#1146411 RFS: mini-httpd/1.30-18 -- Small HTTP server

#1146411#5
Date:
2026-09-01 15:45:55 UTC
From:
To:
Dear mentors,

I am looking for a sponsor for my package "mini-httpd":
Marked urgent because of CVE-2026-68005.

 * Package name     : mini-httpd
   Version          : 1.30-18
   Upstream contact : Jef Poskanzer jef@mail.acme.com
 * URL              : https://www.acme.com/software/mini_httpd
 * License          : BSD-2-clause
 * Vcs              : https://salsa.debian.org/debian/mini-httpd
   Section          : web

The source builds the following binary packages:

  mini-httpd - Small HTTP server

To access further information about this package, please visit the
following URL:

  https://mentors.debian.net/package/mini-httpd/

Alternatively, you can download the package with 'dget' using this
command:

  dget -x
https://mentors.debian.net/debian/pool/main/m/mini-httpd/mini-httpd_1.30-18.dsc

Changes since the last upload:

 mini-httpd (1.30-18) unstable; urgency=high
 .
   * Fix memory exhaustion DoS in header parsing (CVE-2026-68005).
     (Closes: #1144953)
   * Fix potential Slowloris in the same place by removing old
alarm(60)
     based timeout mechanism.
   * Update copyright year on debian/

Regards,

#1146411#10
Date:
2026-09-01 16:08:49 UTC
From:
To:
Hi Alexandru,

Please consider fixing this Lintian output on your next upload:

Running lintian...
N:
I: mini-httpd source: quilt-patch-uses-dpatch-placeholder [debian/patches/0004-manpage:11]
N:
N:   This quilt patch file uses dpatch-specific placeholders like the #!/bin/sh
N:   /usr/share/dpatch/dpatch-run shebang or the @DPATCH@ tag.
N:
N:   dpatch has been deprecated and the corresponding quilt patches should not
N:   use dpatch-specific syntax anymore.
N:
N:   Visibility: info
N:   Show-Always: no
N:   Check: debian/patches/quilt
N:
N:
I: mini-httpd source: quilt-patch-uses-dpatch-placeholder [debian/patches/0004-manpage:6]
N:
P: mini-httpd source: package-uses-old-debhelper-compat-version 13
N:
N:   This package uses a debhelper compatibility level that is no longer
N:   recommended. Please consider using the recommended level.
N:
N:   For most packages, the best way to set the compatibility level is to
N:   specify debhelper-compat (= X) as a Build-Depends in debian/control. You
N:   can also use the debian/compat file or export DH_COMPAT in debian/rules.
N:
N:   If no level is selected debhelper defaults to level 1, which is
N:   deprecated.
N:
N:   Please refer to the debhelper(7) manual page for details.
N:
N:   Visibility: pedantic
N:   Show-Always: no
N:   Check: debhelper
N:

I: Lintian run successful (worst tag: info)

Otherwise, done:

$ dput ssh-upload ../mini-httpd_1.30-18_source.changes
Uploading mini-httpd using sftp to ssh-upload (host: ssh.upload.debian.org; directory: /srv/upload.debian.org/UploadQueue/)
running allowed-distribution: check whether a local profile permits uploads to the target distribution
running protected-distribution: warn before uploading to distributions where a special policy applies
running checksum: verify checksums before uploading
running suite-mismatch: check the target distribution for common errors
running gpg: check GnuPG signatures before the upload
Logging into host ssh.upload.debian.org as tsimonq2
Uploading mini-httpd_1.30-18.dsc
Uploading mini-httpd_1.30-18.debian.tar.xz
Uploading mini-httpd_1.30-18_source.buildinfo
Uploading mini-httpd_1.30-18_source.changes

Best regards,
Simon Quigley
tsimonq2@debian.org