Bug#1051466: bookworm-pu: package ovn/23.03.1-1~deb12u1

2023-09-28 Thread Adam D. Barratt
On Tue, 2023-09-19 at 08:59 +0100, Luca Boccassi wrote: > On Tue, 19 Sept 2023 at 08:21, Salvatore Bonaccorso < > car...@debian.org> wrote: [...] > > Two obervations: Can you please close #1043598 in the > > debian/changelog as well as the update addresses CVE-2023-3153. [...] > Changelog mentions

Bug#1052211: bookworm-pu: package electrum/4.3.4+dfsg1-1+deb12u1

2023-09-28 Thread Adam D. Barratt
Control: tags -1 confirmed On Thu, 2023-09-28 at 12:49 -0700, Soren Stoutner wrote: > Are the any changes I should make before I upload a package? More patience. :-p A week is not long to have waited, there's no need to chase. Please go ahead. Regards, Adam

Bug#1053130: bookworm-pu: package glibc/2.36-9+deb12u2

2023-09-28 Thread Adam D. Barratt
Control: tags -1 confirmed On Wed, 2023-09-27 at 23:47 +0200, Aurelien Jarno wrote: > The upstream glibc stable branch got a few fixes since the latest > point > released, including two security fixes. > Please go ahead. Regards, Adam

Bug#1052629: bookworm-pu: package roundcube/1.6.3+dfsg-1~deb12u1

2023-09-28 Thread Adam D. Barratt
On Thu, 2023-09-28 at 20:33 +0200, Guilhem Moulin wrote: > On Thu, 28 Sep 2023 at 18:53:46 +0100, Adam D. Barratt wrote: > > --- a/CHANGELOG.md > > +++ b/CHANGELOG.md > > @@ -1,5 +1,54 @@ > > # Changelog Roundcube Webmail > > > > +## Unreleased > > +

Bug#1052629: bookworm-pu: package roundcube/1.6.3+dfsg-1~deb12u1

2023-09-28 Thread Adam D. Barratt
Control: tags -1 confirmed On Mon, 2023-09-25 at 15:31 +0200, Guilhem Moulin wrote: > On Mon, 25 Sep 2023 at 15:15:57 +0200, Guilhem Moulin wrote: > > [ Other info ] > > > > In addition to the debdiff.gz between 1.6.1+dfsg-1 (bookworm) and > > 1.6.3+dfsg-1~deb12u1, > > I attach a patch-applied

Bug#1053102: bookworm-pu: package curl/7.88.1-10+deb12u3

2023-09-28 Thread Adam D. Barratt
Control: tags -1 confirmed On Wed, 2023-09-27 at 21:24 +0800, Carlos Henrique Lima Melara wrote: > A vulnerability was discovered and reported to Curl upstream [1] with > the following CVE ID: CVE-2023-38039. > > The description of the CVE is: > > > When curl retrieves an HTTP response, it

Bug#1053177: bullseye-pu: package xen/4.14.6-1

2023-09-28 Thread Adam D. Barratt
On Thu, 2023-09-28 at 18:27 +0200, Hans van Kranenburg wrote: > Xen 4.14 support (and security support) has ended upstream. The > upstream > stable branch for version 4.14 is frozen now, and a final maintenance > release version 4.14.6 has been released. We'd like to put this final > update into

Bug#1051910: mirror submission for ossmirror.mycloud.services

2023-09-28 Thread Adam D. Barratt
iscuss/review this? > > Best regards, > > -Original Message- > From: Adam D. Barratt > Date: Tuesday, 26 September 2023 at 1:54 AM > To: OSSMirror@OnboardCloud > Cc: 1051...@bugs.debian.org <1051...@bugs.debian.org> > Subject: Re: Bug#1051

Bug#1052363: bullseye-pu: cups/2.3.3op2-3+deb11u4

2023-09-27 Thread Adam D. Barratt
Control: tags -1 confirmed On Wed, 2023-09-27 at 17:44 +, Thorsten Alteholz wrote: > Control: tags 1052363 - moreinfo > > > On Sat, 23 Sep 2023, Adam D. Barratt wrote: > > The same query as for bookworm applies here - do we expect users to > > kn

Bug#1052361: bookworm-pu: cups/2.4.2-3+deb12u2

2023-09-27 Thread Adam D. Barratt
Control: tags -1 confirmed On Wed, 2023-09-27 at 17:43 +, Thorsten Alteholz wrote: > Control: tags 1052361 - moreinfo > > Hi Adam, > > On Sat, 23 Sep 2023, Adam D. Barratt wrote: > > Hmm. Is there a better way we can point users to the required > > change > &g

Bug#1052710: modsecurity 3.0.9-1+deb12u1 flagged for acceptance

2023-09-27 Thread Adam D Barratt
package release.debian.org tags 1052710 = bookworm pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bookworm. Thanks for your contribution! Upload details == Package: modsecurity Version:

Bug#1053001: openssl 3.0.11-1~deb12u1 flagged for acceptance

2023-09-27 Thread Adam D Barratt
package release.debian.org tags 1053001 = bookworm pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bookworm. Thanks for your contribution! Upload details == Package: openssl Version:

Bug#1052698: flann 1.9.2+dfsg-1+deb12u1 flagged for acceptance

2023-09-27 Thread Adam D Barratt
package release.debian.org tags 1052698 = bookworm pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bookworm. Thanks for your contribution! Upload details == Package: flann Version:

Bug#1052648: unbound 1.17.1-2+deb12u1 flagged for acceptance

2023-09-27 Thread Adam D Barratt
package release.debian.org tags 1052648 = bookworm pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bookworm. Thanks for your contribution! Upload details == Package: unbound Version:

Bug#1052611: roundcube 1.4.14+dfsg.1-1~deb11u1 flagged for acceptance

2023-09-27 Thread Adam D Barratt
package release.debian.org tags 1052611 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: roundcube Version:

Bug#1051384: highway 1.0.3-3+deb12u1 flagged for acceptance

2023-09-27 Thread Adam D Barratt
package release.debian.org tags 1051384 = bookworm pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bookworm. Thanks for your contribution! Upload details == Package: highway Version:

Bug#1006292: bullseye-pu: package plasma-discover/5.20.5-3

2023-09-26 Thread Adam D. Barratt
On Thu, 2023-08-03 at 02:03 +0200, Patrick Franz wrote: > Hi, > > On Tue, 25 Jul 2023 22:31:30 +0100 Jonathan Wiltshire > > wrote: > > Hi, > > > > This request was approved but not uploaded in time for the > > previous > > point release (11.7). Should it be part of 11.8 in a few weeks > >

Bug#1052692: spamprobe 1.4d-16+deb12u1 flagged for acceptance

2023-09-26 Thread Adam D Barratt
package release.debian.org tags 1052692 = bookworm pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bookworm. Thanks for your contribution! Upload details == Package: spamprobe Version:

Bug#1051239: dar 2.7.8-2 flagged for acceptance

2023-09-26 Thread Adam D Barratt
package release.debian.org tags 1051239 = bookworm pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bookworm. Thanks for your contribution! Upload details == Package: dar Version: 2.7.8-2

Bug#1052611: bullseye-pu: package roundcube/1.4.14+dfsg.1-1~deb11u1

2023-09-26 Thread Adam D. Barratt
Control: tags -1 confirmed On Mon, 2023-09-25 at 12:11 +0200, Guilhem Moulin wrote: > roundcube 1.4.13+dfsg.1-1~deb11u1 is vulnerable to CVE-2023-43770: > cross-site scripting (XSS) vulnerability in handling of linkrefs in > plain text messages. > Please go ahead. Regards, Adam

Bug#1052698: bookworm-pu: package flann/1.9.2+dfsg-1

2023-09-26 Thread Adam D. Barratt
Control: tags -1 confirmed On Tue, 2023-09-26 at 12:24 +0200, Jochen Sprickerhof wrote: > The flann.pc pkg-config contains a stray semicolon in Libs. > > [ Impact ] > It is hard to use on the command line, as reported in #1052649. > Please go ahead. Regards, Adam

Bug#1052710: bookworm-pu: package modsecurity/3.0.9-1+deb12u1

2023-09-26 Thread Adam D. Barratt
Control: tags -1 confirmed On Tue, 2023-09-26 at 12:33 +0200, Alberto Gonzalez Iniesta wrote: > Fix for CVE-2023-38285, not DSA for it. > > > [ Impact ] > Possible DoS. > Please go ahead. Regards, Adam

Bug#1052648: bookworm-pu: package unbound/1.17.1-2+deb12u1

2023-09-26 Thread Adam D. Barratt
Control: tags -1 confirmed On Mon, 2023-09-25 at 19:02 +0300, Michael Tokarev wrote: > There's a mode of operation of the server (which is becoming > more common with time) which makes it to loop endlessly and > to become useless, and to flood system log. This happens with > libssl3 (which we

Bug#1052577: mate-notification-daemon 1.26.0-1+deb12u1 flagged for acceptance

2023-09-25 Thread Adam D Barratt
package release.debian.org tags 1052577 = bookworm pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bookworm. Thanks for your contribution! Upload details == Package: mate-notification-daemon

Bug#1052564: libmatemixer 1.26.0-2+deb12u1 flagged for acceptance

2023-09-25 Thread Adam D Barratt
package release.debian.org tags 1052564 = bookworm pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bookworm. Thanks for your contribution! Upload details == Package: libmatemixer Version:

Bug#1052218: monitoring-plugins 2.3.3-5+deb12u1 flagged for acceptance

2023-09-25 Thread Adam D Barratt
package release.debian.org tags 1052218 = bookworm pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bookworm. Thanks for your contribution! Upload details == Package: monitoring-plugins Version:

Bug#1049955: qemu 7.2+dfsg-7+deb12u2 flagged for acceptance

2023-09-25 Thread Adam D Barratt
package release.debian.org tags 1049955 = bookworm pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bookworm. Thanks for your contribution! Upload details == Package: qemu Version:

Bug#1042058: pandoc 2.17.1.1-2~deb12u1 flagged for acceptance

2023-09-25 Thread Adam D Barratt
package release.debian.org tags 1042058 = bookworm pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bookworm. Thanks for your contribution! Upload details == Package: pandoc Version:

Bug#1052455: freetype 2.12.1+dfsg-5+deb12u1 flagged for acceptance

2023-09-25 Thread Adam D Barratt
package release.debian.org tags 1052455 = bookworm pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bookworm. Thanks for your contribution! Upload details == Package: freetype Version:

Bug#1052420: flameshot 0.9.0+ds1-2+deb11u2 flagged for acceptance

2023-09-25 Thread Adam D Barratt
package release.debian.org tags 1052420 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: flameshot Version:

Bug#1052420: flameshot 0.9.0+ds1-2+deb11u1 flagged for acceptance

2023-09-25 Thread Adam D Barratt
package release.debian.org tags 1052420 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: flameshot Version:

Bug#1052288: qemu 5.2+dfsg-11+deb11u3 flagged for acceptance

2023-09-25 Thread Adam D Barratt
package release.debian.org tags 1052288 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: qemu Version:

Bug#1050537: batik 1.16+dfsg-1+deb12u1 flagged for acceptance

2023-09-25 Thread Adam D Barratt
package release.debian.org tags 1050537 = bookworm pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bookworm. Thanks for your contribution! Upload details == Package: batik Version:

Bug#1052222: python2.7 2.7.18-8+deb11u1 flagged for acceptance

2023-09-25 Thread Adam D Barratt
package release.debian.org tags 105 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: python2.7 Version:

Bug#1051902: dpkg 1.20.13 flagged for acceptance

2023-09-25 Thread Adam D Barratt
package release.debian.org tags 1051902 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: dpkg Version: 1.20.13

Bug#1050538: batik 1.12-4+deb11u2 flagged for acceptance

2023-09-25 Thread Adam D Barratt
package release.debian.org tags 1050538 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: batik Version:

Bug#1050121: cryptmount 5.3.3-1+deb11u1 flagged for acceptance

2023-09-25 Thread Adam D Barratt
package release.debian.org tags 1050121 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: cryptmount Version:

Bug#1051910: mirror submission for ossmirror.mycloud.services

2023-09-25 Thread Adam D. Barratt
irror/list-full#SG > > > May I enquire do you know roughly how long does it take for the > mirror to be listed? > > Best regards, > > -Original Message- > From: OSSMirror@OnboardCloud > Date: Sunday, 24 September 2023 at 3:31 AM > To: Adam D. Barratt >

Bug#1049974: Bug#1052543: plasma-workspace 5.27.5-2+deb12u1 flagged for acceptance

2023-09-24 Thread Adam D. Barratt
package release.debian.org tags 1049974 = bookworm pending thanks Re-sending to the right bug... On Sun, 2023-09-24 at 19:38 +, Adam D Barratt wrote: > package release.debian.org > tags 1052543 = bookworm pending > thanks > > Hi, > > The upload referenced by thi

Bug#1052552: libapache-mod-jk 1.2.48-1+deb11u1 flagged for acceptance

2023-09-24 Thread Adam D Barratt
package release.debian.org tags 1052552 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: libapache-mod-jk Version:

Bug#1052150: openssh 8.4p1-5+deb11u2 flagged for acceptance

2023-09-24 Thread Adam D Barratt
package release.debian.org tags 1052150 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: openssh Version:

Bug#1050332: inetutils 2.0-1+deb11u2 flagged for acceptance

2023-09-24 Thread Adam D Barratt
package release.debian.org tags 1050332 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: inetutils Version:

Bug#1042057: pandoc 2.9.2.1-1+deb11u1 flagged for acceptance

2023-09-24 Thread Adam D Barratt
package release.debian.org tags 1042057 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: pandoc Version:

Bug#1052543: plasma-workspace 5.27.5-2+deb12u1 flagged for acceptance

2023-09-24 Thread Adam D Barratt
package release.debian.org tags 1052543 = bookworm pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bookworm. Thanks for your contribution! Upload details == Package: plasma-workspace Version:

Bug#1052543: plasma-framework 5.103.0-1+deb12u1 flagged for acceptance

2023-09-24 Thread Adam D Barratt
package release.debian.org tags 1052543 = bookworm pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bookworm. Thanks for your contribution! Upload details == Package: plasma-framework Version:

Bug#1052149: openssh 9.2p1-2+deb12u1 flagged for acceptance

2023-09-24 Thread Adam D Barratt
package release.debian.org tags 1052149 = bookworm pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bookworm. Thanks for your contribution! Upload details == Package: openssh Version:

Bug#1051594: samba 4.17.11+dfsg-0+deb12u1 flagged for acceptance

2023-09-24 Thread Adam D Barratt
package release.debian.org tags 1051594 = bookworm pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bookworm. Thanks for your contribution! Upload details == Package: samba Version:

Bug#1051171: qtlocation-opensource-src 5.15.8+dfsg-3+deb12u1 flagged for acceptance

2023-09-24 Thread Adam D Barratt
package release.debian.org tags 1051171 = bookworm pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bookworm. Thanks for your contribution! Upload details == Package: qtlocation-opensource-src

Bug#1052479: lxc 5.0.2-1+deb12u1 flagged for acceptance

2023-09-24 Thread Adam D Barratt
package release.debian.org tags 1052479 = bookworm pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bookworm. Thanks for your contribution! Upload details == Package: lxc Version:

Bug#1052070: mutt 2.2.12-0.1~deb12u1 flagged for acceptance

2023-09-24 Thread Adam D Barratt
package release.debian.org tags 1052070 = bookworm pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bookworm. Thanks for your contribution! Upload details == Package: mutt Version:

Bug#1052553: libapache-mod-jk 1.2.48-2+deb12u1 flagged for acceptance

2023-09-24 Thread Adam D Barratt
package release.debian.org tags 1052553 = bookworm pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bookworm. Thanks for your contribution! Upload details == Package: libapache-mod-jk Version:

Bug#1052007: lxcfs 5.0.3-1+deb12u1 flagged for acceptance

2023-09-24 Thread Adam D Barratt
package release.debian.org tags 1052007 = bookworm pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bookworm. Thanks for your contribution! Upload details == Package: lxcfs Version:

Bug#1051302: jekyll 4.3.1+dfsg-3+deb12u1 flagged for acceptance

2023-09-24 Thread Adam D Barratt
package release.debian.org tags 1051302 = bookworm pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bookworm. Thanks for your contribution! Upload details == Package: jekyll Version:

Bug#1050997: lemonldap-ng 2.16.1+ds-deb12u1 flagged for acceptance

2023-09-24 Thread Adam D Barratt
package release.debian.org tags 1050997 = bookworm pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bookworm. Thanks for your contribution! Upload details == Package: lemonldap-ng Version:

Bug#1042903: firewalld 1.3.3-1~deb12u1 flagged for acceptance

2023-09-24 Thread Adam D Barratt
package release.debian.org tags 1042903 = bookworm pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bookworm. Thanks for your contribution! Upload details == Package: firewalld Version:

Bug#1051902: bullseye-pu: package dpkg/1.20.13

2023-09-24 Thread Adam D. Barratt
Control: tags -1 confirmed On Thu, 2023-09-14 at 00:28 +0200, Guillem Jover wrote: > This update backports the loong64 arch support as requested in > #1051763 because some of the Debian infra is still using bullseye. > There's also a fix for a segfault on virtual field formatting which > is

Bug#1042058: bookworm-pu: package pandoc/2.17.1.1-2~deb12u1

2023-09-24 Thread Adam D. Barratt
Control: tags -1 confirmed On Tue, 2023-07-25 at 23:40 +0200, Guilhem Moulin wrote: > pandoc 2.17.1.1-1.1 is vulnerable to CVE-2023-35936: Arbitrary file > write vulnerability via specially crafted image element in the input > when generating files using the `--extract-media` option or >

Bug#1052420: bullseye-pu: package flameshot/0.9.0+ds1-2+deb11u1

2023-09-24 Thread Adam D. Barratt
On Sat, 2023-09-23 at 22:10 +0100, Adam D. Barratt wrote: > Control: tags -1 confirmed > > On Thu, 2023-09-21 at 13:37 -0400, Boyuan Yang wrote: > > As reported in https://bugs.debian.org/1051408 , current flameshot > > in Debian 11 (Bullseye) will silently upload

Bug#1049955: bookworm-pu: package qemu/1:7.2+dfsg-7+deb12u2

2023-09-24 Thread Adam D. Barratt
On Sun, 2023-09-24 at 06:52 +0300, Michael Tokarev wrote: > 23.09.2023 23:45, Adam D. Barratt wrote: > > Control: tags -1 confirmed > > > > On Thu, 2023-08-17 at 12:54 +0300, Michael Tokarev wrote: > > > There's a next upstream qemu stable/bugfix release, fixing

Bug#1052227: bookworm-pu (pre-approval): mutter/43.8-0+deb12u1

2023-09-24 Thread Adam D. Barratt
On Sun, 2023-09-24 at 11:31 +0100, Simon McVittie wrote: > On Sat, 23 Sep 2023 at 20:44:14 +0100, Adam D. Barratt wrote: > > On Tue, 2023-09-19 at 11:26 +0100, Simon McVittie wrote: > > > Several new upstream bugfix releases. I've been trying to get > > > these > &

Bug#1052543: bookworm-pu: package plasma-framework/5.103.0-1+deb12u1

2023-09-24 Thread Adam D. Barratt
Control: tags -1 confirmed On Sun, 2023-09-24 at 13:26 +0200, Patrick Franz wrote: > Upstream KDE has received a number of bug reports about plasmashell > crashing when closing windows. This patch backports the fix to > avoid these crashes back into bookworm. > Please go ahead. Regards, Adam

Bug#1052455: bookworm-pu: package freetype/2.12.1+dfsg-5+deb12u1

2023-09-24 Thread Adam D. Barratt
Control: tags -1 confirmed On Sun, 2023-09-24 at 22:27 +1000, Hugh McMaster wrote: > Control: tags -1 -moreinfo > > Hi Adam, > > On Sun, 24 Sept 2023 at 05:53, Adam D. Barratt wrote: > > Control: tags -1 moreinfo > > > > On Fri, 2023-09-22 at 22:16 +1000, Hu

Bug#1052420: bullseye-pu: package flameshot/0.9.0+ds1-2+deb11u1

2023-09-23 Thread Adam D. Barratt
Control: tags -1 confirmed On Thu, 2023-09-21 at 13:37 -0400, Boyuan Yang wrote: > As reported in https://bugs.debian.org/1051408 , current flameshot > in Debian 11 (Bullseye) will silently upload the current captured > screenshot to imgur without confirmation whenever the corresponding > hotkey

Bug#1052363: bullseye-pu: cups/2.3.3op2-3+deb11u4

2023-09-23 Thread Adam D. Barratt
Control: tags -1 moreinfo On Wed, 2023-09-20 at 21:40 +, Thorsten Alteholz wrote: > The attached debdiff for cups fixes CVE-2023-4504 and CVE-2023-32360 > in > Bullseye. These CVEs have been marked as no-dsa by the security team, > but > at least CVE-2023-32360 got anRC bug (#1051953). >

Bug#1052288: bullseye-pu: package qemu/1:5.2+dfsg-11+deb11u3

2023-09-23 Thread Adam D. Barratt
Control: tags -1 confirmed On Tue, 2023-09-19 at 23:11 +0200, Moritz Muehlenhoff wrote: > Various low severity security issues in qemu, debdiff below. > I've tested this on a Bullseye ganeti cluster using the > updated qemu. > Please go ahead. Regards, Adam

Bug#1052222: bullseye-pu: package python2.7/2.7.18-8+deb11u1

2023-09-23 Thread Adam D. Barratt
Control: tags -1 confirmed On Tue, 2023-09-19 at 10:36 +0200, Helmut Grohne wrote: > I know that officially, we do not consider Python 2.7 covered by > security support. In bullseye, it has merely been kept to support a > small minority of applications that would otherwise have been > removed. >

Bug#1052150: bullseye-pu: package openssh/1:8.4p1-5+deb11u2

2023-09-23 Thread Adam D. Barratt
Control: tags -1 confirmed On Mon, 2023-09-18 at 09:03 +0100, Colin Watson wrote: > https://bugs.debian.org/1042460 is a security issue affecting > bullseye. > The security team doesn't think it warrants a DSA, but thinks it's > worth > fixing in a point release. I agree. > > [ Impact ] >

Bug#1050538: bullseye-pu: package batik/1.12-4+deb11u2

2023-09-23 Thread Adam D. Barratt
Control: tags -1 confirmed On Fri, 2023-08-25 at 22:27 +0200, Pierre Gruet wrote: > I would like to propose an upload of batik in the next point release. > > [ Reason ] > CVE-2022-44729 and CVE-2022-44730 have been filed against batik. They > are fixed > in sid (and soon trixie). I discussed

Bug#1050332: bullseye-pu: package inetutils/2:2.0-1+deb11u2

2023-09-23 Thread Adam D. Barratt
Control: tags -1 confirmed On Wed, 2023-08-23 at 12:44 +0200, Guillem Jover wrote: > This update fixes a minor security issue, that the security team did > not feel worth a DSA. It is now fixed already in unstable and > testing. > Please go ahead. Regards, Adam

Bug#1049982: bullseye-pu: package riemann-c-client/1.10.4-2+b2

2023-09-23 Thread Adam D. Barratt
Control: tags -1 confirmed On Sat, 2023-08-19 at 10:41 -1000, Romain Tartière wrote: > On Thu, Aug 17, 2023 at 10:52:17PM +0100, Adam D. Barratt wrote: > > Please supply an appropriate debdiff. > > Sorry for the confusion, here is an updated debdiff. Thank you! Please go ahead. Regards, Adam

Bug#1050121: bullseye-pu: package cryptmount/5.3.3-1+deb11u1

2023-09-23 Thread Adam D. Barratt
Control: tags -1 confirmed On Sun, 2023-08-20 at 11:11 +0100, RW Penney wrote: > When cryptmount is passed invalid command-line arguments, it is > likely > to crash with a SEGV error due to inappropriately zeroed memory > passed > to getopt_long(). > Please go ahead. Regards, Adam

Bug#1035464: bullseye-pu: package lttng-modules/2.12.5-1+deb11u1

2023-09-23 Thread Adam D. Barratt
Control: tags -1 confirmed On Wed, 2023-05-03 at 11:34 -0400, Michael Jeanson wrote: > Fix the dkms build of lttng-modules against the current bullseye > kernel 5.10.0-22. > Please go ahead; sorry for the delay. Regards, Adam

Bug#1042057: bullseye-pu: package pandoc/2.9.2.1-1+deb11u1

2023-09-23 Thread Adam D. Barratt
Control: tags -1 confirmed On Tue, 2023-07-25 at 23:39 +0200, Guilhem Moulin wrote: > pandoc 2.9.2.1-1 is vulnerable to CVE-2023-35936: Arbitrary file > write > vulnerability via specially crafted image element in the input when > generating > files using the `--extract-media` option or

Bug#1036083: bullseye-pu: package galera-4 26.4.14-0+deb11u1

2023-09-23 Thread Adam D. Barratt
Control: tags -1 confirmed On Tue, 2023-07-25 at 14:52 -0700, Otto Kekäläinen wrote: > Sorry - attached now. Please go ahead; sorry for the delay. Regards, Adam

Bug#1035466: bullseye-pu: package postfix/3.5.18-0+deb11u1

2023-09-23 Thread Adam D. Barratt
Control: tags -1 confirmed On Sun, 2023-06-25 at 14:06 -0400, Scott Kitterman wrote: > While this has been pending, another postfix maintenance update has > been > released for 3.5. Postfix 3.5.20 provides the relevant fixes already > provided > to Bookworm via the 3.7.6 update. Debdiff

Bug#1042903: bookworm-pu: package firewalld/1.3.3-1~deb12u1

2023-09-23 Thread Adam D. Barratt
Control: tags -1 confirmed On Wed, 2023-08-02 at 16:47 +0200, Michael Biebl wrote: > Sorry, forgot the attach the actual files. Please go ahead; sorry for the delay. Regards, Adam

Bug#1049955: bookworm-pu: package qemu/1:7.2+dfsg-7+deb12u2

2023-09-23 Thread Adam D. Barratt
Control: tags -1 confirmed On Thu, 2023-08-17 at 12:54 +0300, Michael Tokarev wrote: > There's a next upstream qemu stable/bugfix release, fixing a > big number of various issues, including 3 (minor) security > issues too. The full list is in the changelog below and > in the upstream git

Bug#1049988: bookworm-pu: package riemann-c-client/1.10.4-2

2023-09-23 Thread Adam D. Barratt
Control: tags -1 confirmed On Sat, 2023-08-19 at 10:42 -1000, Romain Tartière wrote: > On Sat, Aug 19, 2023 at 04:58:51PM +0100, Jonathan Wiltshire wrote: > > This seems to be a copy of the most recent upload to unstable; > > please > > consult the developers' reference and prepare an appropriate

Bug#1049974: bookworm-pu: package plasma-workspace/5.27.5-2+deb12u1

2023-09-23 Thread Adam D. Barratt
Control: tags -1 confirmed On Thu, 2023-08-17 at 20:01 +0200, Patrick Franz wrote: > krunner (a launcher built into KDE Plasma capable of doing all > sorts of things) crashes when characters or numbers are typed > in a rapid fashion. > The bug was sadly introduced in Plasma 5.27.5, but

Bug#1051024: bookworm-pu: package igtf-policy-bundle/1.22-1~deb12u1

2023-09-23 Thread Adam D. Barratt
Control: tags -1 moreinfo On Fri, 2023-09-01 at 13:30 +0200, Dennis van Dok wrote: > The IGTF bundle provides important trust anchors for the Research and > Education communities. Both for reliance on the identity of servers > for compute and storage services, as well as user identification >

Bug#1050997: bookworm-pu: package lemonldap-ng/2.16.1+ds-deb12u1

2023-09-23 Thread Adam D. Barratt
Control: tags -1 confirmed On Fri, 2023-09-01 at 12:34 +0400, Yadd wrote: > Version 2.17.0 of lemonldap-ng fixes two low-level security issues: > * the "login" security regex wasn't applied when using AuthSlave > * lemonldap-ng portal can be used as open-redirection due to > incorrect >

Bug#1050537: bookworm-pu: package batik/1.16+dfsg-1+deb12u1

2023-09-23 Thread Adam D. Barratt
Control: tags -1 confirmed On Fri, 2023-08-25 at 22:26 +0200, Pierre Gruet wrote: > CVE-2022-44729 and CVE-2022-44730 have been filed against batik. They > are fixed > in sid (and soon trixie). I discussed with Security team, they said a > DSA is > not needed but suggested to fix the CVE in

Bug#1052479: bookworm-pu: package lxc/1:5.0.2-1+deb12u1

2023-09-23 Thread Adam D. Barratt
Control: tags -1 confirmed On Fri, 2023-09-22 at 16:59 +, Mathias Gibbens wrote: > lxc 1:5.0.2-1 contains a typo in its IPv6 NAT rules, as reported in > #1049976. This prevents the lxc-net service from starting if > LXC_IPV6_NAT is set to true. > Please go ahead. Regards, Adam

Bug#1052425: dpdk 22.11.3-1~deb12u1 flagged for acceptance

2023-09-23 Thread Adam D Barratt
package release.debian.org tags 1052425 = bookworm pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bookworm. Thanks for your contribution! Upload details == Package: dpdk Version:

Bug#1052402: dpdk 20.11.9-1~deb11u1 flagged for acceptance

2023-09-23 Thread Adam D Barratt
package release.debian.org tags 1052402 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: dpdk Version:

Bug#1052068: dbus 1.14.10-1~deb12u1 flagged for acceptance

2023-09-23 Thread Adam D Barratt
package release.debian.org tags 1052068 = bookworm pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bookworm. Thanks for your contribution! Upload details == Package: dbus Version:

Bug#1052455: bookworm-pu: package freetype/2.12.1+dfsg-5+deb12u1

2023-09-23 Thread Adam D. Barratt
Control: tags -1 moreinfo On Fri, 2023-09-22 at 22:16 +1000, Hugh McMaster wrote: > FreeType 2.12.1 shipped with experimental COLRv1 support enabled. > This was > unintentional, as the implementation shipped in this release was > incomplete and > incompatible with the final COLRv1 API. > >

Bug#1052361: bookworm-pu: cups/2.4.2-3+deb12u2

2023-09-23 Thread Adam D. Barratt
Control: tags -1 moreinfo On Wed, 2023-09-20 at 21:05 +, Thorsten Alteholz wrote: > The attached debdiff for cups fixes CVE-2023-4504 and CVE-2023-32360 > in > Bookworm. These CVEs have been marked as no-dsa by the security > team, > but at least CVE-2023-32360 got an RC bug (#1051953). >

Bug#1052229: bookworm-pu (pre-approval): gnome-shell/43.9-0+deb12u1

2023-09-23 Thread Adam D. Barratt
Control: tags -1 confirmed On Tue, 2023-09-19 at 11:40 +0100, Simon McVittie wrote: > Several new upstream bugfix releases. I've been trying to get these > into > a suitable state for a stable update since 12.1, but every time I've > been testing one long enough to think about asking for upload >

Bug#1052227: bookworm-pu (pre-approval): mutter/43.8-0+deb12u1

2023-09-23 Thread Adam D. Barratt
Control: tags -1 confirmed On Tue, 2023-09-19 at 11:26 +0100, Simon McVittie wrote: > Several new upstream bugfix releases. I've been trying to get these > into > a suitable state for a stable update since 12.1, but every time I've > been testing one long enough to think about asking for upload >

Bug#1052218: bookworm-pu: package monitoring-plugins/2.3.3-5+deb12u1

2023-09-23 Thread Adam D. Barratt
Control: tags -1 confirmed On Tue, 2023-09-19 at 08:35 +0200, Jan Wagner wrote: > As reported in #1051768, check_disk has gotten very slow on a > machine > with a huge number of mount points (in excess of 16000). > > [ Impact ] > check_disk used to take around 10 seconds on bullseye in this >

Bug#1052149: bookworm-pu: package openssh/1:9.2p1-2+deb12u1

2023-09-23 Thread Adam D. Barratt
Control: tags -1 confirmed On Mon, 2023-09-18 at 08:59 +0100, Colin Watson wrote: > https://bugs.debian.org/1042460 is a security issue affecting > bookworm. > The security team doesn't think it warrants a DSA, but thinks it's > worth > fixing in a point release. I agree. > > [ Impact ] >

Bug#1052070: bookworm-pu: package mutt/2.2.12-0.1~deb12u1

2023-09-23 Thread Adam D. Barratt
Control: tags -1 confirmed On Sat, 2023-09-16 at 23:34 +0200, Sebastian Andrzej Siewior wrote: > On 2023-09-16 23:30:44 [+0200], To sub...@bugs.debian.org wrote: > > forgot to attach the debdiff. Here it comes… > Please go ahead. Regards, Adam

Bug#1052007: bookworm-pu: package lxcfs/5.0.3-1+deb12u1

2023-09-23 Thread Adam D. Barratt
Control: tags -1 confirmed On Fri, 2023-09-15 at 22:03 +, Mathias Gibbens wrote: > lxcfs 5.0.3-1 has a bug where /proc/cpuinfo is not properly reported > within a 32bit arm container when the 64bit host has more than ~13 > CPUs. This was initially reported in #1036818 and impacts some >

Bug#1051594: bookworm-pu: package samba/2:4.17.11+dfsg-0+deb12u1

2023-09-23 Thread Adam D. Barratt
Control: tags -1 confirmed On Sun, 2023-09-10 at 13:11 +0300, Michael Tokarev wrote: > There's a next upstream stable/bugfix release of samba series 4.17, > with a next share of bugfixes. This is the last regular stable > release, 4.17 switched to security-only bugfix mode once 4.19 is > out.

Bug#1051302: bookworm-pu: package jekyll/4.3.1+dfsg-3+deb12u1

2023-09-23 Thread Adam D. Barratt
Control: tags -1 confirmed This update fixes processing user configuration that used YAML > aliases. > > [ Impact ] > User configuration with YAML aliases will cause jekyll to crash while > parsing it, and therefore jekyll will not work at all. > Please go ahead. Regards, Adam

Bug#1051239: bookworm-pu: package dar/2.7.8-2

2023-09-23 Thread Adam D. Barratt
Control: tags -1 confirmed On Mon, 2023-09-04 at 15:57 -0500, John Goerzen wrote: > A bug was recently reported to Debian as #1050663, and subsequently > to upstream. > This bug causes dar to create isolated catalog files that cannot be > read by a > future dar invocation. The catalog files are

Bug#1051171: bookworm-pu: package qtlocation-opensource-src/5.15.8+dfsg-3+deb12u1

2023-09-23 Thread Adam D. Barratt
Control: tags -1 + confirmed On Sun, 2023-09-03 at 22:29 +0300, Dmitry Shachnev wrote: > This fixes bug which made applications using Qt Location freeze when > trying to > load the map tiles. > Please go ahead. Regards, Adam

Bug#1052480: libpam-mklocaluser 0.18+deb12u1 flagged for acceptance

2023-09-23 Thread Adam D Barratt
package release.debian.org tags 1052480 = bookworm pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bookworm. Thanks for your contribution! Upload details == Package: libpam-mklocaluser Version:

Bug#1052463: debian-edu-doc 2.12.18~deb12u1 flagged for acceptance

2023-09-23 Thread Adam D Barratt
package release.debian.org tags 1052463 = bookworm pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bookworm. Thanks for your contribution! Upload details == Package: debian-edu-doc Version:

<    1   2   3   4   5   6   7   8   9   10   >