Red Hat Bugzilla – Bug 734348
Figure out what to do about ajaxterm
Last modified: 2012-02-08 05:41:29 EST
During the nova build, we delete ajaxterm as a temporary solution
What's the correct solution? Can we use the system version of ajaxterm?
Some notes to myself:
Ajaxterm was recently orphaned and retired in Fedora: http://lists.fedoraproject.org/pipermail/devel/2011-April/150169.html
Upstream seems to be stagnant (is it perfect?): https://github.com/antonylesuisse/qweb/tree/master/ajaxterm
But fixes do seem to happen in debian/ubuntu packaging:
There was exploit: http://www.cvedetails.com/cve/CVE-2009-1629/
fixed in Fedora http://lwn.net/Alerts/421312/
And, ajaxterm wins googlefight with anyterm! http://www.googlefight.com/index.php?lang=en_GB&word1=ajaxterm&word2=anyterm
Suggested for removal upstream:
"- Ajaxterm (unmaintained, security issues, replaced by VNC console)"
Removed upstream https://review.openstack.org/#change,3850