Bug#318728: mozilla-thunderbird: Multiple security problems

2005-07-17 Thread Moritz Muehlenhoff
Package: mozilla-thunderbird Severity: grave Tags: security Justification: user security hole Thunderbird 1.0.5 fixes these nine security issues, some of which are classified as critical by the Mozilla developers: CAN-2005-2270: Code execution through shared function objects CAN-2005-2269: XHTML

Bug#147505: Any news on this bug?

2005-07-17 Thread Helge Kreutzmann
Hello, over three years ago I reported this bug, and every time I play [1] xpat2 I see it. Is there some work/progress on this bug? Do you need more info? Greetings Helge [1] Reproduced on alpha, ppc and amd64, now on Sarge (stable) -- Dr. Helge Kreutzmann, Dipl.-Phys. [EMAI

Bug#285533: bluez-hcidump: FTBFS (amd64/gcc-4.0): static declaration of 'sdp_siz_idx_lookup_table' follows non-static declaration

2005-07-17 Thread Edd Dumbill
On Sun, 2005-07-17 at 00:47 -0700, Steve Langasek wrote: > Hi Edd, > > > This has been fixed in upstream's CVS and will be in the next release. > > That was five months ago, and gcc-4.0 is now the default compiler in etch. > When could we expect this new upstream release to be uploaded to Debian?

Bug#318730: uw-imapd: Description makes strange suggestions

2005-07-17 Thread Justin B Rye
Package: uw-imapd Severity: wishlist >From the Description: > If you do install uw-imapd you will almost certainly want to install a > Mail Transfer Agent such as Smail or Sendmail, as remote mail > programs which use IMAP to access incoming and saved mail will > usually want to send mail using SM

Bug#155998: Please close when appropriate

2005-07-17 Thread Helge Kreutzmann
Hello, there will be no more point release for woody and this bug is not security-related. You have not even replied to this bug. So I think it can be closed, correct? Greetings Helge -- Dr. Helge Kreutzmann, Dipl.-Phys. [EMAIL PROTECTED] gpg signed m

Bug#317757: [dpatch-maintainers] Bug#317757: dpep; debianonly: when failing, it gives a shell error

2005-07-17 Thread Marc Haber
On Sat, Jul 16, 2005 at 04:45:47PM +0900, Junichi Uekawa wrote: > after running : > > cd tests/ > ./run-test.sh > > Could you send me the contents of: > tests/log/11_dpep_debianonly_origtargz_in_upstream.sh I have noted that the tests won't run ok without debhelper installed, so we'd probably ne

Bug#318493: libavcodec-dev: MPEG encoding broken for MMX

2005-07-17 Thread Tobias Grimm
Michael Niedermayr gave me the hint, that gcc might address memory operands through %esp, so modifying the stack pointer with push/pop is not gueranteed to work under all conditions. One way would be, to backup the register to the stack manually, without modifiying %esp, but this might not be nece

Bug#318630: apt: Small additions

2005-07-17 Thread Goswin Brederlow
Package: apt Version: 0.6.38-0.0.0.1.mrvn Followup-For: Bug #318630 Hi, some small additions to the patch. 1. Accept broken Release files from [TRUSTED] sources This might sound odd but I stumbled across this with: deb [TRUSTED] copy:///mnt/mirror/debian dists/sarge/main/binary-i386/ This inc

Bug#318677: fox: unused library in testing/unstable

2005-07-17 Thread Torsten Landschoff
On Sat, Jul 16, 2005 at 04:37:37PM -0700, Steve Langasek wrote: > Rezound has been rebuilt against libfox1.2 after sarge's release, so the fox > package (libfox1.0) has no reverse-dependencies in the archive in either > testing or unstable. Unless you know of some other reason why this package >

Bug#318726: mozilla-firefox: java plugin is not able to initialize

2005-07-17 Thread Patrick Cornelissen
Package: mozilla-firefox Version: 1.0.5-1 Severity: important When you try to install a javaplugin (f.e. blackdown jre) you'll get this message when you start firefox: LoadPlugin: failed to initialize shared library /usr/lib/j2se/1.4/jre/plugin/i386/mozilla/javaplugin_oji.so [/usr/lib/j2se/1.4

Bug#318727: esh: error messages on exec

2005-07-17 Thread Justin B Rye
Package: esh Version: 0.8-7 Severity: minor Any attempt to exec rather than simply run ssh gives an error: [EMAIL PROTECTED]:~$ exec esh esh: could not put myself in my own process group. esh: permission denied. $ The esh shell does successfully replace bash, so it's more offputting than ha

Bug#318723: javascript crasher

2005-07-17 Thread Joey Hess
Package: mozilla-browser Version: 2:1.7.8-1 Severity: serious Tags: security I've successfully crashed this version of mozilla using the proof of concept exploits linked to from http://marc.theaimsgroup.com/?l=bugtraq&m=112008299210033&w=2 mozilla-firefox 1.0.5-1 doesn't crash. This is CAN-2005-

Bug#312488: libc0.3: Indirect linking to libpthread fails [patch]

2005-07-17 Thread GOTO Masanori
At Wed, 8 Jun 2005 13:44:34 +0200, Michael Banck wrote: > We've encountered a rather strange linking problem. gconftool-2 (part > of gconf) uses libxml which in turn uses libpthread. gconftool-2 does > not directly need libpthread and hence does not need to link against > it. When gconftool-2 is

Bug#318672: mozilla-firefox: should probably conflict with mozilla-tabextensions 1.14.2005051901-1

2005-07-17 Thread Mike Hommey
On Sun, Jul 17, 2005 at 11:28:56AM +0200, Vincent Lefevre <[EMAIL PROTECTED]> wrote: > On 2005-07-17 11:10:40 +0300, Andreas Metzler wrote: > > On 2005-07-17 Eric Dorland <[EMAIL PROTECTED]> wrote: > > > It's not entirely clear, are you saying that you only have these > > > problems with mozilla-t

Bug#295117: pfinet

2005-07-17 Thread GOTO Masanori
At Thu, 14 Jul 2005 13:57:49 +0200, Marcus Brinkmann wrote: > _all_ ioctls are non-hurdish, and only provided for compatibility. > Thus, it is always ok to add more if that allows easier porting of > applications. > > The Hurd part is almost "in", I think there was only a tiny little > question le

Bug#318724: mysql-server-4.1: Updated German debconf translation

2005-07-17 Thread Alwin Meschede
Package: mysql-server-4.1 Severity: wishlist Tags: patch l10n Please find attached an updated German debconf translation for mysql-4.1 -- System Information: Debian Release: testing/unstable APT prefers testing APT policy: (500, 'testing') Architecture: i386 (i686) Shell: /bin/sh linked to /

Bug#318725: libpcre3-dev: Cannot be installed (wrong dependency)

2005-07-17 Thread Helge Kreutzmann
Package: libpcre3-dev Severity: grave Tags: sarge (This has been reproduced on an i386 sarge changeroot) I wanted to rebuild arson which in turn need kdelibs4-dev which in turn needs libpcre3-dev which cannot be installed: remaxp:~# env LANG=C apt-get install libpcre3-dev Reading Package Lists...

Bug#318062: CVE Ids for the vulnerabilities

2005-07-17 Thread Moritz Muehlenhoff
The Mozilla vulnerabilities have been assigned these CVE ids: CAN-2005-2270: Code execution through shared function objects CAN-2005-2269: XHTML node spoofing CAN-2005-2268: Javascript prompt origin spoofing CAN-2005-2266: Same origin violation: frame calling top.focus() CAN-2005-2265: Possible ex

Bug#318714: Additional information

2005-07-17 Thread Marcoski
Hi, I've missing to tell you that the problem depends on the package kdelibs4 who can't be installed 'couse the package libaspell15 is nomore installable. The command "apt-get install kdelibs4" return the following reply: The following packages have unmet dependencies: kdelibs4: Depends: liba

Bug#286210: Any news on this bug?

2005-07-17 Thread Helge Kreutzmann
Hello, almost 7 month ago I reported a problem with upgrading libpng-dev from woody to sarge. (sorry, in the report I typed woody twice). Any news on this one? Greetings Helge -- Dr. Helge Kreutzmann, Dipl.-Phys. [EMAIL PROTECTED] gpg signed mail pre

Bug#318722: [amd64]Can't display japanese letter directry at flashplayer-nonfree

2005-07-17 Thread Kyuma Ohta
Package: xorg-x11 Version: 6.8.2.dfsg.1-2 Severity: Important After upgrading x-window-system from XF86 4.3.0 to X.Org 6.8.2, restarting system,I can't look Japanese TrueType Fonts (ttf-kochi-*) with 32bit flashplayer-nonfree and 32bit mozilla-firefox. But, I tryed to send Japanese TrueType Fo

Bug#313631: mozilla-firefox: segmentation faut on http://www.rtl.fr/rtlinfo/

2005-07-17 Thread Vincent Lefevre
On 2005-07-17 01:38:31 -0400, Eric Dorland wrote: > Which version of Flashblock are you running? 1.3.1 (the latest version). -- Vincent Lefèvre <[EMAIL PROTECTED]> - Web: 100% accessible validated (X)HTML - Blog: Work: CR INRIA - computer ar

Bug#318672: mozilla-firefox: should probably conflict with mozilla-tabextensions 1.14.2005051901-1

2005-07-17 Thread Vincent Lefevre
On 2005-07-17 11:10:40 +0300, Andreas Metzler wrote: > On 2005-07-17 Eric Dorland <[EMAIL PROTECTED]> wrote: > > It's not entirely clear, are you saying that you only have these > > problems with mozilla-tabextensions? On my side, I've noticed problems with mozilla-tabextensions only. I don't know

Bug#196762: status of groff multibyte patch

2005-07-17 Thread Alexander E. Patrakov
I have tried those patches. The "ascii8" device is broken in them. -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Bug#318719: tecnoballz: Segfaults on startup

2005-07-17 Thread Helge Kreutzmann
Package: tecnoballz Version: 0.91-2 Severity: important On amd64, tecnoballz segfaults on startup. I suspect this is a 64bit issue, as there are 14 warnings about casts from pointer to integer (the first 64bit, the latter 32bit) and another, simmilar warning during compilation. N.B. severity imp

Bug#318720: crm114: Error with mailfilter.crm --learnspam, non-existent variable :classify_status:

2005-07-17 Thread Christopher Cashell
Package: crm114 Version: 20050628-1 Severity: normal Aw, crud. Mailfilter.crm broke. Here's the error: /usr/bin/crm: *WARNING* Attempt to alter the value of a nonexistent variable, so I'm creating an ISOLATED variable. I hope that's OK. The nonexistent variable is: :classify_status: I'll t

Bug#318711: oops - this one is already filed

2005-07-17 Thread dann frazier
severity 318711 important merge 226530 318711 thanks -- dann frazier <[EMAIL PROTECTED]> -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Bug#308825: gdm hangs sometimes immediately after succesful login

2005-07-17 Thread Henricus J. Holtman
Package: gdm Version: 2.6.0.8-1 Followup-For: Bug #308825 and before the 'debian' window appears, telling me what stage the setup has reached. When the gdm is so broken it consistently hangs at this point. I tried resetting it with 'ctl-alt-bs' but to no avail, it remain stuck at the same place.

Bug#318715: tecnoballz: Broken build / does not use -g and -O0 is never used

2005-07-17 Thread Helge Kreutzmann
Package: tecnoballz Version: 0.91-2 Severity: normal I wanted to debug tecnoballz (see seperate report following soon) and downloaded the source & debian.diff. I ran the following: #export DEB_BUILD_OPTIONS= #dpkg-buildpackage -uc -b -rfakeroot > ../tecnobuild-build1 2>&1 #export DEB_BUILD_OPTION

Bug#318717: pg_ctlcluster: errors in autovacuum_start

2005-07-17 Thread Roger Leigh
Package: postgresql-common Version: 22 Severity: normal Hi Martin, During postgresql startup, I see this: hardknott:/home/rleigh# /etc/init.d/postgresql-8.0 start * Starting PostgreSQL 8.0 database server: main Use of uninitialized value in -r at /usr/bin/pg_ctlcluster line 112. The PostgreSQL

Bug#318714: k3b is no more installable

2005-07-17 Thread Trognoni Marco
Package: k3b Version: 0.12.1-2 Severity: critical Justification: breaks unrelated software There's a problem with dependencies: The following packages have unmet dependencies: k3b: Depends: k3blibs (>= 0.12.1) but it is not going to be installed Depends: kdelibs4 (>= 4:3.3.2-6.1) but it

Bug#318716: nbd: FTBFS (ppc64): Please support the ppc64 architecture

2005-07-17 Thread Andreas Jochens
Package: nbd Version: 1:2.7.4-1 Severity: wishlist Tags: patch When building 'nbd' on ppc64/unstable, I get the following error: dh_shlibdeps -a if [ `uname -s` = 'Linux' ]; then dh_gencontrol -a; else dh_gencontrol -pnbd-server; fi dpkg-gencontrol: error: current build architecture ppc64 does n

Bug#309489: hurd-enable-ldconfig.dpatch update

2005-07-17 Thread GOTO Masanori
At Tue, 31 May 2005 10:40:08 +0200, Michael Banck wrote: > Adding --without-tls to the configure options make glibc build on > hurd-i386, however, binary-arch fails due to ldconfig not being > available. The attached update of hurd-enable-ldconfig.dpatch makes > ldconfig being built again, once th

Bug#318713: [Fwd: Log for successful build of ace-of-penguins_1.2-7.1 (dist=unstable)]

2005-07-17 Thread dann frazier
Package: ace-of-penguins Version: 1.2-7.1 Severity: important Tags: patch Our automated buildd log filter[1] detected a problem that will cause your package to segfault on architectures where the size of a pointer is greater than the size of an integer, such as ia64. [1]http://people.debian.org/~

Bug#318672: mozilla-firefox: should probably conflict with mozilla-tabextensions 1.14.2005051901-1

2005-07-17 Thread Andreas Metzler
On 2005-07-17 Eric Dorland <[EMAIL PROTECTED]> wrote: > * Vincent Lefevre ([EMAIL PROTECTED]) wrote: > > Package: mozilla-firefox > > Version: 1.0.5-1 [...] > > There seem to be very important incompatibilities between > > mozilla-firefox 1.0.5-1 (to which I've just upgraded) and > > mozilla-tabex

Bug#318712: openssh-server: please include "tattle" and "never before seen"

2005-07-17 Thread Paul Wise
Package: openssh-server Version: 1:4.1p1-6 Severity: wishlist In a recent whitedust article[1] about the current ssh brute force attacks, they discuss ways to prevent the spread of these worms. One of the counter-measures is "tattle"[2], a program to automatically report brute-force attempts to th

Bug#285533: bluez-hcidump: FTBFS (amd64/gcc-4.0): static declaration of 'sdp_siz_idx_lookup_table' follows non-static declaration

2005-07-17 Thread Steve Langasek
Hi Edd, > This has been fixed in upstream's CVS and will be in the next release. That was five months ago, and gcc-4.0 is now the default compiler in etch. When could we expect this new upstream release to be uploaded to Debian? Thanks, -- Steve Langasek postmodern programmer signature.asc De

Bug#318711: [Fwd: Log for successful build of tex-guy_1.2.4-4.1 (dist=unstable)]

2005-07-17 Thread dann frazier
Package: tex-guy Version: 1.2.4-4.1 Our automated buildd log filter[1] detected a problem that will cause your package to segfault on architectures where the size of a pointer is greater than the size of an integer, such as ia64. tex-guy builds with -ansi, but uses the fdopen() and popen() functi

Bug#313028: findutils: debug info as requested

2005-07-17 Thread Andreas Metzler
On 2005-07-16 Martin-Éric Racine <[EMAIL PROTECTED]> wrote: > Package: findutils > Here is the debug info produced by the patch you sent me. What filesystem are you using? cu andreas

Bug#318666: mozilla-firefox: Bookmarks not visible until I click on "Manage Bookmarks"

2005-07-17 Thread J.H.M. Dassen (Ray)
On Sun, Jul 17, 2005 at 00:15:19 +0200, Vincent Lefevre wrote: > Version: 1.0.5-1 > Just after Firefox starts up, the Bookmark menu contains only the > following items: > * Bookmark This Page... > * Manage Bookmarks... > > I need to click on "Manage Bookmarks..." and close the window to > mak

Bug#317982: udev: Does not properly add/remove usb disk drives

2005-07-17 Thread Kurt Roeckx
Horms <[EMAIL PROTECTED]> wrote: > Hi Kurt, > > Could you please send the output of lsmod and lspci -v, > hopefully your hardware is reasonably common and i can > reproduce this problem. However, a quick fix might be > to try the 2.6.11 kernels in unstable. lsmod: Module Size U

Bug#318707: INTL:vi Vietnamese translation for squidguard

2005-07-17 Thread Clytie Siddall
Package: squidguard Version: 1.2.0-5 Severity: wishlist Tags: l10n, patch Please find attached the Vietnamese translation for debconf template: squidguard squidguard_1.2.0-5.vi.po.gz Description: GNU Zip compressed data I strongly recommend you look at using the dbconfig-common package to

Bug#318708: gandalf: FTBFS on 64 arches: image/io/*_rl.lo: No such file or directory

2005-07-17 Thread Kurt Roeckx
Package: gandalf Version: 1.5-1 Severity: serious Tags: sid Hi, Your package is failing to build on all 64 arches with the following error: ../libtool --mode=compile gcc -I../.. -g -O2 -Wall -c image_pyramid.c -o image_pyramid_rl.o rm -f .libs/image_pyramid_rl.lo gcc -I../.. -g -O2 -Wall -c imag

Bug#318706: Grub breaks at auto-kernel update with splashscreen

2005-07-17 Thread Uwe Dippel
Package: grub $ uname -a Linux mylinux 2.6.8-2-686 #1 Thu May 19 17:53:30 JST 2005 i686 GNU/Linux version: grub-0.95+cvs20040624-17 I had reported about a messed up display; no grub menu showing; etc about a year ago to the debian-list http://lists.debian.org/debian-user/2004/11/msg02892.html N

Bug#318709: 1.2-1

2005-07-17 Thread martin f krafft
Package: pyblosxom Severity: minor README.Debian says that "The contributed plugins is found in /usr/share/pyblosxom/contrib/", but there are is no such directory. -- System Information: Debian Release: 3.1 APT prefers testing APT policy: (600, 'testing'), (98, 'unstable'), (1, 'experimental'

Bug#318710: icheck: FTBFS on 64 bit arches: tests failed

2005-07-17 Thread Kurt Roeckx
Package: icheck Version: 0.9.4-1 Severity: serious Tags: sid Hi, Your package is failing to build on all 64 arches with the following error: Differences in canonify output @@ -1,6 +1,6 @@ struct foo; # 1 "t/02_struct/source/bar.c" -struct __attribute__((aligned(4))) foo +struct __attribute__((a

Bug#318705: INTL:vi Vietnamese translation for squid

2005-07-17 Thread Clytie Siddall
Package: squid Version: 2.5.10-1 Severity: wishlist Tags: l10n, patch Please find attached the Vietnamese translation for debconf template: squid squid_2.5.10-1.vi.po.gz Description: GNU Zip compressed data translated and submitted by: Clytie Siddall (vi-VN, Vietnamese free-software transl

Bug#316277: directfb: FTBFS on amd64: Includes .

2005-07-17 Thread Kurt Roeckx
reopen 316277 thanks Hi, It's still failing to build, with different but about the same error now. See: http://amd64.ftbfs.de/fetch.php?&pkg=directfb&ver=0.9.22-5&arch=amd64&stamp=1121549537&file=log&as=raw Kurt -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe

Bug#305883: darcs ignores $VISUAL, and $DARCS_EDITOR

2005-07-17 Thread William S
Package: darcs Version: 1.0.2-1 Followup-For: Bug #305883 I have set $EDITOR, $DARCS_EDITOR, and $VISUAL to /usr/bin/vi, which on my machine is a symlink to /etc/alternatives/vi, which is a symlink to /usr/bin/nvi, yet darcs still fails to edit a long comment. I have nano, but I don't have emac

Bug#317752: zangband: Okay, now it works.

2005-07-17 Thread andy
Package: zangband Version: 1:2.7.3-3 Followup-For: Bug #317752 Okay, I'm able to do things with the equipment list, without it crashing, if I set my console into 1024x768 (128x64 charcel). Still crashing on normal-sized console. -- System Information: Debian Release: testing/unstable APT pref

Bug#318703: INTL:vi Vietnamese translation for sqlite

2005-07-17 Thread Clytie Siddall
Package: sqlite Version: 2.8.16-1 Severity: wishlist Tags: l10n, patch Please find attached the Vietnamese translation for debconf template: sqlite sqlite_2.8.16-1.vi.po.gz Description: GNU Zip compressed data I strongly recommend you look at using the dbconfig-common package to simplify

Bug#316436: mozilla-firefox: firefox should honor /etc/ssl/certs/

2005-07-17 Thread Eric Dorland
severity 316436 wishlist thanks * Peter Palfrader ([EMAIL PROTECTED]) wrote: > Package: mozilla-firefox > Version: 1.0.4-3 > Severity: normal > > Hi, > > as a site admin I tend to place my local root certificate in > /etc/ssl/certs on all my systems. wget and w3m use this directory and > now ac

Bug#318704: INTL:vi Vietnamese translation for sqlrelay

2005-07-17 Thread Clytie Siddall
Package: sqlrelay Version: 1/0.35-10 Severity: wishlist Tags: l10n, patch Please find attached the Vietnamese translation for debconf template: sqlrelay sqlrelay_1:0.35-10.vi.po.gz Description: GNU Zip compressed data translated and submitted by: Clytie Siddall (vi-VN, Vietnamese free-soft

<    1   2