Bug#1036279: XSS in RSS syntax

2023-06-04 Thread Salvatore Bonaccorso
Control: retitle -1 dokuwiki: CVE-2023-34408: XSS in RSS syntax Hi, On Thu, May 18, 2023 at 03:19:05PM +0200, Moritz Muehlenhoff wrote: > Source: dokuwiki > Version: 0.0.20220731.a-1 > Severity: grave > Tags: security > X-Debbugs-Cc: Debian Security Team > > No CVE yet: >

Bug#1037079: unblock: configobj/5.0.8-2

2023-06-04 Thread Salvatore Bonaccorso
Hi, On Sun, Jun 04, 2023 at 09:50:23PM +0200, Sebastian Ramacher wrote: > retitle 1037079 bookworm-pu: configobj/5.0.8-2 > tags 1037079 bookworm moreinfo > user release.debian@packages.debian.org > usertags 1037079 + pu - unblock > thanks > > Hi Stefano > > On 2023-06-03 16:28:41 -0400,

Bug#1037111: ITP: pipewire-module-xrdp -- xRDP module for the PipeWire sound server

2023-06-04 Thread Arnaud Rebillout
Package: wnpp Severity: wishlist Owner: Arnaud Rebillout X-Debbugs-Cc: debian-de...@lists.debian.org, pkg-utopia-maintain...@lists.alioth.debian.org * Package name: pipewire-module-xrdp Version : git HEAD Upstream Contact:

Bug#1037110: ITP: libgraphviz2-perl -- Perl interface to the GraphViz graphing tool

2023-06-04 Thread Andrew Ruthven
Package: wnpp Owner: Andrew Ruthven Severity: wishlist X-Debbugs-CC: debian-de...@lists.debian.org, debian-p...@lists.debian.org * Package name: libgraphviz2-perl Version : 2.67 Upstream Author : Ron Savage * URL : https://metacpan.org/release/GraphViz2 * License

Bug#1037109: ITP: libtest-snapshot-perl -- test against data stored in automatically-named file

2023-06-04 Thread Andrew Ruthven
Package: wnpp Owner: Andrew Ruthven Severity: wishlist X-Debbugs-CC: debian-de...@lists.debian.org, debian-p...@lists.debian.org * Package name    : libtest-snapshot-perl    Version : 0.06   Upstream Author : Ed J * URL : https://metacpan.org/release/Test-Snapshot  *

Bug#1033065: release-notes: i386 notes should specify minimum CPU requirements

2023-06-04 Thread Martin-Éric Racine
Hey Paul, On Sun, Jun 4, 2023 at 10:36 PM Paul Gevers wrote: > On 04-06-2023 21:28, Martin-Éric Racine wrote: > > As previously stated, the Geode LX (but not older Geodes) does fulfill > > the baseline requirement for i686. NOPL, PAE and others were marked by > > Intel as optional features. If

Bug#1036740: [Pkg-netatalk-devel] Bug#1036740: closed by Markus Koschany (Re: Bug#1036740: Fix for CVE-2022-23123 causes afpd segfault with valid metadata)

2023-06-04 Thread Daniel Markstedt
On Sat, Jun 3, 2023 at 11:07 PM Jonas Smedegaard wrote: > > Quoting Salvatore Bonaccorso (2023-06-04 07:39:12) > > Hi Daniel, > > > > On Sat, Jun 03, 2023 at 02:56:00PM -0700, Daniel Markstedt wrote: > > > > -- Forwarded message -- > > > > From: Markus Koschany > > > > To: Daniel

Bug#1036899: logiops: logid does not work for MX Master 3

2023-06-04 Thread Chow Loong Jin
On Sun, May 28, 2023 at 11:01:16PM +0200, Hendrik Tews wrote: > Package: logiops > Version: 0.3.1-1 > Severity: important > X-Debbugs-Cc: none, Hendrik Tews > > Dear Maintainer, > > after upgrading to logiops version 0.3.1-1 the logid daemon does not > seem to do anything any more. For my

Bug#1025011: [Pkg-netatalk-devel] Bug#1025011: fixed in netatalk 3.1.15~ds-1

2023-06-04 Thread Daniel Markstedt
On Wed, May 24, 2023 at 7:18 AM Moritz Mühlenhoff wrote: > [...] > It's nice that there's renewed interest, but this involves also taking > care of netatalk in stable, there's a range of issues (full list at > https://security-tracker.debian.org/tracker/source-package/netatalk) > which need to be

Bug#1035985: Built without GLESv2 support causing errors on machines only supporting GLES

2023-06-04 Thread Lisandro Damián Nicanor Pérez Meyer
Hi! On Tue, 30 May 2023 at 17:12, Leonardo Held wrote: > > Package: qt6-base-dev > Followup-For: Bug #1035985 > > Dear Maintainer, > > please consider bumping the severity level of #1035985, as it makes > Debian unable to use qt on the many embedded platforms, and the next > stable will be

Bug#945269: debian-policy: packages should use tmpfiles.d(5) to create directories below /var

2023-06-04 Thread Luca Boccassi
On Sun, 4 Jun 2023 at 14:56, Simon McVittie wrote: > > (Newly cc'd elogind maintainers: Please see #945269 for context) > > On Sun, 04 Jun 2023 at 12:15:41 +0100, Luca Boccassi wrote: > > On Sun, 4 Jun 2023 at 12:02, Sean Whitton wrote: > > > On Tue 09 May 2023 at 01:44AM +01, Luca Boccassi

Bug#1037108: evolution-data-server: gnome-keyring should not be a dependency

2023-06-04 Thread Sebastian Crane
Package: evolution-data-server Version: 3.38.3-1+deb11u2 Severity: minor X-Debbugs-Cc: none, Sebastian Crane Currently, gnome-keyring is listed as a run-time dependency. gnome-keyring is only one implementation of the freedesktop.org Secret Service API, and so other secrets management software

Bug#1035733: debian -policy: packages must not use dpkg-divert to override default systemd configuraton files

2023-06-04 Thread Luca Boccassi
On Sun, 4 Jun 2023 19:39:49 +0200 Bill Allombert wrote: > On Sun, Jun 04, 2023 at 12:25:54PM +0100, Luca Boccassi wrote: > > If you prefer, I can reword the general rule to be stricter, ie: > > "packages must not use diversions where native mechanisms are > > available" or so. Would this be

Bug#1035949: mariadb: upgrade issue: mariadb-server-10.5 fails to stop after all other -10.5 packages were removed

2023-06-04 Thread Otto Kekäläinen
Forwarded: https://jira.mariadb.org/browse/MDEV-28640 For reference: * The upgrade scenario this MR fixed: https://salsa.debian.org/mariadb-team/mariadb-server/-/commit/15cbf6e691827608636e6ff7f0a50432f50d0c4f * Release notes mention:

Bug#1037107: pre-unblock: bookworm-pu: mariadb/1:10.11.3-2/+deb12u1

2023-06-04 Thread Otto Kekäläinen
Package: release.debian.org Severity: serious Tags. bookworm User: release.debian@packages.debian.org Usertags: unblock Control: affects -1 src:mariadb This pre-unblock request is to get a decision from the Bookworm release team if you prefer to have this Bug#1035949 fix: a) in Bookworm in a

Bug#1037106: asciidoctor: Some tips to improve the formatting quality of man pages

2023-06-04 Thread Bjarni Ingi Gislason
Package: asciidoctor Version: 2.0.18-2 Severity: minor Dear Maintainer, here are some observations about created man pages with asciidoctor. Do not use '.sp' right after paragraphing macros like "SH". Begin each sentence on a new line, applies to both the source file and the man

Bug#1037105: dkms unable to compile r8168-dkms to backported kernel

2023-06-04 Thread epp
Package: r8168-dkms Version: 8.048.03-3 I installed SpiralLinux, which installs the current Debian stable at the time the image was released, in this case, bullseye and it also enables Backports by default. During the upgrade process after the initial installation, dkms reported it was having

Bug#1037104: sasl2-bin in conflict with SASL library for subversion?

2023-06-04 Thread DGhost
package: sasl2-bin version: 2.1.27 When installing subversion on Debian Bullseye, the svnserve is running fine; svnserve --version svnserve, version 1.14.1 (r1886195) compiled Apr 5 2022, 23:23:59 on x86_64-pc-linux-gnu Copyright (C) 2021 The Apache Software Foundation. This software

Bug#1037087: chromium-l10n: The following packages have unmet dependencies: chromium-l10n : Depends: chromium (< 112.0.5615.138-1~deb11u1.1~) but 114.0.5735.90-2~deb11u1 is to be installed

2023-06-04 Thread inasprecali
Hi, I tried installing chromium-l10n again on a freshly updated Bullseye machine (with the bullseye-security and bullseye-updates repositories enabled, of course) and this time the operation succeeded with no conflicts. Unless there are new reports about this problem persisting, I think this bug

Bug#1037102: stack trace

2023-06-04 Thread Tim McConnell
Stack trace of thread 621419: #0 0x5608483faf53 n/a (distort + 0x5f53) #1 0x5608483fc62b n/a (distort + 0x762b) #2

Bug#1037103: release-notes: MariaDB 10.11, versionless package names, potential upgrade issue

2023-06-04 Thread Otto Kekäläinen
Package: release-notes Severity: normal Tags: patch Hi! Please consider including https://salsa.debian.org/ddp-team/release-notes/-/merge_requests/187 in release notes for Bookworm. Details in submission.

Bug#1037101: ITP: mobilitydb -- geospatial trajectory data management & analysis platform

2023-06-04 Thread Bradford D. Boyle
Package: wnpp Severity: wishlist Owner: "Bradford D. Boyle" X-Debbugs-Cc: debian-de...@lists.debian.org, bradford.d.bo...@gmail.com * Package name: mobilitydb Version : 1.1 Upstream Contact: Esteban Zimanyi * URL : https://github.com/MobilityDB/MobilityDB * License

Bug#1037079: unblock: configobj/5.0.8-2

2023-06-04 Thread Sebastian Ramacher
retitle 1037079 bookworm-pu: configobj/5.0.8-2 tags 1037079 bookworm moreinfo user release.debian@packages.debian.org usertags 1037079 + pu - unblock thanks Hi Stefano On 2023-06-03 16:28:41 -0400, Stefano Rivera wrote: > Package: release.debian.org > Severity: normal > User:

Bug#1033065: release-notes: i386 notes should specify minimum CPU requirements

2023-06-04 Thread Paul Gevers
Hi Martin-Éric, On 04-06-2023 21:28, Martin-Éric Racine wrote: As previously stated, the Geode LX (but not older Geodes) does fulfill the baseline requirement for i686. NOPL, PAE and others were marked by Intel as optional features. If what the new Debian baseline really means is something that

Bug#1033065: release-notes: i386 notes should specify minimum CPU requirements

2023-06-04 Thread Martin-Éric Racine
On Mon, 29 May 2023 06:52:22 +0200 Paul Gevers wrote: > On 28-05-2023 17:32, Paul Gevers wrote: > > On 11-05-2023 20:20, Paul Gevers wrote: > >> Please review my proposal here: > >> > >> https://salsa.debian.org/ddp-team/release-notes/-/merge_requests/166 > > > > The release notes now document

Bug#1036751: RFS: mini-httpd/1.30-4 [ITA] -- Small HTTP server

2023-06-04 Thread Alexandru Mihail
Hello again, Uploaded again to mentors. Turns out bullseye-backports lintian (2.115.1~bpo11+1) only checks for 4.6.1 Standards, therefore a more serious error (depends-on-obsolete-package lsb-base) was reported by sid lintian. Upon inspecting the situation (lsb-base is now a transitional empty

Bug#1037100: cpp-httplib: CVE-2023-26130

2023-06-04 Thread Salvatore Bonaccorso
Source: cpp-httplib Version: 0.11.4+ds-1 Severity: important Tags: security upstream X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerability was published for cpp-httplib. CVE-2023-26130[0]: | Versions of the package yhirose/cpp-httplib before 0.12.4 are |

Bug#1033341: org-mode: CVE-2023-28617

2023-06-04 Thread David Bremner
Salvatore Bonaccorso writes: > > Looking at https://security-tracker.debian.org/tracker/CVE-2023-28617 > I think we should be fine for bookworm already, correct? Yes, I think what is there makes sense, given the constraints of expressing a weird situation. d

Bug#1037087: chromium-l10n: The following packages have unmet dependencies: chromium-l10n : Depends: chromium (< 112.0.5615.138-1~deb11u1.1~) but 114.0.5735.90-2~deb11u1 is to be installed

2023-06-04 Thread Salvatore Bonaccorso
Hi Moritz, On Sun, Jun 04, 2023 at 08:40:19PM +0200, Salvatore Bonaccorso wrote: > Hi Moritz, > > On Sun, Jun 04, 2023 at 07:22:47PM +0200, Moritz Muehlenhoff wrote: > > On Sun, Jun 04, 2023 at 12:06:01PM -0400, Andres Salomon wrote: > > > Hi Security Team, > > > > > > Looking at > > >

Bug#1037087: chromium-l10n: The following packages have unmet dependencies: chromium-l10n : Depends: chromium (< 112.0.5615.138-1~deb11u1.1~) but 114.0.5735.90-2~deb11u1 is to be installed

2023-06-04 Thread Salvatore Bonaccorso
Hi Moritz, On Sun, Jun 04, 2023 at 07:22:47PM +0200, Moritz Muehlenhoff wrote: > On Sun, Jun 04, 2023 at 12:06:01PM -0400, Andres Salomon wrote: > > Hi Security Team, > > > > Looking at https://security.debian.org/debian-security/pool/main/c/chromium/ > > , I see that chromium-l10n built for

Bug#1037099: RFS: lighttpd/1.4.71-1 -- light, fast, functional web server

2023-06-04 Thread gs-bugs . debian . org
Package: sponsorship-requests Severity: normal X-Debbugs-Cc: gs-bugs.debian@gluelogic.com Dear mentors, I am looking for a DD sponsor for my package "lighttpd": https://salsa.debian.org/debian/lighttpd/ I am an upstream lighttpd developer and have participated in maintaining lighttpd on

Bug#1035733: debian -policy: packages must not use dpkg-divert to override default systemd configuraton files

2023-06-04 Thread Bill Allombert
On Sun, Jun 04, 2023 at 12:25:54PM +0100, Luca Boccassi wrote: > If you prefer, I can reword the general rule to be stricter, ie: > "packages must not use diversions where native mechanisms are > available" or so. Would this be better? "native mechanisms" seems to vague. Cheers, -- Bill.

Bug#1036952: rootskel: text installs on aarch64 lack glyphs for many languages

2023-06-04 Thread Samuel Thibault
Hello, Cyril Brulebois, le jeu. 01 juin 2023 21:12:18 +0200, a ecrit: > Do we have other ttys than just tty1 that people might want to switch > to, and that might benefit from a similar adjustment? This script is actually not used for the other consoles, so it has never had any effect on them on

Bug#1036952: rootskel: text installs on aarch64 lack glyphs for many languages

2023-06-04 Thread Samuel Thibault
Emanuele Rocca, le jeu. 01 juin 2023 15:11:53 +0200, a ecrit: > On 2023-05-31 05:46, Samuel Thibault wrote: > > I'd rather see a patch like > > > > if [ "$TERM" = vt102 -a `tty` = /dev/tty1 ] ; then > > # Busybox's init uses a global TERM across all consoles. > > # If the serial

Bug#1037087: chromium-l10n: The following packages have unmet dependencies: chromium-l10n : Depends: chromium (< 112.0.5615.138-1~deb11u1.1~) but 114.0.5735.90-2~deb11u1 is to be installed

2023-06-04 Thread Moritz Muehlenhoff
On Sun, Jun 04, 2023 at 12:06:01PM -0400, Andres Salomon wrote: > Hi Security Team, > > Looking at https://security.debian.org/debian-security/pool/main/c/chromium/ > , I see that chromium-l10n built for bookworm (deb12u1) but not for bullseye > (deb11u1). I'm guessing that the arch:all build was

Bug#1037098: RFS: serious-engine/0~git20230515+dfsg-1 [ITP]

2023-06-04 Thread Sébastien Noel
Package: sponsorship-requests Severity: wishlist Dear mentors, I am looking for a sponsor for my package "serious-engine": * Package name : serious-engine Version : 0~git20230515+dfsg-1 Upstream contact : https://github.com/ptitSeb/Serious-Engine/issues * URL :

Bug#1037086: dropbear-initramfs: /etc/dropbear/initramfs/dropbear_dss_host_key file not generated

2023-06-04 Thread Guilhem Moulin
Control: tag -1 moreinfo unreproducible Hi, On Sun, 04 Jun 2023 at 10:41:56 +0200, Georg Gast wrote: > But dropbear did not start as it was complaining about the missing dss host > key. > […] > If i delete /etc/dropbear/initramfs/dropbear_dss_host_key and generate a new > one > dropbearkeygen -t

Bug#1037087: chromium-l10n: The following packages have unmet dependencies: chromium-l10n : Depends: chromium (< 112.0.5615.138-1~deb11u1.1~) but 114.0.5735.90-2~deb11u1 is to be installed

2023-06-04 Thread Andres Salomon
Hi Security Team, Looking at https://security.debian.org/debian-security/pool/main/c/chromium/ , I see that chromium-l10n built for bookworm (deb12u1) but not for bullseye (deb11u1). I'm guessing that the arch:all build was interrupted or is still in a needs-build state or something, but

Bug#1036268: gnome-shell: Session crashes, thrown out to login screen, after the session has been idle & screen switched off

2023-06-04 Thread Amr Ibrahim
Am Samstag, dem 27.05.2023 um 21:32 +0100 schrieb Simon McVittie: > What is logged in the systemd journal when this crash occurs? Today another crash. Attached is gnome-logs-important.txt > A backtrace from the crash would be very useful information for this or any > other crash. Please see

Bug#1037096: Acknowledgement (firmware-iwlwifi: Intel AC 8265 Wifi card missing with iwlwifi-8265-36.ucode: Failed to start INIT ucode: -110)

2023-06-04 Thread Leon Weber
For others affected, installing firmware-iwlwifi from bullseye is a possible workaround for this issue. This can be achieved e.g. by pinning: Add an entry to /etc/apt/sources.list such as # https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1037096 deb http://deb.debian.org/debian

Bug#1037042: graphicsmagick: GetImageDepth has a thread arena and memory leak

2023-06-04 Thread Bob Friesenhahn
My own testing is under Ubuntu 20.04 using GCC 10. Do you think it might be a problem with another system component, a GCC optimization or this is fixed meanwhile? At least I do wonder why this issue is CPU / machine dependent. As a further data point, I compiled the test program under

Bug#1037097: shotwell: problem with sendto and thunderbird : there is no attachment file since the dropping of nautilus sendto in version 0.3.15 (it works with other mailers)

2023-06-04 Thread Romain Kobylanski
Package: shotwell Version: 0.30.17-1+b1 Severity: normal X-Debbugs-Cc: romain.kobylan...@free.fr Dear Maintainer, *** Reporter, please consider answering these questions, where appropriate *** * What led up to the situation? * What exactly did you do (or not do) that was effective (or

Bug#1037096: firmware-iwlwifi: Intel AC 8265 Wifi card missing with iwlwifi-8265-36.ucode: Failed to start INIT ucode: -110

2023-06-04 Thread Leon Weber
Package: firmware-iwlwifi Version: 20230210-5 Severity: important After an upgrade from bullseye to bookworm today, during which firmware-iwlwifi was upgraded from 20210315-3 to 20230210-5, the wifi interface is missing. I believe this is the same issue that was previously reported as #1001927.

Bug#945269: debian-policy: packages should use tmpfiles.d(5) to create directories below /var

2023-06-04 Thread Simon McVittie
(Newly cc'd elogind maintainers: Please see #945269 for context) On Sun, 04 Jun 2023 at 12:15:41 +0100, Luca Boccassi wrote: > On Sun, 4 Jun 2023 at 12:02, Sean Whitton wrote: > > On Tue 09 May 2023 at 01:44AM +01, Luca Boccassi wrote: > > > For now I've kept only a mention of the

Bug#1037075: diffoscope: Get's killed trying to diff 2 large images (> 5GB)

2023-06-04 Thread Holger Levsen
On Sat, Jun 03, 2023 at 02:08:12PM +0200, Evangelos Ribeiro Tzaras wrote: > [1]21386 killed diffoscope --debug > l5-phosh-{1,2}/mobian-librem5-phosh-20230603.img fwiw, I can reproduce this bug on bullseye and unstable, with and without --no-default-limits. -- cheers, Holger

Bug#1035669: gir1.2-harfbuzz-0.0: Can not recreate GIR information from gir1.2-harfbuzz-0.0.typelib

2023-06-04 Thread James Addison
Package: gir1.2-harfbuzz-0.0 Followup-For: Bug #1035669 X-Debbugs-Cc: abou.almonta...@sfr.fr Control: tags -1 patch Dear Maintainer and Abou, The attached patch allows me to serialize GIR XML from the HarfBuzz-0.0.typelib file contained in the resulting gir1.2-harfbuzz-0.0 package. For more

Bug#1035669: Can not recreate GIR information from gir1.2-harfbuzz-0.0.typelib

2023-06-04 Thread James Addison
Hi Abou, Please find some slightly re-ordered responses below, and with the gtk-gnome list and bug on cc because others are likely to know more than me about this. On Sat, 3 Jun 2023 at 22:40, Abou Al Montacir wrote: ... > However, when starting the conversion, g-ir-generate crashes with an

Bug#1037095: eyed3: --no-prompt is not recognized

2023-06-04 Thread Björn Wiberg
Package: eyed3 Version: 0.8.10-4 Severity: normal Hello, Just a heads-up that the --no-prompt option mentioned in the eyeD3 (1) man page appears not to be supported: bwiberg@glimmer:/tmp/bw$ eyeD3 --no-prompt --preserve-file-times --remove-all-comments --remove-all-images --remove-all-lyrics

Bug#932957: Please migrate Release Notes to reStructuredText

2023-06-04 Thread Holger Wansing
Hi Stuart, Stuart Prescott wrote (Sat, 3 Jun 2023 14:45:46 +1000): > > - The list of archs is hardcoded in the Makefile for now. > > The following might provide you with some useful way of not hard-coding > such information: > > curl -s 'https://api.ftp-master.debian.org/suite/bookworm'

Bug#1037094: gzip: Build for linux should not depend on mingw64

2023-06-04 Thread Henry N.
Package: gzip Version: 1.12-1 Severity: minor Tags: ftbfs Usertags: rebootstrap Dear Maintainer, there exist dependency to mingw-w64 build system, and in label binary-indep is called i686-w64-mingw32-strip. This is not nice for cross building, where not need any w64 binaries, and typically the

Bug#1037093: libarchive: CVE-2023-30571

2023-06-04 Thread Salvatore Bonaccorso
Source: libarchive Version: 3.6.2-1 Severity: important Tags: security upstream Forwarded: https://github.com/libarchive/libarchive/issues/1876 X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerability was published for libarchive. CVE-2023-30571[0]: | Libarchive

Bug#1037091: podman run fails because of missing ~/.config/docker/config.json

2023-06-04 Thread Felix Stupp
For others having the same issue, just creating an empty file with "touch ~/.config/docker/config.json" does fix the issue. Podman does not seem to require any configuration in there (at least in my case). However, as someone might assume that Podman wants any content there, they still might be

Bug#1037092: erofs-utils: CVE-2023-33551 CVE-2023-33552

2023-06-04 Thread Salvatore Bonaccorso
Source: erofs-utils Version: 1.6-1 Severity: important Tags: security upstream X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerabilities were published for erofs-utils. CVE-2023-33551[0]: | Heap Buffer Overflow in the erofsfsck_dirent_iter function in |

Bug#1037042: graphicsmagick: GetImageDepth has a thread arena and memory leak

2023-06-04 Thread Bob Friesenhahn
On Sun, 4 Jun 2023, László Böszörményi wrote: Hi, On Sat, Jun 3, 2023 at 8:30 PM Bob Friesenhahn wrote: I am definitely able to confirm that memory consumption builds due to invoking GetImageDepth() via a POSIX thread. The rate that it builds is image sensitive since some images cause

Bug#1037091: podman run fails because of missing ~/.config/docker/config.json

2023-06-04 Thread Felix Stupp
Package: podman Version: 4.3.1+ds1-8+b1 Severity: important Dear maintainer, the current version of podman does not allow me to run any container due to the following error message: Error: stat /home/$USER/.config/docker/config.json: no such file or directory I can trigger this issue with a

Bug#1037090: imagemagick: CVE-2021-3610

2023-06-04 Thread Salvatore Bonaccorso
Source: imagemagick Version: 8:6.9.11.60+dfsg-1.6 Severity: important Tags: security upstream X-Debbugs-Cc: car...@debian.org, Debian Security Team Control: fixed -1 8:6.9.12.20+dfsg1-1 Hi, The following vulnerability was published for imagemagick. CVE-2021-3610[0]: | A heap-based buffer

Bug#1037089: seatd: improve d/control homepage and add upstream/metadata

2023-06-04 Thread Patrice Duroux
Package: seatd Version: 0.7.0-6 Severity: wishlist Dear Maintainer, Could it be https://sr.ht/~kennylevinsen/seatd/ instead of https://git.sr.ht/~kennylevinsen/seatd ? It would also be more consistent to the greetd and wlsunset packages. See

Bug#1037075: diffoscope: Get's killed trying to diff 2 large images (> 5GB)

2023-06-04 Thread Holger Levsen
hi, thanks Evangelos, for filing this bug and providing the images exposing it to https://fortysixandtwo.eu/upload/mobian-librem5-phosh-20230603-{1,2}.img now. -- cheers, Holger ⢀⣴⠾⠻⢶⣦⠀ ⣾⠁⢠⠒⠀⣿⡁ holger@(debian|reproducible-builds|layer-acht).org ⢿⡄⠘⠷⠚⠋⠀ OpenPGP:

Bug#1035733: debian -policy: packages must not use dpkg-divert to override default systemd configuraton files

2023-06-04 Thread Luca Boccassi
On Sun, 4 Jun 2023 at 12:25, Luca Boccassi wrote: > > On Sun, 4 Jun 2023 at 11:54, Sean Whitton wrote: > > > > Hello Luca, > > > > On Mon 08 May 2023 at 08:07PM +01, Luca Boccassi wrote: > > > > > The specific difference, for which I think an explicit call out is > > > needed, is because these

Bug#1033341: org-mode: CVE-2023-28617

2023-06-04 Thread Salvatore Bonaccorso
Hi David, On Sun, Jun 04, 2023 at 08:34:18AM -0300, David Bremner wrote: > Nicholas D Steeves writes: > > > fixed 1033341 org/mode/9.5.2+dfsh-5 > > fixed 1033341 org-mode/9.6.6+dfsg-1~exp1 > > thanks > > Are you sure about that? It depends on emacs 28.2, which afaik has the > vulnerable

Bug#1037088: libzstd build fails with profile "nodoc"

2023-06-04 Thread Henry N.
Source: libzstd Version: 1.5.4+dfsg2-3 Severity: normal Tags: ftbfs patch Usertags: rebootstrap Dear Maintainer, build from source with profile "nodoc" fails. Follow these steps: # apt source libzstd # apt build-dep libzstd # cd libzstd-1.5.4+dfsg2 # dpkg-buildpackage -B -Pnodoc,nocheck -uc -us

Bug#1035949: mariadb: upgrade issue: mariadb-server-10.5 fails to stop after all other -10.5 packages were removed

2023-06-04 Thread Andreas Beckmann
On 04/06/2023 07.03, Otto Kekäläinen wrote: What do you Andreas suggest we do now? I'd suggest uploading it to experimental immediately (for NEW processing) and filing a pre-approval bug and let the release team decide what to do. This fix will probably be delayed to the first point

Bug#1034387: update youtube-dl control file to reflect transitional package

2023-06-04 Thread Andreas Tille
Control: tags -1 pending Am Sat, Jun 03, 2023 at 12:54:33PM -0400 schrieb Jesse Rhodes: > The debian/control fields for youtube-dl still have a lot of leftover > information from when it was a binary package, which should be cleaned > up to reflect what the package actually does at present.

Bug#1033341: org-mode: CVE-2023-28617

2023-06-04 Thread David Bremner
Nicholas D Steeves writes: > fixed 1033341 org/mode/9.5.2+dfsh-5 > fixed 1033341 org-mode/9.6.6+dfsg-1~exp1 > thanks Are you sure about that? It depends on emacs 28.2, which afaik has the vulnerable org-mode embedded. I guess it's a question of interpretation, but the vulnerability is still

Bug#1037087: chromium-l10n: The following packages have unmet dependencies: chromium-l10n : Depends: chromium (< 112.0.5615.138-1~deb11u1.1~) but 114.0.5735.90-2~deb11u1 is to be installed

2023-06-04 Thread Attila Hammer
Package: chromium-l10n Severity: important Dear Maintainer, *** Reporter, please consider answering these questions, where appropriate *** * What led up to the situation? sudo apt install chromium chromium-l10n command results me following error message: "Reading package lists... Done

Bug#975495: gping

2023-06-04 Thread Tom Forbes
Thank you, there is no rush! Please let me know if there is anything I can do to make this easier on my side. On Sun, 4 Jun 2023, at 10:26 AM, matthias.geiger1...@tutanota.de wrote: > Hi Tom, > > I have prepared the packaging so far. I didn't have time yet to upload it > because I was busy

Bug#1035733: debian -policy: packages must not use dpkg-divert to override default systemd configuraton files

2023-06-04 Thread Luca Boccassi
On Sun, 4 Jun 2023 at 11:54, Sean Whitton wrote: > > Hello Luca, > > On Mon 08 May 2023 at 08:07PM +01, Luca Boccassi wrote: > > > The specific difference, for which I think an explicit call out is > > needed, is because these config files are shipped by some packages but > > are not used _by_

Bug#945269: debian-policy: packages should use tmpfiles.d(5) to create directories below /var

2023-06-04 Thread Luca Boccassi
On Sun, 4 Jun 2023 at 12:02, Sean Whitton wrote: > > Hello, > > On Tue 09 May 2023 at 01:44AM +01, Luca Boccassi wrote: > > > I've done an initial attempt to define the wording, although I'm sure > > it will need quite a few changes. Attached as a patch, and also > > available on Salsa: > > > >

Bug#826425: deborphan: reports package as unused whereas it's used

2023-06-04 Thread Martin-Éric Racine
On Sun, 26 May 2019 13:11:51 + nodiscc wrote: > Confirming this bug on Debian Stretch, deborphan 1.7.28.8-0.3+b1 > > $ deborphan --guess-all |grep cffi > python3-cffi-backend:amd64 > python-cffi-backend:amd64 > > $ aptitude why python3-cffi-backend:amd64 > i python3-cryptography Depends

Bug#945269: debian-policy: packages should use tmpfiles.d(5) to create directories below /var

2023-06-04 Thread Sean Whitton
Hello, On Tue 09 May 2023 at 01:44AM +01, Luca Boccassi wrote: > I've done an initial attempt to define the wording, although I'm sure > it will need quite a few changes. Attached as a patch, and also > available on Salsa: > > https://salsa.debian.org/bluca/policy/-/commits/tmpfiles > > Happy to

Bug#1035733: debian -policy: packages must not use dpkg-divert to override default systemd configuraton files

2023-06-04 Thread Sean Whitton
Hello Luca, On Mon 08 May 2023 at 08:07PM +01, Luca Boccassi wrote: > The specific difference, for which I think an explicit call out is > needed, is because these config files are shipped by some packages but > are not used _by_ them, they are consumed by systemd (or udev, or > kmod, etc).

Bug#1035733: debian -policy: packages must not use dpkg-divert to override default systemd configuraton files

2023-06-04 Thread Sean Whitton
Hello, On Mon 08 May 2023 at 12:52PM -07, Russ Allbery wrote: > Sean Whitton writes: >> On Mon 08 May 2023 at 08:48AM -07, Russ Allbery wrote: > >>> In other words, dpkg-divert is primarily for local administrators, >>> non-Policy-compliant local packages that are doing unusual things, and >>>

Bug#1037042: graphicsmagick: GetImageDepth has a thread arena and memory leak

2023-06-04 Thread GCS
Hi, On Sat, Jun 3, 2023 at 8:30 PM Bob Friesenhahn wrote: > I am definitely able to confirm that memory consumption builds due to > invoking GetImageDepth() via a POSIX thread. The rate that it builds > is image sensitive since some images cause GetImageDepth() to perform > more OpenMP loops.

Bug#955523: polari: Join button is grayed out. No rooms shown.

2023-06-04 Thread cacatoès
Package: polari Version: 43.0-1 Followup-For: Bug #955523 X-Debbugs-Cc: cacat...@tuxfamily.org Dear Maintainers, I'm giving polari a try, so on a fresh install, I was unable to connect to any server. When selecting a server, the rotating wheel icon shows it tries to connect, then in abandons,

Bug#975495: gping

2023-06-04 Thread matthias . geiger1024
Hi Tom, I have prepared the packaging so far. I didn't have time yet to upload it because I was busy with other debian work. I have some time next week so I can update it to the latest version and then upload. regards, --- Matthias Geiger (werdahias) -BEGIN PGP PUBLIC KEY BLOCK-

Bug#1035535: Debian 11 -> 12: manual "apt install" needed to update some packages (vkd3d, appindicator, wx)

2023-06-04 Thread Paul Gevers
reassign Hi, First of all, thanks for reporting issues you experience and sorry it took a while to reply. On 05-05-2023 04:27, kolafl...@kolahilft.de wrote: But "apt dist-upgrade" didn't upgrade some packages. Did you follow the upgrade procedure as outlined in the release notes, or is

Bug#1037036: ITP: autogram -- eIDAS-compliant document signing tool

2023-06-04 Thread Andrej Shadura
Hi, On Fri, 2 Jun 2023, at 20:42, Gioele Barabucci wrote: > On 02/06/23 20:25, Andrej Shadura wrote: >>> This (current?) limitation should be mentioned in the short and long >>> descriptions. >> >> It does in fact work with anything, as long as has a PKCS #11 provider. > The README on GitHub

Bug#1037086: dropbear-initramfs: /etc/dropbear/initramfs/dropbear_dss_host_key file not generated

2023-06-04 Thread Georg Gast
Package: dropbear-initramfs Version: 2022.83-1 Severity: normal Dear Maintainer, *** Reporter, please consider answering these questions, where appropriate *** * What led up to the situation? One of my systems did not start and landed in rescue shell. I wanted to install dropbear-initramfs

Bug#1037085: RFP: strawberry-graphql -- GraphQL library for Python that leverages type annotations

2023-06-04 Thread Carsten Schoenert
Package: wnpp Severity: wishlist * Package name: strawberry-graphql Version : 0.180.5 Upstream Contact: Patrick Arminio * URL : https://github.com/strawberry-graphql/strawberry * License : Expat Programming Lang: Python Description : GraphQL library

Bug#824521: Bug#1034771: generate_firmware_patterns failed: 512 at ./tmp/debian-cd/tools/make_disc_trees.pl line 1257

2023-06-04 Thread Vagrant Cascadian
Control: block 1034771 by 824521 On 2023-04-24, Daniel Leidert wrote: > 2023-04-24 03:07:41 ERROR build/debian-cd: missing metadata file > ./tmp/mirror/dists/bullseye/main/dep11/Components-amd64.yml.gz at > ./tmp/debian-cd/tools/generate_firmware_patterns line 172. > 2023-04-24 03:07:41 ERROR

Bug#1036740: [Pkg-netatalk-devel] Bug#1036740: closed by Markus Koschany (Re: Bug#1036740: Fix for CVE-2022-23123 causes afpd segfault with valid metadata)

2023-06-04 Thread Jonas Smedegaard
Quoting Salvatore Bonaccorso (2023-06-04 07:39:12) > Hi Daniel, > > On Sat, Jun 03, 2023 at 02:56:00PM -0700, Daniel Markstedt wrote: > > > -- Forwarded message -- > > > From: Markus Koschany > > > To: Daniel Markstedt , 1036740-d...@bugs.debian.org > > > Cc:

Bug#1037084: bookworm: When using gdm3 to start non-GNOME wayland sessions, PATH may be set differently

2023-06-04 Thread Jay
Package: release-notes X-Debbugs-Cc: jlsan...@protonmail.com Severity: important Starting non-GNOME wayland sessions through GDM leads to a user's PATH being set to /usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin instead of /usr/local/bin:/usr/bin:/bin:/usr/local/games:/usr/games