Bug#543097: marked as done (dolfin: FTBFS: Please install SWIG version 1.3.36 or recompile UFC with present SWIG.)

2009-12-08 Thread Debian Bug Tracking System
Your message dated Tue, 8 Dec 2009 08:55:57 +0100
with message-id 69e9f5e30912072355u3eedd3efn64856e8ed880d...@mail.gmail.com
and subject line Re: [Pkg-scicomp-devel] Bug#543097: Bug#543097: Bug#543097: 
dolfin:  FTBFS: Please install SWIG version 1.3.36 or recompile UFC with 
present SWIG.
has caused the Debian Bug report #543097,
regarding dolfin: FTBFS: Please install SWIG version 1.3.36 or recompile UFC 
with present SWIG.
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
543097: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=543097
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
---BeginMessage---
Package: dolfin
Version: 0.9.2-1
Severity: serious
User: debian...@lists.debian.org
Usertags: qa-ftbfs-20090822 qa-ftbfs
Justification: FTBFS on amd64

Hi,

During a rebuild of all packages in sid, your package failed to build on
amd64.

Relevant part:
 make[1]: Entering directory 
 `/build/user-dolfin_0.9.2-1-amd64-q0hiv1/dolfin-0.9.2'
 make[1]: Nothing to be done for `update-config'.
 make[1]: Leaving directory 
 `/build/user-dolfin_0.9.2-1-amd64-q0hiv1/dolfin-0.9.2'
 scons --directory=. CC=cc CFLAGS=-g -O2 -g -Wall -O2 CXX=g++ 
 CXXFLAGS=-g -O2 -g -Wall -O2  prefix=/usr -j10 enableMpi=1 enableUmfpack=1 
 enableGts=1 enablePetsc=1 withPetscDir=/usr/lib/petsc enableTrilinos=0 
 enableSlepc=1 withSlepcDir=/usr/lib/slepc enableScotch=1 enableDocs=0 
 enableDemos=0 enableTests=0 enablePydolfin=1
 scons: Reading SConscript files ...
 
 scons: warning: The BoolOption() function is deprecated; use the 
 BoolVariable() function instead.
 File /build/user-dolfin_0.9.2-1-amd64-q0hiv1/dolfin-0.9.2/SConstruct, line 
 65, in module
 
 scons: warning: The PathOption() function is deprecated; use the 
 PathVariable() function instead.
 File /build/user-dolfin_0.9.2-1-amd64-q0hiv1/dolfin-0.9.2/SConstruct, line 
 97, in module
 SCons.Script:133: DeprecationWarning: Option 'enablePydolfin' is deprecated 
 and will be removed in the future. Please use the option 'enablePython' 
 instead to enable/disable compiling of Python wrappers.
 
 scons: warning: The Options class is deprecated; use the Variables class 
 instead.
 File 
 /build/user-dolfin_0.9.2-1-amd64-q0hiv1/dolfin-0.9.2/scons/simula-scons/simula_scons/__init__.py,
  line 252, in __init__
 Using options from 
 /build/user-dolfin_0.9.2-1-amd64-q0hiv1/dolfin-0.9.2/scons/options.cache
 Checking for pkg-config... yes
 Checking for numpy-1... no (pkg-config file not found)
  Trying to generate pkg-config file for numpy-1... done
  Found NumPy and generated pkg-config file in 
  '/build/user-dolfin_0.9.2-1-amd64-q0hiv1/dolfin-0.9.2/scons/pkgconfig'
 Checking for scotch... no (pkg-config file not found)
  Trying to generate pkg-config file for scotch... done
  Found SCOTCH and generated pkg-config file in
  '/build/user-dolfin_0.9.2-1-amd64-q0hiv1/dolfin-0.9.2/scons/pkgconfig'
 Checking for parmetis... no (pkg-config file not found)
  Trying to generate pkg-config file for parmetis... failed
 Checking for ufc-1... yes
 Checking for umfpack... no (pkg-config file not found)
  Trying to generate pkg-config file for umfpack... done
  Found UMFPACK and generated pkg-config file in
  '/build/user-dolfin_0.9.2-1-amd64-q0hiv1/dolfin-0.9.2/scons/pkgconfig'
 Checking for mtl4... no (pkg-config file not found)
  Trying to generate pkg-config file for mtl4... failed
 Checking for petsc... no (pkg-config file not found)
  Trying to generate pkg-config file for petsc... done
  Found PETSc and generated pkg-config file in
  '/build/user-dolfin_0.9.2-1-amd64-q0hiv1/dolfin-0.9.2/scons/pkgconfig'
 Checking for gts... yes
 Checking for boost... no (pkg-config file not found)
  Trying to generate pkg-config file for boost... failed
 Checking for cholmod... no (pkg-config file not found)
  Trying to generate pkg-config file for cholmod... done
  Found CHOLMOD and generated pkg-config file in
  '/build/user-dolfin_0.9.2-1-amd64-q0hiv1/dolfin-0.9.2/scons/pkgconfig'
 Checking for python-2... no (pkg-config file not found)
  Trying to generate pkg-config file for python-2... done
  Found 'Python' and generated pkg-config file in 
  /build/user-dolfin_0.9.2-1-amd64-q0hiv1/dolfin-0.9.2/scons/pkgconfig
 Checking for slepc... no (pkg-config file not found)
  Trying to generate pkg-config file for slepc... done
  Found SLEPc and generated pkg-config file in 
  '/build/user-dolfin_0.9.2-1-amd64-q0hiv1/dolfin-0.9.2/scons/pkgconfig'
 Checking for libxml-2.0... yes
 Resolving compiler... done
 Warning: Unknown dependency package: boost
 *** UFC compiled with different version of SWIG.
 Please install SWIG 

Bug#560001: llvm-snapshot should stay in unstable

2009-12-08 Thread Arthur Loiret
Package: llvm-snapshot
Severity: serious


llvm-snapshot is not intended to be ever released with a stable Debian
release. This bug is intended to serve as a marker bug to make sure
llvm-snapshot won't enter resting.



-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#540118: marked as done (dolfin: FTBFS: No targets specified and no Default() targets found.)

2009-12-08 Thread Debian Bug Tracking System
Your message dated Tue, 8 Dec 2009 09:04:16 +0100
with message-id 69e9f5e30912080004n1350a6c7s858d6d1fa071b...@mail.gmail.com
and subject line Re: [Pkg-scicomp-devel] Bug#540118: dolfin: FTBFS: No targets  
specified and no Default() targets found.
has caused the Debian Bug report #540118,
regarding dolfin: FTBFS: No targets specified and no Default() targets found.
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
540118: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=540118
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
---BeginMessage---
Source: dolfin
Version: 0.9.2-1
Severity: serious

Hi,

There was an error while trying to autobuild your package:

 Start Time: 20090805-1956

[...]

 Build-Depends: cdbs (= 0.4.49), debhelper (= 5), python-all-dev, 
 python-central (= 0.5.6), scons, swig (= 1.3.35), python-numpy, libgts-dev, 
 libxml2-dev, libboost-dev, libsuitesparse-dev, python-ufc (= 1.1.1), 
 libscotch-dev, libpetsc3.0.0-dev, libslepc3.0.0-dev

[...]

 Toolchain package versions: libc6-dev_2.9-23 linux-libc-dev_2.6.30-4 
 g++-4.3_4.3.4-1 gcc-4.3_4.3.4-1 binutils_2.19.51.20090723-1 
 libstdc++6_4.4.1-1 libstdc++6-4.3-dev_4.3.4-1
 

[...]

 Checking for pkg-config... yes
 Checking for numpy-1... no (pkg-config file not found)
  Trying to generate pkg-config file for numpy-1... done
  Found NumPy and generated pkg-config file in 
  '/build/buildd-dolfin_0.9.2-1-i386-FalENm/dolfin-0.9.2/scons/pkgconfig'
 Checking for scotch... no (pkg-config file not found)
  Trying to generate pkg-config file for scotch... done
  Found SCOTCH and generated pkg-config file in
  '/build/buildd-dolfin_0.9.2-1-i386-FalENm/dolfin-0.9.2/scons/pkgconfig'
 Checking for parmetis... no (pkg-config file not found)
  Trying to generate pkg-config file for parmetis... failed
 Checking for ufc-1... yes
 Checking for umfpack... no (pkg-config file not found)
  Trying to generate pkg-config file for umfpack... done
  Found UMFPACK and generated pkg-config file in
  '/build/buildd-dolfin_0.9.2-1-i386-FalENm/dolfin-0.9.2/scons/pkgconfig'
 Checking for mtl4... no (pkg-config file not found)
  Trying to generate pkg-config file for mtl4... failed
 Checking for petsc... no (pkg-config file not found)
  Trying to generate pkg-config file for petsc... done
  Found PETSc and generated pkg-config file in
  '/build/buildd-dolfin_0.9.2-1-i386-FalENm/dolfin-0.9.2/scons/pkgconfig'
 Checking for gts... yes
 Checking for boost... no (pkg-config file not found)
  Trying to generate pkg-config file for boost... failed
 Checking for cholmod... no (pkg-config file not found)
  Trying to generate pkg-config file for cholmod... done
  Found CHOLMOD and generated pkg-config file in
  '/build/buildd-dolfin_0.9.2-1-i386-FalENm/dolfin-0.9.2/scons/pkgconfig'
 Checking for python-2... no (pkg-config file not found)
  Trying to generate pkg-config file for python-2... done
  Found 'Python' and generated pkg-config file in 
  /build/buildd-dolfin_0.9.2-1-i386-FalENm/dolfin-0.9.2/scons/pkgconfig
 Checking for slepc... no (pkg-config file not found)
  Trying to generate pkg-config file for slepc... done
  Found SLEPc and generated pkg-config file in 
  '/build/buildd-dolfin_0.9.2-1-i386-FalENm/dolfin-0.9.2/scons/pkgconfig'
 Checking for libxml-2.0... yes
 Resolving compiler... done
 Warning: Unknown dependency package: boost
 Enabling compilation of Python wrappers
 scons: done reading SConscript files.
 scons: *** No targets specified and no Default() targets found.  Stop.
 -
 If there were no errors, run
 
 scons install
 
 to install DOLFIN on your system. Note that you may need
 to be root in order to install. To specify an alternative
 installation directory, run
 
 scons install prefix=path
 
 You may also run ./scons.local for a local installation
 in the DOLFIN source tree.
 
 You can compile all the demo programs in the subdirectory
 demo by running
 
scons enableDemos=yes
 
 -
 make: *** [debian/stamp-scons-build] Error 2
 dpkg-buildpackage: error: debian/rules build gave error exit status 2

A full build log can be found at:
http://buildd.debian.org/build.php?arch=i386pkg=dolfinver=0.9.2-1


Kurt



---End Message---
---BeginMessage---
Package: dolfin
Version: 0.9.2-2

Hi,

I'm closing this bug for the reasons explained here:

http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=540118#16

Johannes

---End Message---


Bug#559765: jetty: CVE-2007-6672 info disclosure

2009-12-08 Thread Torsten Werner

Michael Gilbert schrieb:

it is much more straightforward to simply check that the
existing fix is applied. since you should have a relationship with
upstream, it should be relatively straightforward to get a response
from them.


Upstream states that the package is fixed in version 6.1.7 at 
http://jira.codehaus.org/browse/JETTY-386#action_117699 and this page 
is linked from 
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6672. The 
oldest version from the jetty6 code base we ever had in Debian is 6.1.18.



also, this package is your responsibility, so you can't
expect others to do your job for you.


You have reported a bug that is more than 2.5 years old. How much 
history should the maintainer check in your opinion before he ever 
uploads to Debian? 2 years, 5 years, 10 years, 20 years...?



if you think this request is overburdensome/unjustified, you can send an
email to secur...@debian.org.  be aware that they expect this level of
thoroughness at a minimum.


I do accept bug reports with false positives from the security team when 
time constraints do not allow proper checking because getting the 
information fast is more important in such cases than verifying the 
information. But that is a different story. You are reporting a bug that 
has been fixed some years ago and you could have verified it yourself.


Torsten



--
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#559798: CVE-2009-3736 local privilege escalation

2009-12-08 Thread Sune Vuorela
On Tuesday 08 December 2009 00:06:05 Moritz Muehlenhoff wrote:
 On Sun, Dec 06, 2009 at 11:50:06PM -0500, Michael Gilbert wrote:
  Package: arts
  Severity: grave
  Tags: security
 
 Is arts still needed since KDE 4 uses Phonon or should we remove it
 for Squeeze?

I have been looking for volunteers who wants to remove arts. We can remove it, 
but it changes the abi of the kdelibs4c2a package, so this needs to be renamed 
(and all rdeps rebuilt)

/Sune
-- 
How can I get access over the folder of the virus over a 9-inch BIOS bus from 
Office?

From the panel menu within Netscape you must turn off a tool for logging from 
a line.



--
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#559980: aptitude: Totally broken on GNU/kFreeBSD

2009-12-08 Thread Petr Salinger

| +sigprocmask(SIG_SETMASK, mask, NULL);



(I'm Cc-ing debian-bsd@, in case somebody has an idea about what's going
on exactly.)


It might be due to The use of the sigprocmask() function is unspecified 
in a multi-threaded process.

http://www.opengroup.org/onlinepubs/9699919799/functions/pthread_sigmask.html

I do not have kfreebsd box handy now.
Kibi, please, does it work with pthread_sigmask() instead of sigprocmask() ?

Petr



--
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#559970: marked as done (zfs-fuse 0.6.0~beta+433snapshot-3 should depend upon libfuse2 (= 1.8))

2009-12-08 Thread Debian Bug Tracking System
Your message dated Tue, 08 Dec 2009 09:50:01 +
with message-id e1nhwhl-00061u...@ries.debian.org
and subject line Bug#559970: fixed in zfs-fuse 0.6.0~beta+433snapshot-4
has caused the Debian Bug report #559970,
regarding zfs-fuse 0.6.0~beta+433snapshot-3 should depend upon libfuse2 (= 1.8)
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
559970: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=559970
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
---BeginMessage---
Package: zfs-fuse
Version: 0.6.0~beta+433snapshot-3
Severity: grave
Justification: renders package unusable

This latest version of zfs-fuse incorrectly specifies a dependency upon
libfuse2 (= 2.6). When attempting to run zfs-fuse with libfuse2 2.7.4-2,
zfs-fuse exits with an error, noting that it requires FUSE API 26, which
is only satisfied by libfuse2 (= 2.8). zfs-fuse runs fine after upgrading
to libfuse2 2.8.1-1 from unstable.

-- System Information:
Debian Release: squeeze/sid
  APT prefers testing
  APT policy: (990, 'testing'), (500, 'unstable'), (500, 'stable')
Architecture: i386 (i686)

Kernel: Linux 2.6.30-2-686 (SMP w/2 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/bash

Versions of packages zfs-fuse depends on:
ii  fuse-utils 2.8.1-1   Filesystem in USErspace (utilities
ii  libaio10.3.107-7 Linux kernel AIO access library - 
ii  libc6  2.10.2-2  GNU C Library: Shared libraries
ii  libfuse2   2.8.1-1   Filesystem in USErspace library
ii  lsb-base   3.2-23Linux Standard Base 3.2 init scrip
ii  zlib1g 1:1.2.3.3.dfsg-15 compression library - runtime

zfs-fuse recommends no packages.

zfs-fuse suggests no packages.

-- no debconf information


---End Message---
---BeginMessage---
Source: zfs-fuse
Source-Version: 0.6.0~beta+433snapshot-4

We believe that the bug you reported is fixed in the latest version of
zfs-fuse, which is due to be installed in the Debian FTP archive:

zfs-fuse_0.6.0~beta+433snapshot-4.diff.gz
  to main/z/zfs-fuse/zfs-fuse_0.6.0~beta+433snapshot-4.diff.gz
zfs-fuse_0.6.0~beta+433snapshot-4.dsc
  to main/z/zfs-fuse/zfs-fuse_0.6.0~beta+433snapshot-4.dsc
zfs-fuse_0.6.0~beta+433snapshot-4_i386.deb
  to main/z/zfs-fuse/zfs-fuse_0.6.0~beta+433snapshot-4_i386.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 559...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Sebastien Delafond s...@debian.org (supplier of updated zfs-fuse package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@debian.org)


-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

Format: 1.8
Date: Tue, 08 Dec 2009 09:07:45 +0100
Source: zfs-fuse
Binary: zfs-fuse
Architecture: source i386
Version: 0.6.0~beta+433snapshot-4
Distribution: unstable
Urgency: low
Maintainer: Sebastien Delafond s...@debian.org
Changed-By: Sebastien Delafond s...@debian.org
Description: 
 zfs-fuse   - ZFS on FUSE
Closes: 559970
Changes: 
 zfs-fuse (0.6.0~beta+433snapshot-4) unstable; urgency=low
 .
   * Versioned build-dep on libfuse-dev = 2.8.1, since before that libfuse
 didn't set shlibs correctly, per #557143 (Closes: #559970).
Checksums-Sha1: 
 e1bd3f2cc9d5e4981f7258405b6a46daff373b5a 1288 
zfs-fuse_0.6.0~beta+433snapshot-4.dsc
 f3e6842f7c09dc2e7184da1a03ef6e8c51b9045a 36775 
zfs-fuse_0.6.0~beta+433snapshot-4.diff.gz
 229117276616c31c11470be50b22e1e77ab5e2ff 1518668 
zfs-fuse_0.6.0~beta+433snapshot-4_i386.deb
Checksums-Sha256: 
 3b8992200e8b3a4a0117ed4075f8e93067c67c18223eb6d68a6c2dc37366cc1d 1288 
zfs-fuse_0.6.0~beta+433snapshot-4.dsc
 1d99f9a8522cea75116dedbff787abb3c1cb8aab99d5cb7f9b334f9c711b73a1 36775 
zfs-fuse_0.6.0~beta+433snapshot-4.diff.gz
 0c7d838cf09f82b3cbd48aa812e56706896d1b02756d178fc2782aa6d9ef8cdc 1518668 
zfs-fuse_0.6.0~beta+433snapshot-4_i386.deb
Files: 
 b281ca24e2a0652415fa974318874315 1288 otherosfs optional 
zfs-fuse_0.6.0~beta+433snapshot-4.dsc
 ef715e72c343eaaf7cd4ac60f12702bc 36775 otherosfs optional 
zfs-fuse_0.6.0~beta+433snapshot-4.diff.gz
 52dec032745f0d5d29c04d9b3f0421f0 1518668 otherosfs optional 
zfs-fuse_0.6.0~beta+433snapshot-4_i386.deb

-BEGIN PGP SIGNATURE-
Version: GnuPG v1.4.10 (GNU/Linux)


Bug#560013: nvidia-glx-legacy-96xx: conflicts with xserver

2009-12-08 Thread A Mennucc
Package: nvidia-glx-legacy-96xx
Version: 96.43.13+1-1
Severity: grave
Justification: renders package unusable

hi,

this package provides xserver-xorg-video-2
but xserver-xorg-core conflicts with xserver-xorg-video-2

the net result is as follows:

v
# apt-get install nvidia-glx-legacy-96xx
Reading package lists... Done
Building dependency tree   
Reading state information... Done
The following packages will be REMOVED:
  xserver-xorg xserver-xorg-core xserver-xorg-input-all
  xserver-xorg-input-evdev xserver-xorg-input-kbd xserver-xorg-input-mouse
  xserver-xorg-input-synaptics xserver-xorg-input-wacom xserver-xorg-video-nv
The following NEW packages will be installed:
  nvidia-glx-legacy-96xx
^^

I tried to force install, just to see if it may work nonetheless,
but it does not : 
when loading the 'nvidia kernel module' the kernel log reports
v
[55703.629627] Xorg:15448 conflicting memory types e800-e888 
uncached-minus-write-combining
[55703.629639] reserve_memtype failed 0xe800-0xe888, track 
uncached-minus, req write-combining
[55703.630180] Xorg:15448 conflicting memory types e800-e888 
uncached-minus-write-combining
[55703.630186] reserve_memtype failed 0xe800-0xe888, track 
uncached-minus, req write-combining
^^^

When starting X, it crashes saying

Backtrace:
0: X(xorg_backtrace+0x3b) [0x81314cb]
1: X(xf86SigHandler+0x51) [0x80c1df1]
2: [0xb7fdc400]


So this package is unusable in sid/squeeze

a.


-- System Information:
Debian Release: squeeze/sid
  APT prefers unstable
  APT policy: (500, 'unstable')
Architecture: i386 (x86_64)

Kernel: Linux 2.6.31-1-amd64 (SMP w/2 CPU cores)
Locale: LANG=it_IT.UTF-8, LC_CTYPE=it_IT.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/bash

-- 
Andrea Mennucc
 E' un mondo difficile. Che vita intensa! (Tonino Carotone)



-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Processed: retitle 559970 to zfs-fuse should depend on libfuse2 (= 2.8)

2009-12-08 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org:

 retitle 559970 zfs-fuse should depend on libfuse2 (= 2.8)
Bug #559970 {Done: Sebastien Delafond s...@debian.org} [zfs-fuse] zfs-fuse 
0.6.0~beta+433snapshot-3 should depend upon libfuse2 (= 1.8)
Changed Bug title to 'zfs-fuse should depend on libfuse2 (= 2.8)' from 
'zfs-fuse 0.6.0~beta+433snapshot-3 should depend upon libfuse2 (= 1.8)'

End of message, stopping processing here.

Please contact me if you need assistance.

Debian bug tracking system administrator
(administrator, Debian Bugs database)


-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#559502: marked as done (postinst scripts query for -source instead of -dkms)

2009-12-08 Thread Debian Bug Tracking System
Your message dated Tue, 08 Dec 2009 10:06:08 +
with message-id e1nhwxm-0008u4...@ries.debian.org
and subject line Bug#559502: fixed in virtualbox-ose 3.1.0-dfsg-2
has caused the Debian Bug report #559502,
regarding postinst scripts query for -source instead of -dkms
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
559502: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=559502
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
---BeginMessage---
Package: virtualbox-ose
Version: 3.1.0-dfsg-1
Severity: grave
Tags: patch

Hello,

with your new virtualbox-ose-dkms package you are querying the modul version
in your postinst like following:
 dpkg-query -W -f='${Version}' virtualbox-ose-source | awk -F - '{print $1}' 
| cut -d\: -f2

This is the wrong package. It has to look like this:
 dpkg-query -W -f='${Version}' virtualbox-ose-dkms | awk -F - '{print $1}' | 
cut -d\: -f2

Your postinst fails if -source isn't installed (which isn't needed).

So this line just has to be changed.


-- System Information:
Debian Release: squeeze/sid
  APT prefers unstable
  APT policy: (500, 'unstable'), (200, 'experimental')
Architecture: amd64 (x86_64)

Kernel: Linux 2.6.31-1-amd64 (SMP w/2 CPU cores)
Locale: LANG=de_DE.UTF-8, LC_CTYPE=de_DE.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/bash

Versions of packages virtualbox-ose depends on:
ii  adduser3.111 add and remove users and groups
ii  libc6  2.10.2-2  GNU C Library: Shared libraries
ii  libcurl3   7.19.7-1  Multi-protocol file transfer libra
ii  libgcc11:4.4.2-3 GCC support library
ii  libgl1-mesa-glx [libgl 7.6-1 A free implementation of the OpenG
ii  libpng12-0 1.2.41-1  PNG library - runtime
ii  libqt4-opengl  4:4.5.3-4 Qt 4 OpenGL module
ii  libqtcore4 4:4.5.3-4 Qt 4 core module
ii  libqtgui4  4:4.5.3-4 Qt 4 GUI module
ii  libsdl1.2debian1.2.13-5  Simple DirectMedia Layer
ii  libssl0.9.80.9.8k-7  SSL shared libraries
ii  libstdc++6 4.4.2-3   The GNU Standard C++ Library v3
ii  libx11-6   2:1.3.2-1 X11 client-side library
ii  libxcursor11:1.1.10-1X cursor management library
ii  libxext6   2:1.0.4-1 X11 miscellaneous extension librar
ii  libxml22.7.6.dfsg-1  GNOME XML library
ii  libxmu62:1.0.5-1 X11 miscellaneous utility library
ii  libxt6 1:1.0.7-1 X11 toolkit intrinsics library
ii  python 2.5.4-2   An interactive high-level object-o
ii  python-central 0.6.14+nmu2   register and build utility for Pyt
ii  python2.5  2.5.4-3   An interactive high-level object-o
ii  zlib1g 1:1.2.3.3.dfsg-15 compression library - runtime

Versions of packages virtualbox-ose recommends:
ii  libgl1-mesa-glx [libgl1]7.6-1A free implementation of the OpenG
ii  virtualbox-ose-dkms 3.1.0-dfsg-1 x86 virtualization solution - kern
ii  virtualbox-ose-qt   3.1.0-dfsg-1 x86 virtualization solution - Qt b
ii  virtualbox-ose-source   3.1.0-dfsg-1 x86 virtualization solution - kern

Versions of packages virtualbox-ose suggests:
ii  libasound21.0.21a-1  shared library for ALSA applicatio
ii  libpulse0 0.9.21-1   PulseAudio client libraries
pn  virtualbox-guest-additionsnone (no description available)

-- no debconf information


---End Message---
---BeginMessage---
Source: virtualbox-ose
Source-Version: 3.1.0-dfsg-2

We believe that the bug you reported is fixed in the latest version of
virtualbox-ose, which is due to be installed in the Debian FTP archive:

virtualbox-ose-dbg_3.1.0-dfsg-2_amd64.deb
  to main/v/virtualbox-ose/virtualbox-ose-dbg_3.1.0-dfsg-2_amd64.deb
virtualbox-ose-dkms_3.1.0-dfsg-2_all.deb
  to main/v/virtualbox-ose/virtualbox-ose-dkms_3.1.0-dfsg-2_all.deb
virtualbox-ose-guest-dkms_3.1.0-dfsg-2_all.deb
  to main/v/virtualbox-ose/virtualbox-ose-guest-dkms_3.1.0-dfsg-2_all.deb
virtualbox-ose-guest-source_3.1.0-dfsg-2_all.deb
  to main/v/virtualbox-ose/virtualbox-ose-guest-source_3.1.0-dfsg-2_all.deb
virtualbox-ose-guest-utils_3.1.0-dfsg-2_amd64.deb
  to main/v/virtualbox-ose/virtualbox-ose-guest-utils_3.1.0-dfsg-2_amd64.deb
virtualbox-ose-guest-x11_3.1.0-dfsg-2_amd64.deb
  to main/v/virtualbox-ose/virtualbox-ose-guest-x11_3.1.0-dfsg-2_amd64.deb

Bug#559758: marked as done (postinst scripts query for -source instead of -dkms)

2009-12-08 Thread Debian Bug Tracking System
Your message dated Tue, 08 Dec 2009 10:06:08 +
with message-id e1nhwxm-0008u4...@ries.debian.org
and subject line Bug#559502: fixed in virtualbox-ose 3.1.0-dfsg-2
has caused the Debian Bug report #559502,
regarding postinst scripts query for -source instead of -dkms
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
559502: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=559502
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
---BeginMessage---
Package: virtualbox-ose-dkms
Version: 3.1.0-dfsg-1
Severity: normal

Error! Invalid number of arguments passed.
Usage: add -m module -v module-version
dpkg: error processing virtualbox-ose-dkms (--configure):
 subprocess installed post-installation script returned error exit status 1
Errors were encountered while processing:
 virtualbox-ose-dkms
E: Sub-process /usr/bin/dpkg returned an error code (1)
A package failed to install.  Trying to recover:
Setting up virtualbox-ose-dkms (3.1.0-dfsg-1) ...
Adding modules to DKMS build system

Error! Invalid number of arguments passed.
Usage: add -m module -v module-version
dpkg: error processing virtualbox-ose-dkms (--configure):
 subprocess installed post-installation script returned error exit status 1
Errors were encountered while processing:
 virtualbox-ose-dkms


--- System information. ---
Architecture: amd64
Kernel:   Linux 2.6.31-1-amd64

Debian Release: squeeze/sid
  500 unstableftp.debian.org 
  500 unstabledebian.netcologne.de 
  500 testing ftp.debian.org 
  500 stable  ftp.debian.org 
1 experimentalftp.debian.org 

--- Package information. ---
Depends  (Version) | Installed
==-+-===
make   | 3.81-7
 OR build-essential| 11.4
 OR dpkg-dev   | 1.15.5.3


Recommends  (Version) | Installed
=-+-===
dkms  | 2.1.0.1-2


Package's Suggests field is empty.





---End Message---
---BeginMessage---
Source: virtualbox-ose
Source-Version: 3.1.0-dfsg-2

We believe that the bug you reported is fixed in the latest version of
virtualbox-ose, which is due to be installed in the Debian FTP archive:

virtualbox-ose-dbg_3.1.0-dfsg-2_amd64.deb
  to main/v/virtualbox-ose/virtualbox-ose-dbg_3.1.0-dfsg-2_amd64.deb
virtualbox-ose-dkms_3.1.0-dfsg-2_all.deb
  to main/v/virtualbox-ose/virtualbox-ose-dkms_3.1.0-dfsg-2_all.deb
virtualbox-ose-guest-dkms_3.1.0-dfsg-2_all.deb
  to main/v/virtualbox-ose/virtualbox-ose-guest-dkms_3.1.0-dfsg-2_all.deb
virtualbox-ose-guest-source_3.1.0-dfsg-2_all.deb
  to main/v/virtualbox-ose/virtualbox-ose-guest-source_3.1.0-dfsg-2_all.deb
virtualbox-ose-guest-utils_3.1.0-dfsg-2_amd64.deb
  to main/v/virtualbox-ose/virtualbox-ose-guest-utils_3.1.0-dfsg-2_amd64.deb
virtualbox-ose-guest-x11_3.1.0-dfsg-2_amd64.deb
  to main/v/virtualbox-ose/virtualbox-ose-guest-x11_3.1.0-dfsg-2_amd64.deb
virtualbox-ose-qt_3.1.0-dfsg-2_amd64.deb
  to main/v/virtualbox-ose/virtualbox-ose-qt_3.1.0-dfsg-2_amd64.deb
virtualbox-ose-source_3.1.0-dfsg-2_all.deb
  to main/v/virtualbox-ose/virtualbox-ose-source_3.1.0-dfsg-2_all.deb
virtualbox-ose_3.1.0-dfsg-2.diff.gz
  to main/v/virtualbox-ose/virtualbox-ose_3.1.0-dfsg-2.diff.gz
virtualbox-ose_3.1.0-dfsg-2.dsc
  to main/v/virtualbox-ose/virtualbox-ose_3.1.0-dfsg-2.dsc
virtualbox-ose_3.1.0-dfsg-2_amd64.deb
  to main/v/virtualbox-ose/virtualbox-ose_3.1.0-dfsg-2_amd64.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 559...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Michael Meskes mes...@debian.org (supplier of updated virtualbox-ose package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@debian.org)


-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

Format: 1.8
Date: Tue, 08 Dec 2009 08:11:09 +0100
Source: virtualbox-ose
Binary: virtualbox-ose-qt virtualbox-ose virtualbox-ose-dbg virtualbox-ose-dkms 
virtualbox-ose-source virtualbox-ose-guest-dkms virtualbox-ose-guest-source 
virtualbox-ose-guest-x11 virtualbox-ose-guest-utils
Architecture: source amd64 all
Version: 3.1.0-dfsg-2
Distribution: unstable
Urgency: low
Maintainer: Debian Virtualbox Team 
pkg-virtualbox-de...@lists.alioth.debian.org
Changed-By: Michael Meskes mes...@debian.org
Description: 

Bug#559876: marked as done (postinst scripts query for -source instead of -dkms)

2009-12-08 Thread Debian Bug Tracking System
Your message dated Tue, 08 Dec 2009 10:06:08 +
with message-id e1nhwxm-0008u4...@ries.debian.org
and subject line Bug#559502: fixed in virtualbox-ose 3.1.0-dfsg-2
has caused the Debian Bug report #559502,
regarding postinst scripts query for -source instead of -dkms
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
559502: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=559502
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
---BeginMessage---
Package: virtualbox-ose-guest-dkms
Version: 3.1.0-dfsg-1
Severity: grave
Justification: renders package unusable

During install one gets the following error:
Setting up virtualbox-ose-guest-dkms (3.1.0-dfsg-1) ...
Adding Module to DKMS build system 

Error! Invalid number of arguments passed.
Usage: add -m module -v module-version


This is due to a reference in the postinst and prerm scripts.
both still refer to the virtualbox-ose-guest-source package name

-- System Information:
Debian Release: squeeze/sid
  APT prefers unstable 
  APT policy: (500, 'unstable'), (500, 'testing'), (500, 'stable'), (1, 
'experimental')
Architecture: amd64 (x86_64)
   

Kernel: Linux 2.6.31-1-amd64 (SMP w/1 CPU core)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash

Versions of packages virtualbox-ose-guest-dkms depends on:
ii  build-essential   11.4   Informational list of build-essent
ii  dpkg-dev  1.15.5.3   Debian package development tools  
ii  make  3.81-7 An utility for Directing compilati

Versions of packages virtualbox-ose-guest-dkms recommends:
ii  dkms  2.1.0.1-3  Dynamic Kernel Module Support Fram

virtualbox-ose-guest-dkms suggests no packages.

-- no debconf information


---End Message---
---BeginMessage---
Source: virtualbox-ose
Source-Version: 3.1.0-dfsg-2

We believe that the bug you reported is fixed in the latest version of
virtualbox-ose, which is due to be installed in the Debian FTP archive:

virtualbox-ose-dbg_3.1.0-dfsg-2_amd64.deb
  to main/v/virtualbox-ose/virtualbox-ose-dbg_3.1.0-dfsg-2_amd64.deb
virtualbox-ose-dkms_3.1.0-dfsg-2_all.deb
  to main/v/virtualbox-ose/virtualbox-ose-dkms_3.1.0-dfsg-2_all.deb
virtualbox-ose-guest-dkms_3.1.0-dfsg-2_all.deb
  to main/v/virtualbox-ose/virtualbox-ose-guest-dkms_3.1.0-dfsg-2_all.deb
virtualbox-ose-guest-source_3.1.0-dfsg-2_all.deb
  to main/v/virtualbox-ose/virtualbox-ose-guest-source_3.1.0-dfsg-2_all.deb
virtualbox-ose-guest-utils_3.1.0-dfsg-2_amd64.deb
  to main/v/virtualbox-ose/virtualbox-ose-guest-utils_3.1.0-dfsg-2_amd64.deb
virtualbox-ose-guest-x11_3.1.0-dfsg-2_amd64.deb
  to main/v/virtualbox-ose/virtualbox-ose-guest-x11_3.1.0-dfsg-2_amd64.deb
virtualbox-ose-qt_3.1.0-dfsg-2_amd64.deb
  to main/v/virtualbox-ose/virtualbox-ose-qt_3.1.0-dfsg-2_amd64.deb
virtualbox-ose-source_3.1.0-dfsg-2_all.deb
  to main/v/virtualbox-ose/virtualbox-ose-source_3.1.0-dfsg-2_all.deb
virtualbox-ose_3.1.0-dfsg-2.diff.gz
  to main/v/virtualbox-ose/virtualbox-ose_3.1.0-dfsg-2.diff.gz
virtualbox-ose_3.1.0-dfsg-2.dsc
  to main/v/virtualbox-ose/virtualbox-ose_3.1.0-dfsg-2.dsc
virtualbox-ose_3.1.0-dfsg-2_amd64.deb
  to main/v/virtualbox-ose/virtualbox-ose_3.1.0-dfsg-2_amd64.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 559...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Michael Meskes mes...@debian.org (supplier of updated virtualbox-ose package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@debian.org)


-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

Format: 1.8
Date: Tue, 08 Dec 2009 08:11:09 +0100
Source: virtualbox-ose
Binary: virtualbox-ose-qt virtualbox-ose virtualbox-ose-dbg virtualbox-ose-dkms 
virtualbox-ose-source virtualbox-ose-guest-dkms virtualbox-ose-guest-source 
virtualbox-ose-guest-x11 virtualbox-ose-guest-utils
Architecture: source amd64 all
Version: 3.1.0-dfsg-2
Distribution: unstable
Urgency: low
Maintainer: Debian Virtualbox Team 
pkg-virtualbox-de...@lists.alioth.debian.org
Changed-By: Michael Meskes mes...@debian.org
Description: 
 virtualbox-ose - x86 virtualization solution - base binaries
 virtualbox-ose-dbg - x86 

Bug#559837: Bug#559824: CVE-2009-3736 local privilege escalation

2009-12-08 Thread Sergey B Kirpichev
severity 559824 minor
severity 559837 minor
tags 559824 + fixed pending
tags 559837 + fixed pending
thanks

It's very unlikely to exploit either parser3 or it's mysql-extension
this way.  If you have
write access to the parser3 working directory - just edit auto.p
(@conf method) to include
additional SQL-extensions to be dlopen'ed ($SQL table):
http://www.parser.ru/en/docs/lang/?parserconfmethod.htm

Anyway, this minor fix is already in git repo.

On Mon, Dec 7, 2009 at 8:02 AM, Michael Gilbert
michael.s.gilb...@gmail.com wrote:
 The following CVE (Common Vulnerabilities  Exposures) id was
 published for libtool.  I have determined that this package embeds a
 vulnerable copy of the libtool source code.  However, since this is a
 mass bug filing (due to so many packages embedding libtool), I have not
 had time to determine whether the vulnerable code is actually present
 in any of the binary packages. Please determine whether this is the
 case. If the binary packages are not affected, please feel free to close
 the bug with a message containing the details of what you did to check.

 CVE-2009-3736[0]:
 | ltdl.c in libltdl in GNU Libtool 1.5.x, and 2.2.6 before 2.2.6b,
 | attempts to open a .la file in the current working directory, which
 | allows local users to gain privileges via a Trojan horse file.

 Note that this problem also affects etch and lenny, so if your package
 is affected, please coordinate with the security team to release the
 DSA for the affected packages.

 If you fix the vulnerability please also make sure to include the
 CVE id in your changelog entry.

 For further information see:

 [0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3736
    http://security-tracker.debian.org/tracker/CVE-2009-3736






--
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Processed: Re: Bug#559824: CVE-2009-3736 local privilege escalation

2009-12-08 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org:

 severity 559824 minor
Bug #559824 [parser-mysql] CVE-2009-3736 local privilege escalation
Severity set to 'minor' from 'grave'

 severity 559837 minor
Bug #559837 [parser] CVE-2009-3736 local privilege escalation
Severity set to 'minor' from 'grave'

 tags 559824 + fixed pending
Bug #559824 [parser-mysql] CVE-2009-3736 local privilege escalation
Added tag(s) fixed and pending.
 tags 559837 + fixed pending
Bug #559837 [parser] CVE-2009-3736 local privilege escalation
Added tag(s) fixed and pending.
 thanks
Stopping processing here.

Please contact me if you need assistance.

Debian bug tracking system administrator
(administrator, Debian Bugs database)


-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#537226: marked as done (Please don't migrate to testing)

2009-12-08 Thread Debian Bug Tracking System
Your message dated Tue, 08 Dec 2009 12:02:10 +
with message-id e1nhyle-0002h4...@ries.debian.org
and subject line Bug#537226: fixed in webkitkde 0.4svn1059630-1
has caused the Debian Bug report #537226,
regarding Please don't migrate to testing
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
537226: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=537226
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
---BeginMessage---
Package: kpart-webkit
Severity: serious

don-migrate-to-testing pro forma bug.

KDE webkit kpart is part of KDE playground and not good enough for release.  
But people will still want to play around with it, so it's still packaged.

Once it migrates from playground to regular KDE, it'll probably be released 
as part of kdelibs or some other kde package, so the separate source package 
will go away.

cheers
-- vbi

-- 
And those meanies used what we said to you and they misconstrued it to
mean what we said, and that's so unfair.
-- SCO lawyers about IBM (paraphrased - groklaw)



signature.asc
Description: This is a digitally signed message part.
---End Message---
---BeginMessage---
Source: webkitkde
Source-Version: 0.4svn1059630-1

We believe that the bug you reported is fixed in the latest version of
webkitkde, which is due to be installed in the Debian FTP archive:

kpart-webkit_0.4svn1059630-1_i386.deb
  to main/w/webkitkde/kpart-webkit_0.4svn1059630-1_i386.deb
libkwebkit-dbg_0.4svn1059630-1_i386.deb
  to main/w/webkitkde/libkwebkit-dbg_0.4svn1059630-1_i386.deb
libkwebkit-dev_0.4svn1059630-1_i386.deb
  to main/w/webkitkde/libkwebkit-dev_0.4svn1059630-1_i386.deb
libkwebkit1_0.4svn1059630-1_i386.deb
  to main/w/webkitkde/libkwebkit1_0.4svn1059630-1_i386.deb
webkitkde_0.4svn1059630-1.diff.gz
  to main/w/webkitkde/webkitkde_0.4svn1059630-1.diff.gz
webkitkde_0.4svn1059630-1.dsc
  to main/w/webkitkde/webkitkde_0.4svn1059630-1.dsc
webkitkde_0.4svn1059630.orig.tar.gz
  to main/w/webkitkde/webkitkde_0.4svn1059630.orig.tar.gz



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 537...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Adrian von Bidder c...@debian.org (supplier of updated webkitkde package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@debian.org)


-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

Format: 1.8
Date: Tue, 08 Dec 2009 12:39:06 +0100
Source: webkitkde
Binary: kpart-webkit libkwebkit1 libkwebkit-dev libkwebkit-dbg
Architecture: source i386
Version: 0.4svn1059630-1
Distribution: unstable
Urgency: low
Maintainer: Adrian von Bidder c...@debian.org
Changed-By: Adrian von Bidder c...@debian.org
Description: 
 kpart-webkit - WebKit KPart
 libkwebkit-dbg - KDE bindings for WebKit, Development files
 libkwebkit-dev - KDE bindings for WebKit, Development files
 libkwebkit1 - KDE bindings for WebKit
Closes: 537226
Changes: 
 webkitkde (0.4svn1059630-1) unstable; urgency=low
 .
   * Let it migrate to testing normally (closes: #537226)
   * New upstream snapshot
 - there is a version number hidden in part/webkitpart.cpp
 - KWallet integration
 - fix a few crashes
Checksums-Sha1: 
 5d3e1f75bd7f7fd7b47d396243b6f944d914c808 1453 webkitkde_0.4svn1059630-1.dsc
 f13c07ab63ca632115316edc30923e990ffb992d 113382 
webkitkde_0.4svn1059630.orig.tar.gz
 3090cdc67769efbde97067a7495211be460f50a7 3627 webkitkde_0.4svn1059630-1.diff.gz
 280ceda05df02caa04e02f3d1b3968fcdecfb6c9 45016 
kpart-webkit_0.4svn1059630-1_i386.deb
 319a13e77c0e2900aacd4a99fbb7a567f70ac02a 134322 
libkwebkit1_0.4svn1059630-1_i386.deb
 8010a92e29e1ccb5791de4f95f810ca9ca54fa87 8546 
libkwebkit-dev_0.4svn1059630-1_i386.deb
 ab8474b0b089a99797030986e182766458900313 49940 
libkwebkit-dbg_0.4svn1059630-1_i386.deb
Checksums-Sha256: 
 b061d5e2edd47f160225305f6db7bcad394e880320ffc0a5612afd215cafcb60 1453 
webkitkde_0.4svn1059630-1.dsc
 2c1a76725c845ed5e1d60cd8cabf4a8a444e417e41a47a3b9eb22e6aa36c7e98 113382 
webkitkde_0.4svn1059630.orig.tar.gz
 677f38ddf2f536e645ae30ee8cae8dc4dd65de0339b23a9be80743a177cc38e0 3627 
webkitkde_0.4svn1059630-1.diff.gz
 1a45bfb73ff78877e48c2155732b708d55e4b61d84a8851d6dfcd3412d6add23 45016 
kpart-webkit_0.4svn1059630-1_i386.deb
 e3f0f38555bc4866f7f1caeb291fc167673531d5902e254f1f9615f547fb3f11 134322 
libkwebkit1_0.4svn1059630-1_i386.deb
 

Bug#559986: FTBFS: default-jdk-builddep: Depends: gcj-jdk but it is not going to be installed

2009-12-08 Thread Adam C Powell IV
On Tue, 2009-12-08 at 06:08 +0100, Cyril Brulebois wrote:
 Package: babel
 Version: 1.4.0.dfsg-5
 Severity: serious
 Justification: FTBFS
 
 Your package FTBFS, slightly differently depending on the arch:
 |   default-jdk-builddep: Depends: default-jdk (= 1.5-33) but it is not going 
 to be installed
 or:
 |   default-jdk-builddep: Depends: gcj-jdk but it is not going to be installed

Uh, how is that not a bug in default-jdk-builddep, if that's what's
failing to install?

I'm going to reassign unless there's a reason not to.

-Adam
-- 
GPG fingerprint: D54D 1AEE B11C CE9B A02B  C5DD 526F 01E8 564E E4B6

Engineering consulting with open source tools
http://www.opennovation.com/


signature.asc
Description: This is a digitally signed message part


Processed: Yorick doesn't catch SIGFPE on HPPA

2009-12-08 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org:

 package yorick
Limiting to bugs with field 'package' containing at least one of 'yorick'
Limit currently set to 'package':'yorick'

 found 559406 2.1.05
Bug #559406 [yorick] FTBFS [hppa]: Floating point exception
There is no source info for the package 'yorick' at version '2.1.05' with 
architecture ''
Unable to make a source version for version '2.1.05'
Bug Marked as found in versions 2.1.05.
 severity 559406 normal
Bug #559406 [yorick] FTBFS [hppa]: Floating point exception
Severity set to 'normal' from 'serious'

 retitle 559406 Yorick doesn't catch SIGFPE on HPPA
Bug #559406 [yorick] FTBFS [hppa]: Floating point exception
Changed Bug title to 'Yorick doesn't catch SIGFPE on HPPA' from 'FTBFS 
[hppa]: Floating point exception'
 tags 559406 help
Bug #559406 [yorick] Yorick doesn't catch SIGFPE on HPPA
Added tag(s) help.
 thanks
Stopping processing here.

Please contact me if you need assistance.

Debian bug tracking system administrator
(administrator, Debian Bugs database)


-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#559971: [Pkg-mozext-maintainers] Bug#559971: itsalltext: Source package does not contain corresponding source for work

2009-12-08 Thread Jan Luebbe
On Tue, 2009-12-08 at 12:17 +1100, Ben Finney wrote: 
 Package: itsalltext
 Version: 1.3.1-1
 Severity: serious
 Justification: Policy 2.3
 
 The source package for ‘itsalltext’ is not the corresponding source
 for the work. Instead, it is a bundling of the binary ‘*.jar’
 libraries.

The jar 'libraries' are just zip archives of the source code.

 This violates the license terms of the work (GPLv3 §6) and as such
 means the package is currently illegal to distribute by the Debian
 project.

 The GPLv3 defines the “corresponding source” as:
 
 The Corresponding Source for a work in object code form means
 all the source code needed to generate, install, and (for an
 executable work) run the object code and to modify the work,
 including scripts to control those activities.

The work is not shipped in 'object code' as i understand it, just
compressed original .js and .xul files. The jar files have been obtained
by extracting upstream's .xpi file.

 So, fixing this bug involves changing the source package to consist of
 the corresponding source for the work plus the Debian packaging, all
 licensed appropriately.

For the next upstream version, i will change it to the recommended
pkg-mozext style where the the jars are extracted. 

 For this package, the source package needs to include all the files
 from the VCS repository (currently a Git repository located at
 ‘git://gerf.org/itsalltext.git’). The Debian packaging then should use
 the ‘Makefile’ to build the binary package from source.

I've had not seen this git repo before and have now compared the source
files in my package to those in git. They seem to be identical.

 The package's build system uses the third-party packages ‘jslint’
 URL:http://bugs.debian.org/559969 and (for the documentation)
 ‘jsdoc-toolkit’ URL:http://bugs.debian.org/559963.

Building without those tools also works, and produces the same as
upstreams .xpi.

What do you think we would gain by using the git repo as upstream?

Best regards,
Jan




--
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#559992: FTBFS [hppa] - ruby1.9: command not found

2009-12-08 Thread Nico Golde
Hi,
* dann frazier da...@debian.org [2009-12-08 13:30]:
 Package: stfl
 Version: 0.21-1
 Severity: serious
 User: debian-h...@lists.debian.org
 Usertags: hppa
 
 stfl reliably fails to build on hppa:
   https://buildd.debian.org/build.php?pkg=stflver=0.21-1arch=hppafile=log

Hmm. It fails because it doesn't find ruby1.9. Why is that? It is in the 
Depends and the binary is also in the ruby1.9 hppa packages.

Cheers
Nico
-- 
Nico Golde - http://www.ngolde.de - n...@jabber.ccc.de - GPG: 0xA0A0
For security reasons, all text in this mail is double-rot13 encrypted.


pgp7wc1Mhta4s.pgp
Description: PGP signature


Bug#559765: jetty: CVE-2007-6672 info disclosure

2009-12-08 Thread Michael Gilbert
On Tue, 08 Dec 2009 09:26:54 +0100, Torsten Werner wrote:
 Michael Gilbert schrieb:
  it is much more straightforward to simply check that the
  existing fix is applied. since you should have a relationship with
  upstream, it should be relatively straightforward to get a response
  from them.
 
 Upstream states that the package is fixed in version 6.1.7 at 
 http://jira.codehaus.org/browse/JETTY-386#action_117699 and this page 
 is linked from 
 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6672. The 
 oldest version from the jetty6 code base we ever had in Debian is 6.1.18.

you've mentioned this before, and i had seen that before submitting the
bug.  if changelog entries were considered sufficient, i would have
had no reason to submit the bug in the first place.

  also, this package is your responsibility, so you can't
  expect others to do your job for you.
 
 You have reported a bug that is more than 2.5 years old. How much 
 history should the maintainer check in your opinion before he ever 
 uploads to Debian? 2 years, 5 years, 10 years, 20 years...?

for security-related issues, yes, the entire lifetime of the program.

  if you think this request is overburdensome/unjustified, you can send an
  email to secur...@debian.org.  be aware that they expect this level of
  thoroughness at a minimum.
 
 I do accept bug reports with false positives from the security team when 
 time constraints do not allow proper checking because getting the 
 information fast is more important in such cases than verifying the 
 information. But that is a different story. You are reporting a bug that 
 has been fixed some years ago and you could have verified it yourself.

like i said, i did do the verification that you mentioned), but again
this is not sufficient.  triaging this issue has been a todo for the
security team for the past 2.5 years, and i am trying to close it off.
please help me out.  thank you.

mike



-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#554890: Nautilus crash when edit preferences

2009-12-08 Thread Jesús Martín Jiménez
Package: nautilus
Version: 2.26.3-1
Severity: normal

$ nautilus

(nautilus:14487): Gtk-CRITICAL **: gtk_size_group_add_widget: assertion 
`GTK_IS_WIDGET (widget)' failed

(nautilus:14487): Gtk-CRITICAL **: gtk_size_group_add_widget: assertion 
`GTK_IS_WIDGET (widget)' failed

(nautilus:14487): Gtk-CRITICAL **: gtk_size_group_add_widget: assertion 
`GTK_IS_WIDGET (widget)' failed

(nautilus:14487): Gtk-CRITICAL **: gtk_size_group_add_widget: assertion 
`GTK_IS_WIDGET (widget)' failed

(nautilus:14487): Gtk-CRITICAL **: gtk_size_group_add_widget: assertion 
`GTK_IS_WIDGET (widget)' failed

(nautilus:14487): Gtk-CRITICAL **: gtk_size_group_add_widget: assertion 
`GTK_IS_WIDGET (widget)' failed

(nautilus:14487): Gtk-CRITICAL **: gtk_size_group_add_widget: assertion 
`GTK_IS_WIDGET (widget)' failed

(nautilus:14487): Gtk-CRITICAL **: gtk_size_group_add_widget: assertion 
`GTK_IS_WIDGET (widget)' failed

(nautilus:14487): Gtk-CRITICAL **: gtk_combo_box_append_text: assertion 
`GTK_IS_COMBO_BOX (combo_box)' failed

(nautilus:14487): Gtk-CRITICAL **: gtk_combo_box_append_text: assertion 
`GTK_IS_COMBO_BOX (combo_box)' failed

(nautilus:14487): Gtk-CRITICAL **: gtk_combo_box_append_text: assertion 
`GTK_IS_COMBO_BOX (combo_box)' failed

(nautilus:14487): GLib-GObject-CRITICAL **: g_object_set_data_full: assertion 
`G_IS_OBJECT (object)' failed

(nautilus:14487): Eel-CRITICAL **: eel_preferences_add_callback_while_alive: 
assertion `G_IS_OBJECT (alive_object)' failed

(nautilus:14487): GLib-GObject-CRITICAL **: g_object_get_data: assertion 
`G_IS_OBJECT (object)' failed

(nautilus:14487): GLib-GObject-WARNING **: invalid (NULL) pointer instance

(nautilus:14487): GLib-GObject-CRITICAL **: g_signal_connect_data: assertion 
`G_TYPE_CHECK_INSTANCE (instance)' failed

(nautilus:14487): GLib-GObject-CRITICAL **: g_object_get_data: assertion 
`G_IS_OBJECT (object)' failed

(nautilus:14487): Eel-CRITICAL **: eel_preferences_get_boolean: assertion `name 
!= NULL' failed

(nautilus:14487): GLib-GObject-WARNING **: invalid (NULL) pointer instance

(nautilus:14487): GLib-GObject-CRITICAL **: g_signal_handlers_block_matched: 
assertion `G_TYPE_CHECK_INSTANCE (instance)' failed

(nautilus:14487): Gtk-CRITICAL **: gtk_toggle_button_set_active: assertion 
`GTK_IS_TOGGLE_BUTTON (toggle_button)' failed

(nautilus:14487): GLib-GObject-WARNING **: invalid (NULL) pointer instance

(nautilus:14487): GLib-GObject-CRITICAL **: g_signal_handlers_unblock_matched: 
assertion `G_TYPE_CHECK_INSTANCE (instance)' failed

(nautilus:14487): GLib-GObject-CRITICAL **: g_object_set_data_full: assertion 
`G_IS_OBJECT (object)' failed

(nautilus:14487): Eel-CRITICAL **: eel_preferences_add_callback_while_alive: 
assertion `G_IS_OBJECT (alive_object)' failed

(nautilus:14487): GLib-GObject-CRITICAL **: g_object_get_data: assertion 
`G_IS_OBJECT (object)' failed

(nautilus:14487): GLib-GObject-WARNING **: invalid (NULL) pointer instance

(nautilus:14487): GLib-GObject-CRITICAL **: g_signal_connect_data: assertion 
`G_TYPE_CHECK_INSTANCE (instance)' failed

(nautilus:14487): GLib-GObject-CRITICAL **: g_object_get_data: assertion 
`G_IS_OBJECT (object)' failed

(nautilus:14487): Eel-CRITICAL **: eel_preferences_get_boolean: assertion `name 
!= NULL' failed

(nautilus:14487): GLib-GObject-WARNING **: invalid (NULL) pointer instance

(nautilus:14487): GLib-GObject-CRITICAL **: g_signal_handlers_block_matched: 
assertion `G_TYPE_CHECK_INSTANCE (instance)' failed

(nautilus:14487): Gtk-CRITICAL **: gtk_toggle_button_set_active: assertion 
`GTK_IS_TOGGLE_BUTTON (toggle_button)' failed

(nautilus:14487): GLib-GObject-WARNING **: invalid (NULL) pointer instance

(nautilus:14487): GLib-GObject-CRITICAL **: g_signal_handlers_unblock_matched: 
assertion `G_TYPE_CHECK_INSTANCE (instance)' failed

(nautilus:14487): GLib-GObject-CRITICAL **: g_object_set_data_full: assertion 
`G_IS_OBJECT (object)' failed

(nautilus:14487): Eel-CRITICAL **: eel_preferences_add_callback_while_alive: 
assertion `G_IS_OBJECT (alive_object)' failed

(nautilus:14487): GLib-GObject-CRITICAL **: g_object_get_data: assertion 
`G_IS_OBJECT (object)' failed

(nautilus:14487): GLib-GObject-WARNING **: invalid (NULL) pointer instance

(nautilus:14487): GLib-GObject-CRITICAL **: g_signal_connect_data: assertion 
`G_TYPE_CHECK_INSTANCE (instance)' failed

(nautilus:14487): GLib-GObject-CRITICAL **: g_object_get_data: assertion 
`G_IS_OBJECT (object)' failed

(nautilus:14487): Eel-CRITICAL **: eel_preferences_get_boolean: assertion `name 
!= NULL' failed

(nautilus:14487): GLib-GObject-WARNING **: invalid (NULL) pointer instance

(nautilus:14487): GLib-GObject-CRITICAL **: g_signal_handlers_block_matched: 
assertion `G_TYPE_CHECK_INSTANCE (instance)' failed

(nautilus:14487): Gtk-CRITICAL **: gtk_toggle_button_set_active: assertion 
`GTK_IS_TOGGLE_BUTTON (toggle_button)' failed

(nautilus:14487): GLib-GObject-WARNING **: invalid (NULL) pointer instance

(nautilus:14487): GLib-GObject-CRITICAL **: 

Bug#560042: scilab-sivp: FTBFS (Scilab cannot create Scilab Java Main-Class)

2009-12-08 Thread Laurent Bonnaud
Package: scilab-sivp
Version: 0.5.0-5
Severity: serious


Hi,

I tried to rebuild scilab-sivp (which is currently not installable in
sid after the OpenCV 2.0 upload) and failed.  Here is the problem:

$ fakeroot apt-get -b source scilab-sivp
Reading package lists... Done   
Building dependency tree
Reading state information... Done   
Need to get 3,163kB of source archives. 
Get:1 http://ftp.fr.debian.org sid/main sivp 0.5.0-5 (dsc) [1,448B]
Get:2 http://ftp.fr.debian.org sid/main sivp 0.5.0-5 (tar) [3,159kB]
Get:3 http://ftp.fr.debian.org sid/main sivp 0.5.0-5 (diff) [3,374B]
Fetched 3,163kB in 0s (5,165kB/s)   
dpkg-source: info: extracting sivp in sivp-0.5.0
dpkg-source: info: unpacking sivp_0.5.0.orig.tar.gz 
dpkg-source: info: applying sivp_0.5.0-5.diff.gz
dpkg-buildpackage: set CFLAGS to default value: -g -O2  
dpkg-buildpackage: set CPPFLAGS to default value:   
dpkg-buildpackage: set LDFLAGS to default value:
dpkg-buildpackage: set FFLAGS to default value: -g -O2  
dpkg-buildpackage: set CXXFLAGS to default value: -g -O2
dpkg-buildpackage: source package sivp  
dpkg-buildpackage: source version 0.5.0-5   
dpkg-buildpackage: source changed by Sylvestre Ledru sylves...@debian.org
dpkg-buildpackage: host architecture i386  
dpkg-checkbuilddeps: warning: relation  is deprecated: use  or =   
 debian/rules clean
test -x debian/rules   
dh_testroot
SCI_DISABLE_TK=1 SCI_JAVA_ENABLE_HEADLESS=1 
DOCBOOK_ROOT=/usr/share/sgml/docbook/stylesheet/xsl/nwalsh /usr/bin/make  -C .  
-k distclean
  
make[1]: Entering directory `/tmp/sivp-0.5.0'   
   
make[1]: *** No rule to make target `distclean'.
   
make[1]: Leaving directory `/tmp/sivp-0.5.0'
   
make: [makefile-clean] Error 2 (ignored)
   
rm -f debian/stamp-makefile-build   
   
for i in ./config/config.guess ./config/config.sub  ; do \  
   
if test -e $i.cdbs-orig ; then \
   
mv $i.cdbs-orig $i ; \  
   
fi ; \  
   
done
   
dh_clean
   
rm -f debian/stamp-autotools-files  
   
 debian/rules build 
   
test -x debian/rules
   
mkdir -p .
   
if test -e /usr/share/misc/config.guess ; then \
   
for i in ./config/config.guess ; do \   
   
if ! test -e $i.cdbs-orig ; then \  
   
mv $i $i.cdbs-orig ; \  
   
cp --remove-destination 
/usr/share/misc/config.guess $i ; \
fi ; \  
   
done ; \
   
fi  
   
if test -e /usr/share/misc/config.sub ; then \  
   
for i in ./config/config.sub ; do \   

Bug#549407: [buildd-tools-devel] Bug#549407: ivtools 1.2.6-1 FTBFS on sparc and powerpc

2009-12-08 Thread Roger Leigh
On Tue, Dec 08, 2009 at 03:11:32AM +0100, Agustin Martin wrote:
 2009/12/6 Agustin Martin agmar...@debian.org:
 
  Good news. I finally found the reason for this problem. An explanation
  was not that far. Quoting http://www.ivtools.org/ivtools/faq.html,
 
  ---
  ... For example, most
  PC-based uses of gcc have i386 defined to 1, so a path like
  /usr/src/i386/ivtools-1.0 gets expanded to /usr/src/1/ivtools-1.0. ..
  ---
 
  As I understand it, this problem should also be present in other
  packages using imake.  Not sure if many packages still use imake, but
  if so there is a problem with the temporary dir naming in sbuild.
 
 In case this is ever needed, seems that is enough to change to a
 lowbar one of the hyphen $(ARCH) boundaries in tempdir name, like in
 
 -
 --- Build.pm.orig   2009-11-20 19:48:42.0 +0100
 +++ Build.pm2009-12-07 01:00:07.0 +0100
 @@ -233,7 +233,7 @@
  $self-set('Chroot Build Dir',
tempdir($self-get_conf('USERNAME') . '-' .
$self-get('Package_SVersion') . '-' .
 -  $self-get('Arch') . '-XX',
 +  $self-get('Arch') . '_XX',
DIR = $session-get('Build Location')));
  # TODO: Don't hack the build location in; add a means to customise
  # the chroot directly.

Thanks for identifying the cause of the problem!

So, to state the problem clearly: Imake is substituting the
$(ARCH) part of the path to something else.  Such as 'i386' being
swapped for something else entirely, thus resulting in an
invalid path.

This is, IMO, completely broken on the part of Imake.  I'm reluctant
to alter sbuild to accommodate such bad behaviour.  For one thing,
it can substitute /any part/ of the path, so there's no guarantee it
won't randomly break on the XX random part or any other path
component for any given build.  The fix just makes the arch
mismatch because underscore makes the two parts a single token, but
that is not to say it will /never/ match.  I accept that it solves
the immediate issue, but it doesn't correct the fundamental
underlying defect in imake.

What's worse is that the random path might actually be /valid/, in
which case it might scribble junk into, or delete files from, a
directory other than the build directory.  Unlikely, but possible,
so a potential security problem on the buildd.

Is this possible to fix in ivtools using the -u option to undefine
things as suggested in the FAQ?  Given the package-specific nature
of the problem, I feel this would be a more appropriate place for
a fix.


Regards,
Roger

-- 
  .''`.  Roger Leigh
 : :' :  Debian GNU/Linux http://people.debian.org/~rleigh/
 `. `'   Printing on GNU/Linux?   http://gutenprint.sourceforge.net/
   `-GPG Public Key: 0x25BFB848   Please GPG sign your mail.


signature.asc
Description: Digital signature


Bug#554890: marked as done (nautilus crashes when trying to edit preference)

2009-12-08 Thread Debian Bug Tracking System
Your message dated Tue, 08 Dec 2009 16:12:28 +0100
with message-id 1260285148.31834.8.ca...@shizuru
and subject line Re: Bug#554890: Nautilus crash when edit preferences
has caused the Debian Bug report #554890,
regarding nautilus crashes when trying to edit preference
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
554890: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=554890
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
---BeginMessage---
Package: nautilus
Version: 2.26.3-1
Severity: grave
Justification: renders package unusable

(nautilus:3292): Gtk-CRITICAL **: gtk_toggle_button_set_active: assertion 
`GTK_IS_TOGGLE_BUTTON (toggle_button)' failed

(nautilus:3292): GLib-GObject-WARNING **: invalid (NULL) pointer instance

(nautilus:3292): GLib-GObject-CRITICAL **: g_signal_handlers_unblock_matched: 
assertion `G_TYPE_CHECK_INSTANCE (instance)' failed

(nautilus:3292): GLib-GObject-CRITICAL **: g_object_set_data_full: assertion 
`G_IS_OBJECT (object)' failed

(nautilus:3292): GLib-GObject-CRITICAL **: g_object_set_data: assertion 
`G_IS_OBJECT (object)' failed

(nautilus:3292): GLib-GObject-CRITICAL **: g_object_set_data_full: assertion 
`G_IS_OBJECT (object)' failed

(nautilus:3292): Eel-CRITICAL **: eel_preferences_add_callback_while_alive: 
assertion `G_IS_OBJECT (alive_object)' failed

(nautilus:3292): GLib-GObject-CRITICAL **: g_object_get_data: assertion 
`G_IS_OBJECT (object)' failed

(nautilus:3292): GLib-GObject-WARNING **: invalid (NULL) pointer instance

(nautilus:3292): GLib-GObject-CRITICAL **: g_signal_connect_data: assertion 
`G_TYPE_CHECK_INSTANCE (instance)' failed

(nautilus:3292): GLib-GObject-CRITICAL **: g_object_get_data: assertion 
`G_IS_OBJECT (object)' failed

(nautilus:3292): Eel-CRITICAL **: eel_preferences_get: assertion `name != NULL' 
failed

(nautilus:3292): GLib-GObject-CRITICAL **: g_object_get_data: assertion 
`G_IS_OBJECT (object)' failed

(nautilus:3292): GLib-CRITICAL **: g_hash_table_lookup: assertion `hash_table 
!= NULL' failed

(nautilus:3292): GLib-GObject-CRITICAL **: g_object_get_data: assertion 
`G_IS_OBJECT (object)' failed

(nautilus:3292): GLib-GObject-WARNING **: invalid (NULL) pointer instance

(nautilus:3292): GLib-GObject-CRITICAL **: g_signal_handlers_block_matched: 
assertion `G_TYPE_CHECK_INSTANCE (instance)' failed

(nautilus:3292): Gtk-CRITICAL **: gtk_combo_box_set_active: assertion 
`GTK_IS_COMBO_BOX (combo_box)' failed

(nautilus:3292): GLib-GObject-WARNING **: invalid (NULL) pointer instance

(nautilus:3292): GLib-GObject-CRITICAL **: g_signal_handlers_unblock_matched: 
assertion `G_TYPE_CHECK_INSTANCE (instance)' failed

(nautilus:3292): GLib-GObject-CRITICAL **: g_object_set_data_full: assertion 
`G_IS_OBJECT (object)' failed

(nautilus:3292): GLib-GObject-CRITICAL **: g_object_set_data: assertion 
`G_IS_OBJECT (object)' failed

(nautilus:3292): GLib-GObject-CRITICAL **: g_object_set_data_full: assertion 
`G_IS_OBJECT (object)' failed

(nautilus:3292): Eel-CRITICAL **: eel_preferences_add_callback_while_alive: 
assertion `G_IS_OBJECT (alive_object)' failed

(nautilus:3292): GLib-GObject-CRITICAL **: g_object_get_data: assertion 
`G_IS_OBJECT (object)' failed

(nautilus:3292): GLib-GObject-WARNING **: invalid (NULL) pointer instance

(nautilus:3292): GLib-GObject-CRITICAL **: g_signal_connect_data: assertion 
`G_TYPE_CHECK_INSTANCE (instance)' failed

(nautilus:3292): GLib-GObject-CRITICAL **: g_object_get_data: assertion 
`G_IS_OBJECT (object)' failed

(nautilus:3292): Eel-CRITICAL **: eel_preferences_get: assertion `name != NULL' 
failed

(nautilus:3292): GLib-GObject-CRITICAL **: g_object_get_data: assertion 
`G_IS_OBJECT (object)' failed

(nautilus:3292): GLib-CRITICAL **: g_hash_table_lookup: assertion `hash_table 
!= NULL' failed

(nautilus:3292): GLib-GObject-CRITICAL **: g_object_get_data: assertion 
`G_IS_OBJECT (object)' failed

(nautilus:3292): GLib-GObject-WARNING **: invalid (NULL) pointer instance

(nautilus:3292): GLib-GObject-CRITICAL **: g_signal_handlers_block_matched: 
assertion `G_TYPE_CHECK_INSTANCE (instance)' failed

(nautilus:3292): Gtk-CRITICAL **: gtk_combo_box_set_active: assertion 
`GTK_IS_COMBO_BOX (combo_box)' failed

(nautilus:3292): GLib-GObject-WARNING **: invalid (NULL) pointer instance

(nautilus:3292): GLib-GObject-CRITICAL **: g_signal_handlers_unblock_matched: 
assertion `G_TYPE_CHECK_INSTANCE (instance)' failed

(nautilus:3292): GLib-GObject-CRITICAL **: g_object_set_data_full: assertion 
`G_IS_OBJECT (object)' failed

(nautilus:3292): GLib-GObject-CRITICAL **: g_object_set_data: assertion 

Bug#559944: marked as done (FTBFS: /usr/bin/ld: bufrdc/bbuprs0.o: relocation R_X86_64_32S against `.rodata.str1.1'…)

2009-12-08 Thread Debian Bug Tracking System
Your message dated Tue, 08 Dec 2009 15:34:20 +
with message-id e1ni24y-000533...@ries.debian.org
and subject line Bug#559944: fixed in emoslib 000371+dfsg-2
has caused the Debian Bug report #559944,
regarding FTBFS: /usr/bin/ld: bufrdc/bbuprs0.o: relocation R_X86_64_32S against 
`.rodata.str1.1'…
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
559944: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=559944
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
---BeginMessage---
Package: emoslib
Version: 000371+dfsg-1
Severity: serious
Justification: FTBFS

Hi,

your package FTBFS, at least on amd64 and kfreebsd-amd64:
| /usr/bin/ld: bufrdc/bbuprs0.o: relocation R_X86_64_32S against 
`.rodata.str1.1' can not be used when making a shared object; recompile with 
-fPIC
| bufrdc/bbuprs0.o: could not read symbols: Bad value
| collect2: ld returned 1 exit status
| make[1]: *** [build] Error 1

Build logs at the usual place:
  https://buildd.debian.org/status/package.php?suite=unstablep=emoslib

Mraw,
KiBi.


---End Message---
---BeginMessage---
Source: emoslib
Source-Version: 000371+dfsg-2

We believe that the bug you reported is fixed in the latest version of
emoslib, which is due to be installed in the Debian FTP archive:

emoslib_000371+dfsg-2.debian.tar.gz
  to main/e/emoslib/emoslib_000371+dfsg-2.debian.tar.gz
emoslib_000371+dfsg-2.dsc
  to main/e/emoslib/emoslib_000371+dfsg-2.dsc
libemos-data_000371+dfsg-2_i386.deb
  to main/e/emoslib/libemos-data_000371+dfsg-2_i386.deb
libemos-dev_000371+dfsg-2_i386.deb
  to main/e/emoslib/libemos-dev_000371+dfsg-2_i386.deb
libemos0d_000371+dfsg-2_i386.deb
  to main/e/emoslib/libemos0d_000371+dfsg-2_i386.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 559...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Alastair McKinstry mckins...@debian.org (supplier of updated emoslib package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@debian.org)


-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

Format: 1.8
Date: Tue, 08 Dec 2009 13:38:29 +
Source: emoslib
Binary: libemos0d libemos-dev libemos-data
Architecture: source i386
Version: 000371+dfsg-2
Distribution: unstable
Urgency: low
Maintainer: Alastair McKinstry mckins...@debian.org
Changed-By: Alastair McKinstry mckins...@debian.org
Description: 
 libemos-data - Data files for the ECMWF Interpolation library
 libemos-dev - ECMWF Interpolation Library - development
 libemos0d  - ECMWF Interpolation Library
Closes: 559944
Changes: 
 emoslib (000371+dfsg-2) unstable; urgency=low
 .
   * Fix broken patch that lead to non-shared code. Closes: #559944.
   * Source format 3.0
Checksums-Sha1: 
 bbbf7539c6be66c4fc47339dda611dc8baf7920b 1175 emoslib_000371+dfsg-2.dsc
 9afff9d6498f56abaf4dca082ef4ffbdef7fb629 13133 
emoslib_000371+dfsg-2.debian.tar.gz
 8854d85534f672f24ca6723ab1d555ab95de94b7 1415180 
libemos0d_000371+dfsg-2_i386.deb
 8338e9951fb0db6db4eb665c8a904560ad73a1e3 1926994 
libemos-dev_000371+dfsg-2_i386.deb
 3bd87afde9988d419827e70a734780d39f091834 1175774 
libemos-data_000371+dfsg-2_i386.deb
Checksums-Sha256: 
 1f714295185045c3b70a54e5f26bf7f27cb1f91078031752a7981ee2c8542ad6 1175 
emoslib_000371+dfsg-2.dsc
 164f98bea8d22d4065866abf020d7546720afa6919a52837f44a51a2b61e444b 13133 
emoslib_000371+dfsg-2.debian.tar.gz
 80c386e208ad63d333b1bc33acd60c2740abb6ef618ef413e42a07dbfecb6921 1415180 
libemos0d_000371+dfsg-2_i386.deb
 825b94bc9e2e2861e0d77ba0cd593d537fcc4b675023fb4b6a9f376324c44ea6 1926994 
libemos-dev_000371+dfsg-2_i386.deb
 59e27dc2d803c82a2667b5d0d96e157533322d0ac27d189804f2232ed00c60c9 1175774 
libemos-data_000371+dfsg-2_i386.deb
Files: 
 91afcbd161457ff148df76e910b802fc 1175 utils optional emoslib_000371+dfsg-2.dsc
 ec8090cba2132873eba6b8dc6d0859d3 13133 utils optional 
emoslib_000371+dfsg-2.debian.tar.gz
 9c9872049cb6c2aa58164d7d32d2fc7c 1415180 libs optional 
libemos0d_000371+dfsg-2_i386.deb
 6922c38fbc78a331dcc4884f34bc1ac0 1926994 libdevel optional 
libemos-dev_000371+dfsg-2_i386.deb
 8c8bf5d9c05b476be5aabced031a2fc1 1175774 utils optional 
libemos-data_000371+dfsg-2_i386.deb

-BEGIN PGP SIGNATURE-
Version: GnuPG v1.4.10 (GNU/Linux)

iD8DBQFLHl8KQTK/kCo4XFcRAhIVAJ9p62i61sJF/4qijnKgQkDdKe0eDgCfVvxb
nf2o/kONbj3XwlYu0rdDw0I=
=15X2
-END PGP SIGNATURE-



Bug#552851: marked as done (gmfsk: FTBFS: misc.h:110: error: conflicting types for 'log2')

2009-12-08 Thread Debian Bug Tracking System
Your message dated Tue, 08 Dec 2009 15:35:32 +
with message-id e1ni268-0005na...@ries.debian.org
and subject line Bug#552851: fixed in gmfsk 0.6+0.7pre1-2.2
has caused the Debian Bug report #552851,
regarding gmfsk: FTBFS: misc.h:110: error: conflicting types for 'log2'
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
552851: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=552851
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
---BeginMessage---
Source: gmfsk
Version: 0.6+0.7pre1-2.1
Severity: serious
User: debian...@lists.debian.org
Usertags: qa-ftbfs-20091028 qa-ftbfs
Justification: FTBFS on amd64

Hi,

During a rebuild of all packages in sid, your package failed to build on
amd64.

Relevant part:
 if gcc -DHAVE_CONFIG_H -I. -I. -I../.. -DPACKAGE_DATA_DIR=\/usr/share\ 
 -DPACKAGE_LOCALE_DIR=\/usr/share/locale\ -DORBIT2=1 -pthread -D_REENTRANT 
 -I/usr/include/libgnomeui-2.0 -I/usr/include/libart-2.0 
 -I/usr/include/gconf/2 -I/usr/include/gnome-keyring-1 
 -I/usr/include/libgnome-2.0 -I/usr/include/libbonoboui-2.0 
 -I/usr/include/libgnomecanvas-2.0 -I/usr/include/gtk-2.0 
 -I/usr/include/gnome-vfs-2.0 -I/usr/lib/gnome-vfs-2.0/include 
 -I/usr/include/orbit-2.0 -I/usr/include/dbus-1.0 -I/usr/lib/dbus-1.0/include 
 -I/usr/include/glib-2.0 -I/usr/lib/glib-2.0/include 
 -I/usr/include/libbonobo-2.0 -I/usr/include/bonobo-activation-2.0 
 -I/usr/include/libxml2 -I/usr/include/pango-1.0 -I/usr/include/gail-1.0 
 -I/usr/include/freetype2 -I/usr/include/atk-1.0 -I/usr/lib/gtk-2.0/include 
 -I/usr/include/cairo -I/usr/include/pixman-1 -I/usr/include/directfb 
 -I/usr/include/libpng12  -g -O2 -Wall -MT misc.o -MD -MP -MF 
 .deps/misc.Tpo \
 -c -o misc.o `test -f 'misc.c' || echo './'`misc.c; \
   then mv -f .deps/misc.Tpo .deps/misc.Po; \
   else rm -f .deps/misc.Tpo; exit 1; \
   fi
 In file included from misc.c:25:
 misc.h:110: error: conflicting types for 'log2'
 make[4]: *** [misc.o] Error 1

The full build log is available from:
   
http://people.debian.org/~lucas/logs/2009/10/28/gmfsk_0.6+0.7pre1-2.1_lsid64.buildlog

A list of current common problems and possible solutions is available at 
http://wiki.debian.org/qa.debian.org/FTBFS . You're welcome to contribute!

About the archive rebuild: The rebuild was done on about 50 AMD64 nodes
of the Grid'5000 platform, using a clean chroot.  Internet was not
accessible from the build systems.

-- 
| Lucas Nussbaum
| lu...@lucas-nussbaum.net   http://www.lucas-nussbaum.net/ |
| jabber: lu...@nussbaum.fr GPG: 1024D/023B3F4F |


---End Message---
---BeginMessage---
Source: gmfsk
Source-Version: 0.6+0.7pre1-2.2

We believe that the bug you reported is fixed in the latest version of
gmfsk, which is due to be installed in the Debian FTP archive:

gmfsk_0.6+0.7pre1-2.2.diff.gz
  to main/g/gmfsk/gmfsk_0.6+0.7pre1-2.2.diff.gz
gmfsk_0.6+0.7pre1-2.2.dsc
  to main/g/gmfsk/gmfsk_0.6+0.7pre1-2.2.dsc
gmfsk_0.6+0.7pre1-2.2_i386.deb
  to main/g/gmfsk/gmfsk_0.6+0.7pre1-2.2_i386.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 552...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Kęstutis Bilūnas ke...@kaunas.init.lt (supplier of updated gmfsk package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@debian.org)


-BEGIN PGP SIGNED MESSAGE-
Hash: SHA512

Format: 1.8
Date: Tue, 08 Dec 2009 11:20:38 +0100
Source: gmfsk
Binary: gmfsk
Architecture: source i386
Version: 0.6+0.7pre1-2.2
Distribution: unstable
Urgency: low
Maintainer: Hamish Moffatt ham...@debian.org
Changed-By: Kęstutis Bilūnas ke...@kaunas.init.lt
Description: 
 gmfsk  - MFSK, RTTY and other digital mode terminal for HF/amateur radio
Closes: 552851
Changes: 
 gmfsk (0.6+0.7pre1-2.2) unstable; urgency=low
 .
   [ Kęstutis Bilūnas ]
   * Non-maintainer upload.
   * debian/patches: added the patch 13_log2_fix.dpatch for fix FTBFS
 (Closes: #552851).
   * debian/rules:
 - fixed the order of calling debhelper programs dh_;
 - fixed the clean target.
 .
   [ Christoph Egger ]
   * Update config.*, remove again in clean so they don't show up in the diff
Checksums-Sha1: 
 44a31232f90eb6c057c8c58dcf6b8713101a1046 1727 gmfsk_0.6+0.7pre1-2.2.dsc
 6e538847544fe88821e3082d22fc5ddf29aa0fa9 8955 gmfsk_0.6+0.7pre1-2.2.diff.gz
 

Bug#549399: marked as done (fails to build with newer eglibc)

2009-12-08 Thread Debian Bug Tracking System
Your message dated Tue, 08 Dec 2009 15:33:10 +
with message-id e1ni23q-0004nq...@ries.debian.org
and subject line Bug#549399: fixed in cdrdao 1:1.2.2-18.1
has caused the Debian Bug report #549399,
regarding fails to build with newer eglibc
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
549399: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=549399
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
---BeginMessage---
Package: cdrdao
Version: 1:1.2.2-17
Severity: normal
Tags: patch

Hi,

thanks for maintaining cdrdao.

During Ubuntu's rebuild test, cdrdao fail to build [1]. The reason is that 
getline is provided by Ubuntu's newer eglibc (experimental's eglibc should 
more or less match it), as it was added to POSIX.

Attached is a patch that renames the local definition of getline.

Cheers,
   Stefan.

[1]:
https://edge.launchpad.net/ubuntu/+archive/test-rebuild-20090909/+build/1211879/+files/buildlog_ubuntu-karmic-amd64.cdrdao_1:1.2.2-17_FAILEDTOBUILD.txt.gz

-- System Information:
Debian Release: squeeze/sid
  APT prefers karmic-updates
  APT policy: (500, 'karmic-updates'), (500, 'karmic-security'), (500, 'karmic')
Architecture: amd64 (x86_64)

Kernel: Linux 2.6.31-11-generic (SMP w/2 CPU cores)
Locale: LANG=de_DE.UTF-8, LC_CTYPE=de_DE.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash

Versions of packages cdrdao depends on:
ii  libao2  0.8.8-5ubuntu1   Cross Platform Audio Output Librar
ii  libc6   2.10.1-0ubuntu12 GNU C Library: Shared libraries
ii  libgcc1 1:4.4.1-4ubuntu4 GCC support library
ii  libogg0 1.1.4~dfsg-1 Ogg bitstream library
ii  libstdc++6  4.4.1-4ubuntu4   The GNU Standard C++ Library v3
ii  libvorbis0a 1.2.0.dfsg-6 The Vorbis General Audio Compressi
ii  libvorbisfile3  1.2.0.dfsg-6 The Vorbis General Audio Compressi

cdrdao recommends no packages.

cdrdao suggests no packages.

-- no debconf information
Index: cdrdao-1.2.2/scsilib/include/schily.h
===
--- cdrdao-1.2.2.orig/scsilib/include/schily.h	2009-10-03 01:43:15.0 +0200
+++ cdrdao-1.2.2/scsilib/include/schily.h	2009-10-03 01:42:27.0 +0200
@@ -187,7 +187,7 @@
 extern	char	*findbytes __PR((const void *, int, char));
 extern	int	findline __PR((const char *, char, const char *,
 			int, char **, int));
-extern	int	getline __PR((char *, int));
+extern	int	getline_schily __PR((char *, int));
 extern	int	getstr __PR((char *, int));
 extern	int	breakline __PR((char *, char, char **, int));
 extern	int	getallargs __PR((int *, char * const**, const char *, ...));
Index: cdrdao-1.2.2/scsilib/libscg/scsitransp.c
===
--- cdrdao-1.2.2.orig/scsilib/libscg/scsitransp.c	2009-10-03 01:43:13.0 +0200
+++ cdrdao-1.2.2/scsilib/libscg/scsitransp.c	2009-10-03 01:42:45.0 +0200
@@ -324,7 +324,7 @@
 
 	js_printf(%s, msg);
 	flush();
-	if (getline(okbuf, sizeof (okbuf)) == EOF)
+	if (getline_schily(okbuf, sizeof (okbuf)) == EOF)
 		exit(EX_BAD);
 	if (streql(okbuf, y) || streql(okbuf, yes) ||
 	streql(okbuf, Y) || streql(okbuf, YES))
Index: cdrdao-1.2.2/scsilib/libschily/stdio/fgetline.c
===
--- cdrdao-1.2.2.orig/scsilib/libschily/stdio/fgetline.c	2009-10-03 01:43:15.0 +0200
+++ cdrdao-1.2.2/scsilib/libschily/stdio/fgetline.c	2009-10-03 01:43:04.0 +0200
@@ -64,7 +64,7 @@
 }
 
 EXPORT int
-getline(buf, len)
+getline_schily(buf, len)
 	char	*buf;
 	int	len;
 {
---End Message---
---BeginMessage---
Source: cdrdao
Source-Version: 1:1.2.2-18.1

We believe that the bug you reported is fixed in the latest version of
cdrdao, which is due to be installed in the Debian FTP archive:

cdrdao_1.2.2-18.1.diff.gz
  to main/c/cdrdao/cdrdao_1.2.2-18.1.diff.gz
cdrdao_1.2.2-18.1.dsc
  to main/c/cdrdao/cdrdao_1.2.2-18.1.dsc
cdrdao_1.2.2-18.1_i386.deb
  to main/c/cdrdao/cdrdao_1.2.2-18.1_i386.deb
gcdmaster_1.2.2-18.1_i386.deb
  to main/c/cdrdao/gcdmaster_1.2.2-18.1_i386.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 549...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Christoph Egger christ...@debian.org (supplier of updated cdrdao package)

(This message was generated automatically at their 

Bug#559836: marked as done (CVE-2009-3736 local privilege escalation)

2009-12-08 Thread Debian Bug Tracking System
Your message dated Tue, 08 Dec 2009 15:39:17 +
with message-id e1ni29l-0006vl...@ries.debian.org
and subject line Bug#559836: fixed in openmpi 1.3.3-4
has caused the Debian Bug report #559836,
regarding CVE-2009-3736 local privilege escalation
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
559836: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=559836
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
---BeginMessage---
Package: openmpi
Severity: grave
Tags: security

Hi,

The following CVE (Common Vulnerabilities  Exposures) id was
published for libtool.  I have determined that this package embeds a
vulnerable copy of the libtool source code.  However, since this is a
mass bug filing (due to so many packages embedding libtool), I have not
had time to determine whether the vulnerable code is actually present
in any of the binary packages. Please determine whether this is the
case. If the binary packages are not affected, please feel free to close
the bug with a message containing the details of what you did to check.

CVE-2009-3736[0]:
| ltdl.c in libltdl in GNU Libtool 1.5.x, and 2.2.6 before 2.2.6b,
| attempts to open a .la file in the current working directory, which
| allows local users to gain privileges via a Trojan horse file.

Note that this problem also affects etch and lenny, so if your package
is affected, please coordinate with the security team to release the
DSA for the affected packages.

If you fix the vulnerability please also make sure to include the
CVE id in your changelog entry.

For further information see:

[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3736
http://security-tracker.debian.org/tracker/CVE-2009-3736


---End Message---
---BeginMessage---
Source: openmpi
Source-Version: 1.3.3-4

We believe that the bug you reported is fixed in the latest version of
openmpi, which is due to be installed in the Debian FTP archive:

libopenmpi-dbg_1.3.3-4_amd64.deb
  to main/o/openmpi/libopenmpi-dbg_1.3.3-4_amd64.deb
libopenmpi-dev_1.3.3-4_amd64.deb
  to main/o/openmpi/libopenmpi-dev_1.3.3-4_amd64.deb
libopenmpi1.3_1.3.3-4_amd64.deb
  to main/o/openmpi/libopenmpi1.3_1.3.3-4_amd64.deb
openmpi-bin_1.3.3-4_amd64.deb
  to main/o/openmpi/openmpi-bin_1.3.3-4_amd64.deb
openmpi-checkpoint_1.3.3-4_amd64.deb
  to main/o/openmpi/openmpi-checkpoint_1.3.3-4_amd64.deb
openmpi-common_1.3.3-4_all.deb
  to main/o/openmpi/openmpi-common_1.3.3-4_all.deb
openmpi-doc_1.3.3-4_all.deb
  to main/o/openmpi/openmpi-doc_1.3.3-4_all.deb
openmpi_1.3.3-4.diff.gz
  to main/o/openmpi/openmpi_1.3.3-4.diff.gz
openmpi_1.3.3-4.dsc
  to main/o/openmpi/openmpi_1.3.3-4.dsc



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 559...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Manuel Prinz man...@debian.org (supplier of updated openmpi package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@debian.org)


-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

Format: 1.8
Date: Tue, 08 Dec 2009 00:58:02 +0100
Source: openmpi
Binary: openmpi-bin libopenmpi-dev libopenmpi1.3 openmpi-common openmpi-doc 
libopenmpi-dbg openmpi-checkpoint
Architecture: source amd64 all
Version: 1.3.3-4
Distribution: unstable
Urgency: medium
Maintainer: Debian OpenMPI Maintainers 
pkg-openmpi-maintain...@lists.alioth.debian.org
Changed-By: Manuel Prinz man...@debian.org
Description: 
 libopenmpi-dbg - high performance message passing library -- debug library
 libopenmpi-dev - high performance message passing library -- header files
 libopenmpi1.3 - high performance message passing library -- shared library
 openmpi-bin - high performance message passing library -- binaries
 openmpi-checkpoint - high performance message passing library -- checkpoint 
support
 openmpi-common - high performance message passing library -- common files
 openmpi-doc - high performance message passing library -- man pages
Closes: 559836
Changes: 
 openmpi (1.3.3-4) unstable; urgency=medium
 .
   * Fixed security issue in copy of libtool, see CVE-2009-3736.
 Closes: #559836.
Checksums-Sha1: 
 b3ab7e772eb9075bd378c197de5c0be3671f76cd 1585 openmpi_1.3.3-4.dsc
 add0e08c0f5532a26dea91a112239663d0b42e64 22962 openmpi_1.3.3-4.diff.gz
 b49018cd4f726624bb86a50ddfdd5f86176d4736 139812 openmpi-bin_1.3.3-4_amd64.deb
 

Bug#559765: jetty: CVE-2007-6672 info disclosure

2009-12-08 Thread Michael Gilbert
this reference may be informative:
http://lists.alioth.debian.org/pipermail/secure-testing-team/2009-May/002394.html

mike



-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Processed: Re: Bug#556867: cups-pdf: strong kerning errors

2009-12-08 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org:

 severity 556867 important
Bug #556867 [ghostscript] cups-pdf: strong kerning errors
Severity set to 'important' from 'grave'

 thanks
Stopping processing here.

Please contact me if you need assistance.

Debian bug tracking system administrator
(administrator, Debian Bugs database)


-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#560055: FTBFS: pkg-config.patch fails to apply

2009-12-08 Thread dann frazier
Package: hdf-eos5
Version: 5.1.12.dfsg.2-1
Severity: serious

hdf-eos5 fails to build from source. From a recent build attempt:
[...]
configure.ac:150: warning: AC_LANG_PROGRAM(Fortran): ignoring PROLOGUE: []
../../lib/autoconf/lang.m4:211: AC_LANG_SOURCE is expanded from...
../../lib/autoconf/lang.m4:228: AC_LANG_PROGRAM is expanded from...
../../lib/autoconf/lang.m4:194: AC_LANG_CONFTEST is expanded from...
../../lib/autoconf/general.m4:2628: _AC_LINK_IFELSE is expanded from...
../../lib/autoconf/general.m4:2645: AC_LINK_IFELSE is expanded from...
../../lib/autoconf/general.m4:2654: AC_TRY_LINK is expanded from...
configure.ac:150: the top level
mkdir -p .
/usr/bin/make -f debian/rules reverse-config
make[1]: Entering directory `/build/buildd/hdf-eos5-5.1.12.dfsg.2'
for i in ./config/config.guess ./config/config.sub  ; do \
if test -e $i.cdbs-orig ; then \
mv $i.cdbs-orig $i ; \
fi ; \
done
make[1]: Leaving directory `/build/buildd/hdf-eos5-5.1.12.dfsg.2'
cd .  QUILT_PATCHES=/build/buildd/hdf-eos5-5.1.12.dfsg.2/debian/patches quilt 
--quiltrc /dev/null push -a || test $? = 2
Applying patch pthreads.patch
patching file testdrivers/threads/Makefile.in
Hunk #1 succeeded at 228 (offset 7 lines).

Applying patch pkg-config.patch
patching file configure.ac
Hunk #1 FAILED at 327.
1 out of 1 hunk FAILED -- rejects in file configure.ac
The next patch would create the file hdf-eos5.pc.in,
which already exists!  Applying it anyway.
patching file hdf-eos5.pc.in
Hunk #1 FAILED at 1.
1 out of 1 hunk FAILED -- rejects in file hdf-eos5.pc.in
Patch pkg-config.patch does not apply (enforce with -f)
make: *** [debian/stamp-patched] Error 1
dpkg-buildpackage: error: debian/rules build gave error exit status 2



-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Processed: Re: taxbird: uses deprecated gtkhtml3.8

2009-12-08 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org:

 severity 559641 serious
Bug #559641 [taxbird] taxbird: uses deprecated gtkhtml3.8
Severity set to 'serious' from 'important'

 thank you
Stopping processing here.

Please contact me if you need assistance.

Debian bug tracking system administrator
(administrator, Debian Bugs database)


-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Processed: reopen 557767

2009-12-08 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org:

 reopen 557767
Bug #557767 {Done: Muammar El Khatib muammarelkha...@gmail.com} [cegui-mk2] 
cegui-mk2: FTBFS compilation error ('class OIS::InputManager’ has no member 
named ‘numKeyboards')
'reopen' may be inappropriate when a bug has been closed with a version;
you may need to use 'found' to remove fixed versions.
 thanks
Stopping processing here.

Please contact me if you need assistance.

Debian bug tracking system administrator
(administrator, Debian Bugs database)


-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#557767: closed by Muammar El Khatib muammarelkha...@gmail.com (Bug#557767: fixed in cegui-mk2 0.6.2-3)

2009-12-08 Thread Laurent Bonnaud
On Sat, 2009-12-05 at 23:09 +, Debian Bug Tracking System wrote:

  cegui-mk2 (0.6.2-3) unstable; urgency=low
  .
* Bug: FTBFS compilation error ('class OIS::InputManager’ has no 
 member named
  ‘numKeyboards') has been fixed in this revision. A patch has 
 been applied
  to CEGuiOgreBaseApplication.cpp. (Closes: #557767)

Thank you for the fix!

However there is still a compilation error:

libtool: compile:  g++ -DHAVE_CONFIG_H -I. -I. -I../../../include 
-I../../../Samples/common/include -I../../../include -I../../.. 
-DCEGUI_SAMPLE_DATAPATH=\/usr/share/CEGUI\ -DOGRE_GUI_GLX 
-DOGRE_CONFIG_LITTLE_ENDIAN -I/usr/include/OGRE -I/usr/include/CEGUI 
-I/usr//include/OIS -I/usr//include -D_REENTRANT -I/usr/include/directfb -g -O2 
-g -Wall -O2 -c CEGuiOgreBaseApplication.cpp  -fPIC -DPIC -o 
.libs/libCEGUISampleHelper_la-CEGuiOgreBaseApplication.o
CEGuiOgreBaseApplication.cpp: In constructor 
‘CEGuiDemoFrameListener::CEGuiDemoFrameListener(CEGuiBaseApplication*, 
Ogre::RenderWindow*, Ogre::Camera*, bool, bool)’:
CEGuiOgreBaseApplication.cpp:226: error: ‘class OIS::InputManager’ has no 
member named ‘getNumberOfDevices’
CEGuiOgreBaseApplication.cpp:234: error: ‘class OIS::InputManager’ has no 
member named ‘getNumberOfDevices’

-- 
Laurent Bonnaud.
http://www.lis.inpg.fr/pages_perso/bonnaud/



smime.p7s
Description: S/MIME cryptographic signature


Bug#560063: FTBFS: autoreconf: automake failed with exit status: 1

2009-12-08 Thread Cyril Brulebois
Package: hdf-eos5
Version: 5.1.12.dfsg.2-1
Severity: serious
Justification: FTBFS

Hi,

in addition to #560055 (which may or may not be due to the version of
dpkg-dev installed on the buildds), one can get the following failure:
| […]
| configure.ac:150: the top level
| configure.ac:592: required file `gctp/Makefile.in' not found
| configure.ac:592: required file `gctp/include/Makefile.in' not found
| configure.ac:592: required file `gctp/src/Makefile.in' not found
| Makefile.am:20: required directory ./gctp does not exist
| autoreconf: automake failed with exit status: 1
| make: *** [makebuilddir/libhe5-hdfeos-dev] Error 1

Build logs at the usual place:
  https://buildd.debian.org/status/package.php?suite=unstablep=hdf-eos5

Mraw,
KiBi.



-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Processed: fixed

2009-12-08 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org:

 notfound 555439 2.6-3
Bug #555439 {Done: Arthur Loiret aloi...@debian.org} [llvm-dev] syntax errors 
in llvm-config
Ignoring request to alter found versions of bug #555439 to the same values 
previously set

End of message, stopping processing here.

Please contact me if you need assistance.

Debian bug tracking system administrator
(administrator, Debian Bugs database)


-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#490216: marked as done (llvm_2.3-1~exp0/ia64: FTBFS: ExecutionEngine.h:260: undefined reference to `__register_frame')

2009-12-08 Thread Debian Bug Tracking System
Your message dated Tue, 8 Dec 2009 18:18:35 +0100
with message-id dacf4780912080918y5de92df2m391fe4103b95c...@mail.gmail.com
and subject line ANAIS
has caused the Debian Bug report #490216,
regarding llvm_2.3-1~exp0/ia64: FTBFS: ExecutionEngine.h:260: undefined 
reference to `__register_frame'
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
490216: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=490216
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
---BeginMessage---
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

Package: llvm
Version: 2.3-1~exp0
Severity: serious

Your upload of llvm fails to build from source on the ia64 experimental
autobuilder.

On Thu, Jul 10, 2008 at 12:33:31AM +, Buildd user wrote:
 Automatic build of llvm_2.3-1~exp0 on alkman.ayous.org by sbuild/ia64 98-farm
 Build started at 20080709-2337
 **
 Checking available source versions...
 Fetching source files...
 Reading package lists...
 Building dependency tree...
 Need to get 5811kB of source archives.
 Get:1 http://debian.oregonstate.edu experimental/main llvm 2.3-1~exp0 (dsc) 
 [1339B]
 Get:2 http://debian.oregonstate.edu experimental/main llvm 2.3-1~exp0 (tar) 
 [5796kB]
 Get:3 http://debian.oregonstate.edu experimental/main llvm 2.3-1~exp0 (diff) 
 [13.4kB]
 Fetched 5811kB in 2s (2885kB/s)
 Download complete and in download only mode
 ** Using build dependencies supplied by package:
 Build-Depends: debhelper (= 6.0.0), flex, bison, dejagnu, tcl8.4, expect, 
 autoconf, automake1.9, perl, libtool, doxygen, chrpath, texinfo, sharutils
[...]
 llvm[3]: Linking Release executable lli (without symbols)
 /build/buildd/llvm-2.3/build-llvm/mklib --tag=CXX --tag=disable-shared 
 --mode=link ia64-linux-gnu-g++ -I/build/buildd/llvm-2.3/build-llvm/include 
 -I/build/buildd/llvm-2.3/build-llvm/tools/lli 
 -I/build/buildd/llvm-2.3/include -I/build/buildd/llvm-2.3/tools/lli  -D_DEBUG 
  -D_GNU_SOURCE -D__STDC_LIMIT_MACROS -O2 -fomit-frame-pointer -fno-exceptions 
 -g -O2 -Woverloaded-virtual -pedantic -Wall -W -Wwrite-strings -Wno-long-long 
 -Wunused -Wno-unused-parameter  -O2  -rpath 
 /build/buildd/llvm-2.3/build-llvm/Release/bin -export-dynamic 
 -L/build/buildd/llvm-2.3/build-llvm/Release/lib 
 -L/build/buildd/llvm-2.3/build-llvm/Release/lib   -o 
 /build/buildd/llvm-2.3/build-llvm/Release/bin/lli  
 /build/buildd/llvm-2.3/build-llvm/tools/lli/Release/lli.o -lLLVMBitReader 
 /build/buildd/llvm-2.3/build-llvm/Release/lib/LLVMIA64.o -lLLVMSelectionDAG 
 /build/buildd/llvm-2.3/build-llvm/Release/lib/LLVMInterpreter.o 
 /build/buildd/llvm-2.3/build-llvm/Release/lib/LLVMExecutionEngine.o 
 /build/buildd/llvm-2.3/build-llvm/Release/lib/LLVMJIT.o -lLLVMCodeGen 
 -lLLVMScalarOpts -lLLVMTransformUtils -lLLVMipa -lLLVMAnalysis -lLLVMTarget 
 -lLLVMCore -lLLVMSupport -lLLVMSystem 
 -L/build/buildd/llvm-2.3/build-llvm/Release/lib \
  -lpthread -ldl -lm 
 ia64-linux-gnu-g++ -I/build/buildd/llvm-2.3/build-llvm/include 
 -I/build/buildd/llvm-2.3/build-llvm/tools/lli 
 -I/build/buildd/llvm-2.3/include -I/build/buildd/llvm-2.3/tools/lli -D_DEBUG 
 -D_GNU_SOURCE -D__STDC_LIMIT_MACROS -O2 -fomit-frame-pointer -fno-exceptions 
 -g -O2 -Woverloaded-virtual -pedantic -Wall -W -Wwrite-strings -Wno-long-long 
 -Wunused -Wno-unused-parameter -O2 -o 
 /build/buildd/llvm-2.3/build-llvm/Release/bin/lli 
 /build/buildd/llvm-2.3/build-llvm/tools/lli/Release/lli.o 
 /build/buildd/llvm-2.3/build-llvm/Release/lib/LLVMIA64.o 
 /build/buildd/llvm-2.3/build-llvm/Release/lib/LLVMInterpreter.o 
 /build/buildd/llvm-2.3/build-llvm/Release/lib/LLVMExecutionEngine.o 
 /build/buildd/llvm-2.3/build-llvm/Release/lib/LLVMJIT.o -Wl,--export-dynamic  
 -L/build/buildd/llvm-2.3/build-llvm/Release/lib -lLLVMBitReader 
 -lLLVMSelectionDAG -lLLVMCodeGen -lLLVMScalarOpts -lLLVMTransformUtils 
 -lLLVMipa -lLLVMAnalysis -lLLVMTarget -lLLVMCore -lLLVMSupport -lLLVMSystem 
 -lpthread -ldl -lm -Wl,--rpath 
 -Wl,/build/buildd/llvm-2.3/build-llvm/Release/bin
 /build/buildd/llvm-2.3/build-llvm/Release/lib/LLVMJIT.o: In function 
 `llvm::ExecutionEngine::InstallExceptionTableRegister(void (*)(void*))':
 /build/buildd/llvm-2.3/include/llvm/ExecutionEngine/ExecutionEngine.h:260: 
 undefined reference to `__register_frame'
 collect2: ld returned 1 exit status
 make[3]: *** [/build/buildd/llvm-2.3/build-llvm/Release/bin/lli] Error 1
 make[3]: Leaving directory `/build/buildd/llvm-2.3/build-llvm/tools/lli'
 make[2]: *** [lli/.makeall] Error 2
 make[2]: Leaving directory `/build/buildd/llvm-2.3/build-llvm/tools'
 

Bug#559986: FTBFS: default-jdk-builddep: Depends: gcj-jdk but it is not going to be installed

2009-12-08 Thread Cyril Brulebois
Adam C Powell IV hazel...@debian.org (08/12/2009):
 Uh, how is that not a bug in default-jdk-builddep, if that's what's
 failing to install?
 
 I'm going to reassign unless there's a reason not to.

If the build was tried, edos must have found a solution. It could just
be apt-get being stupid. Or edos failed to detect an uninstallability
issue. You may want to clone/reassign/block etc. this bug, rather than
just reassigning it, your package does fail to build.

Mraw,
KiBi.


signature.asc
Description: Digital signature


Bug#560068: libslang2: Library reduction for Debian Installer fails

2009-12-08 Thread Frans Pop
Package: libslang2
Version: 2.2.2-1
Severity: serious
Tags: d-i
Justification: Breaks Debian Installer image builds

Since the update of libslang2 earlier today building Debian Installer images
on amd64 fails during library reduction (mklibs) with:

/usr/bin/ld: /usr/lib//libslang.a(sldisply.o): relocation R_X86_64_32 against 
`.bss' can not be used when making a shared object; recompile with -fPIC
/usr/lib//libslang.a: could not read symbols: Bad value
collect2: ld returned 1 exit status
Command failed with status 1 : gcc -nostdlib -nostartfiles -shared 
-Wl,-soname=libnewt.so.0.52 -unewtVerticalScrollbar -unewtPopHelpLine 
-unewtTextboxSetHeight -unewtFormSetHeight -unewtCompactButton -unewtListbox 
-unewtCheckboxSetFlags -unewtSetColors -unewtListboxSetCurrent 
-unewtCenteredWindow -unewtListboxAppendEntry -unewtDrawForm -unewtScaleSet 
-unewtForm -unewtPushHelpLine -unewtFormSetBackground -unewtFormWatchFd 
-unewtDefaultColorPalette -unewtFormSetTimer -unewtRefresh 
-unewtFormAddComponent -unewtPopWindow -unewtGetScreenSize 
-unewtSetHelpCallback -unewtScale -unewtFormRun -unewtFormSetWidth -unewtCls 
-unewtFormSetCurrent -unewtEntry -unewtInit -unewtRunForm 
-unewtListboxGetCurrent -unewtCheckbox -unewtComponentTakesFocus 
-unewtDrawRootText -unewtFormDestroy -unewtTextboxSetText 
-unewtFormAddComponents -unewtFinished -unewtTextbox -unewtEntrySet -unewtLabel 
-unewtTextboxGetNumLines -o ./tmp/netboot/tree/lib/libnewt.so.0.52-so 
/usr/lib//libnewt_pic.a -Wl,--version-s
 cript=/usr/lib//libnewt_pic.map -lgcc -L./tmp/netboot/tree/lib 
-L./tmp/netboot/tree/usr/lib -L./tmp/netboot/udeblibs 
-L./tmp/netboot/tree/usr/lib/cdebconf/frontend -L/lib/ -L/usr/lib/ 
-L/usr/X11R6/lib/ -L./tmp/netboot/tree//usr/lib/cdebconf -lslang -lc

I've verified that the udeb used during the D-I build has the same version
as the libslang2 packages installed on the system.

-- System Information:
Debian Release: squeeze/sid
  APT prefers unstable
  APT policy: (500, 'unstable')
Architecture: amd64 (x86_64)

Kernel: Linux 2.6.32 (SMP w/2 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/bash

Versions of packages libslang2 depends on:
ii  libc6 2.10.2-2   GNU C Library: Shared libraries

Versions of packages libslang2 recommends:
ii  libpng12-01.2.41-1   PNG library - runtime

libslang2 suggests no packages.

-- no debconf information



-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#560067: network-manager-gnome: nm connects to WPA2 with certificate after .pem file was delated

2009-12-08 Thread Witold Baryluk
Package: network-manager-gnome
Version: 0.7.2-1
Severity: grave
Tags: security
Justification: user security hole

After configuring WPA2 Enterprise with TTLS and PAP, I was using certificate 
file
in /etc/ssl/certs/...pem  (autmatically imported from 
/usr/local/share/ca-certificates/domain/certrootfile.crt)


Then i reinstalled system, and not configured certifcates yet.

After reinstalling system and restoring /home directory, i logged into my new 
stystem.

After giving password to gnome-keyring NM automatically connected to my network,
even cosindering that it is not existing:

** (nm-applet:6704): WARNING **: utils_fill_connection_certs: couldn't read CA 
certificate: 4 Nie można otworzyć pliku 
/etc/ssl/certs/SMP_Root_Certification_Authority_2.pem: Nie ma takiego pliku 
ani katalogu



But NM thinks that it should connect anyway. And it connects,
possibly leaking my credentials, login and password, and all
keys, and of course network traffic.


It should be considerebly more verbose error provided to an user (using 
nm-applet),
and NM should abort connecting.



-- System Information:
Debian Release: squeeze/sid
  APT prefers unstable
  APT policy: (500, 'unstable')
Architecture: i386 (i686)

Kernel: Linux 2.6.31-1-686-bigmem (SMP w/1 CPU core)
Locale: LANG=pl_PL.UTF-8, LC_CTYPE=pl_PL.UTF-8 (charmap=UTF-8) (ignored: LC_ALL 
set to pl_PL.UTF-8)
Shell: /bin/sh linked to /bin/dash

Versions of packages network-manager-gnome depends on:
ii  dbus-x11  1.2.16-2   simple interprocess messaging syst
ii  gconf22.28.0-1   GNOME configuration database syste
ii  gnome-icon-theme  2.28.0-1   GNOME Desktop icon theme
ii  libc6 2.10.2-2   GNU C Library: Shared libraries
ii  libdbus-1-3   1.2.16-2   simple interprocess messaging syst
ii  libdbus-glib-1-2  0.82-2 simple interprocess messaging syst
ii  libgconf2-4   2.28.0-1   GNOME configuration database syste
ii  libglade2-0   1:2.6.4-1  library to load .glade files at ru
ii  libglib2.0-0  2.22.3-1   The GLib library of C routines
ii  libgnome-keyring0 2.28.1-2   GNOME keyring services library
ii  libgtk2.0-0   2.18.4-1   The GTK+ graphical user interface 
ii  libnm-glib-vpn0   0.7.2-2network management framework (GLib
ii  libnm-glib0   0.7.2-2network management framework (GLib
ii  libnm-util1   0.7.2-2network management framework (shar
ii  libnotify1 [libnotify1-gtk2.1 0.4.5-1sends desktop notifications to a n
ii  libpango1.0-0 1.26.1-1   Layout and rendering of internatio
ii  libpolkit-gnome0  0.9.2-2PolicyKit-gnome library
ii  libpolkit20.9-4  library for accessing PolicyKit
ii  network-manager   0.7.2-2network management framework daemo
ii  policykit-gnome   0.9.2-2GNOME dialogs for PolicyKit

Versions of packages network-manager-gnome recommends:
ii  libpam-gnome-keyring [libpam- 2.28.1-2   PAM module to unlock the GNOME key
ii  notification-daemon   0.4.0-2a daemon that displays passive pop

Versions of packages network-manager-gnome suggests:
ii  network-manager-openvpn-gnome 0.7.2-1network management framework (Open
ii  network-manager-pptp-gnome0.7.2-1network management framework (PPTP
ii  network-manager-vpnc-gnome0.7.2-1network management framework (VPNC

-- no debconf information



-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#558463: Cups fails to print after upgrade

2009-12-08 Thread André Wöbbeking
Hi,

even with cups (1.4.2-4) installed I still can't print.


Cheers,
André



--
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#559980: aptitude: Totally broken on GNU/kFreeBSD

2009-12-08 Thread Cyril Brulebois
Petr Salinger petr.salin...@seznam.cz (08/12/2009):
 It might be due to The use of the sigprocmask() function is
 unspecified in a multi-threaded process.
 http://www.opengroup.org/onlinepubs/9699919799/functions/pthread_sigmask.html

 I do not have kfreebsd box handy now.
 Kibi, please, does it work with pthread_sigmask() instead of sigprocmask() ?

It indeed seems to work fine. Please find attached the new patch.

[ By the way, my original patch isn't very okay actually. __GLIBC__
gets set on Linux too, e.g. when stdio.h gets included, which is quite
common; sorry about that, and many thanks to kolter for raising this
point on IRC. ]

Mraw,
KiBi.
--- a/src/main.cc
+++ b/src/main.cc
@@ -535,7 +535,7 @@ int main(int argc, char *argv[])
 
 sigaddset(mask, SIGWINCH);
 
-sigprocmask(SIG_SETMASK, mask, NULL);
+pthread_sigmask(SIG_SETMASK, mask, NULL);
   }
 
   srandom(time(0));


signature.asc
Description: Digital signature


Processed: severity of 549074 is serious

2009-12-08 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org:

 severity 549074 serious
Bug #549074 [opensync-plugin-moto] Unattainable Dependency 
'opensync-plugin-moto'
Severity set to 'serious' from 'important'


End of message, stopping processing here.

Please contact me if you need assistance.

Debian bug tracking system administrator
(administrator, Debian Bugs database)


-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Processed: severity of 553253 is serious

2009-12-08 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org:

 severity 553253 serious
Bug #553253 [calendarserver] calendarserver: uninstallable due to broken 
dependency
Severity set to 'serious' from 'normal'


End of message, stopping processing here.

Please contact me if you need assistance.

Debian bug tracking system administrator
(administrator, Debian Bugs database)


-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#560072: FTBFS: java-gcj-compat-dev can't be installed

2009-12-08 Thread Cyril Brulebois
Package: brltty
Version: 4.1-2
Severity: serious
Justification: FTBFS

Hi,

your package FTBFS on some archs because java-gcj-compat-dev can't be
installed:
|   java-gcj-compat-dev: Depends: java-gcj-compat (= 1.0.80-5.1)
|Depends: gcj but it is not going to be installed
| E: Broken packages

This wasn't detected by edos, so it might be a bug anywhere within:
 - edos
 - sbuild
 - java stuff
 - your package.

I don't think your package is responsible, but it still currently FTBFS,
so let's open a bug to track this.

Build logs as usual:
  https://buildd.debian.org/status/package.php?suite=unstablep=brltty

Hopefully a give back once the bug found and fixed will be sufficient.

Mraw,
KiBi.



-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Processed: severity of 434925 is serious

2009-12-08 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org:

 # Automatically generated email from bts, devscripts version 2.10.25~bpo40+1
 severity 434925 serious
Bug #434925 [suikyo-elisp] suikyo-elisp: please prefer emacs22
Severity set to 'serious' from 'important'


End of message, stopping processing here.

Please contact me if you need assistance.

Debian bug tracking system administrator
(administrator, Debian Bugs database)


-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org




Processed: unmerging 449272, reassign 449272 to linux-2.6

2009-12-08 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org:

 unmerge 449272
Bug#449272: Alternative (buggy, incomplete) firewire stack shipped instead of 
the stable one
Bug#438336: kino: Depends on deprecated raw1394
Disconnected #449272 from all other report(s).

 reassign 449272 linux-2.6
Bug #449272 [kino] Alternative (buggy, incomplete) firewire stack shipped 
instead of the stable one
Bug reassigned from package 'kino' to 'linux-2.6'.

End of message, stopping processing here.

Please contact me if you need assistance.

Debian bug tracking system administrator
(administrator, Debian Bugs database)


-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#559820: marked as done (CVE-2009-3736 local privilege escalation)

2009-12-08 Thread Debian Bug Tracking System
Your message dated Tue, 08 Dec 2009 19:54:47 +0200
with message-id 87ljhd73mg@bubble.risko.hu
and subject line libtool is only included in libmcrypt's source package, but 
never goes into the binary
has caused the Debian Bug report #559820,
regarding CVE-2009-3736 local privilege escalation
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
559820: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=559820
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
---BeginMessage---
Package: libmcrypt
Severity: grave
Tags: security

Hi,

The following CVE (Common Vulnerabilities  Exposures) id was
published for libtool.  I have determined that this package embeds a
vulnerable copy of the libtool source code.  However, since this is a
mass bug filing (due to so many packages embedding libtool), I have not
had time to determine whether the vulnerable code is actually present
in any of the binary packages. Please determine whether this is the
case. If the binary packages are not affected, please feel free to close
the bug with a message containing the details of what you did to check.

CVE-2009-3736[0]:
| ltdl.c in libltdl in GNU Libtool 1.5.x, and 2.2.6 before 2.2.6b,
| attempts to open a .la file in the current working directory, which
| allows local users to gain privileges via a Trojan horse file.

Note that this problem also affects etch and lenny, so if your package
is affected, please coordinate with the security team to release the
DSA for the affected packages.

If you fix the vulnerability please also make sure to include the
CVE id in your changelog entry.

For further information see:

[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3736
http://security-tracker.debian.org/tracker/CVE-2009-3736


---End Message---
---BeginMessage---
Hi,

SSIA.

In the configure.in there is an `AC_ARG_ENABLE(dynamic-loading...', but
--enable-dynamic-loading is not specified in debian/rules.

Neither in the current version, nor in the oldstable/stable/testing
version.

Thanks for the report,
Gergely

---End Message---


Processed: retitle 438336 to kino: capture doesn't work anymore, block 438336 by 545112

2009-12-08 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org:

 retitle 438336 kino: capture doesn't work anymore, block 438336 by 545112
Bug #438336 [kino] kino: Depends on deprecated raw1394
Changed Bug title to 'kino: capture doesn't work anymore, block 438336 by 
545112' from 'kino: Depends on deprecated raw1394'

End of message, stopping processing here.

Please contact me if you need assistance.

Debian bug tracking system administrator
(administrator, Debian Bugs database)


-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#559992: FTBFS [hppa] - ruby1.9: command not found

2009-12-08 Thread dann frazier
On Tue, Dec 08, 2009 at 03:10:41PM +0100, Nico Golde wrote:
 Hi,
 * dann frazier da...@debian.org [2009-12-08 13:30]:
  Package: stfl
  Version: 0.21-1
  Severity: serious
  User: debian-h...@lists.debian.org
  Usertags: hppa
  
  stfl reliably fails to build on hppa:

  https://buildd.debian.org/build.php?pkg=stflver=0.21-1arch=hppafile=log
 
 Hmm. It fails because it doesn't find ruby1.9. Why is that? It is in the 
 Depends and the binary is also in the ruby1.9 hppa packages.

Yep, looks like the previous buildd maintainer installed a diversion
to prevent hangs that were being triggered by ruby1.9. I disabled
this diversion, and stfl built fine. Sorry about that :)

-- 
dann frazier




-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#560074: ntp: CVE-2009-3563 DoS through mode 7 packets

2009-12-08 Thread Nico Golde
Package: ntp
Severity: grave
Tags: security

Hi,
the following CVE (Common Vulnerabilities  Exposures) id was
published for ntp.

CVE-2009-3563[0]:
| The topology used includes two nodes running ntp and an attacker's PC:
| 
| PC---  [node1 ntpd1]:11.0.0.1 11.0.0.2:[node2 ntpd2]
| 
| PC sends one crafted UDP packet with one byte payload 0x17, i.e. NTP Request 
in
| mode 7.
| This UDP packet has spoofed source IP of 11.0.0.2, destination = 11.0.0.1,
| source port 123 and destination port 123.
| Node1 responds with mode 7 Error Response to Node2, and here comes something 
we
| cannot conceive. Ntpd2 responds back with the same mode 7 Error Response to
| Node1, Ntpd1 does again the same, etc. with the aggregate rate of few thousand
| pps. CPU is taken away on both sides, network is busy...
| Better yet, if we spoof the Node1's address 11.0.0.1 as a source, Node1 sends
| all these packets to itself all the time! Endless.
| Payload 97 00 00 00 (Response mode 7) works too.
| If you fix the vulnerability please also make sure to include the
| CVE id in your changelog entry.

Upstream has release 4.2.4p8 to fix this issue.

For further information see:

[0] https://support.ntp.org/bugs/show_bug.cgi?id=1331
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3563
http://security-tracker.debian.org/tracker/CVE-2009-3563

-- 
Nico Golde - http://www.ngolde.de - n...@jabber.ccc.de - GPG: 0xA0A0
For security reasons, all text in this mail is double-rot13 encrypted.


pgp6YCCk7wJKN.pgp
Description: PGP signature


Bug#556983: marked as done (ofono-phonesim: add trolltech to copyright file)

2009-12-08 Thread Debian Bug Tracking System
Your message dated Tue, 08 Dec 2009 18:49:01 +
with message-id e1ni57n-0008k9...@ries.debian.org
and subject line Bug#556983: fixed in ofono-phonesim 1.0-2
has caused the Debian Bug report #556983,
regarding ofono-phonesim: add trolltech to copyright file
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
556983: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=556983
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
---BeginMessage---
Package: ofono-phonesim
Version: 1.0-1
Severity: serious

 In debian/copyright
 you have the copyright holder as Intel.  As far as I can tell, most
 of the files are (C) Trolltech.  Should probably be corrected in a
 subsequent upload.
 

Thanks!  I will fix that in the next upload.  I'm filing a bug so that
I don't forget.


---End Message---
---BeginMessage---
Source: ofono-phonesim
Source-Version: 1.0-2

We believe that the bug you reported is fixed in the latest version of
ofono-phonesim, which is due to be installed in the Debian FTP archive:

ofono-phonesim_1.0-2.diff.gz
  to main/o/ofono-phonesim/ofono-phonesim_1.0-2.diff.gz
ofono-phonesim_1.0-2.dsc
  to main/o/ofono-phonesim/ofono-phonesim_1.0-2.dsc
ofono-phonesim_1.0-2_i386.deb
  to main/o/ofono-phonesim/ofono-phonesim_1.0-2_i386.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 556...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Andres Salomon dilin...@debian.org (supplier of updated ofono-phonesim 
package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@debian.org)


-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

Format: 1.8
Date: Tue, 08 Dec 2009 18:22:13 +
Source: ofono-phonesim
Binary: ofono-phonesim
Architecture: source i386
Version: 1.0-2
Distribution: unstable
Urgency: low
Maintainer: Andres Salomon dilin...@debian.org
Changed-By: Andres Salomon dilin...@debian.org
Description: 
 ofono-phonesim - Modem emulator used by the oFono mobile telephony stack
Closes: 556983
Changes: 
 ofono-phonesim (1.0-2) unstable; urgency=low
 .
   * Fix up debian/copyright (closes: #556983).
Checksums-Sha1: 
 7e63bcd25f96f99d55e309a1468a5bb77dd17a7a 1048 ofono-phonesim_1.0-2.dsc
 ff1fb5bd51769489e45c0eec73ccf62081139fc6 1454 ofono-phonesim_1.0-2.diff.gz
 edd7b81a92dbad24a1b0440756babfa873af6062 241600 ofono-phonesim_1.0-2_i386.deb
Checksums-Sha256: 
 c630456946eb81d98b3160f9bc81506d47de5ef2103ec17c69bab60c6ea3f8e7 1048 
ofono-phonesim_1.0-2.dsc
 77af4b8346f80be6660c14cbe98433799d48b4d3b7459e8d98220efaf6f3 1454 
ofono-phonesim_1.0-2.diff.gz
 1b762d58d15e7e06fbba22e0dcc2b909e56b9876f671a2622562a24c355e96ce 241600 
ofono-phonesim_1.0-2_i386.deb
Files: 
 89ec5695a1ad4b677cf3c458b58c7b16 1048 devel optional ofono-phonesim_1.0-2.dsc
 fb176cab65d9c9f0b4ab47cc429272b4 1454 devel optional 
ofono-phonesim_1.0-2.diff.gz
 b8cf715bc128a4c08caf88e9305f2952 241600 devel optional 
ofono-phonesim_1.0-2_i386.deb

-BEGIN PGP SIGNATURE-
Version: GnuPG v1.4.9 (GNU/Linux)

iEYEARECAAYFAksem64ACgkQOmXwGc/ULybvfwCeJ3VNCqZ1EGV7hQJFFIrsv8DL
umIAnjLPyiDxWffcKQ87Ip3BMLKbdldj
=g0+b
-END PGP SIGNATURE-


---End Message---


Processed: tagging as pending bugs that are closed by packages in NEW

2009-12-08 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org:

 # Tue Dec  8 19:03:25 UTC 2009
 # Tagging as pending bugs that are closed by packages in NEW
 # http://ftp-master.debian.org/new.html
 #
 # Source package in NEW: execnet
 tags 559152 + pending
Bug #559152 [wnpp] ITP: python-execnet -- perform zero-install bootstrapping 
into other interpreters
Added tag(s) pending.
 # Source package in NEW: envstore
 tags 558684 + pending
Bug #558684 [wnpp] ITP: envstore -- save and restore environment variables
Added tag(s) pending.
 # Source package in NEW: cecil-flowanalysis
 tags 556837 + pending
Bug #556837 [src:cecil-flowanalysis] cecil-flowanalysis: FTBFS: mono stuff
Added tag(s) pending.
 # Source package in NEW: cecil-flowanalysis
 tags 493513 + pending
Bug #493513 [cecil-flowanalysis] libmono-cecil-flowanalysis0.1-cil needs better 
short and long descriptions
Added tag(s) pending.

End of message, stopping processing here.

Please contact me if you need assistance.

Debian bug tracking system administrator
(administrator, Debian Bugs database)


-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#545043: marked as done (taxbird: Taxbird fails to send data: ERROR: Value out of range 0 to 16: 50)

2009-12-08 Thread Debian Bug Tracking System
Your message dated Tue, 8 Dec 2009 19:55:22 +0100
with message-id 200912081955.26571.m...@der-marv.de
and subject line Re: taxbird: Taxbird fails to send data: ERROR: Value out of 
range 0 to 16: 50
has caused the Debian Bug report #545043,
regarding taxbird: Taxbird fails to send data: ERROR: Value out of range 0 to 
16: 50
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
545043: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=545043
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
---BeginMessage---
Package: taxbird
Version: 0.12-2
Severity: grave
Justification: renders package unusable

When trying to send the data the following message is printed in the
console, and nothing else happens.

** (taxbird:22534): CRITICAL **: global error handler called, damn.

No backtrace available.
ERROR: Value out of range 0 to 16: 50



-- System Information:
Debian Release: squeeze/sid
  APT prefers testing
  APT policy: (990, 'testing'), (500, 'unstable')
Architecture: amd64 (x86_64)

Kernel: Linux 2.6.30-1-amd64 (SMP w/2 CPU cores)
Locale: LANG=en_GB.UTF-8, LC_CTYPE=en_GB.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/bash

Versions of packages taxbird depends on:
ii  guile-1.8-libs1.8.7+1-1  Main Guile libraries
ii  libart-2.0-2  2.3.20-2   Library of functions for 2D graphi
ii  libatk1.0-0   1.26.0-1   The ATK accessibility toolkit
ii  libbonobo2-0  2.24.1-1   Bonobo CORBA interfaces library
ii  libbonoboui2-02.24.1-1   The Bonobo UI library
ii  libc6 2.9-25 GNU C Library: Shared libraries
ii  libcairo2 1.8.8-2The Cairo 2D vector graphics libra
ii  libfontconfig12.6.0-4generic font configuration library
ii  libfreetype6  2.3.9-5FreeType 2 font engine, shared lib
ii  libgconf2-4   2.26.2-3   GNOME configuration database syste
ii  libgeier0 0.10-1 Elster client library (German tax 
ii  libglade2-0   1:2.6.4-1  library to load .glade files at ru
ii  libglib2.0-0  2.20.4-1   The GLib library of C routines
ii  libgmp3c2 2:4.3.1+dfsg-3 Multiprecision arithmetic library
ii  libgnome2-0   2.26.0-1   The GNOME library - runtime files
ii  libgnomecanvas2-0 2.26.0-1   A powerful object-oriented display
ii  libgnomeui-0  2.24.1-1   The GNOME 2 libraries (User Interf
ii  libgnomevfs2-01:2.24.1-4 GNOME Virtual File System (runtime
ii  libgtk2.0-0   2.16.5-1   The GTK+ graphical user interface 
ii  libgtkhtml2-0 2.11.1-2   HTML rendering/editing library - r
ii  libice6   2:1.0.5-1  X11 Inter-Client Exchange library
ii  libltdl7  2.2.6a-4   A system independent dlopen wrappe
ii  liborbit2 1:2.14.17-0.1  libraries for ORBit2 - a CORBA ORB
ii  libpango1.0-0 1.24.5-1   Layout and rendering of internatio
ii  libpopt0  1.14-4 lib for parsing cmdline parameters
ii  libsm62:1.1.0-2  X11 Session Management library
ii  libxml2   2.7.3.dfsg-2.1 GNOME XML library

Versions of packages taxbird recommends:
ii  cups-bsd [lpr]   1.3.11-1+b1 Common UNIX Printing System(tm) - 

Versions of packages taxbird suggests:
ii  html2ps   1.0b5-5HTML to PostScript converter
ii  html2text 1.3.2a-14  advanced HTML to text converter

-- no debconf information


---End Message---
---BeginMessage---
Hi,

I forgot to close this bug. This issue is fixed in 0.14.

Regards,
-- 
 .`. Marvin Stark m...@der-marv.de
: :  :Homepage: www.der-marv.de
`. ``
  `-  Debian - when you have better things to do than fix a system


signature.asc
Description: This is a digitally signed message part.
---End Message---


Bug#556271: marked as done (kazehakase: CVE-2007-1084 bookmarklets cross-site info disclosure)

2009-12-08 Thread Debian Bug Tracking System
Your message dated Tue, 08 Dec 2009 19:03:28 +
with message-id e1ni5lm-0001gi...@ries.debian.org
and subject line Bug#556271: fixed in kazehakase 0.5.8-2
has caused the Debian Bug report #556271,
regarding kazehakase: CVE-2007-1084 bookmarklets cross-site info disclosure
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
556271: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=556271
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
---BeginMessage---
Package: kazehakase
Version: 0.5.8-1
Severity: serious
Tags: security

Hi,

The following CVE (Common Vulnerabilities  Exposures) id was
published.

CVE-2007-1084[0]:
| Mozilla Firefox 2.0.0.1 and earlier does not prompt users before
| saving bookmarklets, which allows remote attackers to bypass the
| same-domain policy by tricking a user into saving a bookmarklet with a
| data: scheme, which is executed in the context of the last visited web
| page.

If you fix the vulnerability please also make sure to include the
CVE id in your changelog entry.

For further information see:

[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1084
http://security-tracker.debian.org/tracker/CVE-2007-1084


---End Message---
---BeginMessage---
Source: kazehakase
Source-Version: 0.5.8-2

We believe that the bug you reported is fixed in the latest version of
kazehakase, which is due to be installed in the Debian FTP archive:

kazehakase-dbg_0.5.8-2_i386.deb
  to main/k/kazehakase/kazehakase-dbg_0.5.8-2_i386.deb
kazehakase-gecko_0.5.8-2_i386.deb
  to main/k/kazehakase/kazehakase-gecko_0.5.8-2_i386.deb
kazehakase-webkit_0.5.8-2_i386.deb
  to main/k/kazehakase/kazehakase-webkit_0.5.8-2_i386.deb
kazehakase_0.5.8-2.diff.gz
  to main/k/kazehakase/kazehakase_0.5.8-2.diff.gz
kazehakase_0.5.8-2.dsc
  to main/k/kazehakase/kazehakase_0.5.8-2.dsc
kazehakase_0.5.8-2_i386.deb
  to main/k/kazehakase/kazehakase_0.5.8-2_i386.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 556...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Yavor Doganov ya...@gnu.org (supplier of updated kazehakase package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@debian.org)


-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

Format: 1.8
Date: Mon, 07 Dec 2009 21:31:11 +0200
Source: kazehakase
Binary: kazehakase kazehakase-gecko kazehakase-webkit kazehakase-dbg
Architecture: source i386
Version: 0.5.8-2
Distribution: unstable
Urgency: medium
Maintainer: Yavor Doganov ya...@gnu.org
Changed-By: Yavor Doganov ya...@gnu.org
Description: 
 kazehakase - GTK+-based web browser that allows pluggable rendering engines
 kazehakase-dbg - GTK+-based web browser (debugging symbols)
 kazehakase-gecko - Gecko rendering engine for kazehakase
 kazehakase-webkit - WebKit rendering engine for kazehakase
Closes: 551268 554935 556271
Changes: 
 kazehakase (0.5.8-2) unstable; urgency=medium
 .
   * debian/patches/CVE-2007-1084.dpatch: New; disallow adding bookmarks
 with data:/javascript: URIs (CVE-2007-1084, Closes: #556271).
   * debian/patches/webkit-uri.dpatch: New; prepend http://; to URIs
 if missing, thanks Andres Salomon (Closes: #551268).
   * debian/patches/47_ldflags-rpath.dpatch: Link kz-embed-process with
 $(GTK_LIBS) to avoid FTBFS with GNU gold, thanks Peter Fritzsche
 (Closes: #554935).
   * debian/patches/50_autoreconf.dpatch: Regenerate.
   * debian/patches/00list: Update.
Checksums-Sha1: 
 c945cc8ec923f8dbc0211a1a6a7e044523268be9 1455 kazehakase_0.5.8-2.dsc
 27d17f2d1e9e863b6fb511fdd85d9d21200add46 57313 kazehakase_0.5.8-2.diff.gz
 2f9e11f0a13a4add1a50ed07c6ddece70e2c4960 708166 kazehakase_0.5.8-2_i386.deb
 50e470390de138d8eeec9aede5831b2ed00b56d7 228556 
kazehakase-gecko_0.5.8-2_i386.deb
 8bb1a4362f4a6edfef3b2614cf84d1298a06a62c 105212 
kazehakase-webkit_0.5.8-2_i386.deb
 7d85fa20525b480aa58bc70a81ce1a64483d634b 1698630 
kazehakase-dbg_0.5.8-2_i386.deb
Checksums-Sha256: 
 0cbf6db3290d00c9c4ed1d6ea796c54ecb317230f75cb58e8004713015123771 1455 
kazehakase_0.5.8-2.dsc
 1ca046e8a8dd2e662b46c77521589def79efc66262dddf02b531d159d3f55eec 57313 
kazehakase_0.5.8-2.diff.gz
 5355c57e94a76cd7b28ed3017dc5eb6a87b298478a330b73ac91215ea0bc7e87 708166 
kazehakase_0.5.8-2_i386.deb
 9c0f85836c17e4a9d2aef64f5ca5c451c934d562b966f4d72129653fc09e3ff7 228556 

Bug#559992: marked as done (FTBFS [hppa] - ruby1.9: command not found)

2009-12-08 Thread Debian Bug Tracking System
Your message dated Tue, 8 Dec 2009 20:12:42 +0100
with message-id 20091208191242.gj25...@ngolde.de
and subject line Re: Bug#559992: FTBFS [hppa] - ruby1.9: command not found
has caused the Debian Bug report #559992,
regarding FTBFS [hppa] - ruby1.9: command not found
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
559992: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=559992
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
---BeginMessage---
Package: stfl
Version: 0.21-1
Severity: serious
User: debian-h...@lists.debian.org
Usertags: hppa

stfl reliably fails to build on hppa:
  https://buildd.debian.org/build.php?pkg=stflver=0.21-1arch=hppafile=log

From the most recent build attempt:
[...]
mv -f Makefile.deps_new Makefile.deps
make[1]: Leaving directory `/build/buildd/stfl-0.21'
make[1]: Entering directory `/build/buildd/stfl-0.21'
gcc -pthread -g -O2 -fPIC -I. -Wall -Os -ggdb -D_GNU_SOURCE -fPIC   -c -o 
public.o public.c
gcc -pthread -g -O2 -fPIC -I. -Wall -Os -ggdb -D_GNU_SOURCE -fPIC   -c -o 
base.o base.c
gcc -pthread -g -O2 -fPIC -I. -Wall -Os -ggdb -D_GNU_SOURCE -fPIC   -c -o 
parser.o parser.c
gcc -pthread -g -O2 -fPIC -I. -Wall -Os -ggdb -D_GNU_SOURCE -fPIC   -c -o 
dump.o dump.c
gcc -pthread -g -O2 -fPIC -I. -Wall -Os -ggdb -D_GNU_SOURCE -fPIC   -c -o 
style.o style.c
gcc -pthread -g -O2 -fPIC -I. -Wall -Os -ggdb -D_GNU_SOURCE -fPIC   -c -o 
binding.o binding.c
gcc -pthread -g -O2 -fPIC -I. -Wall -Os -ggdb -D_GNU_SOURCE -fPIC   -c -o 
iconv.o iconv.c
gcc -pthread -g -O2 -fPIC -I. -Wall -Os -ggdb -D_GNU_SOURCE -fPIC   -c -o 
widgets/wt_box.o widgets/wt_box.c
gcc -pthread -g -O2 -fPIC -I. -Wall -Os -ggdb -D_GNU_SOURCE -fPIC   -c -o 
widgets/wt_input.o widgets/wt_input.c
gcc -pthread -g -O2 -fPIC -I. -Wall -Os -ggdb -D_GNU_SOURCE -fPIC   -c -o 
widgets/wt_label.o widgets/wt_label.c
gcc -pthread -g -O2 -fPIC -I. -Wall -Os -ggdb -D_GNU_SOURCE -fPIC   -c -o 
widgets/wt_list.o widgets/wt_list.c
gcc -pthread -g -O2 -fPIC -I. -Wall -Os -ggdb -D_GNU_SOURCE -fPIC   -c -o 
widgets/wt_table.o widgets/wt_table.c
gcc -pthread -g -O2 -fPIC -I. -Wall -Os -ggdb -D_GNU_SOURCE -fPIC   -c -o 
widgets/wt_textview.o widgets/wt_textview.c
gcc -pthread -shared -Wl,-soname,libstfl.so.0 -o libstfl.so.0.21 public.o 
base.o parser.o dump.o style.o binding.o iconv.o widgets/wt_box.o 
widgets/wt_input.o widgets/wt_label.o widgets/wt_list.o widgets/wt_table.o 
widgets/wt_textview.o -lncursesw
rm -f libstfl.a
ar qc libstfl.a public.o base.o parser.o dump.o style.o binding.o iconv.o 
widgets/wt_box.o widgets/wt_input.o widgets/wt_label.o widgets/wt_list.o 
widgets/wt_table.o widgets/wt_textview.o
ranlib libstfl.a
gcc -pthread -g -O2 -fPIC -I. -Wall -Os -ggdb -D_GNU_SOURCE -fPIC   -c -o 
example.o example.c
gcc -pthread   example.o libstfl.a  -lncursesw -o example
gcc -pthread -shared -fPIC -g -O2 -fPIC -I. -Wall -Os -ggdb -D_GNU_SOURCE -fPIC 
-I/usr/include  spl/mod_stfl.c \
-L. libstfl.a -lncursesw -o spl/mod_stfl.so
make[1]: Leaving directory `/build/buildd/stfl-0.21'
# perl
test ! -f perl5/Makefile || /usr/bin/make -C perl5 clean
cd perl5  swig -perl5 stfl.i  perl Makefile.PL INSTALLDIRS=vendor
../swig/basedecls.i:87: Warning(314): 'dump' is a perl keyword
../swig/basedecls.i:181: Warning(314): 'dump' is a perl keyword
Writing Makefile for stfl
/usr/bin/make -C perl5
make[1]: Entering directory `/build/buildd/stfl-0.21/perl5'
cp example.pl blib/lib/example.pl
cp stfl.pm blib/lib/stfl.pm
cc -c   -pthread -I.. -D_LARGEFILE64_SOURCE -D_GNU_SOURCE -O2 -g   
-DVERSION=\\ -DXS_VERSION=\\ -fPIC -I/usr/lib/perl/5.10/CORE   stfl_wrap.c
Running Mkbootstrap for stfl ()
chmod 644 stfl.bs
rm -f blib/arch/auto/stfl/stfl.so
cc  -shared -O2 -g -L/usr/local/lib stfl_wrap.o ../libstfl.a  -o 
blib/arch/auto/stfl/stfl.so\
   -lpthread -lncursesw \
  
chmod 755 blib/arch/auto/stfl/stfl.so
cp stfl.bs blib/arch/auto/stfl/stfl.bs
chmod 644 blib/arch/auto/stfl/stfl.bs
make[1]: Leaving directory `/build/buildd/stfl-0.21/perl5'
touch build-stamp
cp -a ruby ruby1.8
cd ruby1.8  swig -ruby stfl.i  ruby1.8 extconf.rb
../swig/basedecls.i:51: Warning(801): Wrong class name (corrected to 
`Stfl_form')
../swig/basedecls.i:51: Warning(801): Wrong class name (corrected to 
`Stfl_form')
creating Makefile
/usr/bin/make -C ruby1.8 clean  /usr/bin/make -C ruby1.8 LIBS+=../libstfl.a 
-lncursesw CFLAGS+=-I.. -fPIC
make[1]: Entering directory `/build/buildd/stfl-0.21/ruby1.8'
make[1]: Leaving directory `/build/buildd/stfl-0.21/ruby1.8'
make[1]: Entering directory `/build/buildd/stfl-0.21/ruby1.8'
cc -I. 

Bug#560077: [s3d] FTBFS with libgps-dev 2.90

2009-12-08 Thread Sven Eckelmann
Package: s3d
Version: 0.2.1.1-3
Severity: serious

[ 56%] Building C object apps/s3dosm/CMakeFiles/s3dosm.dir/gps.c.o
cd /tmp/buildd/s3d-0.2.1.1/obj-x86_64-linux-gnu/apps/s3dosm  /usr/bin/gcc   
-g -O2  -I/usr/include/freetype2 -
I/usr/include/glib-2.0 -I/usr/lib/glib-2.0/include -I/usr/include/SDL 
-I/usr/include/libxml2 -I/tmp/buildd/s3d-0.2.1.1/obj-
x86_64-linux-gnu -I/tmp/buildd/s3d-0.2.1.1/libs3d 
-I/tmp/buildd/s3d-0.2.1.1/libs3dw   -Wall -Wextra -pedantic -
fvisibility=hidden -DHAVE_GCCVISIBILITY -o CMakeFiles/s3dosm.dir/gps.c.o   -c 
/tmp/buildd/s3d-0.2.1.1/apps/s3dosm/gps.c
/tmp/buildd/s3d-0.2.1.1/apps/s3dosm/gps.c: In function 'show_gpsdata':
/tmp/buildd/s3d-0.2.1.1/apps/s3dosm/gps.c:58: error: 'struct gps_data_t' has no 
member named 'satellites'
/tmp/buildd/s3d-0.2.1.1/apps/s3dosm/gps.c: In function 'gps_init':
/tmp/buildd/s3d-0.2.1.1/apps/s3dosm/gps.c:216: warning: implicit declaration of 
function 'gps_query'
make[3]: *** [apps/s3dosm/CMakeFiles/s3dosm.dir/gps.c.o] Error 1
make[3]: Leaving directory `/tmp/buildd/s3d-0.2.1.1/obj-x86_64-linux-gnu'
make[2]: *** [apps/s3dosm/CMakeFiles/s3dosm.dir/all] Error 2
make[2]: Leaving directory `/tmp/buildd/s3d-0.2.1.1/obj-x86_64-linux-gnu'
make[1]: *** [all] Error 2
make[1]: Leaving directory `/tmp/buildd/s3d-0.2.1.1/obj-x86_64-linux-gnu'
dh_auto_build: make -j1 returned exit code 2



--- System information. ---
Architecture: amd64
Kernel:   Linux 2.6.31-1-amd64

Debian Release: squeeze/sid
  500 unstableftp.debian.org 
--- Package information. ---
Depends (Version) | Installed
=-+-==
libc6  (= 2.2.5) | 2.10.2-2
libgl1-mesa-glx   | 7.6.1~rc2-1
 OR libgl1| 
libsdl1.2debian (= 1.2.10-1) | 1.2.13-5


Recommends (Version) | Installed
-+-==
dotmcp (= 0.2.1.1-3) | 0.2.1.1-3


Package's Suggests field is empty.





signature.asc
Description: This is a digitally signed message part.


Bug#559578: [Debian-eeepc-devel] Bug#559578: eeepc-acpi-scripts: EeePC 701 freezes with garbled screen while booting

2009-12-08 Thread Alexey Morozov
Hello!

I can confirm this bug. However it 's not a problem with acpi scripts, but 
rather a bug in the kernel [module]. I experience exactly the same problem 
when I manually switch performance settings from 'normal' (default), to 
'performance':

echo 0 /sys/devices/platform/eeepc/cpufv

My Eee PC is also 701 4G (originally shipped with MS Windows XP) and currently 
has Karmic Koala with 2.6.31-15-generic kernel installed. Maybe I should try a 
different kernel, or try to load a specific module or whatever else... 

Actually I would prefer to have a 'powersave' mode rather than performance. 
However only 0 and 1 are reported in available_cpufv. BTW Windows was able to 
downgrade performance when battery was close to discharge. But maybe it was a 
hardware feature activated specially for an operating system which is known to 
be a speed hog :)

Sincerely, Alexey Morozov



-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#559836: [Pkg-openmpi-maintainers] Bug#559836: CVE-2009-3736 local privilege escalation

2009-12-08 Thread Moritz Muehlenhoff
On Tue, Dec 08, 2009 at 01:42:23AM +0100, Manuel Prinz wrote:
 Here's the debdiff. Changes are checked into our SVN repo.
 
 Best regards
 Manuel

You should rather use the copy of libltdl currently in the
archive or is there a technical reason, which prevents this?

Cheers,
Moritz



-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#527840: First shot at updating xpdf

2009-12-08 Thread Moritz Muehlenhoff
On Mon, Dec 07, 2009 at 10:59:59PM -0200, Rogério Brito wrote:
 (I'm including Derek in the CC'ies, so that he sees our discussion.
 Please, keep everybody in the loop, unless asked otherwise.)
 
 Hi.
 
 I have just made a first-stage update to xpdf, to get it a bit more
 flexible to build, maintain etc.
 
 I think that many of the patches in the BTS implement very nice ideas
 and they should be pushed forward to upstream. Perhaps we can see a new
 release before the end closes?
 
 Anyway, attached is the debdiff between the version currently in
 unstable (3.02-1.4+lenny1) and a newer version (3.02-2).
 
 I'm still undecided on the version, since I'm not sure if I will adopt
 the package, but I am surely interested in co-maintaining it at least.

Any new maintainer team needs to commit to prepare/test security updates
for oldstable and stable on a _reliable_ basis. 

An excellent opportunity to demonstrate that commitment is preparing
updated packages for the issues still open in Etch and Lenny:
http://security-tracker.debian.org/tracker/source-package/xpdf

Cheers,
Moritz



-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#560080: CVE-2009-3994: Buffer overflow in DICOM code

2009-12-08 Thread Moritz Muehlenhoff
Package: devil
Severity: grave
Tags: security

Please see
http://sourceforge.net/tracker/?func=detailaid=2908728group_id=4470atid=304470
 

Cheers,
Moritz

-- System Information:
Debian Release: squeeze/sid
  APT prefers unstable
  APT policy: (500, 'unstable')
Architecture: i386 (i686)

Kernel: Linux 2.6.31-1-686 (SMP w/1 CPU core)
Locale: LANG=C, lc_ctype=de_de.iso-8859...@euro (charmap=ISO-8859-15)
Shell: /bin/sh linked to /bin/bash



-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Processed: tagging 533031

2009-12-08 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org:

 tags 533031 + unreproducible
Bug #533031 [mplayer-skin-blue] mplayer-skin-blue: gmplayer fails to start due 
to bad  PNG format
Added tag(s) unreproducible.

End of message, stopping processing here.

Please contact me if you need assistance.

Debian bug tracking system administrator
(administrator, Debian Bugs database)


-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#559967: FTBFS [hppa]: method openConnection() in the type URL is not...

2009-12-08 Thread Damien Raude-Morvan
Hi,

Le mardi 08 décembre 2009 01:59:27, dann frazier a écrit :
 libxmlrpc3-java reliably fails to build on hppa:
  
  https://buildd.debian.org/build.php?pkg=libxmlrpc3-javaver=3.1.2-1arch=
 hppafile=log
 
 From the most recent build attempt:
[...]
 [javac] 30. ERROR in
  /build/buildd-libxmlrpc3-java_3.1.2-1-hppa-Bsgr47/libxmlrpc3-java-3.1.2/cl
 ient/src/main/java/org/apache/xmlrpc/client/XmlRpcSun15HttpTransport.java
  [javac]  (at line 62)
 [javac]   final URLConnection conn = prox == null ?
  pURL.openConnection() : pURL.openConnection(prox); [javac] 
  ^^
  [javac] The method openConnection() in the type URL is not applicable for
  the arguments (Proxy) [javac] --
[...]

There is someting wrong here regarding gcj-4.4 :

AFAIK, on hppa there is no support for openjdk-6 so default-jdk is in fact 
gcj-4.4-jdk. This package (GCJ 4.4) is promoted as Java5 compliant (Provides: 
java5-sdk). libxmlrpc3-java source code seems ok, since openConnection(Proxy) 
method exist since Java 5 API.

But from what I've tested on paer.debian.org, GCJ-4.4 can correctly *compile* 
Java 5 source code but doesn't provide *Java 5 library*.

Is there anyone on debian-java with throughts on how to fix this ?

Cheers,
-- 
Damien Raude-Morvan - http://damien.raude-morvan.com/


signature.asc
Description: This is a digitally signed message part.


Bug#560090: dependecy: linux-kbuild-2.6.32 not availible

2009-12-08 Thread Achim Schaefer
Package: linux-headers-2.6.32-rc8-686
Version: 2.6.32~rc8-1~experimental.1
Severity: grave
Justification: renders package unusable

the dependency linux-kbuild-2.6.32 is not availble in the debian archives.
So the package can not be installed.

--  SystemInformation:
Debian Release: squeeze/sid
  APT prefers unstable
  APT policy: (800, 'unstable'), (800, 'testing'), (500, 'experimental'), (500, 
'stable')
Architecture: i386 (i686)

Kernel: Linux 2.6.30-2-686 (SMP w/1 CPU core)
Locale: LANG=de_LU.UTF-8, LC_CTYPE=de_LU.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/bash



-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#559836: [Pkg-openmpi-maintainers] Bug#559836: Bug#559836: CVE-2009-3736 local privilege escalation

2009-12-08 Thread Manuel Prinz
Hi Moritz!

Am Dienstag, den 08.12.2009, 20:35 +0100 schrieb Moritz Muehlenhoff:
 You should rather use the copy of libltdl currently in the
 archive or is there a technical reason, which prevents this?

I'm aware of that and discussed it with upstream. They said it would
require quite some changes to the build system, since they decided to
use a copy of libtool for technical and practical reasons and only
support that. I of course might be able to hack support for using the
system libtool into it but I thought fixing security issues in a timely
manner is generally prefered, especially if the issue is that simple to
fix.

Also, I do not quite understand how using Debian's libtool would help,
as it seems vulnerable as well and is not fixed yet. If I misunderstood
the situation, please correct me.

Don't get me wrong: I really appreciate the work the security team does
and I wanted to help you by fixing the issue ASAP. If this was wrong, I
apologize! The solution as is should be seen as an interim solution. I
will try to make Open MPI use libtool, though this is something I can't
see to happen in a reasonable time frame at the moment. Leaving RC bugs
open for weeks does not help anyone, so I fixed the issue the way I did,
by patching the local copy. If this is not an acceptable solution,
please reopen. I just had good intentions, and am open to criticism and
discussion, and willed to learn.

Also, please clarify on the state in etch and lenny. We did not build
static libs, so no .la files there. This version of libtool is not used
outside of MPI. Am I supposed to fix those packages as well as users
might modify debian/rules and build static binaries? I did assume this
not to be the case, but I'm irritated now.

Best regards
Manuel




-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#560093: java-gcj-compat-dev: Not installable (Conflicting Depends)

2009-12-08 Thread Niels Thykier
Package: java-gcj-compat-dev
Severity: serious

Hi

java-gcj-compat-dev cannot be installed in unstable due to conflicts between
gjdoc and gcj-jdk.

java-gcj-compat-dev (1.0.80-5.1) Depends on ..., gcj, ..., gjdoc (= 0.7.8), ...
gcj (4:4.4.2-1) Depends on ..., gcj-jdk (= 4:4.4.2-1)
gcj-jdk (4:4.4.2-1) Conflicts with ..., gjdoc, ...

~Niels


-- System Information:
Debian Release: squeeze/sid
  APT prefers testing
  APT policy: (990, 'testing'), (500, 'unstable'), (1, 'experimental')
Architecture: i386 (i686)

Kernel: Linux 2.6.30-2-686 (SMP w/2 CPU cores)
Locale: LANG=en_DK.UTF-8, LC_CTYPE=en_DK.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash

Versions of packages java-gcj-compat-dev depends on:
ii  ecj-gcj   3.5.1-1standalone version of the Eclipse 
pn  gappletviewer-4.3 none (no description available)
pn  gcj   none (no description available)
ii  gcj-jre [java-gcj-compat] 4:4.3.4-1  Java runtime environment using GIJ
pn  gjdoc none (no description available)
ii  java-gcj-compat   1.0.80-5.1 Java runtime environment using GIJ

Versions of packages java-gcj-compat-dev recommends:
pn  libgcj9-src   none (no description available)

java-gcj-compat-dev suggests no packages.



-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#560095: svn-buildpackage: Can't locate Locale/gettext.pm

2009-12-08 Thread Kurt Roeckx
Package: svn-buildpackage
Version: 0.7.0
Severity: serious

Hi,

I'm getting the following error:
Can't locate Locale/gettext.pm in @INC (@INC contains: /etc/perl 
/usr/local/lib/perl/5.10.1 /usr/local/share/perl/5.10.1 /usr/lib/perl5 
/usr/share/perl5 /usr/lib/perl/5.10 /usr/share/perl/5.10 
/usr/local/lib/site_perl .) at /usr/bin/svn-buildpackage line 22.
BEGIN failed--compilation aborted at /usr/bin/svn-buildpackage line 22.

Installing liblocale-gettext-perl fixes that problem.


Kurt




-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#559806: Bug#559816: CVE-2009-3736 local privilege escalation

2009-12-08 Thread Dirk Eddelbuettel

Just as a further follow-up and Ack! -- I have seen the bug report; I would
appreciate news as to whether we can expect a new libtool or whether we are
expected to deal with this ourselves.

Dirk

-- 
Three out of two people have difficulties with fractions.



-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#560074: ntp: CVE-2009-3563 DoS through mode 7 packets

2009-12-08 Thread Jamie Strandboge
Package: ntp
Version: 1:4.2.4p6+dfsg-2
Severity: normal
Tags: patch
User: ubuntu-de...@lists.ubuntu.com
Usertags: origin-ubuntu karmic ubuntu-patch

In Ubuntu, we've applied the attached patch to achieve the following:

  * SECURITY UPDATE: fix DoS with mode 7 (MODE_PRIVATE) packets
- debian/patches/CVE-2009-3563.patch: update ntpd/ntp_request.c to
  not send a response packet for and rate limit logging of invalid mode 7
  requests and responses
- CVE-2009-3563

We thought you might be interested in doing the same. Here are a couple
more references:
https://support.ntp.org/bugs/show_bug.cgi?id=1331
http://support.ntp.org/bin/view/Main/SecurityNotice#DoS_attack_from_certain_NTP_mode

The attached patch should work fine going back to etch as well (with a
little fuzz), as we used it as far back as ntp-4.2.0a+stable.

Jamie

-- System Information:
Debian Release: squeeze/sid
  APT prefers karmic-updates
  APT policy: (500, 'karmic-updates'), (500, 'karmic-security'), (500, 'karmic')
Architecture: amd64 (x86_64)

Kernel: Linux 2.6.31-15-generic (SMP w/2 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
diff -u ntp-4.2.4p6+dfsg/debian/changelog ntp-4.2.4p6+dfsg/debian/changelog
diff -u ntp-4.2.4p6+dfsg/debian/patches/series ntp-4.2.4p6+dfsg/debian/patches/series
--- ntp-4.2.4p6+dfsg/debian/patches/series
+++ ntp-4.2.4p6+dfsg/debian/patches/series
@@ -15,0 +16 @@
+CVE-2009-3563.patch
only in patch2:
unchanged:
--- ntp-4.2.4p6+dfsg.orig/debian/patches/CVE-2009-3563.patch
+++ ntp-4.2.4p6+dfsg/debian/patches/CVE-2009-3563.patch
@@ -0,0 +1,31 @@
+Description: DoS with mode 7 packets - CVE-2009-3563
+Origin: CERT VU#568372
+
+diff -Nur ntp-4.2.4p6+dfsg/ntpd/ntp_request.c ntp-4.2.4p6+dfsg.new/ntpd/ntp_request.c
+--- ntp-4.2.4p6+dfsg/ntpd/ntp_request.c	2008-08-10 06:02:41.0 -0500
 ntp-4.2.4p6+dfsg.new/ntpd/ntp_request.c	2009-12-03 14:15:58.943054585 -0600
+@@ -409,6 +409,7 @@
+ 	int mod_okay
+ 	)
+ {
++	static u_long quiet_until;
+ 	struct req_pkt *inpkt;
+ 	struct req_pkt_tail *tailinpkt;
+ 	struct sockaddr_storage *srcadr;
+@@ -444,8 +445,14 @@
+ 	|| (++ec, INFO_MBZ(inpkt-mbz_itemsize) != 0)
+ 	|| (++ec, rbufp-recv_length  REQ_LEN_HDR)
+ 		) {
+-		msyslog(LOG_ERR, process_private: INFO_ERR_FMT: test %d failed, pkt from %s, ec, stoa(srcadr));
+-		req_ack(srcadr, inter, inpkt, INFO_ERR_FMT);
++		NLOG(NLOG_SYSEVENT)
++			if (current_time = quiet_until) {
++msyslog(LOG_ERR,
++	process_private: drop test %d
++	 failed, pkt from %s,
++	ec, stoa(srcadr));
++quiet_until = current_time + 60;
++			}
+ 		return;
+ 	}
+ 


Bug#559971: [Pkg-mozext-maintainers] Bug#559971: itsalltext: Source package does not contain corresponding source for work

2009-12-08 Thread Ben Finney
On 08-Dec-2009, Jan Luebbe wrote:
 On Tue, 2009-12-08 at 12:17 +1100, Ben Finney wrote: 
  The source package for ‘itsalltext’ is not the corresponding
  source for the work. Instead, it is a bundling of the binary
  ‘*.jar’ libraries.
 
 The jar 'libraries' are just zip archives of the source code.

Not quite; see below.

  The GPLv3 defines the “corresponding source” as:
  
  The Corresponding Source for a work in object code form
  means all the source code needed to generate, install, and
  (for an executable work) run the object code and to modify the
  work, including scripts to control those activities.
 
 The work is not shipped in 'object code' as i understand it, just
 compressed original .js and .xul files. The jar files have been
 obtained by extracting upstream's .xpi file.

That's still not the “corresponding source”. As can be seen, it
doesn't include the source in the form the upstream developers use to
build the package. It is missing at least the ‘Makefile’, which in
turn requires the working tree to be laid out as the upstream VCS
repository is laid out.

  So, fixing this bug involves changing the source package to
  consist of the corresponding source for the work plus the Debian
  packaging, all licensed appropriately.
 
 For the next upstream version, i will change it to the recommended
 pkg-mozext style where the the jars are extracted. 

The ‘foo.xpi’ is not the complete source though, even when extracted.

Since the upstream source is kept under VCS in a Git repository, would
it not be better to base the source package on an export from a
specific tag from that repository?

Even better, of course, would be to encourage upstream to make source
tarball releases of each version, and use those as the pristine
source.

 I've had not seen this git repo before and have now compared the
 source files in my package to those in git. They seem to be
 identical.

Great, that makes it clearer that the VCS working tree contents are
the pristine source (or convince upstream to make tarball releases
each version).

 What do you think we would gain by using the git repo as upstream?

The recipient of the Debian source package should be in a position to
modify the source and build new binary packages, as much like the
upstream developers as feasible.

The Debian policy § 4.14. strongly implies that ‘dpkg-source -x
foo.dsc’ should result in the complete source of the package ready for
editing and building. This seems simplest if the source package is
based directly on the source the upstream developer is using (e.g.
from their VCS or a tarball export), not from a reverse-engineered
binary package with no build script support.

-- 
 \   “Always do right. This will gratify some people, and astonish |
  `\the rest.” —Mark Twain |
_o__)  |
Ben Finney b...@benfinney.id.au


signature.asc
Description: Digital signature


Processed: tagging 560095

2009-12-08 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org:

 tags 560095 + pending
Bug #560095 [svn-buildpackage] svn-buildpackage: Can't locate Locale/gettext.pm
Added tag(s) pending.

End of message, stopping processing here.

Please contact me if you need assistance.

Debian bug tracking system administrator
(administrator, Debian Bugs database)


-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#559836: [Pkg-openmpi-maintainers] Bug#559836: Bug#559836: CVE-2009-3736 local privilege escalation

2009-12-08 Thread Moritz Muehlenhoff
On Tue, Dec 08, 2009 at 09:46:45PM +0100, Manuel Prinz wrote:
 Hi Moritz!
 
 Am Dienstag, den 08.12.2009, 20:35 +0100 schrieb Moritz Muehlenhoff:
  You should rather use the copy of libltdl currently in the
  archive or is there a technical reason, which prevents this?
 
 I'm aware of that and discussed it with upstream. They said it would
 require quite some changes to the build system, since they decided to
 use a copy of libtool for technical and practical reasons and only
 support that. I of course might be able to hack support for using the
 system libtool into it but I thought fixing security issues in a timely
 manner is generally prefered, especially if the issue is that simple to
 fix.
 
 Also, I do not quite understand how using Debian's libtool would help,
 as it seems vulnerable as well and is not fixed yet. If I misunderstood
 the situation, please correct me.
 
 Don't get me wrong: I really appreciate the work the security team does
 and I wanted to help you by fixing the issue ASAP. If this was wrong, I
 apologize! The solution as is should be seen as an interim solution. I
 will try to make Open MPI use libtool, though this is something I can't
 see to happen in a reasonable time frame at the moment. Leaving RC bugs
 open for weeks does not help anyone, so I fixed the issue the way I did,
 by patching the local copy. If this is not an acceptable solution,
 please reopen. I just had good intentions, and am open to criticism and
 discussion, and willed to learn.

No problem, fixing the issue ad hoc is of course preferred and using the
system copy the long term goal (if there're technical issues (that's why
I asked) you can also leave it as-is). Embedding a copy of libtool is
rather harmless to, e.g. an embedded copy of libavcodec.
 
 Also, please clarify on the state in etch and lenny. We did not build
 static libs, so no .la files there. This version of libtool is not used
 outside of MPI. Am I supposed to fix those packages as well as users
 might modify debian/rules and build static binaries? I did assume this
 not to be the case, but I'm irritated now.

You can leave etch and lenny untouched, the impact doesn't warrant an
update.

Cheers,
Moritz



-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#548048: dvipsk-ja: diff for NMU version 5.96+jp1.7a-3.1

2009-12-08 Thread Enrico Tassi
Dear maintainer,

I've prepared an NMU for dvipsk-ja (versioned as 5.96+jp1.7a-3.1) and
uploaded it to DELAYED/2 accoording to developer reference 5.11.1, since
the bug is RC and older than 7 days.

The upload simply adds the patch already attached to the bugreport, that
renaming getline to get_line avoids the name clash with the getline
function defined in stdio.h.

Regards.
-- 
Enrico Tassi
diff -u dvipsk-ja-5.96+jp1.7a/config.guess dvipsk-ja-5.96+jp1.7a/config.guess
--- dvipsk-ja-5.96+jp1.7a/config.guess
+++ dvipsk-ja-5.96+jp1.7a/config.guess
@@ -1,10 +1,10 @@
 #! /bin/sh
 # Attempt to guess a canonical system name.
 #   Copyright (C) 1992, 1993, 1994, 1995, 1996, 1997, 1998, 1999,
-#   2000, 2001, 2002, 2003, 2004, 2005, 2006 Free Software Foundation,
-#   Inc.
+#   2000, 2001, 2002, 2003, 2004, 2005, 2006, 2007, 2008, 2009
+#   Free Software Foundation, Inc.
 
-timestamp='2007-07-22'
+timestamp='2009-06-10'
 
 # This file is free software; you can redistribute it and/or modify it
 # under the terms of the GNU General Public License as published by
@@ -56,8 +56,8 @@
 GNU config.guess ($timestamp)
 
 Originally written by Per Bothner.
-Copyright (C) 1992, 1993, 1994, 1995, 1996, 1997, 1998, 1999, 2000, 2001, 2002, 2003, 2004, 2005
-Free Software Foundation, Inc.
+Copyright (C) 1992, 1993, 1994, 1995, 1996, 1997, 1998, 1999, 2000, 2001,
+2002, 2003, 2004, 2005, 2006, 2007, 2008 Free Software Foundation, Inc.
 
 This is free software; see the source for copying conditions.  There is NO
 warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
@@ -170,7 +170,7 @@
 	arm*|i386|m68k|ns32k|sh3*|sparc|vax)
 		eval $set_cc_for_build
 		if echo __ELF__ | $CC_FOR_BUILD -E - 2/dev/null \
-			| grep __ELF__ /dev/null
+			| grep -q __ELF__
 		then
 		# Once all utilities can be ECOFF (netbsdecoff) or a.out (netbsdaout).
 		# Return netbsd for either.  FIX?
@@ -324,6 +324,9 @@
 	case `/usr/bin/uname -p` in
 	sparc) echo sparc-icl-nx7; exit ;;
 	esac ;;
+s390x:SunOS:*:*)
+	echo ${UNAME_MACHINE}-ibm-solaris2`echo ${UNAME_RELEASE}|sed -e 's/[^.]*//'`
+	exit ;;
 sun4H:SunOS:5.*:*)
 	echo sparc-hal-solaris2`echo ${UNAME_RELEASE}|sed -e 's/[^.]*//'`
 	exit ;;
@@ -331,7 +334,20 @@
 	echo sparc-sun-solaris2`echo ${UNAME_RELEASE}|sed -e 's/[^.]*//'`
 	exit ;;
 i86pc:SunOS:5.*:* | i86xen:SunOS:5.*:*)
-	echo i386-pc-solaris2`echo ${UNAME_RELEASE}|sed -e 's/[^.]*//'`
+	eval $set_cc_for_build
+	SUN_ARCH=i386
+	# If there is a compiler, see if it is configured for 64-bit objects.
+	# Note that the Sun cc does not turn __LP64__ into 1 like gcc does.
+	# This test works for both compilers.
+	if [ $CC_FOR_BUILD != 'no_compiler_found' ]; then
+	if (echo '#ifdef __amd64'; echo IS_64BIT_ARCH; echo '#endif') | \
+		(CCOPTS= $CC_FOR_BUILD -E - 2/dev/null) | \
+		grep IS_64BIT_ARCH /dev/null
+	then
+		SUN_ARCH=x86_64
+	fi
+	fi
+	echo ${SUN_ARCH}-pc-solaris2`echo ${UNAME_RELEASE}|sed -e 's/[^.]*//'`
 	exit ;;
 sun4*:SunOS:6*:*)
 	# According to config.sub, this is the proper way to canonicalize
@@ -532,7 +548,7 @@
 		echo rs6000-ibm-aix3.2
 	fi
 	exit ;;
-*:AIX:*:[45])
+*:AIX:*:[456])
 	IBM_CPU_ID=`/usr/sbin/lsdev -C -c processor -S available | sed 1q | awk '{ print $1 }'`
 	if /usr/sbin/lsattr -El ${IBM_CPU_ID} | grep ' POWER' /dev/null 21; then
 		IBM_ARCH=rs6000
@@ -640,7 +656,7 @@
 	# = hppa64-hp-hpux11.23
 
 	if echo __LP64__ | (CCOPTS= $CC_FOR_BUILD -E - 2/dev/null) |
-		grep __LP64__ /dev/null
+		grep -q __LP64__
 	then
 		HP_ARCH=hppa2.0w
 	else
@@ -796,13 +812,19 @@
 	x86)
 		echo i586-pc-interix${UNAME_RELEASE}
 		exit ;;
-	EM64T | authenticamd)
+	EM64T | authenticamd | genuineintel)
 		echo x86_64-unknown-interix${UNAME_RELEASE}
 		exit ;;
+	IA64)
+		echo ia64-unknown-interix${UNAME_RELEASE}
+		exit ;;
 	esac ;;
 [345]86:Windows_95:* | [345]86:Windows_98:* | [345]86:Windows_NT:*)
 	echo i${UNAME_MACHINE}-pc-mks
 	exit ;;
+8664:Windows_NT:*)
+	echo x86_64-pc-mks
+	exit ;;
 i*:Windows_NT*:* | Pentium*:Windows_NT*:*)
 	# How do we know it's Interix rather than the generic POSIX subsystem?
 	# It also conflicts with pre-2.0 versions of ATT UWIN. Should we
@@ -833,7 +855,14 @@
 	echo ${UNAME_MACHINE}-pc-minix
 	exit ;;
 arm*:Linux:*:*)
-	echo ${UNAME_MACHINE}-unknown-linux-gnu
+	eval $set_cc_for_build
+	if echo __ARM_EABI__ | $CC_FOR_BUILD -E - 2/dev/null \
+	| grep -q __ARM_EABI__
+	then
+	echo ${UNAME_MACHINE}-unknown-linux-gnu
+	else
+	echo ${UNAME_MACHINE}-unknown-linux-gnueabi
+	fi
 	exit ;;
 avr32*:Linux:*:*)
 	echo ${UNAME_MACHINE}-unknown-linux-gnu
@@ -856,40 +885,17 @@
 m68*:Linux:*:*)
 	echo ${UNAME_MACHINE}-unknown-linux-gnu
 	exit ;;
-mips:Linux:*:*)
+mips:Linux:*:* | mips64:Linux:*:*)
 	eval $set_cc_for_build
 	sed 's/^	//'  EOF $dummy.c
 	#undef CPU
-	#undef mips
-	#undef mipsel
+	#undef ${UNAME_MACHINE}
+	#undef ${UNAME_MACHINE}el
 	#if defined(__MIPSEL__) || 

Processed: Re: Bug#560095: svn-buildpackage: Can't locate Locale/gettext.pm

2009-12-08 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org:

 severity 560095 important
Bug #560095 [svn-buildpackage] svn-buildpackage: Can't locate Locale/gettext.pm
Severity set to 'important' from 'serious'

 thanks
Stopping processing here.

Please contact me if you need assistance.

Debian bug tracking system administrator
(administrator, Debian Bugs database)


-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#560095: svn-buildpackage: Can't locate Locale/gettext.pm

2009-12-08 Thread Neil Williams
severity 560095 important
thanks

On Tue, 8 Dec 2009 22:00:38 +0100
Kurt Roeckx k...@roeckx.be wrote:

 Package: svn-buildpackage
 Version: 0.7.0
 Severity: serious

Unjustified severity.

liblocale-gettext-perl is Priority: required and has 41 reverse
dependencies including adduser and has a popcon % of 99.90%.

Not many systems are going to experience this bug.
 
 Installing liblocale-gettext-perl fixes that problem.


-- 


Neil Williams
=
http://www.data-freedom.org/
http://www.linux.codehelp.co.uk/
http://e-mail.is-not-s.ms/



pgpPfX8TgSj6D.pgp
Description: PGP signature


Bug#560080: marked as done (CVE-2009-3994: Buffer overflow in DICOM code)

2009-12-08 Thread Debian Bug Tracking System
Your message dated Tue, 08 Dec 2009 21:49:43 +
with message-id e1ni7wf-f4...@ries.debian.org
and subject line Bug#560080: fixed in devil 1.7.8-6
has caused the Debian Bug report #560080,
regarding CVE-2009-3994: Buffer overflow in DICOM code
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
560080: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=560080
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
---BeginMessage---
Package: devil
Severity: grave
Tags: security

Please see
http://sourceforge.net/tracker/?func=detailaid=2908728group_id=4470atid=304470
 

Cheers,
Moritz

-- System Information:
Debian Release: squeeze/sid
  APT prefers unstable
  APT policy: (500, 'unstable')
Architecture: i386 (i686)

Kernel: Linux 2.6.31-1-686 (SMP w/1 CPU core)
Locale: LANG=C, lc_ctype=de_de.iso-8859...@euro (charmap=ISO-8859-15)
Shell: /bin/sh linked to /bin/bash


---End Message---
---BeginMessage---
Source: devil
Source-Version: 1.7.8-6

We believe that the bug you reported is fixed in the latest version of
devil, which is due to be installed in the Debian FTP archive:

devil_1.7.8-6.diff.gz
  to main/d/devil/devil_1.7.8-6.diff.gz
devil_1.7.8-6.dsc
  to main/d/devil/devil_1.7.8-6.dsc
libdevil-dev_1.7.8-6_amd64.deb
  to main/d/devil/libdevil-dev_1.7.8-6_amd64.deb
libdevil1c2_1.7.8-6_amd64.deb
  to main/d/devil/libdevil1c2_1.7.8-6_amd64.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 560...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Bradley Smith bradsm...@debian.org (supplier of updated devil package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@debian.org)


-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

Format: 1.8
Date: Tue, 08 Dec 2009 20:09:02 +
Source: devil
Binary: libdevil1c2 libdevil-dev
Architecture: source amd64
Version: 1.7.8-6
Distribution: unstable
Urgency: high
Maintainer: Bradley Smith bradsm...@debian.org
Changed-By: Bradley Smith bradsm...@debian.org
Description: 
 libdevil-dev - Cross-platform image loading and manipulation toolkit
 libdevil1c2 - Cross-platform image loading and manipulation toolkit
Closes: 560080
Changes: 
 devil (1.7.8-6) unstable; urgency=high
 .
   * Fix CVE-2009-3994. Closes: #560080.
Checksums-Sha1: 
 3e7c88cbfe8bedc6d3f736cdaaefc8e961dd976d 1286 devil_1.7.8-6.dsc
 2b85f767ed3b0150524fe59c65d3f2a7a89af184 6219 devil_1.7.8-6.diff.gz
 c391ec1ae82ea335e9efa6f1cc30be1525f46b9e 659726 libdevil1c2_1.7.8-6_amd64.deb
 566de515c80d8a19510b572980cf8515ee89bf3f 340658 libdevil-dev_1.7.8-6_amd64.deb
Checksums-Sha256: 
 c4703988d04aecd543266e11302a597ccd3c634481a0f205242a8d74c3d87104 1286 
devil_1.7.8-6.dsc
 2ac658764c54480c01bcb636db970e276dd6d86a3ab748132685a9fbdc11d584 6219 
devil_1.7.8-6.diff.gz
 cf203ae2c1a96875cea4cb284be3627defdc5ce0466eacdd87fc5635883dbe99 659726 
libdevil1c2_1.7.8-6_amd64.deb
 1930e99e1be962920c73ed0c60a1fd82c1ea356476882e413fa0b1fd2ae38ab2 340658 
libdevil-dev_1.7.8-6_amd64.deb
Files: 
 183571a67c537d2d4dad31bf862440a1 1286 devel optional devil_1.7.8-6.dsc
 befc8ac4d04e76df5271344ef196581a 6219 devel optional devil_1.7.8-6.diff.gz
 bb6e333fd73d91e0da3bc8b5ff98619c 659726 libs optional 
libdevil1c2_1.7.8-6_amd64.deb
 aba05bdd36ec7f966ffd06ee2806d04d 340658 libdevel optional 
libdevil-dev_1.7.8-6_amd64.deb

-BEGIN PGP SIGNATURE-
Version: GnuPG v1.4.10 (GNU/Linux)

iEYEARECAAYFAkses3EACgkQj3BimscY00eEYwCgi6oIrMcdyI0ET74DZDd/JoBv
8gMAnjQF9uPxvTrxUa4Bk3/NwtruYsII
=mv0+
-END PGP SIGNATURE-


---End Message---


Bug#560055: marked as done (FTBFS: pkg-config.patch fails to apply)

2009-12-08 Thread Debian Bug Tracking System
Your message dated Tue, 08 Dec 2009 21:52:45 +
with message-id e1ni7zb-jf...@ries.debian.org
and subject line Bug#560055: fixed in hdf-eos5 5.1.12.dfsg.2-2
has caused the Debian Bug report #560055,
regarding FTBFS: pkg-config.patch fails to apply
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
560055: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=560055
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
---BeginMessage---
Package: hdf-eos5
Version: 5.1.12.dfsg.2-1
Severity: serious

hdf-eos5 fails to build from source. From a recent build attempt:
[...]
configure.ac:150: warning: AC_LANG_PROGRAM(Fortran): ignoring PROLOGUE: []
../../lib/autoconf/lang.m4:211: AC_LANG_SOURCE is expanded from...
../../lib/autoconf/lang.m4:228: AC_LANG_PROGRAM is expanded from...
../../lib/autoconf/lang.m4:194: AC_LANG_CONFTEST is expanded from...
../../lib/autoconf/general.m4:2628: _AC_LINK_IFELSE is expanded from...
../../lib/autoconf/general.m4:2645: AC_LINK_IFELSE is expanded from...
../../lib/autoconf/general.m4:2654: AC_TRY_LINK is expanded from...
configure.ac:150: the top level
mkdir -p .
/usr/bin/make -f debian/rules reverse-config
make[1]: Entering directory `/build/buildd/hdf-eos5-5.1.12.dfsg.2'
for i in ./config/config.guess ./config/config.sub  ; do \
if test -e $i.cdbs-orig ; then \
mv $i.cdbs-orig $i ; \
fi ; \
done
make[1]: Leaving directory `/build/buildd/hdf-eos5-5.1.12.dfsg.2'
cd .  QUILT_PATCHES=/build/buildd/hdf-eos5-5.1.12.dfsg.2/debian/patches quilt 
--quiltrc /dev/null push -a || test $? = 2
Applying patch pthreads.patch
patching file testdrivers/threads/Makefile.in
Hunk #1 succeeded at 228 (offset 7 lines).

Applying patch pkg-config.patch
patching file configure.ac
Hunk #1 FAILED at 327.
1 out of 1 hunk FAILED -- rejects in file configure.ac
The next patch would create the file hdf-eos5.pc.in,
which already exists!  Applying it anyway.
patching file hdf-eos5.pc.in
Hunk #1 FAILED at 1.
1 out of 1 hunk FAILED -- rejects in file hdf-eos5.pc.in
Patch pkg-config.patch does not apply (enforce with -f)
make: *** [debian/stamp-patched] Error 1
dpkg-buildpackage: error: debian/rules build gave error exit status 2


---End Message---
---BeginMessage---
Source: hdf-eos5
Source-Version: 5.1.12.dfsg.2-2

We believe that the bug you reported is fixed in the latest version of
hdf-eos5, which is due to be installed in the Debian FTP archive:

hdf-eos5_5.1.12.dfsg.2-2.debian.tar.gz
  to main/h/hdf-eos5/hdf-eos5_5.1.12.dfsg.2-2.debian.tar.gz
hdf-eos5_5.1.12.dfsg.2-2.dsc
  to main/h/hdf-eos5/hdf-eos5_5.1.12.dfsg.2-2.dsc
libhe5-hdfeos-dev_5.1.12.dfsg.2-2_i386.deb
  to main/h/hdf-eos5/libhe5-hdfeos-dev_5.1.12.dfsg.2-2_i386.deb
libhe5-hdfeos0_5.1.12.dfsg.2-2_i386.deb
  to main/h/hdf-eos5/libhe5-hdfeos0_5.1.12.dfsg.2-2_i386.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 560...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Alastair McKinstry mckins...@debian.org (supplier of updated hdf-eos5 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@debian.org)


-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

Format: 1.8
Date: Tue, 08 Dec 2009 20:15:25 +
Source: hdf-eos5
Binary: libhe5-hdfeos0 libhe5-hdfeos-dev
Architecture: source i386
Version: 5.1.12.dfsg.2-2
Distribution: unstable
Urgency: low
Maintainer: Alastair McKinstry mckins...@debian.org
Changed-By: Alastair McKinstry mckins...@debian.org
Description: 
 libhe5-hdfeos-dev - Development files for the HDF-EOS5 library
 libhe5-hdfeos0 - Earth Observation System extensions to HDF5
Closes: 560055 560063
Changes: 
 hdf-eos5 (5.1.12.dfsg.2-2) unstable; urgency=low
 .
   * Remove quilt bits; rely on format 3.0 to apply patches. Closes:  #560055, 
#560063
Checksums-Sha1: 
 6594abc197a00a04e33c43f7b9e612debe1d4d58 1235 hdf-eos5_5.1.12.dfsg.2-2.dsc
 55bb4f886c9a760121eb614eea8bcfba0bc98f03 4538 
hdf-eos5_5.1.12.dfsg.2-2.debian.tar.gz
 73f8bdd106a022219477ab454e5f4a8ec97d1d55 335562 
libhe5-hdfeos0_5.1.12.dfsg.2-2_i386.deb
 db59035c66e92a309786f64385792e5074d9b838 543582 
libhe5-hdfeos-dev_5.1.12.dfsg.2-2_i386.deb
Checksums-Sha256: 
 066079ec361107860aef1f1737b631136269de40f3b9853df8817df692fcb76d 1235 
hdf-eos5_5.1.12.dfsg.2-2.dsc
 

Bug#560063: marked as done (FTBFS: autoreconf: automake failed with exit status: 1)

2009-12-08 Thread Debian Bug Tracking System
Your message dated Tue, 08 Dec 2009 21:52:45 +
with message-id e1ni7zb-jj...@ries.debian.org
and subject line Bug#560063: fixed in hdf-eos5 5.1.12.dfsg.2-2
has caused the Debian Bug report #560063,
regarding FTBFS: autoreconf: automake failed with exit status: 1
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
560063: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=560063
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
---BeginMessage---
Package: hdf-eos5
Version: 5.1.12.dfsg.2-1
Severity: serious
Justification: FTBFS

Hi,

in addition to #560055 (which may or may not be due to the version of
dpkg-dev installed on the buildds), one can get the following failure:
| […]
| configure.ac:150: the top level
| configure.ac:592: required file `gctp/Makefile.in' not found
| configure.ac:592: required file `gctp/include/Makefile.in' not found
| configure.ac:592: required file `gctp/src/Makefile.in' not found
| Makefile.am:20: required directory ./gctp does not exist
| autoreconf: automake failed with exit status: 1
| make: *** [makebuilddir/libhe5-hdfeos-dev] Error 1

Build logs at the usual place:
  https://buildd.debian.org/status/package.php?suite=unstablep=hdf-eos5

Mraw,
KiBi.


---End Message---
---BeginMessage---
Source: hdf-eos5
Source-Version: 5.1.12.dfsg.2-2

We believe that the bug you reported is fixed in the latest version of
hdf-eos5, which is due to be installed in the Debian FTP archive:

hdf-eos5_5.1.12.dfsg.2-2.debian.tar.gz
  to main/h/hdf-eos5/hdf-eos5_5.1.12.dfsg.2-2.debian.tar.gz
hdf-eos5_5.1.12.dfsg.2-2.dsc
  to main/h/hdf-eos5/hdf-eos5_5.1.12.dfsg.2-2.dsc
libhe5-hdfeos-dev_5.1.12.dfsg.2-2_i386.deb
  to main/h/hdf-eos5/libhe5-hdfeos-dev_5.1.12.dfsg.2-2_i386.deb
libhe5-hdfeos0_5.1.12.dfsg.2-2_i386.deb
  to main/h/hdf-eos5/libhe5-hdfeos0_5.1.12.dfsg.2-2_i386.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 560...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Alastair McKinstry mckins...@debian.org (supplier of updated hdf-eos5 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@debian.org)


-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

Format: 1.8
Date: Tue, 08 Dec 2009 20:15:25 +
Source: hdf-eos5
Binary: libhe5-hdfeos0 libhe5-hdfeos-dev
Architecture: source i386
Version: 5.1.12.dfsg.2-2
Distribution: unstable
Urgency: low
Maintainer: Alastair McKinstry mckins...@debian.org
Changed-By: Alastair McKinstry mckins...@debian.org
Description: 
 libhe5-hdfeos-dev - Development files for the HDF-EOS5 library
 libhe5-hdfeos0 - Earth Observation System extensions to HDF5
Closes: 560055 560063
Changes: 
 hdf-eos5 (5.1.12.dfsg.2-2) unstable; urgency=low
 .
   * Remove quilt bits; rely on format 3.0 to apply patches. Closes:  #560055, 
#560063
Checksums-Sha1: 
 6594abc197a00a04e33c43f7b9e612debe1d4d58 1235 hdf-eos5_5.1.12.dfsg.2-2.dsc
 55bb4f886c9a760121eb614eea8bcfba0bc98f03 4538 
hdf-eos5_5.1.12.dfsg.2-2.debian.tar.gz
 73f8bdd106a022219477ab454e5f4a8ec97d1d55 335562 
libhe5-hdfeos0_5.1.12.dfsg.2-2_i386.deb
 db59035c66e92a309786f64385792e5074d9b838 543582 
libhe5-hdfeos-dev_5.1.12.dfsg.2-2_i386.deb
Checksums-Sha256: 
 066079ec361107860aef1f1737b631136269de40f3b9853df8817df692fcb76d 1235 
hdf-eos5_5.1.12.dfsg.2-2.dsc
 37a0d1d22bc675b93327a9294b316a9c01037600385a67d3dd0136ac6f268d83 4538 
hdf-eos5_5.1.12.dfsg.2-2.debian.tar.gz
 ca9853584d17dc447a5b01022d8e12badd431bc0ffd6c6352d5ae5d8d82494b5 335562 
libhe5-hdfeos0_5.1.12.dfsg.2-2_i386.deb
 3f205006949793c0d7a00663bd18fd40621277f2c156e6c561c94e059353608d 543582 
libhe5-hdfeos-dev_5.1.12.dfsg.2-2_i386.deb
Files: 
 b8aa6156a34f1114d2881820559a6b59 1235 libs optional 
hdf-eos5_5.1.12.dfsg.2-2.dsc
 1ac855ccb7e0ece68231f4590fdff885 4538 libs optional 
hdf-eos5_5.1.12.dfsg.2-2.debian.tar.gz
 aba88951c679b347a932942d724c73a2 335562 libs optional 
libhe5-hdfeos0_5.1.12.dfsg.2-2_i386.deb
 bff453c117c6f4d3a97e14dcfb059922 543582 libdevel optional 
libhe5-hdfeos-dev_5.1.12.dfsg.2-2_i386.deb

-BEGIN PGP SIGNATURE-
Version: GnuPG v1.4.10 (GNU/Linux)

iD8DBQFLHrx6QTK/kCo4XFcRAksxAJ4lWKFRS3WZtY9APvl6pHOJCLEK9QCgrGTH
dJ9wL/4mOuvneGmJWspPcGY=
=j2kp
-END PGP SIGNATURE-


---End Message---


Processed (with 1 errors): Re: [DRE-maint] Bug#557778: same problem here

2009-12-08 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org:

 retitle 557778 Should be less strick checking imagemagick version at run
Bug #557778 [librmagick-ruby1.8] Update of imagemagick to 6.5.7.8-1 (testing) 
breaks redmine
Changed Bug title to 'Should be less strick checking imagemagick version at 
run' from 'Update of imagemagick to 6.5.7.8-1 (testing) breaks redmine'
 time
Unknown command or malformed arguments to command.

 severity 557778 serious
Bug #557778 [librmagick-ruby1.8] Should be less strick checking imagemagick 
version at run
Severity set to 'serious' from 'important'

 thanks
Stopping processing here.

Please contact me if you need assistance.

Debian bug tracking system administrator
(administrator, Debian Bugs database)


-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#560077: marked as done ([s3d] FTBFS with libgps-dev 2.90)

2009-12-08 Thread Debian Bug Tracking System
Your message dated Tue, 08 Dec 2009 21:59:40 +
with message-id e1ni85s-0001x9...@ries.debian.org
and subject line Bug#560077: fixed in s3d 0.2.1.1-4
has caused the Debian Bug report #560077,
regarding [s3d] FTBFS with libgps-dev 2.90
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
560077: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=560077
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
---BeginMessage---
Package: s3d
Version: 0.2.1.1-3
Severity: serious

[ 56%] Building C object apps/s3dosm/CMakeFiles/s3dosm.dir/gps.c.o
cd /tmp/buildd/s3d-0.2.1.1/obj-x86_64-linux-gnu/apps/s3dosm  /usr/bin/gcc   
-g -O2  -I/usr/include/freetype2 -
I/usr/include/glib-2.0 -I/usr/lib/glib-2.0/include -I/usr/include/SDL 
-I/usr/include/libxml2 -I/tmp/buildd/s3d-0.2.1.1/obj-
x86_64-linux-gnu -I/tmp/buildd/s3d-0.2.1.1/libs3d 
-I/tmp/buildd/s3d-0.2.1.1/libs3dw   -Wall -Wextra -pedantic -
fvisibility=hidden -DHAVE_GCCVISIBILITY -o CMakeFiles/s3dosm.dir/gps.c.o   -c 
/tmp/buildd/s3d-0.2.1.1/apps/s3dosm/gps.c
/tmp/buildd/s3d-0.2.1.1/apps/s3dosm/gps.c: In function 'show_gpsdata':
/tmp/buildd/s3d-0.2.1.1/apps/s3dosm/gps.c:58: error: 'struct gps_data_t' has no 
member named 'satellites'
/tmp/buildd/s3d-0.2.1.1/apps/s3dosm/gps.c: In function 'gps_init':
/tmp/buildd/s3d-0.2.1.1/apps/s3dosm/gps.c:216: warning: implicit declaration of 
function 'gps_query'
make[3]: *** [apps/s3dosm/CMakeFiles/s3dosm.dir/gps.c.o] Error 1
make[3]: Leaving directory `/tmp/buildd/s3d-0.2.1.1/obj-x86_64-linux-gnu'
make[2]: *** [apps/s3dosm/CMakeFiles/s3dosm.dir/all] Error 2
make[2]: Leaving directory `/tmp/buildd/s3d-0.2.1.1/obj-x86_64-linux-gnu'
make[1]: *** [all] Error 2
make[1]: Leaving directory `/tmp/buildd/s3d-0.2.1.1/obj-x86_64-linux-gnu'
dh_auto_build: make -j1 returned exit code 2



--- System information. ---
Architecture: amd64
Kernel:   Linux 2.6.31-1-amd64

Debian Release: squeeze/sid
  500 unstableftp.debian.org 
--- Package information. ---
Depends (Version) | Installed
=-+-==
libc6  (= 2.2.5) | 2.10.2-2
libgl1-mesa-glx   | 7.6.1~rc2-1
 OR libgl1| 
libsdl1.2debian (= 1.2.10-1) | 1.2.13-5


Recommends (Version) | Installed
-+-==
dotmcp (= 0.2.1.1-3) | 0.2.1.1-3


Package's Suggests field is empty.





signature.asc
Description: This is a digitally signed message part.
---End Message---
---BeginMessage---
Source: s3d
Source-Version: 0.2.1.1-4

We believe that the bug you reported is fixed in the latest version of
s3d, which is due to be installed in the Debian FTP archive:

dotmcp_0.2.1.1-4_amd64.deb
  to main/s/s3d/dotmcp_0.2.1.1-4_amd64.deb
kism3d_0.2.1.1-4_amd64.deb
  to main/s/s3d/kism3d_0.2.1.1-4_amd64.deb
libs3d-dev_0.2.1.1-4_amd64.deb
  to main/s/s3d/libs3d-dev_0.2.1.1-4_amd64.deb
libs3d2_0.2.1.1-4_amd64.deb
  to main/s/s3d/libs3d2_0.2.1.1-4_amd64.deb
libs3dw-dev_0.2.1.1-4_amd64.deb
  to main/s/s3d/libs3dw-dev_0.2.1.1-4_amd64.deb
libs3dw2_0.2.1.1-4_amd64.deb
  to main/s/s3d/libs3dw2_0.2.1.1-4_amd64.deb
meshs3d_0.2.1.1-4_amd64.deb
  to main/s/s3d/meshs3d_0.2.1.1-4_amd64.deb
s3d-data_0.2.1.1-4_all.deb
  to main/s/s3d/s3d-data_0.2.1.1-4_all.deb
s3d-dbg_0.2.1.1-4_amd64.deb
  to main/s/s3d/s3d-dbg_0.2.1.1-4_amd64.deb
s3d-doc_0.2.1.1-4_all.deb
  to main/s/s3d/s3d-doc_0.2.1.1-4_all.deb
s3d_0.2.1.1-4.debian.tar.gz
  to main/s/s3d/s3d_0.2.1.1-4.debian.tar.gz
s3d_0.2.1.1-4.dsc
  to main/s/s3d/s3d_0.2.1.1-4.dsc
s3d_0.2.1.1-4_amd64.deb
  to main/s/s3d/s3d_0.2.1.1-4_amd64.deb
s3dfm_0.2.1.1-4_amd64.deb
  to main/s/s3d/s3dfm_0.2.1.1-4_amd64.deb
s3dosm_0.2.1.1-4_amd64.deb
  to main/s/s3d/s3dosm_0.2.1.1-4_amd64.deb
s3dvt_0.2.1.1-4_amd64.deb
  to main/s/s3d/s3dvt_0.2.1.1-4_amd64.deb
s3dx11gate_0.2.1.1-4_amd64.deb
  to main/s/s3d/s3dx11gate_0.2.1.1-4_amd64.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 560...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Sven Eckelmann sven.eckelm...@gmx.de (supplier of updated s3d package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@debian.org)


-BEGIN PGP SIGNED MESSAGE-
Hash: SHA512

Format: 1.8
Date: Tue, 08 Dec 2009 21:34:58 +0100
Source: s3d
Binary: s3d s3d-dbg 

Bug#559836: [Pkg-openmpi-maintainers] Bug#559836: Bug#559836: CVE-2009-3736 local privilege escalation

2009-12-08 Thread Manuel Prinz
Hi Moritz!

Am Dienstag, den 08.12.2009, 22:28 +0100 schrieb Moritz Muehlenhoff:
 You can leave etch and lenny untouched, the impact doesn't warrant an
 update.

Thanks for clarifying!

Best regards
Manuel




-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Processed: retitle 557778 to Should be less strict checking imagemagick version at run-time

2009-12-08 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org:

 retitle 557778 Should be less strict checking imagemagick version at run-time
Bug #557778 [librmagick-ruby1.8] Should be less strick checking imagemagick 
version at run
Changed Bug title to 'Should be less strict checking imagemagick version at 
run-time' from 'Should be less strick checking imagemagick version at run'

End of message, stopping processing here.

Please contact me if you need assistance.

Debian bug tracking system administrator
(administrator, Debian Bugs database)


-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Processed: retitle 557778 to Should be less strick checking imagemagick version at run

2009-12-08 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org:

 retitle 557778 Should be less strick checking imagemagick version at run
Bug #557778 [librmagick-ruby1.8] Should be less strick checking imagemagick 
version at run
Ignoring request to change the title of bug#557778 to the same title

End of message, stopping processing here.

Please contact me if you need assistance.

Debian bug tracking system administrator
(administrator, Debian Bugs database)


-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#560104: FTBFS [hppa] - undefined reference to `sofa::helper::Factory...

2009-12-08 Thread dann frazier
Package: sofa-framework
Version: 1.0~beta4-3
Severity: serious
User: debian-h...@lists.debian.org
Usertags: hppa

sofa-framework reliably fails to build on hppa:
  
https://buildd.debian.org/build.php?pkg=sofa-frameworkver=1.0~beta4-3arch=hppafile=log

From the most recent build attempt:
[...]
g++ -c -pipe -W -I/usr/include/libxml2 -O2 -D_REENTRANT -fPIC -DSOFA_QT4 
-DSOFA_GUI_QTVIEWER -DSOFA_GUI_GLUT -DSOFA_HAVE_PNG -DSOFA_HAVE_GLEW 
-DSOFA_HAVE_BOOST -DSOFA_PML -DSOFA_SUPPORT_MOVING_FRAMES -DDUMP_VISITOR_INFO 
-DNDEBUG -DSOFA_XML_PARSER_TINYXML -DMINI_FLOWVR -DSOFA_BUILD_SIMULATION_TREE 
-I/usr/share/qt4/mkspecs/linux-g++ -I. -I../../../../include 
-I../../../../framework -I../../../../modules -I/usr/include/qt4 
-I/usr/include/qwt-qt4 -I../../../../extlibs/tinyxml -I/usr/include/libxml2 
-I../../../../extlibs/PML -I../../../../extlibs/PML/PhysicalProperties 
-I../../../../extlibs/LML -I../../../../extlibs/miniFlowVR/include -o 
OBJ/release/ExportDotVisitor.o ExportDotVisitor.cpp
g++ -c -pipe -W -I/usr/include/libxml2 -O2 -D_REENTRANT -fPIC -DSOFA_QT4 
-DSOFA_GUI_QTVIEWER -DSOFA_GUI_GLUT -DSOFA_HAVE_PNG -DSOFA_HAVE_GLEW 
-DSOFA_HAVE_BOOST -DSOFA_PML -DSOFA_SUPPORT_MOVING_FRAMES -DDUMP_VISITOR_INFO 
-DNDEBUG -DSOFA_XML_PARSER_TINYXML -DMINI_FLOWVR -DSOFA_BUILD_SIMULATION_TREE 
-I/usr/share/qt4/mkspecs/linux-g++ -I. -I../../../../include 
-I../../../../framework -I../../../../modules -I/usr/include/qt4 
-I/usr/include/qwt-qt4 -I../../../../extlibs/tinyxml -I/usr/include/libxml2 
-I../../../../extlibs/PML -I../../../../extlibs/PML/PhysicalProperties 
-I../../../../extlibs/LML -I../../../../extlibs/miniFlowVR/include -o 
OBJ/release/GNode.o GNode.cpp
g++ -c -pipe -W -I/usr/include/libxml2 -O2 -D_REENTRANT -fPIC -DSOFA_QT4 
-DSOFA_GUI_QTVIEWER -DSOFA_GUI_GLUT -DSOFA_HAVE_PNG -DSOFA_HAVE_GLEW 
-DSOFA_HAVE_BOOST -DSOFA_PML -DSOFA_SUPPORT_MOVING_FRAMES -DDUMP_VISITOR_INFO 
-DNDEBUG -DSOFA_XML_PARSER_TINYXML -DMINI_FLOWVR -DSOFA_BUILD_SIMULATION_TREE 
-I/usr/share/qt4/mkspecs/linux-g++ -I. -I../../../../include 
-I../../../../framework -I../../../../modules -I/usr/include/qt4 
-I/usr/include/qwt-qt4 -I../../../../extlibs/tinyxml -I/usr/include/libxml2 
-I../../../../extlibs/PML -I../../../../extlibs/PML/PhysicalProperties 
-I../../../../extlibs/LML -I../../../../extlibs/miniFlowVR/include -o 
OBJ/release/GNodeVisitor.o GNodeVisitor.cpp
g++ -c -pipe -W -I/usr/include/libxml2 -O2 -D_REENTRANT -fPIC -DSOFA_QT4 
-DSOFA_GUI_QTVIEWER -DSOFA_GUI_GLUT -DSOFA_HAVE_PNG -DSOFA_HAVE_GLEW 
-DSOFA_HAVE_BOOST -DSOFA_PML -DSOFA_SUPPORT_MOVING_FRAMES -DDUMP_VISITOR_INFO 
-DNDEBUG -DSOFA_XML_PARSER_TINYXML -DMINI_FLOWVR -DSOFA_BUILD_SIMULATION_TREE 
-I/usr/share/qt4/mkspecs/linux-g++ -I. -I../../../../include 
-I../../../../framework -I../../../../modules -I/usr/include/qt4 
-I/usr/include/qwt-qt4 -I../../../../extlibs/tinyxml -I/usr/include/libxml2 
-I../../../../extlibs/PML -I../../../../extlibs/PML/PhysicalProperties 
-I../../../../extlibs/LML -I../../../../extlibs/miniFlowVR/include -o 
OBJ/release/MutationListener.o MutationListener.cpp
g++ -c -pipe -W -I/usr/include/libxml2 -O2 -D_REENTRANT -fPIC -DSOFA_QT4 
-DSOFA_GUI_QTVIEWER -DSOFA_GUI_GLUT -DSOFA_HAVE_PNG -DSOFA_HAVE_GLEW 
-DSOFA_HAVE_BOOST -DSOFA_PML -DSOFA_SUPPORT_MOVING_FRAMES -DDUMP_VISITOR_INFO 
-DNDEBUG -DSOFA_XML_PARSER_TINYXML -DMINI_FLOWVR -DSOFA_BUILD_SIMULATION_TREE 
-I/usr/share/qt4/mkspecs/linux-g++ -I. -I../../../../include 
-I../../../../framework -I../../../../modules -I/usr/include/qt4 
-I/usr/include/qwt-qt4 -I../../../../extlibs/tinyxml -I/usr/include/libxml2 
-I../../../../extlibs/PML -I../../../../extlibs/PML/PhysicalProperties 
-I../../../../extlibs/LML -I../../../../extlibs/miniFlowVR/include -o 
OBJ/release/ParallelVisitorScheduler.o ParallelVisitorScheduler.cpp
g++ -c -pipe -W -I/usr/include/libxml2 -O2 -D_REENTRANT -fPIC -DSOFA_QT4 
-DSOFA_GUI_QTVIEWER -DSOFA_GUI_GLUT -DSOFA_HAVE_PNG -DSOFA_HAVE_GLEW 
-DSOFA_HAVE_BOOST -DSOFA_PML -DSOFA_SUPPORT_MOVING_FRAMES -DDUMP_VISITOR_INFO 
-DNDEBUG -DSOFA_XML_PARSER_TINYXML -DMINI_FLOWVR -DSOFA_BUILD_SIMULATION_TREE 
-I/usr/share/qt4/mkspecs/linux-g++ -I. -I../../../../include 
-I../../../../framework -I../../../../modules -I/usr/include/qt4 
-I/usr/include/qwt-qt4 -I../../../../extlibs/tinyxml -I/usr/include/libxml2 
-I../../../../extlibs/PML -I../../../../extlibs/PML/PhysicalProperties 
-I../../../../extlibs/LML -I../../../../extlibs/miniFlowVR/include -o 
OBJ/release/TreeSimulation.o TreeSimulation.cpp
g++ -c -pipe -W -I/usr/include/libxml2 -O2 -D_REENTRANT -fPIC -DSOFA_QT4 
-DSOFA_GUI_QTVIEWER -DSOFA_GUI_GLUT -DSOFA_HAVE_PNG -DSOFA_HAVE_GLEW 
-DSOFA_HAVE_BOOST -DSOFA_PML -DSOFA_SUPPORT_MOVING_FRAMES -DDUMP_VISITOR_INFO 
-DNDEBUG -DSOFA_XML_PARSER_TINYXML -DMINI_FLOWVR -DSOFA_BUILD_SIMULATION_TREE 
-I/usr/share/qt4/mkspecs/linux-g++ -I. -I../../../../include 
-I../../../../framework -I../../../../modules -I/usr/include/qt4 
-I/usr/include/qwt-qt4 -I../../../../extlibs/tinyxml -I/usr/include/libxml2 

Bug#560074: marked as done (ntp: CVE-2009-3563 DoS through mode 7 packets)

2009-12-08 Thread Debian Bug Tracking System
Your message dated Tue, 08 Dec 2009 22:33:06 +
with message-id e1ni8ce-0006c5...@ries.debian.org
and subject line Bug#560074: fixed in ntp 1:4.2.4p8+dfsg-1
has caused the Debian Bug report #560074,
regarding ntp: CVE-2009-3563 DoS through mode 7 packets
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
560074: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=560074
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
---BeginMessage---
Package: ntp
Severity: grave
Tags: security

Hi,
the following CVE (Common Vulnerabilities  Exposures) id was
published for ntp.

CVE-2009-3563[0]:
| The topology used includes two nodes running ntp and an attacker's PC:
| 
| PC---  [node1 ntpd1]:11.0.0.1 11.0.0.2:[node2 ntpd2]
| 
| PC sends one crafted UDP packet with one byte payload 0x17, i.e. NTP Request 
in
| mode 7.
| This UDP packet has spoofed source IP of 11.0.0.2, destination = 11.0.0.1,
| source port 123 and destination port 123.
| Node1 responds with mode 7 Error Response to Node2, and here comes something 
we
| cannot conceive. Ntpd2 responds back with the same mode 7 Error Response to
| Node1, Ntpd1 does again the same, etc. with the aggregate rate of few thousand
| pps. CPU is taken away on both sides, network is busy...
| Better yet, if we spoof the Node1's address 11.0.0.1 as a source, Node1 sends
| all these packets to itself all the time! Endless.
| Payload 97 00 00 00 (Response mode 7) works too.
| If you fix the vulnerability please also make sure to include the
| CVE id in your changelog entry.

Upstream has release 4.2.4p8 to fix this issue.

For further information see:

[0] https://support.ntp.org/bugs/show_bug.cgi?id=1331
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3563
http://security-tracker.debian.org/tracker/CVE-2009-3563

-- 
Nico Golde - http://www.ngolde.de - n...@jabber.ccc.de - GPG: 0xA0A0
For security reasons, all text in this mail is double-rot13 encrypted.


pgpv3LyhGBqhF.pgp
Description: PGP signature
---End Message---
---BeginMessage---
Source: ntp
Source-Version: 1:4.2.4p8+dfsg-1

We believe that the bug you reported is fixed in the latest version of
ntp, which is due to be installed in the Debian FTP archive:

ntp-doc_4.2.4p8+dfsg-1_all.deb
  to main/n/ntp/ntp-doc_4.2.4p8+dfsg-1_all.deb
ntp_4.2.4p8+dfsg-1.debian.tar.gz
  to main/n/ntp/ntp_4.2.4p8+dfsg-1.debian.tar.gz
ntp_4.2.4p8+dfsg-1.dsc
  to main/n/ntp/ntp_4.2.4p8+dfsg-1.dsc
ntp_4.2.4p8+dfsg-1_amd64.deb
  to main/n/ntp/ntp_4.2.4p8+dfsg-1_amd64.deb
ntp_4.2.4p8+dfsg.orig.tar.gz
  to main/n/ntp/ntp_4.2.4p8+dfsg.orig.tar.gz
ntpdate_4.2.4p8+dfsg-1_amd64.deb
  to main/n/ntp/ntpdate_4.2.4p8+dfsg-1_amd64.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 560...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Kurt Roeckx k...@roeckx.be (supplier of updated ntp package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@debian.org)


-BEGIN PGP SIGNED MESSAGE-
Hash: SHA512

Format: 1.8
Date: Tue, 08 Dec 2009 21:41:51 +0100
Source: ntp
Binary: ntp ntpdate ntp-doc
Architecture: source all amd64
Version: 1:4.2.4p8+dfsg-1
Distribution: unstable
Urgency: high
Maintainer: Debian NTP Team pkg-ntp-maintain...@lists.alioth.debian.org
Changed-By: Kurt Roeckx k...@roeckx.be
Description: 
 ntp- Network Time Protocol daemon and utility programs
 ntp-doc- Network Time Protocol documentation
 ntpdate- client for setting system time from NTP servers
Closes: 560074
Changes: 
 ntp (1:4.2.4p8+dfsg-1) unstable; urgency=high
 .
   * New upstream release.
 - Fixes DoS with mode 7 packets (CVE-2009-3563) (Closes: #560074)
Checksums-Sha1: 
 63a809bf16a46b79ed89637eaf9a549387b56c7b 2101 ntp_4.2.4p8+dfsg-1.dsc
 505f5f0bb9543912ccce1ef2158dacfcae911879 2836606 ntp_4.2.4p8+dfsg.orig.tar.gz
 2d248dd26dab8e1493f558115f35276390c6e7cc 409044 
ntp_4.2.4p8+dfsg-1.debian.tar.gz
 04be3d736e795771dc144553cea50b746c520876 930422 ntp-doc_4.2.4p8+dfsg-1_all.deb
 81b8e894318e03bc2cd6f1c9720490bab170ccee 489264 ntp_4.2.4p8+dfsg-1_amd64.deb
 d1011531ad267c5155e1bce3dc35d45f2548a2f9 64784 ntpdate_4.2.4p8+dfsg-1_amd64.deb
Checksums-Sha256: 
 22745c8174b0989272684fa1542d2869ef007aa4f8d62ea13624c5bf8e60989c 2101 
ntp_4.2.4p8+dfsg-1.dsc
 

Bug#559806: Bug#559816: CVE-2009-3736 local privilege escalation

2009-12-08 Thread Michael Gilbert
On Tue, 8 Dec 2009 15:02:42 -0600, Dirk Eddelbuettel wrote:
 
 Just as a further follow-up and Ack! -- I have seen the bug report; I would
 appreciate news as to whether we can expect a new libtool or whether we are
 expected to deal with this ourselves.

you can expect a new libtool (at least in unstable) soon.  i'll be
looking at this tonight.

mike



-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#560108: xulrunner: remote info disclosure via css

2009-12-08 Thread Michael Gilbert
package: xulrunner
version: 1.9.0.13-0
severity: serious
tags: security

hi,

it has been disclosed that it is possible for any website to query the
user's site viewing history via css.  please see [0].  i have not
personally checked whether this package is vulnerable, but it seems to
be a general css design issue, so all css-supporting browsers are
likely affected. please check, and feel free to close the bug if the
package is not affected.   thanks.

mike

[0] 
http://thecoffeedesk.com/news/index.php/2009/08/02/view-remote-browser-history/



-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#515283: For those following along at home...

2009-12-08 Thread Manuel Prinz
Hi Riccardo!

Am Dienstag, den 04.08.2009, 17:11 +0200 schrieb Riccardo Stagni:
 A lot of development happened to gcx during last months!
 In addition to a gtk2 interface, there is support for raw images produced
 by DSLRs and a minimal support for INDI (for telescope, camera and guider
 control).
 
 But I don't know when they plan to release an updated version.
 I'll write to ask...

I noticed that a new upstream version (1.1) is available from the
project's SF website since October. Do you know if this issue as been
resolved and will you package the new version?

As an aside, your package(s) seem(s) to be interesting for scientists,
so I'd like to invite you to join the Debian Science team. You can find
help and sponsors there. (In case you need it, I did not bother to
check.)

Best regards
Manuel




-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#559978: FTBFS [hppa]: Template Haskell splice illegal in a stage-1 compiler

2009-12-08 Thread John MacFarlane
+++ dann frazier [Dec 07 09 19:37 ]:
 Package: pandoc
 Version: 1.2.1-1
 Severity: serious
 
 pandoc reliably fails to build on hppa:
   
 https://buildd.debian.org/build.php?pkg=pandocver=1.2.1-1arch=hppafile=log
 
 From the most recent build attempt:
 [...]
 Using pkg-config version 0.22 found on system at: /usr/bin/pkg-config
 Using ranlib found on system at: /usr/bin/ranlib
 Using strip found on system at: /usr/bin/strip
 Using tar found on system at: /bin/tar
 /usr/bin/gcc /tmp/23391.c -o /tmp/23391 -D__GLASGOW_HASKELL__=610 -I. 
 -D_HIGHLIGHTING -D_HIGHLIGHTING -I/usr/lib/ghc-6.10.4/process-1.0.1.1/include 
 -I/usr/lib/haskell-packages/ghc6/lib/network-2.2.1.4/ghc-6.10.4/include 
 -I/usr/lib/ghc-6.10.4/directory-1.0.0.3/include 
 -I/usr/lib/ghc-6.10.4/unix-2.3.2.0/include 
 -I/usr/lib/ghc-6.10.4/old-time-1.0.0.2/include 
 -I/usr/lib/ghc-6.10.4/bytestring-0.9.1.4/include 
 -I/usr/lib/ghc-6.10.4/base-4.1.0.0/include -I/usr/lib/ghc-6.10.4/include
 mv dist dist-ghc6
 mv dist-ghc6 dist
 debian/hlibrary.setup build
 Preprocessing library pandoc-1.2.1...
 Preprocessing executables for pandoc-1.2.1...
 Building pandoc-1.2.1...
 [ 1 of 29] Compiling Paths_pandoc ( dist/build/autogen/Paths_pandoc.hs, 
 dist/build/Paths_pandoc.o )
 [ 2 of 29] Compiling Text.Pandoc.XML  ( src/Text/Pandoc/XML.hs, 
 dist/build/Text/Pandoc/XML.o )
 [ 3 of 29] Compiling Text.Pandoc.CharacterReferences ( 
 src/Text/Pandoc/CharacterReferences.hs, 
 dist/build/Text/Pandoc/CharacterReferences.o )
 [ 4 of 29] Compiling Text.Pandoc.Definition ( src/Text/Pandoc/Definition.hs, 
 dist/build/Text/Pandoc/Definition.o )
 [ 5 of 29] Compiling Text.Pandoc.Shared ( src/Text/Pandoc/Shared.hs, 
 dist/build/Text/Pandoc/Shared.o )
 [ 6 of 29] Compiling Text.Pandoc.TH   ( src/Text/Pandoc/TH.hs, 
 dist/build/Text/Pandoc/TH.o )
 [ 7 of 29] Compiling Text.Pandoc.ODT  ( src/Text/Pandoc/ODT.hs, 
 dist/build/Text/Pandoc/ODT.o )
 
 src/Text/Pandoc/ODT.hs:49:24:
 Template Haskell splice illegal in a stage-1 compiler
   makeZip $ data / odt-styles
 make: *** [build-ghc6-stamp] Error 1

Pandoc, like many other Haskell programs, uses Template Haskell, which
requires a stage-2 compiler. I'm not sure why the ghc compiler on hppa
is only stage-1, but that would be the place to fix the problem.




-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#557890: marked as done (lfc: implicit pointer conversions)

2009-12-08 Thread Debian Bug Tracking System
Your message dated Tue, 08 Dec 2009 23:18:59 +
with message-id e1ni9kd-0002sq...@ries.debian.org
and subject line Bug#557890: fixed in lfc 1.7.3.1-4
has caused the Debian Bug report #557890,
regarding lfc: implicit pointer conversions
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
557890: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=557890
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
---BeginMessage---
Package: lfc
Version: 1.7.3.1-2
Severity: serious

Our automated buildd log filter[1] detected a problem that is likely to
cause your package to segfault on architectures where the size of a
pointer is greater than the size of an integer, such as ia64 and amd64.

  Function `lfc_getcwd' implicitly converted to pointer at lfc2_wrap.c:14929
  Function `lfc_listrepset' implicitly converted to pointer at lfc2_wrap.c:15536
  Function `lfc_opendir' implicitly converted to pointer at lfc2_wrap.c:15863
  Function `lfc_opendirg' implicitly converted to pointer at lfc2_wrap.c:15898
  Function `lfc_opendirxg' implicitly converted to pointer at lfc2_wrap.c:15945
  Function `lfc_readdir64' implicitly converted to pointer at lfc2_wrap.c:16020
  Function `lfc_readdirc' implicitly converted to pointer at lfc2_wrap.c:16042
  Function `lfc_readdirg' implicitly converted to pointer at lfc2_wrap.c:16064
  Function `lfc_readdirx' implicitly converted to pointer at lfc2_wrap.c:16086
  Function `lfc_readdirxc' implicitly converted to pointer at lfc2_wrap.c:16108
  Function `lfc_readdirxp' implicitly converted to pointer at lfc2_wrap.c:16152
  Function `lfc_readdirxr' implicitly converted to pointer at lfc2_wrap.c:16204
  Function `lfc_getcwd' implicitly converted to pointer at lfc2thr_wrap.c:15341
  Function `lfc_listrepset' implicitly converted to pointer at 
lfc2thr_wrap.c:15996
  Function `lfc_opendir' implicitly converted to pointer at lfc2thr_wrap.c:16359
  Function `lfc_opendirg' implicitly converted to pointer at 
lfc2thr_wrap.c:16400
  Function `lfc_opendirxg' implicitly converted to pointer at 
lfc2thr_wrap.c:16453
  Function `lfc_readdir64' implicitly converted to pointer at 
lfc2thr_wrap.c:16540
  Function `lfc_readdirc' implicitly converted to pointer at 
lfc2thr_wrap.c:16568
  Function `lfc_readdirg' implicitly converted to pointer at 
lfc2thr_wrap.c:16596
  Function `lfc_readdirx' implicitly converted to pointer at 
lfc2thr_wrap.c:16624
  Function `lfc_readdirxc' implicitly converted to pointer at 
lfc2thr_wrap.c:16652
  Function `lfc_readdirxp' implicitly converted to pointer at 
lfc2thr_wrap.c:16702
  Function `lfc_readdirxr' implicitly converted to pointer at 
lfc2thr_wrap.c:16760

This is often due to a missing function prototype definition.
For more information, see [2].

Though it is guaranteed that this codepath will cause a segfault on certain
architectures, it is not guaranteed that this codepath would ever be executed
(e.g., if the returned pointer is never dereferenced). However, this bug
does prevent the ia64 buildd from successfully building this package, resulting
in a practical FTBFS issue and warranting the serious severity.

[1] http://people.debian.org/~dannf/check-implicit-pointer-functions
[2] http://wiki.debian.org/ImplicitPointerConversions



---End Message---
---BeginMessage---
Source: lfc
Source-Version: 1.7.3.1-4

We believe that the bug you reported is fixed in the latest version of
lfc, which is due to be installed in the Debian FTP archive:

lfc-client_1.7.3.1-4_amd64.deb
  to main/l/lfc/lfc-client_1.7.3.1-4_amd64.deb
lfc-dli_1.7.3.1-4_amd64.deb
  to main/l/lfc/lfc-dli_1.7.3.1-4_amd64.deb
lfc-mysql_1.7.3.1-4_amd64.deb
  to main/l/lfc/lfc-mysql_1.7.3.1-4_amd64.deb
lfc_1.7.3.1-4.diff.gz
  to main/l/lfc/lfc_1.7.3.1-4.diff.gz
lfc_1.7.3.1-4.dsc
  to main/l/lfc/lfc_1.7.3.1-4.dsc
liblcgdm-dev_1.7.3.1-4_amd64.deb
  to main/l/lfc/liblcgdm-dev_1.7.3.1-4_amd64.deb
liblcgdm1_1.7.3.1-4_amd64.deb
  to main/l/lfc/liblcgdm1_1.7.3.1-4_amd64.deb
liblfc-dev_1.7.3.1-4_amd64.deb
  to main/l/lfc/liblfc-dev_1.7.3.1-4_amd64.deb
liblfc-perl_1.7.3.1-4_amd64.deb
  to main/l/lfc/liblfc-perl_1.7.3.1-4_amd64.deb
liblfc1_1.7.3.1-4_amd64.deb
  to main/l/lfc/liblfc1_1.7.3.1-4_amd64.deb
python-lfc_1.7.3.1-4_amd64.deb
  to main/l/lfc/python-lfc_1.7.3.1-4_amd64.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 557...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Mattias Ellert 

Bug#548567: marked as done (Regressions in epiphany-webkit)

2009-12-08 Thread Debian Bug Tracking System
Your message dated Tue, 08 Dec 2009 21:12:46 -0200
with message-id 1260313966.18138.156.ca...@goiaba.horta
and subject line Re: Bug#548567: Regressions in epiphany-webkit
has caused the Debian Bug report #548567,
regarding Regressions in epiphany-webkit
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
548567: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=548567
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
---BeginMessage---
Package: epiphany-webkit
Version: 2.28.0-3
Severity: serious
Justification: renders package unsuitable for release

-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

IMHO epiphany-webkit still has several regressions that make it unsuitable
to replace epiphany-gecko.

 * does a POST when refreshing a view that was obtained with a GET. Results
   very between potential data loss and minor annoyance, depending on the
   quality of the web applications that you are using. For example, may result
   in duplicate submitted data with Bugzilla.
   https://bugzilla.gnome.org/show_bug.cgi?id=595348

 * Passwords for web forms are not saved. Major functionality regression.
   Release notes say that won't be fixed until 2.30.
   https://bugzilla.gnome.org/show_bug.cgi?id=582267

 * Can't use enter to activate a link found with 'find in links'.
   Major accessibility and usability regression.
   https://bugzilla.gnome.org/show_bug.cgi?id=595347

 * URLs such as 'localhost:8000' and 'localhost/manual' result in a Google
   search. Webkit does not like leaving off the initial 'http://' from an
   entered URL. Major functionality regression with privacy implications.
   Unfortunately, upstream can't reproduce it, maybe it's because of a
   Debian specific patch?
   https://bugzilla.gnome.org/show_bug.cgi?id=595690

 * Open button in download dialog no longer present. Usability regression.
   https://bugzilla.gnome.org/show_bug.cgi?id=583426

 * No drag and drop of URLs selected text and images into other programs.
   Rather important usability regression.
   https://bugzilla.gnome.org/show_bug.cgi?id=583427

 * Up button is disabled. Minor functionality regression.
   https://bugzilla.gnome.org/show_bug.cgi?id=583424

 * Find in links no longer works. It finds strings outside of links.
   https://bugzilla.gnome.org/show_bug.cgi?id=595346

 * epiphany's popup menu is replaced with the default webkit menu.
   Useful features such as 'copy image location' unavailable.
   Fixed for 2.29.x but not in 2.28.
   https://bugzilla.gnome.org/show_bug.cgi?id=562617

- -- System Information:
Debian Release: squeeze/sid
  APT prefers testing
  APT policy: (430, 'testing'), (420, 'unstable'), (410, 'experimental')
Architecture: amd64 (x86_64)

Kernel: Linux 2.6.30-1-amd64 (SMP w/4 CPU cores)
Locale: LANG=en_GB.UTF-8, LC_CTYPE=en_GB.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash

Versions of packages epiphany-webkit depends on:
ii  dbus-x111.2.16-2 simple interprocess messaging syst
pn  epiphany-webkit-datanone   (no description available)
ii  gnome-icon-theme2.26.0-1 GNOME Desktop icon theme
ii  iso-codes   3.10.3-1 ISO language, territory, currency,
ii  libavahi-client30.6.25-1 Avahi client library
ii  libavahi-common30.6.25-1 Avahi common library
ii  libavahi-gobject0   0.6.25-1 Avahi GObject library
ii  libc6   2.9-25   GNU C Library: Shared libraries
ii  libdbus-1-3 1.2.16-2 simple interprocess messaging syst
ii  libdbus-glib-1-20.82-1   simple interprocess messaging syst
ii  libgconf2-4 2.26.2-3 GNOME configuration database syste
ii  libglib2.0-02.22.0-1 The GLib library of C routines
ii  libgnome-keyring0   2.26.1-1 GNOME keyring services library
ii  libgtk2.0-0 2.18.0-1 The GTK+ graphical user interface 
ii  libice6 2:1.0.5-1X11 Inter-Client Exchange library
ii  libnotify1 [libnotify1-gtk2 0.4.5-1  sends desktop notifications to a n
ii  libnspr4-0d 4.8-1NetScape Portable Runtime Library
ii  libnss3-1d  3.12.3.1-1   Network Security Service libraries
ii  libpango1.0-0   1.24.5-1 Layout and rendering of internatio
ii  libsm6  2:1.1.1-1X11 Session Management library
ii  libsoup-gnome2.4-1  2.28.0-1 an HTTP library implementation in 
ii  libsoup2.4-12.28.0-1 an HTTP library implementation in 
ii  libwebkit-1.0-2  

Bug#559806: Bug#559816: CVE-2009-3736 local privilege escalation

2009-12-08 Thread Dirk Eddelbuettel

On 8 December 2009 at 18:00, Michael Gilbert wrote:
| On Tue, 8 Dec 2009 15:02:42 -0600, Dirk Eddelbuettel wrote:
|  
|  Just as a further follow-up and Ack! -- I have seen the bug report; I would
|  appreciate news as to whether we can expect a new libtool or whether we are
|  expected to deal with this ourselves.
| 
| you can expect a new libtool (at least in unstable) soon.  i'll be
| looking at this tonight.

Wonderful!  

And one up my two upstream told me that the newer libltdl is 'smarter' and
will automagically defer to the system's libltdl when present which is what
we wanted here all along.  I'll see that both my packages get those updates.

Dirk

-- 
Three out of two people have difficulties with fractions.



-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#548567: Regressions in epiphany-webkit

2009-12-08 Thread Josselin Mouette
Le mardi 08 décembre 2009 à 21:12 -0200, Gustavo Noronha Silva a
écrit : 
  There's also this one, where gnome-keyring asks for authorization for
  every password stored by epiphany. This can result in hundreds of
  dialog
  windows needing to be dismissed the first time epiphany is launched.
  
  https://bugzilla.gnome.org/show_bug.cgi?id=591396
 
 This is a limitation of gnome-keyring, and its API. There's little that
 can be done to remedy this situation, short of what has been proposed by
 Joss.

Proposed and implemented in 2.28.1-2!

Cheers, 
-- 
 .''`.  Josselin Mouette
: :' :
`. `'   “I recommend you to learn English in hope that you in
  `- future understand things”  -- Jörg Schilling


signature.asc
Description: Ceci est une partie de message numériquement signée


Bug#560093: marked as done (java-gcj-compat-dev: Not installable (Conflicting Depends))

2009-12-08 Thread Debian Bug Tracking System
Your message dated Wed, 09 Dec 2009 01:45:18 +0100
with message-id 4b1ef31e.9080...@debian.org
and subject line Re: Bug#560093: java-gcj-compat-dev: Not installable 
(Conflicting Depends)
has caused the Debian Bug report #560093,
regarding java-gcj-compat-dev: Not installable (Conflicting Depends)
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
560093: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=560093
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
---BeginMessage---
Package: java-gcj-compat-dev
Severity: serious

Hi

java-gcj-compat-dev cannot be installed in unstable due to conflicts between
gjdoc and gcj-jdk.

java-gcj-compat-dev (1.0.80-5.1) Depends on ..., gcj, ..., gjdoc (= 0.7.8), ...
gcj (4:4.4.2-1) Depends on ..., gcj-jdk (= 4:4.4.2-1)
gcj-jdk (4:4.4.2-1) Conflicts with ..., gjdoc, ...

~Niels


-- System Information:
Debian Release: squeeze/sid
  APT prefers testing
  APT policy: (990, 'testing'), (500, 'unstable'), (1, 'experimental')
Architecture: i386 (i686)

Kernel: Linux 2.6.30-2-686 (SMP w/2 CPU cores)
Locale: LANG=en_DK.UTF-8, LC_CTYPE=en_DK.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash

Versions of packages java-gcj-compat-dev depends on:
ii  ecj-gcj   3.5.1-1standalone version of the Eclipse 
pn  gappletviewer-4.3 none (no description available)
pn  gcj   none (no description available)
ii  gcj-jre [java-gcj-compat] 4:4.3.4-1  Java runtime environment using GIJ
pn  gjdoc none (no description available)
ii  java-gcj-compat   1.0.80-5.1 Java runtime environment using GIJ

Versions of packages java-gcj-compat-dev recommends:
pn  libgcj9-src   none (no description available)

java-gcj-compat-dev suggests no packages.


---End Message---
---BeginMessage---

Version: 1.91

java-gcj-compat-dev now provides gjdoc and includes dh_javadoc.


On 08.12.2009 21:51, Niels Thykier wrote:

Package: java-gcj-compat-dev
Severity: serious

Hi

java-gcj-compat-dev cannot be installed in unstable due to conflicts between
gjdoc and gcj-jdk.

java-gcj-compat-dev (1.0.80-5.1) Depends on ..., gcj, ..., gjdoc (= 0.7.8), ...
gcj (4:4.4.2-1) Depends on ..., gcj-jdk (= 4:4.4.2-1)
gcj-jdk (4:4.4.2-1) Conflicts with ..., gjdoc, ...

~Niels


-- System Information:
Debian Release: squeeze/sid
   APT prefers testing
   APT policy: (990, 'testing'), (500, 'unstable'), (1, 'experimental')
Architecture: i386 (i686)

Kernel: Linux 2.6.30-2-686 (SMP w/2 CPU cores)
Locale: LANG=en_DK.UTF-8, LC_CTYPE=en_DK.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash

Versions of packages java-gcj-compat-dev depends on:
ii  ecj-gcj   3.5.1-1standalone version of the Eclipse
pn  gappletviewer-4.3none  (no description available)
pn  gcjnone  (no description available)
ii  gcj-jre [java-gcj-compat] 4:4.3.4-1  Java runtime environment using GIJ
pn  gjdocnone  (no description available)
ii  java-gcj-compat   1.0.80-5.1 Java runtime environment using GIJ

Versions of packages java-gcj-compat-dev recommends:
pn  libgcj9-srcnone  (no description available)

java-gcj-compat-dev suggests no packages.






---End Message---


Bug#548567: Regressions in epiphany-webkit

2009-12-08 Thread Gustavo Noronha Silva
On Wed, 2009-12-09 at 01:17 +0100, Josselin Mouette wrote:
 Le mardi 08 décembre 2009 à 21:12 -0200, Gustavo Noronha Silva a
 écrit : 
   There's also this one, where gnome-keyring asks for authorization for
   every password stored by epiphany. This can result in hundreds of
   dialog
   windows needing to be dismissed the first time epiphany is launched.
   
   https://bugzilla.gnome.org/show_bug.cgi?id=591396
  
  This is a limitation of gnome-keyring, and its API. There's little that
  can be done to remedy this situation, short of what has been proposed by
  Joss.
 
 Proposed and implemented in 2.28.1-2!

You rock =)

Cheers,

-- 
Gustavo Noronha Silva k...@debian.org
Debian




--
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Processed: tagging 560090

2009-12-08 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org:

 # Automatically generated email from bts, devscripts version 2.10.35lenny7
 tags 560090 + pending
Bug #560090 [linux-headers-2.6.32-rc8-686] dependecy: linux-kbuild-2.6.32 not 
availible
Added tag(s) pending.

End of message, stopping processing here.

Please contact me if you need assistance.

Debian bug tracking system administrator
(administrator, Debian Bugs database)


-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#560116: pidgin 2.4.* can't connect to MSN messenger

2009-12-08 Thread Yan Li
Package: pidgin
Version: 2.4.3-4lenny5
Severity: grave
Justification: renders package unusable

Start from around Dec 8, 2009. Pidgin 2.4.* can't connect to MSN
messenger any more. The error is Our protocol is not supported by the
server. 

According to a bug report [1] from upstream project, This seems apply
to all pidgin 2.4.* user world wide due to a little change in the
protocol. Sadly that upstream doesn't want to support 2.4.* any
more. Though I think it's not hard to fix this issue in 2.4.*.

We may consider upgrading to pidgin 2.6 or fix 2.4.3 by ourselves.

[1] http://developer.pidgin.im/ticket/10933

-- System Information:
Debian Release: 5.0.3
  APT prefers stable
  APT policy: (500, 'stable')
Architecture: amd64 (x86_64)

Kernel: Linux 2.6.26-2-amd64 (SMP w/2 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/bash

Versions of packages pidgin depends on:
ii  gconf2  2.22.0-1 GNOME configuration database syste
ii  libatk1.0-0 1.22.0-1 The ATK accessibility toolkit
ii  libc6   2.7-18   GNU C Library: Shared libraries
ii  libcairo2   1.6.4-7  The Cairo 2D vector graphics libra
ii  libdbus-1-3 1.2.1-5+lenny1   simple interprocess messaging syst
ii  libdbus-glib-1-20.76-1   simple interprocess messaging syst
ii  libglib2.0-02.16.6-2 The GLib library of C routines
ii  libgstreamer0.10-0  0.10.19-3Core GStreamer libraries and eleme
ii  libgtk2.0-0 2.12.12-1~lenny1 The GTK+ graphical user interface 
ii  libgtkspell02.0.13-1+b1  a spell-checking addon for GTK's T
ii  libice6 2:1.0.4-1X11 Inter-Client Exchange library
ii  libpango1.0-0   1.20.5-5 Layout and rendering of internatio
ii  libpurple0  2.4.3-4lenny5multi-protocol instant messaging l
ii  libsm6  2:1.0.3-2X11 Session Management library
ii  libstartup-notification 0.9-1library for program launch feedbac
ii  libx11-62:1.1.5-2X11 client-side library
ii  libxss1 1:1.1.3-1X11 Screen Saver extension library
ii  perl5.10.0-19lenny2  Larry Wall's Practical Extraction 
ii  perl-base [perlapi-5.10 5.10.0-19lenny2  minimal Perl system
ii  pidgin-data 2.4.3-4lenny5multi-protocol instant messaging c

Versions of packages pidgin recommends:
ii  gstreamer0.10-plugins- 0.10.19-2 GStreamer plugins from the base 
ii  gstreamer0.10-plugins- 0.10.8-4.1~lenny2 GStreamer plugins from the good 

Versions of packages pidgin suggests:
ii  evolution-data-server  2.22.3-1.1+lenny2 evolution database backend server
ii  gnome-panel2.20.3-5  launcher and docking facility for 
ii  libsqlite3-0   3.5.9-6   SQLite 3 shared library

-- no debconf information



-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Processed: forcibly merging 545112 449272

2009-12-08 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org:

 forcemerge 545112 449272
Bug#545112: Errors in new firewire stack, DV camera don't work anymore
Bug#449272: Alternative (buggy, incomplete) firewire stack shipped instead of 
the stable one
Bug#555010: Errors in new firewire stack, DV camera don't work anymore
Forcibly Merged 449272 545112 555010.


End of message, stopping processing here.

Please contact me if you need assistance.

Debian bug tracking system administrator
(administrator, Debian Bugs database)


-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#560119: FTBFS: src/modules/avformat/producer_avformat.c:1425: undefined reference to `lrint'

2009-12-08 Thread Nobuhiro Iwamatsu
Package: mlt
Version: 0.4.8-1
Justification: FTBFS
Severity: serious
Tags: patch

Hi,

mlt package FTBFS on some architecture.
https://buildd.debian.org/pkg.cgi?pkg=mlt

-
cc -g -O2 -Wall -fPIC -DPIC   -O2 -pipe -fomit-frame-pointer -ffast-math
-g -D_FILE_OFFSET_BITS=64 -D_LARGEFILE_SOURCE -pthread -Wall -fPIC -DPIC
-O2 -pipe -fomit-frame-pointer -ffast-math   -g -D_FILE_OFFSET_BITS=64
-D_LARGEFILE_SOURCE -pthread -I../.. -Wall -fPIC -DPIC   -O2 -pipe
-fomit-frame-pointer -ffast-math   -g -D_FILE_OFFSET_BITS=64
-D_LARGEFILE_SOURCE -pthread  -I/usr/include/libavformat
-I/usr/include/libavcodec -I/usr/include/libswscale -DFILTERS -DCODECS
-DSWSCALE   -c -o consumer_avformat.o consumer_avformat.c
cc -shared -o ../libmltavformat.so factory.o filter_avcolour_space.o
filter_avresample.o filter_avdeinterlace.o filter_swscale.o
producer_avformat.o consumer_avformat.o  -Wl,--no-undefined
-Wl,--as-needed -Wl,--no-undefined -Wl,--as-needed -L../../framework
-lmlt -lpthread -Wl,--no-undefined -Wl,--as-needed -lavformat
-lavformat -lavcodec -lavutil -lavdevice  -lswscale
producer_avformat.o: In function `decode_audio':
/build/buildd-mlt_0.4.8-1-armel-Gw6Env/mlt-0.4.8/src/modules/avformat/producer_avformat.c:1425:
undefined reference to `lrint'
collect2: ld returned 1 exit status
-

When we use lrint, we need libm. But it is not set in LDFLAGS.
I created patch and build check. Work file.

Please apply this patch?

Best regards,
  Nobuhiro


-- 
Nobuhiro Iwamatsu
   iwamatsu at {nigauri.org / debian.org}
   GPG ID: 40AD1FA6


fix_lrint.diff
Description: application/octetstream


Bug#559578: single-user boot sometimes wedges eeepc

2009-12-08 Thread jidanni
Indeed it sounds like 559578, and before proceeding further, though
garbled, I have compared the blurred lines to a regular boot, and it
turns out the final words before freezing are:

Wed Dec  9 09:34:02 2009: Loading EeePC support modules...done.
Wed Dec  9 09:34:02 2009: Setting super hybrid engine according to 
configuration...(AC)...done.



-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



  1   2   >