) into unstable (Robert Luberda)
  • [2018-02-16] man2html 1.6g-11 MIGRATED to testing (Debian testing watch)
  • [2018-02-10] Accepted man2html 1.6g-11 (source amd64) into unstable (Robert Luberda)
  • [2018-01-20] man2html 1.6g-10 MIGRATED to testing (Debian testing watch)
  • [2018-01-14] Accepted man2html 1.6g-10 (source amd64) into unstable (Robert Luberda)
  • [2017-04-29] man2html 1.6g-9 MIGRATED to testing (Debian testing watch)
  • [2017-04-19] Accepted man2html 1.6g-9 (source amd64) into unstable (Robert Luberda)
  • [2015-10-31] man2html 1.6g-8 MIGRATED to testing (Britney)
  • [2015-10-26] Accepted man2html 1.6g-8 (source i386) into unstable (Robert Luberda)
  • [2013-11-29] man2html 1.6g-7 MIGRATED to testing (Debian testing watch)
  • [2013-11-18] Accepted man2html 1.6g-7 (source i386) (Robert Luberda)
  • [2011-11-06] Accepted man2html 1.6f+repack-1+squeeze1 (source i386) (Robert Luberda)
  • [2011-11-06] Accepted man2html 1.6f-3+lenny1 (source i386) (Robert Luberda)
  • [2011-11-05] man2html 1.6g-6 MIGRATED to testing (Debian testing watch)
  • [2011-11-02] Accepted man2html 1.6g-6 (source i386) (Robert Luberda)
  • [2011-03-18] man2html 1.6g-5 MIGRATED to testing (Debian testing watch)
  • [2011-03-07] Accepted man2html 1.6g-5 (source i386) (Robert Luberda)
  • [2011-02-24] man2html 1.6g-4 MIGRATED to testing (Debian testing watch)
  • [2011-02-13] Accepted man2html 1.6g-4 (source i386) (Robert Luberda)
  • [2011-02-07] Accepted man2html 1.6g-3 (source i386) (Robert Luberda)
  • [2011-01-16] Accepted man2html 1.6g-2 (source i386) (Robert Luberda)
  • [2011-01-09] Accepted man2html 1.6g-1 (source i386) (Robert Luberda)
  • [2010-06-23] man2html 1.6f+repack-1 MIGRATED to testing (Debian testing watch)
  • [2010-06-12] Accepted man2html 1.6f+repack-1 (source i386) (Robert Luberda)
  • [2008-11-11] man2html 1.6f-3 MIGRATED to testing (Debian testing watch)
  • 1
  • 2
bugs [bug history graph]
  • all: 9
  • RC: 0
  • I&N: 4
  • M&W: 5
  • F&P: 0
  • patch: 4
links
  • homepage
  • lintian (0, 3)
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • screenshots
  • l10n (100, -)
  • debian patches
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 1.6g-14
  • 1 bug

Debian Package Tracker — Copyright 2013-2018 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing