Bug#504149: virtualbox-ose: symlink vulnerability due to bad /tmp handling

2008-11-01 Thread Paul Wise
Package: virtualbox-ose Version: 1.6.6-dfsg-2 Severity: serious Tags: security By creating a symlink /tmp/.vbox-$USER-ipc/lock an attacker can overwrite any file owned by any user who starts virtualbox. Starting and then exiting virtualbox is enough to trigger this, you don't need to start any

Bug#504150: snmpd: DoS in getbulk handling code in net-snmp

2008-11-01 Thread Steffen Joeris
Package: snmpd Severity: grave Tags: security, patch Justification: user security hole Hi The following announcement has been released by net-snmp upstream: SECURITY ISSUE: A bug in the getbulk handling code could let anyone with even minimal access crash the agent. If you have open access to

Bug#504123: dpkg-scanpackages: inexact French translation of the help message

2008-11-01 Thread Christian Perrier
Quoting Julien Valroff ([EMAIL PROTECTED]): Package: dpkg-dev Version: 1.14.22 Severity: normal Tags: l10n French translated dpkg-scanpackage help message asks the user to redirect the output of dpkg-scanpackages to a file called Paquets (French translation for Packages). This string

Bug#499529: 4.17 !!

2008-11-01 Thread Leszek Koltunski
The current version stands at 4.17, and it works very well ( major new features: simple pairing, lots of fixes for A2DP ) -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Bug#504118: Bug unreproducible on my side

2008-11-01 Thread Christian Perrier
(sorry for messages in French but you'll get the point) [EMAIL PROTECTED]:~ apt-get install sbcl Lecture des listes de paquets... Fait Construction de l'arbre des dépendances Lecture des informations d'état... Fait Les paquets supplémentaires suivants seront installés : binfmt-support cl-asdf

Bug#504151: leaves empty temporary directories behind on exit: /tmp/mc-$USER/

2008-11-01 Thread Paul Wise
Package: mc Version: 2:4.6.2~git20080311-4 Severity: normal mc doesn't remove its temporary directory on exit, it leaves /tmp/mc-$USER/ behind, which is annoying for people like me who detest cruft and aim to destroy it. -- System Information: Debian Release: lenny/sid APT prefers testing

Bug#503900: Where is the package to sponsor?

2008-11-01 Thread Christian Perrier
Ryan, a few days ago you pointed http://mentors.debian.net/debian/pool/main/l/libnagios-object-perl/libnagios-object-perl_0.14-2.dsc in this bug report but there's nothing there. Has someone already attempted to sponsor that package? -- signature.asc Description: Digital signature

Bug#504109: Bug #504109: This bug should probably be tagged lenny-ignore

2008-11-01 Thread Christian Perrier
As the bug submitter said, this bug only happens when kdebluetooth is used with KDE4. As KDE4 packages are not and will not be in lenny, I suspect that this bug should be tagged lenny-ignore. CC'ing the release team... -- signature.asc Description: Digital signature

Bug#504152: aptitude: leaves empty ~/.aptitude/config on exit

2008-11-01 Thread Paul Wise
Package: aptitude Version: 0.4.11.10-1lenny1.1 Severity: normal aptitude leaves an empty ~/.aptitude/config file behind on exit which is annoying for people like me who detest cruft and aim to destroy it. Please make aptitude remove ~/.aptitude/config when it is empty and remove ~/.aptitude/

Bug#503900: Where is the package to sponsor?

2008-11-01 Thread Ryan Niebur
On Sat, Nov 01, 2008 at 08:46:43AM +0100, Christian Perrier wrote: Ryan, a few days ago you pointed http://mentors.debian.net/debian/pool/main/l/libnagios-object-perl/libnagios-object-perl_0.14-2.dsc in this bug report but there's nothing there. Has someone already attempted to sponsor that

Bug#504153: aptitude: leaves empty ~/.debtags/ dir on exit

2008-11-01 Thread Paul Wise
Package: aptitude Version: 0.4.11.10-1lenny1.1 Severity: normal aptitude leaves an empty ~/.debtags/ file behind on exit which is annoying for people like me who detest cruft and aim to destroy it. Please make aptitude remove that directory when it is empty. -- Package-specific info: aptitude

Bug#500710: flashplugin-nonfree: Does not install flash plugin on amd64

2008-11-01 Thread Julien Valroff
Hi, I have finally managed to get things work correctly, but still some manual things to do. I have used Christian Marillat's unofficial ia32-libs* packages[0]: ia32-libs-libcurl3 ia32-libs-libidn11 ia32-libs-libnspr4 ia32-libs-libnss3 ia32-libs-libssh2

Bug#504147: [Pkg-xfce-devel] Bug#504147: Thunar detects all JPEG files as MIME type image/pjpeg

2008-11-01 Thread Yves-Alexis Perez
found 504147 0.9.0-10 thanks On ven, 2008-10-31 at 23:53 -0500, [EMAIL PROTECTED] wrote: Thunar seems to think that every JPEG file is a progressive JPEG, with the MIME type image/pjpeg, not image/jpeg. As a result, image viewers whose .desktop files do not list the MIME type image/pjpeg as

Bug#504154: sa-compile: leaves cache directory behind in /root

2008-11-01 Thread Paul Wise
Package: spamassassin Version: 3.2.5-1 Severity: normal File: /usr/bin/sa-compile sa-compile leaves the following files/dirs behind when run, which is annoying for people like me who detest cruft and aim to destroy it. /root/.spamassassin/ /root/.spamassassin/sa-compile.cache/

Bug#504157: dpkg-statoverride: support for ACLs and xattrs

2008-11-01 Thread Stefan Fritsch
Package: dpkg Version: 1.14.22 Severity: wishlist It would be nice if dpkg-statoverride supported setting Posix ACLs and extended attributes. -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Bug#504160: came: camE does not recognise vivi driver's video format

2008-11-01 Thread Németh Márton
Package: came Version: 1.9-3.1+b1 Severity: normal X-Debbugs-CC: Tom Gilbert [EMAIL PROTECTED] camE asks the user to report the unsupported video format: $ su # modprobe -k vivi debug=2 # exit $ camE camE: camE 1.9 - (c) 1999, 2000 Gerd Knorr, Tom Gilbert camE: grabber config: size 320x240,

Bug#504156: RFP: pidgin-facebookchat -- Facebook Chat plugin for Pidgin

2008-11-01 Thread Martin-Éric Racine
Package: wnpp Severity: wishlist * Package name: pidgin-facebookchat Version : 1.38 Upstream Author : Eion Robb [EMAIL PROTECTED] * URL : http://code.google.com/p/pidgin-facebookchat/ * License : GPLv3 Programming Lang: ? Description : Facebook Chat

Bug#504159: safe-rm: [INTL:it] Italian translation of the debconf templates

2008-11-01 Thread vince
Package: safe-rm Severity: wishlist Tags: l10n patch Enclosed please find the Italian translation of the Debconf template. Best regards vince # ITALIAN TRANSLATION OF SAFE-RM'S.PO-DEBCONF FILE # Copyright (C) 2008 THE SAFE-RM'S COPYRIGHT HOLDER # This file is distributed under the same license

Bug#504155: gclcvs: [INTL:it] Italian translation of the debconf templates

2008-11-01 Thread vince
Package: gclcvs Severity: wishlist Tags: l10n patch Enclosed please find the Italian translation of the Debconf template. Best regards vince # ITALIAN TRANSLATION OF GCLCVS'.PO-DEBCONF FILE # #Translators, if you are not familiar with the PO format, gettext #documentation is worth

Bug#504158: email-reminder: [INTL:it] Italian translation of the debconf templates

2008-11-01 Thread vince
Package: email-reminder Severity: wishlist Tags: l10n patch Enclosed please find the Italian translation of the Debconf template. Best regards vince # ITALIAN TRANSLATION OF EMAIL-REMINDER'S.PO-DEBCONF FILE # Copyright (C) 2008 THE EMAIL-REMINDER'S COPYRIGHT HOLDER # This file is distributed

Bug#504162: RFP: usb-modeswitch -- mode switching tool for multimode USB gear

2008-11-01 Thread Martin-Éric Racine
Package: wnpp Severity: wishlist * Package name: usb-modeswitch Version : 0.9.5 Upstream Author : Tobias Stoeber [EMAIL PROTECTED] * URL : http://www.draisberghof.de/usb_modeswitch/ * License : GPLv2+ Programming Lang: C Description : mode switching

Bug#504161: libopenmpi-dev: Package cannot be installed

2008-11-01 Thread Ryo IGARASHI
Package: libopenmpi-dev Version: 1.2.8-1 Severity: important Hi, When I upgrade openmpi related package, libopenmpi-dev package fails to be installed with following output: Unpacking libopenmpi-dev (from .../libopenmpi-dev_1.2.8-1_i386.deb) ... dpkg: error processing

Bug#430156: translate Steve's idea into a patch

2008-11-01 Thread Németh Márton
Tags: patch Steve recomended to remove the buggy line, the attached patch realizes this. Common subdirectories: came-1.9.orig/debian and came-1.9/debian diff -up came-1.9.orig/webcam.c came-1.9/webcam.c --- came-1.9.orig/webcam.c 2008-11-01 09:47:04.0 +0100 +++ came-1.9/webcam.c

Bug#503900: Where is the package to sponsor?

2008-11-01 Thread Christian Perrier
Quoting Ryan Niebur ([EMAIL PROTECTED]): On Sat, Nov 01, 2008 at 08:46:43AM +0100, Christian Perrier wrote: Ryan, a few days ago you pointed http://mentors.debian.net/debian/pool/main/l/libnagios-object-perl/libnagios-object-perl_0.14-2.dsc in this bug report but there's nothing there.

Bug#503870: Acknowledgement (linux-image-2.6.26-1-686: Suspend to RAM fails on HP nc8230)

2008-11-01 Thread Bastian Blank
reopen 503870 severity 503870 serious thanks On Thu, Oct 30, 2008 at 03:11:25PM +, Matthias-Christian Ott wrote: See: http://bugzilla.kernel.org/show_bug.cgi?id=11888 Please describe, why you, as no maintainer, see this as fixed? Even on my notebook, a X60s, suspend broke somewhere between

Bug#388742: corrected printing struct timeval format string

2008-11-01 Thread Németh Márton
Tags: patch The new_delay variable is a struct timeval so convert it first to float and print it with the format string %.2f. The grab_delay is float: also print it with the format string %.2f. Common subdirectories: came-1.9.orig/debian and came-1.9/debian diff -up came-1.9.orig/webcam.c

Bug#504163: latex-make: make distclean misses *.aux.orig, *.idx.orig

2008-11-01 Thread Andreas Beckmann
Package: latex-make Version: 2.1.11-2 Severity: normal Hi Vincent, I just found that running make distclean after a failed/aborted build leaves *.aux.orig *.idx.orig around. (Perhaps some other *.*.orig files as well. Andreas -- System Information: Debian Release: lenny/sid APT

Bug#504109: Bug #504109: This bug should probably be tagged lenny-ignore

2008-11-01 Thread Luk Claes
Christian Perrier wrote: As the bug submitter said, this bug only happens when kdebluetooth is used with KDE4. As KDE4 packages are not and will not be in lenny, I suspect that this bug should be tagged lenny-ignore. CC'ing the release team... Tagging it sid should be enough. It's not

Bug#502311: Exact errors differ by architecture

2008-11-01 Thread Philipp Kern
On Thu, Oct 16, 2008 at 09:54:05PM +0200, Aurelien Jarno wrote: On Thu, Oct 16, 2008 at 07:20:35PM +0200, Frank Lichtenheld wrote: Note that the list of regressions differ by architecture, but it is probably not useful at this point to make a separate bug for each of them, right? Yes, they

Bug#504166: libgtkdatabox: upstream supports glade and has gtk-doc documentation but binary packages do not contain them

2008-11-01 Thread Norbert BÉRCI
Package: libgtkdatabox Version: 0.9.0 Severity: normal Source should build depend on d-shlibs since it is required for building. The upstream version contains stuff for glade integration but build script does not build nor include it in the library or development packages. The upstream

Bug#504070: Patch

2008-11-01 Thread Michal Čihař
Hi attached is patch which implements suggested check. -- Michal Čihař | http://cihar.com | http://blog.cihar.com diff --git a/checks/changelog-file b/checks/changelog-file index c8c69e1..966e120 100644 --- a/checks/changelog-file +++ b/checks/changelog-file @@ -293,6 +293,8 @@ if

Bug#504165: ITP: dm-raid45 -- Source for the dm-raid45 driver

2008-11-01 Thread Giuseppe Iuculano
Package: wnpp Severity: wishlist Owner: Giuseppe Iuculano [EMAIL PROTECTED] -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 * Package name: dm-raid45 Version : 20081027 Upstream Author : Heinz Mauelshagen [EMAIL PROTECTED] * URL :

Bug#503870: Acknowledgement (linux-image-2.6.26-1-686: Suspend to RAM fails on HP nc8230)

2008-11-01 Thread Matthias-Christian Ott
Please describe, why you, as no maintainer, see this as fixed? Because it works on my HP nc8230 (see title of the bug report) and was additionally forwarded to Linux kernel bug tracker (the issue is not fully resolved, but I'm talking to the maintainer about this). Even on my notebook, a

Bug#504164: [linux-image-2.6.26-1-686] System crashes with linux-image-2.6.26-1-686 when X starts

2008-11-01 Thread Mark Brandis
Package: linux-image-2.6.26-1-686 Version: 2.6.26-8 Severity: important --- Please enter the report below this line. --- When using linux-image-2.6.26-1-686 or a customized linux-image-2.6.26 the system crashes when X (kdm) starts. I can see the X cursor and a quarter of the kdm screen when

Bug#503814: foo2zjs

2008-11-01 Thread Anthony Towns
On Fri, Oct 31, 2008 at 03:52:31PM +0100, Andreas Barth wrote: 1. Currently, the submitter claims that the bug is serious, the maintainer don't think so, and there is no decision by the release team yet. So the current state of the bug isn't serious, but important. ie, the views (on serious

Bug#422238: viewing .pdf.gz LaTeX documentation

2008-11-01 Thread Andreas Beckmann
Hi Arnaud, don't open the .pdf.gz files directly, just use the texdoc command, e.g. texdoc latex-make * you don't have to worry about the path to the file * you don't have to worry about decompressing it As it looks, all LaTeX documentation in Debian comes compressed and is easily viewed

Bug#489804: mocp starts and displays the list of the files mp3 and freezes

2008-11-01 Thread Elimar Riesebieter
* N. C. [081101 01:10 +0100] I have the same problem : mocp crashes (play a file but freezes or back to console) with the message FATAL_ERROR: Can't send() int to the server as soon as I browse a directory with music files, or as soon as I want to play a music file if I disable tag

Bug#504109: Bug #504109: This bug should probably be tagged lenny-ignore

2008-11-01 Thread Christian Perrier
Quoting Luk Claes ([EMAIL PROTECTED]): Christian Perrier wrote: As the bug submitter said, this bug only happens when kdebluetooth is used with KDE4. As KDE4 packages are not and will not be in lenny, I suspect that this bug should be tagged lenny-ignore. CC'ing the release

Bug#501151: why was ocfs2 support removed from lenny?

2008-11-01 Thread Robert Velter
Hi, as far as i see there was no security reason to remove this package. The only other reason i could see is that there would be no possible upgrade path from 1.2.x to 1.4.x. Maybe someone can explain me? I think lenny without ocfs2 support at all is worse than having an outdated (but at least

Bug#503870: Acknowledgement (linux-image-2.6.26-1-686: Suspend to RAM fails on HP nc8230)

2008-11-01 Thread Bastian Blank
clone 503870 -1 severity 503870 normal close 503870 retitle -1 linux-2.6 - regression: fails to unblank on resume submitter -1 Jan Korbel [EMAIL PROTECTED] thanks On Sat, Nov 01, 2008 at 09:31:16AM +, Matthias-Christian Ott wrote: Please describe, why you, as no maintainer, see this as

Bug#504109: [Pkg-kde-extras] Bug#504109: Bug #504109: This bug should probably be tagged lenny-ignore

2008-11-01 Thread Sune Vuorela
severity 504109 wishlist retitle 504109 please provide a kde4 version of kdebluetooth thanks On Saturday 01 November 2008 11:25:42 Christian Perrier wrote: No, from the submitter's information, this is not a bug in lenny. and from KDE point of view, it is not a bug as such. /Sune -- I'm not

Bug#504168: CVE-2008-4796: missing input sanitising

2008-11-01 Thread Steffen Joeris
Package: libphp-snoopy Severity: grave Tags: security, patch Justification: user security hole Hi, the following CVE (Common Vulnerabilities Exposures) id was published for libphp-snoopy. CVE-2008-4796[0]: | The _httpsrequest function (Snoopy/Snoopy.class.php) in Snoopy 1.2.3 | and earlier

Bug#504041: lazygal: empty placeholder image in menu if directory has no images

2008-11-01 Thread Alexandre Rossi
There was an issue close to this for dirs that do not contain any pictures, and whose childs do not either. I just fixed it in the developement version. This may be the problem I see. This problem may be related to the dot in directory problem. The examples of empty placeholders I noticed

Bug#504161: [Pkg-openmpi-maintainers] Bug#504161: libopenmpi-dev: Package cannot be installed

2008-11-01 Thread Dirk Eddelbuettel
Thanks for the bug report. We will look into this. Thanks, Dirk On 1 November 2008 at 17:47, Ryo IGARASHI wrote: | Package: libopenmpi-dev | Version: 1.2.8-1 | Severity: important | | Hi, | | When I upgrade openmpi related package, libopenmpi-dev package | fails to be installed with following

Bug#504169: CVE-2008-4796: missing input sanitising in Snoopy.class.php

2008-11-01 Thread Steffen Joeris
Package: ampache Severity: grave Tags: security, patch Justification: user security hole Hi, the following CVE (Common Vulnerabilities Exposures) id was published for ampache. CVE-2008-4796[0]: | The _httpsrequest function (Snoopy/Snoopy.class.php) in Snoopy 1.2.3 | and earlier allows remote

Bug#503184: closed by Christoph Berg [EMAIL PROTECTED] (Re: Bug#503184: O: libapache2-mod-auth-shadow -- Apache2 module for authentication using shadow)

2008-11-01 Thread Bruno De Fraine
As explained in my message, I am aware that the original maintainer removed this package with bug #489862, but I disagree with that decision: mod_auth_shadow provided functionality for which there is currently no good alternative in Debian. I think he should have orphaned his package

Bug#491871: Switch to XAA

2008-11-01 Thread Adnan Hodzic
Everything pretty much the same here too, my life become much happier once I switched to XAA. As I see it right now you only have Option RenderAccel on Take a look at mine Device section in xorg.conf, and pick ones you might need. I'm sure this will solve your problem Section Device

Bug#418659: laziness

2008-11-01 Thread Gabriel Corona
I might be interested in trying to package it if nobody is working on it. Gabriel -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Bug#501946: Orphaned packages that were not part of etch, take 2

2008-11-01 Thread Jan Hauke Rahm
retitle 501946 ITA: php-openid -- php openid library thx On Sat, Nov 01, 2008 at 02:43:10PM +0900, Paul Wise wrote: On Sat, Nov 1, 2008 at 9:12 AM, Raphael Geissert [EMAIL PROTECTED] wrote: php-openid - #501946 I'm not sure if this one should be removed. There's still the openid

Bug#504170: CVE-2008-4796: missing input sanitising in Snoopy.class.php

2008-11-01 Thread Steffen Joeris
Package: mahara Severity: grave Tags: security, patch Justification: user security hole Hi, the following CVE (Common Vulnerabilities Exposures) id was published for mahara. CVE-2008-4796[0]: | The _httpsrequest function (Snoopy/Snoopy.class.php) in Snoopy 1.2.3 | and earlier allows remote

Bug#504171: CVE-2008-4796: missing input sanitising

2008-11-01 Thread Steffen Joeris
Package: pixelpost Severity: grave Tags: security, patch Justification: user security hole Hi, the following CVE (Common Vulnerabilities Exposures) id was published for pixelpost. CVE-2008-4796[0]: | The _httpsrequest function (Snoopy/Snoopy.class.php) in Snoopy 1.2.3 | and earlier allows

Bug#451791: No problems here

2008-11-01 Thread Adnan Hodzic
I have 965 board and card [EMAIL PROTECTED]:~$ lspci | grep -i vga 00:02.0 VGA compatible controller: Intel Corporation Mobile GM965/GL960 Integrated Graphics Controller (rev 0c) I never had problems with font rendering, right now I'm using xserver-xorg-video-intel (2:2.3.2-2+lenny5) and I've

Bug#474737: (no subject)

2008-11-01 Thread markus . mbox
Hmm, thinking more about this... It seems the debian installer uses two sources for modules. Those coming in from initrd (already in /lib/modules/...) and those being loaded from udeb packages. What I have done is booting with a netboot kernel and initrd (having no disk modules) and then

Bug#503184: closed by Christoph Berg [EMAIL PROTECTED] (Re: Bug#503184: O: libapache2-mod-auth-shadow -- Apache2 module for authentication using shadow)

2008-11-01 Thread Christoph Berg
retitle 503184 RFP: libapache2-mod-auth-shadow -- Apache2 module for authentication using shadow thanks Re: Bruno De Fraine 2008-11-01 [EMAIL PROTECTED] reopen 503184 thanks As explained in my message, I am aware that the original maintainer removed this package with bug #489862, but I

Bug#504172: CVE-2008-4796: missing input sanitising in Snoopy.class.php

2008-11-01 Thread Steffen Joeris
Package: mediamate Severity: grave Tags: security, patch Justification: user security hole Hi, the following CVE (Common Vulnerabilities Exposures) id was published for mediamate. CVE-2008-4796[0]: | The _httpsrequest function (Snoopy/Snoopy.class.php) in Snoopy 1.2.3 | and earlier allows

Bug#499414: evtest is using an ioctl() wrong

2008-11-01 Thread Moritz Muehlenhoff
Mark Purcell wrote: On Friday 19 September 2008 15:56:05 Stephen Kitt wrote: Thanks for the patch and the info, the next upload will fix both issues. It won't happen in the next few days though Stephen, Any progress on your upload to resolve this RC bug against lenny? I can't reproduce

Bug#504173: CVE-2008-4796: missing input sanitising in Snoopy.class.php

2008-11-01 Thread Steffen Joeris
Package: opendb Severity: grave Tags: security, patch Justification: user security hole Hi, the following CVE (Common Vulnerabilities Exposures) id was published for opendb. CVE-2008-4796[0]: | The _httpsrequest function (Snoopy/Snoopy.class.php) in Snoopy 1.2.3 | and earlier allows remote

Bug#503999: memory corruption due to use-after-free

2008-11-01 Thread Daniel Stenberg
Hey May I (as upstream maintainer of libcurl) just mention that this bug report is pretty useless to the (lib)curl community as-is, unless there happens to be someone who also knows a lot about the boinc internals. I would also of course like to see A) debian update to libcurl 7.19.0 before

Bug#504174: xoids has no .desktop file

2008-11-01 Thread Siegfried-Angel
Package: xoids Severity: wishlist Version: 1.5-17 User: [EMAIL PROTECTED] Usertags: origin-ubuntu jaunty patch Hi, I'm attaching a .desktop file for xoids (so that it's displayed in Ubuntu's menu). Please add it to the package and install it into /usr/share/applications. Kinds regards, --

Bug#501722: lintian: unused-override is emitted when an override exists for a check which is not -C check

2008-11-01 Thread Adam D. Barratt
On Fri, 2008-10-31 at 15:33 +0100, Frank Lichtenheld wrote: On Fri, Oct 31, 2008 at 06:27:54AM +, Adam D. Barratt wrote: [...] adduser --- The package includes three unused overrides for maintainer-script-needs-depends-on-adduser and lintian issues a number of tags from the

Bug#501612: update-pciids: missing snapshot date - problem still exists in experimental branch

2008-11-01 Thread Florian Kulzer
Package: pciutils Version: 1:3.0.2-1 Severity: normal Hi, I still see this error message with the experimental version of pciutils. -- System Information: Debian Release: lenny/sid APT prefers unstable APT policy: (500, 'unstable'), (500, 'testing'), (500, 'stable'), (1, 'experimental')

Bug#504176: gthumb: does not start anymore

2008-11-01 Thread Xavier Bestel
Package: gthumb Version: 3:2.10.8-1 Severity: normal Hi, since a while, gthumb doesn't start anymore on my system. Well, it starts, runs for a while (strace shows it does a bunch of stuff, looks like normal gtk applications startup), and exits. I tried reinstalling it, it doesn't help. I

Bug#504175: Take login name from ssh config

2008-11-01 Thread Peter Eisentraut
Package: dupload Version: 2.6.6 Severity: wishlist Right now, for the ssh upload targets, you have to put your login name in the dupload.conf or on the command line. It would be nice if it would accept whatever I have configured in .ssh/config. I would guess many people have their Debian

Bug#499504: Info received (Bug#499504: Need Info)

2008-11-01 Thread Scott Kitterman
On Sat, 01 Nov 2008 10:56:18 +0100 Felix Knecht [EMAIL PROTECTED] wrote: Thanks for identifying the problem! I agree that it is not exactly a bug, but I guess python-spf shouldn't crash on this and get the incoming mail rejected. Anyway, heres the info you requested: Scott Kitterman wrote:

Bug#503998: linux-image-2.6.26-1-686: Randomly broken suspend on Thinkpad T61 after update

2008-11-01 Thread Bastian Blank
On Thu, Oct 30, 2008 at 12:08:12PM +0100, Jakub Lucký wrote: I am experiencing problems with suspend after update from 2.6.26-7 or -8 My Thinkpad T61 refuses to wake up from suspend randomly. It only shows blank screen (usually backlighted) and LED's signalize it's not suspended anymore.

Bug#502816: cannot suspend

2008-11-01 Thread Bastian Blank
tags 502816 upstream thanks On Sun, Oct 19, 2008 at 09:53:17PM -0400, Joe Nahmias wrote: I am unable to suspend my T61 thinkpad when using an amd64 kernel. You need to use a matching userspace if you want to use userspace suspend. Noone wrote compatiblity ioctl functions for this. $ sudo

Bug#503645: jhead: CVE-2008-4640, CVE-2008-4641 command injection via filename and insecure file handling

2008-11-01 Thread Nico Golde
Hi Bruno, * Bruno De Fraine [EMAIL PROTECTED] [2008-10-29 18:43]: [...] Nico, do you think this would be sufficient to rule out the vulnerability? I didn't get this message because you didn't CC me. I just had a look at the applied patch and I think this is sufficient. You didn't fix

Bug#502378: Info received (Not reproducible) Now reproducible and reopened

2008-11-01 Thread Bernhard Kleine
Am Freitag, den 17.10.2008, 16:03 + schrieb Debian Bug Tracking System: Your message has been sent to the package maintainer(s): [EMAIL PROTECTED] (Guilherme de S. Pastore) If you wish to submit further information on this problem, please send it to [EMAIL PROTECTED], as before.

Bug#504167: T60

2008-11-01 Thread Jan Korbel
Btw my notebook is T60 with ATI Radeon X1400 (and open source drivers): This machine can be identified by: sys_vendor = LENOVO sys_product = 2007FVG sys_version = ThinkPad T60 bios_version = 79ETD9WW (2.19 ) lspci attached 00:00.0 Host bridge: Intel Corporation Mobile

Bug#492404: (no subject)

2008-11-01 Thread kofi-please
Hi I feel sorry for not having answered for so long time. I did a fresh install with Weekly XFCE CD from october 6th. openchrome drivers were loaded - at least from the point of grep openchrome /var/log/Xorg.0.log hermes:/etc/apt# grep openchrome /var/log/Xorg.0.log (II) Matched openchrome

Bug#350865: apt: documentation references to apt-archive are wrong

2008-11-01 Thread Andre Felipe Machado
Hello, Eugene Thanks for the message. Actually, the apt-secure.8 is generated *from* the apt-secure.8.xml and apt.ent, using the docbook2x-man . I included it for convenience, if desired by the maintainers. Regards. Andre Felipe -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject

Bug#504180: tintin++: Please package latest version 1.98.6

2008-11-01 Thread Stuart Freeman
Package: tintin++ Version: 1.98.3-1 Severity: normal 1.98.6 contains numerous fixes and features that aren't in the currently packaged version. -- System Information: Debian Release: 4.0 APT prefers unstable APT policy: (500, 'unstable'), (1, 'experimental') Architecture: i386 (i686)

Bug#504179: %.pdf: %.fig rule

2008-11-01 Thread Andreas Beckmann
Package: latex-make Version: 2.1.11-2.0anbe0 Severity: wishlist Tags: patch Hi, fig2dev can create .pdf files directly, no need to take the detour via .eps. The attached patch adds a rule to build %.pdf directly from %.fig. Furthermore the patch contains a one-line patch to silence grep if no

Bug#504181: apt_0.7.17~exp4 (ia64/experimental): FTBFS: doc/apt-cache.8: No such file or directory

2008-11-01 Thread Philipp Kern
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Package: apt Version: 0.7.17~exp4 Severity: serious On Sat, Nov 01, 2008 at 06:38:46AM -0600, Buildd user wrote: Automatic build of apt_0.7.17~exp4 on zx6000 by sbuild/ia64 98-farm Build started at 20081101-0631

Bug#503975: Pre-approval for perl/5.10.0-17

2008-11-01 Thread Niko Tyni
On Fri, Oct 31, 2008 at 08:45:59PM +0100, Marc 'HE' Brockschmidt wrote: Niko Tyni [EMAIL PROTECTED] writes: perl (5.10.0-17) unstable; urgency=low [...] Please ack/nack, see the attached (filtered) debdiff for the patches. ACK. Sorry for the delay. No problem, thanks. Got the attached

Bug#504169: CVE-2008-4796: missing input sanitising in Snoopy.class.php

2008-11-01 Thread Steffen Joeris
Hi Charlie Thanks for the bug report. I have addressed this issue in ampache-3.4.3-1 which is currently on m.d.n [1] awaiting sponsoring. With Lenny so close to release I am contacting my usual sponsor for guidance on which would be the best solution for this bug: a. use supplied patch,

Bug#501959: chm2pdf: Major security (temporary dirs) problems

2008-11-01 Thread Nico Golde
Hi Steve, any reason this hasn't yet been uploaded? Cheers Nico -- Nico Golde - http://www.ngolde.de - [EMAIL PROTECTED] - GPG: 0x73647CFF For security reasons, all text in this mail is double-rot13 encrypted. pgpnQVH65Jwco.pgp Description: PGP signature

Bug#504169: CVE-2008-4796: missing input sanitising in Snoopy.class.php

2008-11-01 Thread Charliej
Cheers Steffen For further information see: [0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4796 http://security-tracker.debian.net/tracker/CVE-2008-4796 [1] http://klecker.debian.org/~white/libphp-snoopy/CVE-2008-4796.patch Steffen, Thanks for the bug report. I

Bug#502967: Patch available in upstream VCS

2008-11-01 Thread Nico Golde
Hi Dominic, * Dominic Hargreaves [EMAIL PROTECTED] [2008-10-26 02:51]: CVE-2008-4577 has been fixed in the 1.0 branch, but hasn't been released yet: http://hg.dovecot.org/dovecot-1.0/rev/2dc3a5678fe5 I'm building packages including this fix and the FTBFS fix (#498679); let me know if it's

Bug#163628: Fixed in 3.6+CVS

2008-11-01 Thread Jari Aalto
tags 163628 + fixed-upstream thanks [forwarded from] https://sourceforge.net/tracker/?func=detailatid=378598aid=2211393group_id=23475 Comment By: Joe Allen (jhallen) Date: 2008-10-31 22:14 Message: This is now fixed in CVS: you can now say joe '\!test/file.txt' or joe \\!test/file.txt to edit

Bug#503118: patch for CVE-2008-4686

2008-11-01 Thread Nico Golde
Hi, attached is a ported version of the patch for 0.8.6. Cheers Nico -- Nico Golde - http://www.ngolde.de - [EMAIL PROTECTED] - GPG: 0x73647CFF For security reasons, all text in this mail is double-rot13 encrypted. diff -Nurad vlc-0.8.6.h.orig/modules/demux/ty.c vlc-0.8.6.h/modules/demux/ty.c

Bug#504182: [EMAIL PROTECTED]: [Secure-testing-team] hf - CVE-2008-2378 - local root exploit]

2008-11-01 Thread Nico Golde
Source: hf Severity: grave Tags: security - Forwarded message from Steve Kemp [EMAIL PROTECTED] - From: Steve Kemp [EMAIL PROTECTED] To: [EMAIL PROTECTED] User-Agent: Mutt/1.5.17+20080114 (2008-01-14) Cc: [EMAIL PROTECTED], [EMAIL PROTECTED] Subject: [Secure-testing-team] hf -

Bug#474737: (no subject)

2008-11-01 Thread Frans Pop
On Saturday 01 November 2008, [EMAIL PROTECTED] wrote: What I have done is booting with a netboot kernel and initrd (having no disk modules) and then accessing my local server where the debian dvd is mounted. The dvd obviously misses ide module udeb packages. Maybe because it has the ide

Bug#477523: openvpn=2.1~rc7-1 failes to lookup clientconfig files

2008-11-01 Thread Gockel Andreas
Hi, i have tested it few minutes ago and the problem is fixed. On Sep 29, 2008, at 18:01 , Alberto Gonzalez Iniesta wrote: Hi, was this fixed in rc11? -- Alberto Gonzalez Iniesta| Formación, consultoría y soporte técnico agi@(inittab.org|debian.org)| en GNU/Linux y software libre

Bug#501959: chm2pdf: Major security (temporary dirs) problems

2008-11-01 Thread Steve Stalcup
Hi Nico, I'm just waiting for a sponsor upload. I have uploaded the fix into ubuntu 8.10 Steve -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Bug#504183: Doesn't build in lenny

2008-11-01 Thread Daniel Pocock
Package: nozomi-source The modules don't build. I'm able to build other modules (e.g. for my Wifi card) using module-assistant, so I believe the fault is only in the nozomi package. I tried the following: apt-get update apt-get dist-upgrade (using a machine that had a fresh install of

Bug#504144: htop: Does not filter non-printable characters in process names

2008-11-01 Thread Nico Golde
Hi Josh, * Josh Triplett [EMAIL PROTECTED] [2008-11-01 04:16]: Package: htop Version: 0.7-1 Severity: grave Tags: security Justification: user security hole htop does not filter non-printable characters in process names. Test case: echo -e '#!/bin/sh\nwhile :;do :;done' $(echo -ne

Bug#204449: change of tags / fixed-upstream JOE 3.7

2008-11-01 Thread Jari Aalto
tags 204449 + fixed-upstream thanks [forwarded from] https://sourceforge.net/tracker/?func=detailatid=378598aid=2212363group_id=23475 Comment By: Joe Allen (jhallen) Date: 2008-10-31 19:46 Message: This is now fixed in CVS (for JOE 3.7). -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a

Bug#163628: change of tags / fixed-upstream JOE 3.6+CVS

2008-11-01 Thread Jari Aalto
tags 163628 + fixed-upstream thanks [forwarded from] https://sourceforge.net/tracker/?func=detailatid=378598aid=2211393group_id=23475 Comment By: Joe Allen (jhallen) Date: 2008-10-31 22:14 Message: This is now fixed in CVS: you can now say joe '\!test/file.txt' or joe \\!test/file.txt to edit

Bug#504184: nullmailer: does not allow unqualified mailname

2008-11-01 Thread Adeodato Simó
Package: nullmailer Version: 1:1.04-1 Hello, nullmailer seems to insist that the hostname in /etc/mailname contains at least one dot. If it doesn't, it will qualify mail by duplicating the name found there twice, as in foo.foo. I'd like to be able to use unqualified mailnames, since I have a

Bug#414245: change of tags / fixed-upstream JOE 3.6

2008-11-01 Thread Jari Aalto
tags 414245 + fixed-upstream thanks [forwarded from] https://sourceforge.net/tracker/?func=detailatid=378598aid=2211412group_id=23475 Comment By: Joe Allen (jhallen) Date: 2008-10-31 18:43 Message: This is fixed in JOE 3.6 -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of

Bug#501959: chm2pdf: Major security (temporary dirs) problems

2008-11-01 Thread Nico Golde
Hi Steve, * Steve Stalcup [EMAIL PROTECTED] [2008-11-01 14:55]: I'm just waiting for a sponsor upload. I have uploaded the fix into ubuntu 8.10 I can sponsor the upload if you want. Cheers Nico -- Nico Golde - http://www.ngolde.de - [EMAIL PROTECTED] - GPG: 0x73647CFF For security reasons,

Bug#443181: change of tags / fixed-upstream JOE 3.7

2008-11-01 Thread Jari Aalto
tags 443181 + fixed-upstream thanks [forawrded from] https://sourceforge.net/tracker/?func=detailatid=378598aid=2211533group_id=23475 Comment By: Joe Allen (jhallen) Date: 2008-10-31 18:59 Message: This is now fixed in CVS (for JOE 3.7). -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a

Bug#503645: jhead: CVE-2008-4640, CVE-2008-4641 command injection via filename and insecure file handling

2008-11-01 Thread Ludovic Rousseau
On Sat, Nov 1, 2008 at 1:36 PM, Nico Golde [EMAIL PROTECTED] wrote: Hi Bruno, * Bruno De Fraine [EMAIL PROTECTED] [2008-10-29 18:43]: [...] Nico, do you think this would be sufficient to rule out the vulnerability? I didn't get this message because you didn't CC me. I just had a look at the

Bug#430565: change of tags / fixed-upstream JOE 3.6

2008-11-01 Thread Jari Aalto
tags 430565 + fixed-upstream thanks [forwarded from] https://sourceforge.net/tracker/?func=detailatid=378598aid=2211635group_id=23475 Comment By: Joe Allen (jhallen) Date: 2008-10-31 18:38 Message: This is fixed in JOE 3.6 (it now does just as the bug reporter suggests). However in JOE 3.7

Bug#499414: evtest is using an ioctl() wrong

2008-11-01 Thread Sebastian Andrzej Siewior
* Moritz Muehlenhoff | 2008-11-01 12:42:30 [+0100]: Mark Purcell wrote: On Friday 19 September 2008 15:56:05 Stephen Kitt wrote: Thanks for the patch and the info, the next upload will fix both issues. It won't happen in the next few days though Stephen, Any progress on your upload to

Bug#504183: module found in kernel

2008-11-01 Thread Daniel Pocock
I've found that the nozomi driver is now included in the kernel package - is the source package still needed? Maybe the install script should inform people of this so that they don't persist with it. -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble?

Bug#504185: [xd] undefined symbol: _ZNK3FBB6OneKey6verifyEv

2008-11-01 Thread Ethan Glasser-Camp
Package: xd Version: 3.00.1-1 Severity: normal --- Please enter the report below this line. --- I tried to use xd as documented in the manpage: $ xd ulb 1: /usr/lib/backupninja 2: /usr/lib/bless 3: /usr/lib/blt2.4 4: /usr/lib/bluetooth 5: /usr/lib/bonobo 6: /usr/lib/bonobo-activation 7:

Bug#503533: crafty orphaned.

2008-11-01 Thread Kurt Roeckx
Hi, Did you notice that crafty was orphaned and so is looking for a new maintainer now? You prepared a new version before so I was wondering if you want to be maintainer? I don't think that you're currently a maintainer of any package in Debian so I'm willing to sponsor the package for you.

Bug#504192: xvkbd: please provide general purpose modifiers like matchbox-keyboard

2008-11-01 Thread Timo Juhani Lindfors
Package: xvkbd Version: 3.0-1 Severity: wishlist [ X-Debbugs-CC set to upstream author as this is not debian specific issue. ] matchbox-keyboard allows me to use two general purpose modifiers (mod1 and mod2 in matchbox-keyboard speak). This means I can have only qwerty, shift, backspace, space,

  1   2   3   >