[Bug 1765178] [NEW] Please remove libui-dialog-perl; open security vulnerability

Jeremy Bicha jeremy at bicha.net
Wed Apr 18 19:30:20 UTC 2018


Public bug reported:

Please remove libui-dialog-perl and its reverse depends macchanger-gtk
from Ubuntu 18.04.

libui-dialog-perl was removed from Debian Testing in November 2016 for a
security bug originally reported in 2008. The bug was apparently fixed
in 1.13 but no one cares for this package.

I mean it could be trivially NMU'd in Debian, but… its only reverse
dependency is macchanger-gtk which was last uploaded in 2009.

macchanger-gtk is a simple perl gtk2 app with the source code partially
written in Spanish. The app doesn't use great English and is not
translated. The homepage listed in the Debian packaging no longer works.
The program needs to be either run as root or with gksu (a Recommends)
but that won't work with the Wayland session that Ubuntu will presumably
default to in 18.10.

References
----------
https://tracker.debian.org/pkg/libui-dialog-perl
https://bugs.debian.org/496448
https://rt.cpan.org/Public/Bug/Display.html?id=107364

https://tracker.debian.org/pkg/macchanger-gtk
https://sources.debian.org/src/macchanger-gtk/unstable/

** Affects: libui-dialog-perl (Ubuntu)
     Importance: Undecided
         Status: New

** Affects: macchanger-gtk (Ubuntu)
     Importance: Undecided
         Status: New


** Tags: bionic

** Also affects: macchanger-gtk (Ubuntu)
   Importance: Undecided
       Status: New

** Description changed:

  Please remove libui-dialog-perl and its reverse depends macchanger-gtk
  from Ubuntu 18.04.
  
  libui-dialog-perl was removed from Debian Testing in November 2016 for a
  security bug originally reported in 2008. The bug was apparently fixed
  in 1.13 but no one cares for this package.
  
  I mean it could be trivially NMU'd in Debian, but… its only reverse
  dependency is macchanger-gtk which was last uploaded in 2009.
  
  macchanger-gtk is a simple perl gtk2 app with the source code partially
  written in Spanish. The app doesn't use great English and is not
  translated. The homepage listed in the Debian packaging no longer works.
  The program needs to be either run as root or with gksu (a Recommends)
  but that won't work with the Wayland session that Ubuntu will presumably
  default to in 18.10.
+ 
+ References
+ ----------
+ https://tracker.debian.org/pkg/libui-dialog-perl
+ https://bugs.debian.org/496448
+ https://rt.cpan.org/Public/Bug/Display.html?id=107364
+ 
+ https://tracker.debian.org/pkg/macchanger-gtk
+ https://sources.debian.org/src/macchanger-gtk/unstable/

-- 
You received this bug notification because you are a member of Ubuntu
Package Archive Administrators, which is subscribed to the bug report.
https://bugs.launchpad.net/bugs/1765178

Title:
  Please remove libui-dialog-perl; open security vulnerability

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libui-dialog-perl/+bug/1765178/+subscriptions



More information about the ubuntu-archive mailing list