Bug#880550: g2: Please build-depend on libgd-dev, not libgd2-dev

2017-11-01 Thread Steve Langasek
Package: g2 Version: 0.72-6 Severity: serious Tags: patch Justification: FTBFS User: ubuntu-de...@lists.ubuntu.com Usertags: origin-ubuntu bionic ubuntu-patch Dear maintainers, The g2 package build-depends on libgd2-dev, which is long obsolete. The libgd maintainer has recently dropped the

Bug#880549: nfs-kernel-server: NFSv4 sec=krb5p option broken on stretch

2017-11-01 Thread Roberto C. Sanchez
Package: nfs-kernel-server Version: 1:1.3.4-2.1 Severity: important -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 I have recently upgraded my NFS server from Jessie to Stretch. It was the last system on my network that needed to be upgraded. After the upgrade, I found that NFSv4 was nearly

Bug#880548: gdc (GCC 8) frontend fails to build on hurd-i386

2017-11-01 Thread Matthias Klose
Package: src:gcc-8 X-Debbugs-CC: debian-h...@lists.debian.org https://buildd.debian.org/status/fetch.php?pkg=gcc-8=hurd-i386=8-20171102-1=1509591656=0 /<>/build/./prev-gcc/xg++ -B/<>/build/./prev-gcc/ -B/usr/i686-gnu/bin/ -nostdinc++ -B/<>/build/prev-i686-gnu/libstdc++-v3/src/.libs

Bug#880414: RFS: wordgrinder 0.7-1 -- word processor which runs in a terminal

2017-11-01 Thread Adam Borowski
On Tue, Oct 31, 2017 at 11:33:13AM +0100, David Given wrote: > * Package name: wordgrinder > Version: 0.7-1 > WordGrinder's not a new package --- it's been in Debian since wheezy. > Unfortunately my existing sponsor has retired and is unable to upload > the new version, so for the this version

Bug#880547: dosemu: DPMI unhandled exception instability back again

2017-11-01 Thread Charlie Gibbs
Package: dosemu Version: 1.4.0.8 David Griffith wrote: > Package: dosemu > Version: 1.4.0.7+2013 > Severity: grave > Justification: renders package unusable > > Identical symptoms were reported in https://bugs.debian.org/797378, > but they're back again. That report stated that

Bug#880546: RFP: Isabelle -- generic proof assistant

2017-11-01 Thread GengYu Rao
Package: wnpp Severity: wishlist * Package name    : Isabelle    Version : 2017    Upstream Author :  University of Cambridge * URL : http://www.cl.cam.ac.uk/research/hvg/Isabelle/index.html * License : BSD-3-Clause

Bug#879429: Updating the qtwebkit Uploaders list

2017-11-01 Thread Lisandro Damián Nicanor Pérez Meyer
On sábado, 21 de octubre de 2017 17:56:29 -03 Tobias Frost wrote: > Source: qtwebkit > Version: 2.3.4.dfsg-9.1 > Severity: minor > User: m...@qa.debian.org > Usertags: mia-teammaint > > Fathi Boudra has retired, so can't work on > the qtwebkit package anymore (at least with this

Bug#875626: closed by Adrian Bunk <b...@debian.org> (This was a temporary issue during the opencv transition)

2017-11-01 Thread Lisandro Damián Nicanor Pérez Meyer
On lunes, 30 de octubre de 2017 22:07:27 -03 Thomas Braun wrote: > But I'm using debian stable, so how can a transition in unstable break that? According to rmadison: libopencv-highgui-dev | 2.4.9.1+dfsg1-2 | stable | amd64, arm64, armel, armhf, i386, mips, mips64el, mipsel,

Bug#850741: python-docker 2.x in Sid

2017-11-01 Thread Jason Pleau
Hi Thomas On 11/01/2017 08:51 PM, Thomas Goirand wrote: > Hi, > > Could you please upload the 2.x version of python-docker into Sid? I've > uploaded python-zunclient that needs it. > It's been a while, I think what we (still) have to do is get the rdepends updated to work with the latest

Bug#880545: wireshark: does not dissect protocol foobar

2017-11-01 Thread Xiong Yunuo
Package: wireshark Version: 2.4.2-1 Severity: normal Dear Maintainer, *** Reporter, please consider answering these questions, where appropriate *** * What led up to the situation? * What exactly did you do (or not do) that was effective (or ineffective)? * What was the outcome of

Bug#880544: nagios-plugins-contrib: check_rbl does not handle IPv6 addresses

2017-11-01 Thread Hamish Moffatt
Package: nagios-plugins-contrib Version: 21.20170222 Severity: normal check_rbl does not properly query the DNSBLs for IPv6 addresses. The logic to convert the IP to .zen.spamhaus.org for example assumes an IPv4 dotted quad and doesn't handle IPv6. Hamish -- System Information: Debian

Bug#880527: RFS: fractalnow/0.8.2-1 [ITA]

2017-11-01 Thread Adam Borowski
On Wed, Nov 01, 2017 at 08:06:10PM +0100, Innocent De Marchi wrote: > * Package name: fractalnow >Version : 0.8.2-1 > > https://mentors.debian.net/debian/pool/main/f/fractalnow/fractalnow_0.8.2-1.dsc Alas, it FTBFSes: debian/rules override_dh_auto_configure make[1]:

Bug#880543: lvm2-dbusd fails to Depend on python3-udev hence fails to start

2017-11-01 Thread Eric Côté
Package: lvm2-dbusd Version: 2.02.175-1 Severity: normal Please add python3-udev to dependencies :). Thanks -- System Information: Debian Release: buster/sid APT prefers unstable APT policy: (1001, 'unstable'), (1000, 'experimental'), (500, 'testing') Architecture: amd64 (x86_64) Foreign

Bug#880542: wget: crash (SIGSEGV) when downloading a manual page from manpages.d.o

2017-11-01 Thread Paul Wise
Package: wget Version: 1.19.2-1 Severity: normal Usertags: crash Control: affects -1 + debian-goodies When I run `dman interfaces` I get a core dump from wget. Here is some discussion from #debian-devel about the issue: anyone else running buster/sid get a core dump from wget when running

Bug#879718: aptly: Aptly can't handle deb packages built using dpkg 1.19.0+

2017-11-01 Thread Boyuan Yang
Control: severity -1 grave Control: tags -1 + fixed-upstream Dear maintainer, Upstream now has a fix in trunk code. Just cherry-picked the fix and confirmed that everything works well. I'm looking forward to seeing a fixed version into Debian testing/unstable and stable/oldstable updates into

Bug#870078: libsane1 breaks all 3rd party scanner drivers

2017-11-01 Thread Jeremy Bicha
On Wed, Nov 1, 2017 at 7:49 PM, John Paul Adrian Glaubitz wrote: > On 11/02/2017 12:18 AM, Jeremy Bicha wrote: > Again, changing library package names due to SO bumps happen all > the time. I don't see why the libsane package should be any different > from other

Bug#850741: python-docker 2.x in Sid

2017-11-01 Thread Thomas Goirand
Hi, Could you please upload the 2.x version of python-docker into Sid? I've uploaded python-zunclient that needs it. Cheers, Thomas Goirand (zigo)

Bug#880449: unison: Uncaught exception Failure("input_value: bad bigarray kind")

2017-11-01 Thread Vincent Lefevre
On 2017-11-01 21:20:24 +0100, Stéphane Glondu wrote: > This is a known issue, and not easy to fix. Upstream is not interested > to make unison compatible with other versions of itself (or same version > compiled with another version of OCaml): Unison is designed to work only > with the same

Bug#736567: libdumbnet should be multiarch

2017-11-01 Thread Manuel A. Fernandez Montecelo
Control: tags -1 - moreinfo Control: fixed -1 1.12-7 Control: close -1 According to the changelog, it's already multi-archified, and the reporter address not working, so closing this bug report. === Changes: libdumbnet (1.12-7) unstable; urgency=medium . * QA upload. * Multiarchify

Bug#880541: RFP: unison2.48.3 -- file-synchronization tool for Unix and Windows

2017-11-01 Thread Vincent Lefevre
Package: wnpp Severity: wishlist * Package name: unison2.48.3 Version : 2.48.3 Upstream Author : Benjamin Pierce * URL : see unison package from stretch * License : see unison package from stretch Programming Lang: OCaml Description

Bug#879755: debootstrap fails with current sid without apt-transport-https and https URLs

2017-11-01 Thread Philipp Kern
On 10/28/2017 11:31 AM, Julian Andres Klode wrote: > On Fri, Oct 27, 2017 at 11:24:51PM +0200, Philipp Kern wrote: >> The other half of the point is that sid is symlinked to various suites, >> so when we fix debootstrap we'd have a script divergence for the coming >> release. > It would make most

Bug#878358: dnprogs FTCBFS: many reasons

2017-11-01 Thread Manuel A. Fernandez Montecelo
Hi Helmut, 2017-10-13 08:40 Helmut Grohne: Source: dnprogs Version: 2.65 Tags: patch User: helm...@debian.org Usertags: rebootstrap dnprogs fails to cross build from source for many reasons. The packaging runs plain make without passing any cross toolchain, so it ends up using the build

Bug#870078: libsane1 breaks all 3rd party scanner drivers

2017-11-01 Thread John Paul Adrian Glaubitz
On 11/02/2017 12:18 AM, Jeremy Bicha wrote: > I don't want to drag this out, since in my opinion this issue is > resolved with comment 57. But I think it's worth noting: > 1) There was no soname bump here. My understanding of Debian Policy > and the Lintian warning is that it does not require

Bug#878700: needrestart: False positive with AppImage

2017-11-01 Thread Richard Hector
On 02/11/17 07:46, Thomas Liske wrote: > tags 878700 upstream moreinfo > thanks > > Hi Richard, > > > Richard Hector writes: >> It appears that AppImage packages mount their filesystem under /tmp/, >> and needrestart may find that there are open binaries or libraries

Bug#736567: libdumbnet should be multiarch

2017-11-01 Thread Manuel A. Fernandez Montecelo
Control: tags -1 + moreinfo Hi Ben, 2014-01-25 01:23 Ben Howard: Package: libdumbnet Version: 1.12-4 Severity: normal libdumbnet is not multiarch compliant, it should be Would it be possible that you provide a patch? Cheers. -- Manuel A. Fernandez Montecelo

Bug#870078: libsane1 breaks all 3rd party scanner drivers

2017-11-01 Thread Jeremy Bicha
On Wed, Nov 1, 2017 at 4:30 PM, John Paul Adrian Glaubitz wrote: > On 11/01/2017 09:19 PM, Gunter Königsmann wrote: >> When dealing with 3rd-party products any change in upstream sane or >> debian might cause breaks, though. > > And? As I said, this happens all the

Bug#859387: NeedRestart::UI assumes STDOUT is a terminal

2017-11-01 Thread Thomas Liske
Re, Guillaume writes: > Would the fix make it into the upcoming 2.12 release ? > > I just want to know which version to watch for, no hurry. yes, it will be part of 2.12 as any other fixes and changes being merged before releasing it. There are still a few issues left for

Bug#880540: spip: upgrade removes Postgres access and all sections and articles

2017-11-01 Thread Axel
Package: spip Version: 3.1.4-3~deb9u1 Severity: important Dear Maintainer, after the upgrade to this version, I could no longer log in as an author. After trying lots of things I found this: https://forum.spip.net/fr_264675.html?debut_forums=%40264795#forum264795 (neither the English nor the

Bug#856908: gengetopt: gengetopt can't be used in cross-building

2017-11-01 Thread Manuel A. Fernandez Montecelo
Control: tags -1 + pending Hi, 2017-03-06 05:44 Dima Kogan: Package: gengetopt Severity: normal Hi. Currently projects using gengetopt cannot be cross-built because Build-Depends: gengetopt can only satisfy the build architecture, not the target architecture. This can be solved by adding

Bug#869704: bitcoin-qt: undefined symbol: _ZNK8UniValueixEj

2017-11-01 Thread Witold Baryluk
Package: bitcoin-qt Version: 0.15.0.1~dfsg-1 Followup-For: Bug #869704 Hi, any updates on this? $ bitcoin-qt bitcoin-qt: symbol lookup error: bitcoin-qt: undefined symbol: _ZNK8UniValueixEj $ This basically makes bitcoin-qt unusable to anybody in sid. -- System Information: Debian Release:

Bug#880539: taskwarrior: Bad location of bash completion scheme

2017-11-01 Thread Rubén Gómez Antolí
Package: taskwarrior Version: 2.5.1+dfsg-4 Severity: minor Dear Maintainer, Update Taskwarrior some days ago and note that completion dont't work for me since upgrading. I revised that location of the bash scheme is not correct. Scheme location is on:

Bug#880538: python-djangorestframework: New upstream release

2017-11-01 Thread Chris Lamb
Source: python-djangorestframework Version: 3.4.0-2 Severity: wishlist Hi, New upstream 3.7 release is available at: http://www.django-rest-framework.org/topics/3.7-announcement/ Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk

Bug#878894: Member list

2017-11-01 Thread Joerg Jaspert
Hi as it wouldn't be too nice to put the members mail address list into the bug directly (thanks spammers), any DD can fetch todays variant on master.debian.org in ~joerg/debconf_lists/$listname For the old archives, there is https://lists.debconf.org/mbox/ with a link to the lurker mbox of

Bug#836095: iw FTCBFS: uses build architecture tools

2017-11-01 Thread Manuel A. Fernandez Montecelo
Hi, 2016-08-30 17:13 Helmut Grohne: Source: iw Version: 3.17-1 Tags: patch User: helm...@debian.org Usertags: rebootstrap iw fails to cross build from source, because it uses the build architecture pkg-config instead of the host prefixed one. The attached patch supplies a suitable PKG_CONFIG

Bug#880537: Fails to start

2017-11-01 Thread 128
Package: lxhotkey-gtk Version: 0.1.0-1 When executed fails with the following error. Window manager Openbox isn't supported now, sorry. Thanks

Bug#868170: libemail-address-perl: Email::Address->parse() is vulnerable to CVE-2015-7686

2017-11-01 Thread Pali Rohár
On Wednesday 01 November 2017 13:59:53 gregor herrmann wrote: > On Wed, 01 Nov 2017 11:36:03 +0100, Pali Rohár wrote: > > > On Thursday 13 July 2017 17:36:09 Salvatore Bonaccorso wrote: > > > In particular as initial step we need a packaged > > > libemail-address-xs-perl. Volunteers? > > > ;-) >

Bug#880532: thunderbird: tries to exec nvidia-modprobe which is denied by apparmor

2017-11-01 Thread Philipp Kern
Hi Simon, On 11/01/2017 10:55 PM, Simon Deziel wrote: > On 2017-11-01 05:38 PM, Philipp Kern wrote: >> Package: thunderbird >> Version: 1:52.4.0-1 >> X-Debbugs-Cc: intrig...@debian.org, si...@sdeziel.info >> >> I'm using thunderbird with apparmor enabled and I get the following deny >> with the

Bug#880536: qupzilla: please provide the sources in a VCS

2017-11-01 Thread Rogério Brito
Package: qupzilla Version: 2.2.0~dfsg1-2 Severity: wishlist Hi. I just wanted to check the (debian) sources of qupzilla, but it seems that you don't use any VCS (or, at least, don't support Vcs-* fields in debian/control). Please, if you have not yet done so, please adopt one and document it,

Bug#880532: thunderbird: tries to exec nvidia-modprobe which is denied by apparmor

2017-11-01 Thread Simon Deziel
Hi Philipp, On 2017-11-01 05:38 PM, Philipp Kern wrote: > Package: thunderbird > Version: 1:52.4.0-1 > X-Debbugs-Cc: intrig...@debian.org, si...@sdeziel.info > > I'm using thunderbird with apparmor enabled and I get the following deny > with the proprietary nvidia driver installed and active

Bug#880535: qupzilla: please, provide a variant without KDE integration

2017-11-01 Thread Rogério Brito
Package: qupzilla Version: 2.2.0~dfsg1-2 Severity: wishlist Hi. I have been using qupzilla for a few months now and I like it a lot. Unfortunately, the latest upload introduced support for kwallet which is super nice for the people using KDE and friends, but it is a huge download and code that

Bug#880534: nbconvert: please add dependency “Suggests: python-nbconvert-doc”

2017-11-01 Thread Ben Finney
Source: nbconvert Version: 5.3.1-1 Severity: minor Dear Maintainer, Working with the ‘nbconvert’ packages requires understanding how it works and what it does. Please set a “Suggests: python-nbconvert-doc” dependency to the binary package ‘python3-nbconvert’, and other binary packages for which

Bug#880532: thunderbird: tries to exec nvidia-modprobe which is denied by apparmor

2017-11-01 Thread Philipp Kern
On 11/01/2017 10:38 PM, Philipp Kern wrote: > I'm using thunderbird with apparmor enabled and I get the following deny > with the proprietary nvidia driver installed and active once on every > application startup: > > [37152.076369] audit: type=1400 audit(1509571965.982:138): > apparmor="DENIED"

Bug#880533: ublock-origin: please add dependency “Suggests: ublock-origin-doc”

2017-11-01 Thread Ben Finney
Source: ublock-origin Version: 1.13.8+dfsg-1 Severity: minor Dear Maintainer, Working with the ‘ublock-origin’ packages requires understanding how it works and what it does. Please set a “Suggests: ublock-origin-doc” dependency to the binary packages that “Provides: ublock-origin” (e.g.

Bug#841644: enca FTCBFS: build tool make_hash built with host architecture compiler

2017-11-01 Thread Manuel A. Fernandez Montecelo
2017-11-01 9:51 GMT+01:00 Michal Čihař : > Hello > > On Tue, 2017-10-31 at 23:00 +0100, Manuel A. Fernandez Montecelo wrote: >> This happened a year ago, yet the fix is not in unstable yet. >> >> Would it be possible to include it in the near future? Can we help >> in >> any

Bug#880532: thunderbird: tries to exec nvidia-modprobe which is denied by apparmor

2017-11-01 Thread Philipp Kern
Package: thunderbird Version: 1:52.4.0-1 X-Debbugs-Cc: intrig...@debian.org, si...@sdeziel.info I'm using thunderbird with apparmor enabled and I get the following deny with the proprietary nvidia driver installed and active once on every application startup: [37152.076369] audit: type=1400

Bug#704905: please ship contrib/ scripts in the Debian package

2017-11-01 Thread Roland Hieber
Package: ledger Version: 3.1.2~pre1+g3a00e1c+dfsg1-5 Followup-For: Bug #704905 Yes please! Having the contrib scripts in Debian would be very convenient, as I've just had the need to look for the example implementation of contrib/getquote.pl :-) Cheers, - Roland

Bug#681726: Time to remove eclipse from Testing?

2017-11-01 Thread Markus Koschany
Am 01.11.2017 um 22:04 schrieb Adrian Bunk: > On Wed, Nov 01, 2017 at 09:23:32PM +0100, Markus Koschany wrote: >> Am 01.11.2017 um 20:47 schrieb Jeremy Bicha: >>> On Fri, Oct 20, 2017 at 6:24 PM, Emmanuel Bourg wrote: Le 20/10/2017 à 23:52, Jeremy Bicha a écrit :

Bug#880502: [pkg-lxc-devel] Bug#880502: lxc: cannot start container with kernel 4.13.10

2017-11-01 Thread Ben Hutchings
On Wed, 2017-11-01 at 15:38 +0100, Evgeni Golov wrote: > Ohai, > > On Wed, Nov 01, 2017 at 12:00:12PM -0200, Antonio Terceiro wrote: > > > lxc-start 20171101123914.655 ERRORlxc_apparmor - > > > lsm/apparmor.c:apparmor_process_label_set:220 - If you really want to > > > start this

Bug#681726: Time to remove eclipse from Testing?

2017-11-01 Thread Adrian Bunk
On Wed, Nov 01, 2017 at 09:23:32PM +0100, Markus Koschany wrote: > Am 01.11.2017 um 20:47 schrieb Jeremy Bicha: > > On Fri, Oct 20, 2017 at 6:24 PM, Emmanuel Bourg wrote: > >> Le 20/10/2017 à 23:52, Jeremy Bicha a écrit : > >> > >>> Never mind. I tried doing the dak queries and

Bug#880531: libvncclient1: Can't connect to VMware

2017-11-01 Thread Matthew Gabeler-Lee
Package: libvncclient1 Version: 0.9.11+dfsg-1 Severity: normal Tags: upstream libvncclient has a bug with how it expresses the truecolor pixel format which causes an error talking to VMware servers. This looks to have been fixed upstream, so just need to import this fix or package a new upstream

Bug#866353: rsync: wrong Architecture field in cross built binary package

2017-11-01 Thread Manuel A. Fernandez Montecelo
2017-11-01 10:02 GMT+01:00 Paul Slootman : > On Tue 31 Oct 2017, Manuel A. Fernandez Montecelo wrote: > >> Many packages build-depend on rsync, and this patch seems like a net >> gain to apply even in the absence of more benefits. >> >> What do you think about applying it, Paul? >

Bug#870078: libsane1 breaks all 3rd party scanner drivers

2017-11-01 Thread John Paul Adrian Glaubitz
On 11/01/2017 09:19 PM, Gunter Königsmann wrote: > When dealing with 3rd-party products any change in upstream sane or > debian might cause breaks, though. And? As I said, this happens all the time. Seriously. You are phrasing this as if renaming library packages due to an SO bump is an

Bug#880530: slurm-llnl: CVE-2017-15566

2017-11-01 Thread Salvatore Bonaccorso
Source: slurm-llnl Version: 17.02.7-1 Severity: grave Tags: patch security upstream Forwarded: https://bugs.schedmd.com/show_bug.cgi?id=4228 Control: found -1 16.05.9-1 Hi, the following vulnerability was published for slurm-llnl. CVE-2017-15566[0]: | Insecure SPANK environment variable

Bug#870078: libsane1 breaks all 3rd party scanner drivers

2017-11-01 Thread Gunter Königsmann
> As I said, library transitions happen all the time. Debian's responsibility > lies within the limits of the Debian archive. We can not and we also don't > want to be responsible for any *binary* packages outside the Debian archive. Debian cannot fix the rest of the world in case that it breaks

Bug#681726: Time to remove eclipse from Testing?

2017-11-01 Thread Markus Koschany
Am 01.11.2017 um 20:47 schrieb Jeremy Bicha: > On Fri, Oct 20, 2017 at 6:24 PM, Emmanuel Bourg wrote: >> Le 20/10/2017 à 23:52, Jeremy Bicha a écrit : >> >>> Never mind. I tried doing the dak queries and I eventually got more >>> than 500 reverse-depends before I gave up.

Bug#880449: unison: Uncaught exception Failure("input_value: bad bigarray kind")

2017-11-01 Thread Stéphane Glondu
Control: tags -1 + wishlist wontfix Le 31/10/2017 à 18:43, Vincent Lefevre a écrit : >> Since the upgrade to 2.48.4-1, I get when synchronizing with >> a Debian/stable server: >> >> Unison failed: Uncaught exception Failure("input_value: bad bigarray kind") > [...] > >

Bug#204156: [apt-cache] depends and rdepends should also output dependency types

2017-11-01 Thread Tom
retitle 204156 [apt-cache] depends and rdepends should also output dependency types thanks

Bug#870078: libsane1 breaks all 3rd party scanner drivers

2017-11-01 Thread John Paul Adrian Glaubitz
Hello Rolf! There are obviously some misconceptions on the Ubuntu side, especially among its users what exactly has happened here and why it happened. First of all, it's not Debian's responsibility if Ubuntu as their downstream pulls a package from the *experimental* distribution without making

Bug#870078: libsane1 breaks all 3rd party scanner drivers

2017-11-01 Thread John Paul Adrian Glaubitz
On 11/01/2017 08:21 PM, Rolf Bensch wrote: > This isn't a good idea, because I'm building the ppa from SANE's daily > git snapshots. > > If you decided to rename libsane to libsane1 generally, I can change the > name in my ppa. Can you please take your Ubuntu discussions out of Debian. This

Bug#681726: Time to remove eclipse from Testing?

2017-11-01 Thread Jeremy Bicha
On Fri, Oct 20, 2017 at 6:24 PM, Emmanuel Bourg wrote: > Le 20/10/2017 à 23:52, Jeremy Bicha a écrit : > >> Never mind. I tried doing the dak queries and I eventually got more >> than 500 reverse-depends before I gave up. (Attached) > > Funny, I never realized that src:eclipse

Bug#880528: wordpress: Unsafe queries with wpdb->prepare

2017-11-01 Thread Craig Small
Source: wordpress Version: 4.8.2+dfsg-2 Severity: grave Tags: upstream security Justification: user security hole WordPress versions 4.8.2 and earlier are affected by an issue where $wpdb->prepare() can create unexpected and unsafe queries leading to potential SQL injection (SQLi). WordPress core

Bug#880467: jasperreports: CVE-2017-14941, CVE-2017-5528, CVE-2017-5529

2017-11-01 Thread Markus Koschany
Short update: One staff member told me that my options are to read the advisories, which don't contain any detailed information or patches, or, if I have a commercial license, to contact support. Great, let's buy a license to get more information about security bugs. So far the only viable

Bug#880529: Conffile bacula-dir.conf can be lost; unowned conffiles

2017-11-01 Thread Carsten Leonhardt
Source: bacula Version: 5.2.6+dfsg-9.3 Severity: serious The main configuration files (bacula-{dir,sd,fd}.conf, bconsole.conf, bat.conf) in the bacula packages aren't registered as belonging to their respective packages. This leads to the following problem: Due to the restructuring of the

Bug#880470: libswt-webkit-gtk-3-jni: Depend on libwebkitgtk-1.0-0 which is deprecated

2017-11-01 Thread Adrian Bunk
On Tue, Oct 31, 2017 at 05:54:47PM -0400, Jeremy Bicha wrote: >... > The recent swt-gtk/3.8.2-4.2 NMU fixed an RC bug by introducing > another RC bug. I'm a bit upset because it also clobbered my 3.8.2-4.1 > NMU one day before it was going to migrate to testing and I was not > CC'd on the 4.2 NMU

Bug#879536: qemu: Antialias, graphics artifacts and screen corruptions (SDL2?)

2017-11-01 Thread Antonio
I have same problems. Thanks

Bug#870078: libsane1 breaks all 3rd party scanner drivers

2017-11-01 Thread Rolf Bensch
Am 01.11.2017 um 20:10 schrieb Jeremy Bicha: > Just copy the proposed update libsane-backends > 1.0.27-1~experimental2ubuntu2.1 to your PPA. This isn't a good idea, because I'm building the ppa from SANE's daily git snapshots. If you decided to rename libsane to libsane1 generally, I can change

Bug#880111: duplicity: fails to ask for GPG key passphrase and claims that none was given

2017-11-01 Thread Francesco Poli
On Tue, 31 Oct 2017 21:58:52 +1000 Alexander Zangerl wrote: [...] > On Sun, 29 Oct 2017 16:38:10 +0100, "Francesco Poli (wintermute)" writes: > >When doing so, duplicity (or maybe gpg) complains that it could not > >perform any decryption, since no passphrase was given: > > hmm. Hello

Bug#870078: libsane1 breaks all 3rd party scanner drivers

2017-11-01 Thread Jeremy Bicha
On Wed, Nov 1, 2017 at 3:01 PM, Rolf Bensch wrote: > FYI, this also beaks my Ubuntu PPA Just copy the proposed update libsane-backends 1.0.27-1~experimental2ubuntu2.1 to your PPA. Thanks, Jeremy Bicha

Bug#879063: ipmitool FTBFS with debhelper 10.9.2

2017-11-01 Thread Sebastiaan Couwenberg
Hi Jörg, On 10/30/2017 10:33 PM, Sebastiaan Couwenberg wrote: > On Sat, 28 Oct 2017 13:38:32 +0200 Jörg Frings-Fürst wrote: >> here the FTBFS isn't reproducible. > > I can also reproduce the issue, and the patch to fix the issue is attached. > > From dh_systemd_enable(1): > > " > --name=name >

Bug#870078: libsane1 breaks all 3rd party scanner drivers

2017-11-01 Thread Rolf Bensch
Hi All, Why have you renamed libsane to libsane1? Debian provides more effective mechanisms for versioning a package than renaming it. FYI, this also beaks my Ubuntu PPA (https://launchpad.net/~rolfbensch/+archive/ubuntu/sane-git), which I'm providing as an Ubuntu using SANE maintainer. Hope

Bug#633466: lists.debian.org: List archive search delivers results containing removed spam messages

2017-11-01 Thread Olly Betts
On Sun, Jul 10, 2011 at 04:57:38PM +0200, Frederik Schwarzer wrote: > If I search for e.g. "filmas" in all lists on > http://lists.debian.org/search.html > the result contains about 90% already removed spam messages. > > The results 2,3 and 4 for example are: >

Bug#880527: RFS: fractalnow/0.8.2-1 [ITA]

2017-11-01 Thread Innocent De Marchi
Package: sponsorship-requests Severity: normal Dear mentors, I am looking for a sponsor for my package "fractalnow" * Package name: fractalnow Version : 0.8.2-1 Upstream Author : Marc Pegon * URL : http://fractalnow.sourceforge.net * License

Bug#204156: [apt-cache] depends and rdepends should also output dependency types

2017-11-01 Thread Tom
retitle 204156 [apt-cache] depends and rdepends should also output dependency types Hi Filtering is possible with the --no-pre-depends --no-suggests --no- recommends --no-conflicts --no-breaks --no-replaces --no-enhances switches, so you can control that. But the output should also indicate the

Bug#859387: NeedRestart::UI assumes STDOUT is a terminal

2017-11-01 Thread Guillaume
Le 01/11/2017 à 19:08, Thomas Liske a écrit : > > I've adopted the PR and GetTerminalSize() should be no more called on > a non-TTY STDOUT. Thanks for the report and the PR. > > > Regards, > Thomas > > Hi Thomas, Thank for the quick feedback on the PR. Would the fix make it into the

Bug#880491: RFS: budgie-desktop/10.4+git20171031.10.g9f71bb8-1

2017-11-01 Thread Herbert Fortes
Em 01-11-2017 06:06, foss.freedom escreveu: > Package: sponsorship-requests > Severity: normal > Dear mentors, > > I am looking for a sponsor for my package "budgie-desktop" > > * Package name: budgie-desktop >Version : 10.4+git20171031.10.g9f71bb8-1 >Upstream Author :

Bug#878700: needrestart: False positive with AppImage

2017-11-01 Thread Thomas Liske
tags 878700 upstream moreinfo thanks Hi Richard, Richard Hector writes: > It appears that AppImage packages mount their filesystem under /tmp/, > and needrestart may find that there are open binaries or libraries there > but be unable to find them. Sorry, I'm not sure

Bug#877669: ......Cianix........Free..........Trial..........k1

2017-11-01 Thread eurydice m simon
On November 1, 2017, at 11:40 AM, Kevin Cameron wrote:    Your message dated Wed, 1 Nov 2017 18:12:33 +0100 with message-id and subject line Re: Bug#877669: grammar/typo issues has caused the Debian Bug report #877669, regarding grammar/typo issues to be marked as

Bug#880490: tor: Does not start when the AppArmor LSM is enabled but the apparmor package is not installed

2017-11-01 Thread Viktor Jägersküpper
On Wed, 01 Nov 2017 08:04:37 +0100 intrig...@debian.org wrote: > So I propose we do this: > > --- a/debian/systemd/tor@default.service > +++ b/debian/systemd/tor@default.service > @@ -20,7 +20,7 @@ Restart=on-failure > LimitNOFILE=65536 > > # Hardening > -AppArmorProfile=system_tor >

Bug#880469: Follow-up on bug #880469

2017-11-01 Thread Алексей Шилин
I've found Debian bug #807424 [1] on a similar issue which was resolved by making kdenlive depend on oxygen-icon-theme. Probably, it's time to change this dependency to the Breeze icon set. (The reason I suggested to add this dependency as Recommends is that kdenlive can use other icon themes as

Bug#859387: NeedRestart::UI assumes STDOUT is a terminal

2017-11-01 Thread Thomas Liske
tags 859387 upstream fixed-upstream forwarded 859387 https://github.com/liske/needrestart/issues/86 thanks Hi, I've adopted the PR and GetTerminalSize() should be no more called on a non-TTY STDOUT. Thanks for the report and the PR. Regards, Thomas Guillaume

Bug#871638: [Pkg-rust-maintainers] Bug#871638: Bug#871638: rustc panics when trying to list the target cpus if the current directory does not exist anymore

2017-11-01 Thread Laurent Arnoud
Hi all, This is reported and merged in https://github.com/rust-lang/rust/pull/45505 Cheers, -- Laurent signature.asc Description: PGP signature

Bug#878105: release-notes: problems building the release-notes (jessie) for the Debian website

2017-11-01 Thread Baptiste Jammet
Hi Laura, Dixit Laura Arjona Reina, le 10/10/2017 : >> maybe >> >> works for jessie? >> > >Thanks for the suggestion. >Attaching new patch. Your patch seems to be sufficient, and is surely not very intrusive. Please apply. Baptiste pgpS1RehwRjmG.pgp Description: Signature digitale

Bug#851066: Request for removal

2017-11-01 Thread Alexander Heinlein
Please remove this package if fixing the bug is not an option. In the current state this package is just a really big security nightmare. Either fix the bug or remove the package. Don't let users assume having an up-to-date version of flash installed. This is just dangerous. Regards Alex

Bug#880526: json-c: Please provide libjson-c3-udeb

2017-11-01 Thread Guilhem Moulin
Source: json-c Version: 0.12.1-1.2 Severity: wishlist Dear Maintainer, cryptsetup ≥2.0.0 introduces a new on-disk “LUKS2” format, which uses JSON text format for metadata. Hence libcryptsetup12 (currently in experimental only) now depends on libjson-c3, and for cryptsetup to keep working in the

Bug#880525: libargon2-0: Please provide libargon2-0-udeb

2017-11-01 Thread Guilhem Moulin
Package: libargon2-0 Version: 0~20161029-1 Severity: wishlist Dear Maintainer, cryptsetup ≥2.0.0 introduces a new on-disk “LUKS2” format, which support Argon2i and Argon2id as PBKDF. Hence the package now depends on libargon2-0 (in experimental only), and for cryptsetup to keep working in the

Bug#880475: internal lintian shlib error running lintian -F on gcc-8-cross_1_amd64-changes

2017-11-01 Thread Chris Lamb
tags 880475 + moreinfo thanks Hi Matthias, > $ lintian -F ../gcc-8-cross_1_amd64.changes 2>&1 | tee ../log.lintian > Use of uninitialized value $val in split at > /usr/share/perl5/Lintian/Collect/Binary.pm line 423 Whilst I could probably "fix" this blind, it would be great to have access to

Bug#863663: libgstreamer1.0-0: plays MJPEG AVI files (and possibly other formats) at degraded quality

2017-11-01 Thread Francesco Poli
On Fri, 22 Sep 2017 23:58:39 +0200 Francesco Poli wrote: > On Tue, 5 Sep 2017 23:16:57 +0200 Francesco Poli wrote: > > > On Tue, 05 Sep 2017 10:40:13 +0100 Tim-Philipp Müller wrote: > [...] > > > > > > Someone might have a look later this week. > > > > This would be highly appreciated! > > >

Bug#880524: opendmarc: Hardening

2017-11-01 Thread Jack Bates
Package: opendmarc Tags: patch This patch makes Lintian happy: http://nottheoilrig.com/hardening.patch Lintian info: https://lintian.debian.org/tags/hardening-no-bindnow.html

Bug#852133: ITA: keras -- deep learning framework running on Theano or TensorFlow

2017-11-01 Thread Daniel Stender
On Wed, 1 Nov 2017 12:44:47 -0300 Stephen Sinclair wrote: > Package: sponsorship-requests > Severity: normal > > Dear mentors, > > I am looking for a sponsor for the following package: > > * Package name: keras > Version : 1.0.7-2 > Upstream Author :

Bug#880504: Update

2017-11-01 Thread Andrew Chadwick
Relevant upstream commit merge: https://github.com/torvalds/linux/commit/89db69d670a11274c323af48479841d3d765bd49 Not tested it yet, but I'll try to report back. -- Andrew Chadwick

Bug#880523: remove python3.5 from the archive

2017-11-01 Thread Matthias Klose
Package: release.debian.org python3.6 is now the default python3 version. python3.5 needs to be dropped and removed. Please schedule binNMUs to drop 3.5 as a supported python3 version. See https://release.debian.org/transitions/html/python3.5-rm.html

Bug#880381: apparmor profile breaks xul-ext-exteditor

2017-11-01 Thread Vincas Dargis
Maybe we need TODO inside a profile for the future, to not forget that we need abstraction or explicit rules for xul-ext-editor, when we fix that too-permissive `/usr/bin/* Cx -> sanitized_helper`?

Bug#852133: ITA: keras -- deep learning framework running on Theano or TensorFlow

2017-11-01 Thread Stephen Sinclair
Package: sponsorship-requests Severity: normal Dear mentors, I am looking for a sponsor for the following package: * Package name: keras Version : 1.0.7-2 Upstream Author : François Chollet * URL : http://keras.io/ * License : MIT Section : python

Bug#880522: quagga-core: zebra fails to start (probably due to changes in systemd)

2017-11-01 Thread Christoph Biedl
Package: quagga-core Version: 1.1.1-3 Severity: important Dear Maintainer, after receiving word bgpd no longer starts[1], presumably after systemd went from 234-3 to 235-2, I checked a bit further and the most likely explanation is zebra.service is invalid and used to work in the past rather by

Bug#880521: latexmk: warning about glob being deprecated

2017-11-01 Thread Julian Gilbey
Package: latexmk Version: 1:4.41-1 Severity: normal Tags: upstream erdos:/tmp $ latexmk -c testfile Latexmk: This is Latexmk, John Collins, 1 January 2015, version: 4.41. File::Glob::glob() will disappear in perl 5.30. Use File::Glob::bsd_glob() instead. at /usr/bin/latexmk line 3259. I've let

Bug#880520: ruby-mmap2: FTBFS on hurd-i386: TypeError: madvise(1073741902)

2017-11-01 Thread Aaron M. Ucko
Source: ruby-mmap2 Version: 2.2.7-1 Severity: important Tags: upstream Justification: fails to build from source User: debian-h...@lists.debian.org Usertags: hurd-i386 The build of ruby-mmap2 for hurd-i386 (admittedly not a release architecture) failed per the below excerpt from

Bug#880519: openvswitch: FTBFS on ppc64: tests encounter timeout; two explicitly fail

2017-11-01 Thread Aaron M. Ucko
Source: openvswitch Version: 2.8.1+dfsg1-2 Severity: important Tags: upstream Justification: fails to build from source (but built successfully in the past) User: debian-powe...@lists.debian.org Usertags: ppc64 Builds of openvswitch 2.8.1(+dfsg1) for ppc64 (admittedly not a release architecture)

Bug#880517: openvswitch: FTBFS on m68k: opf10_packet_in size wrong

2017-11-01 Thread Aaron M. Ucko
Source: openvswitch Version: 2.8.1+dfsg1-2 Severity: important Tags: upstream Justification: fails to build from source User: debian-m...@lists.debian.org Usertags: m68k Builds of openvswitch for m68k (admittedly not a release architecture) have been failing. At least at present, the (immediate)

Bug#880518: haskell-xml-hamlet: unsatisfiable B-D: libghc-xml-conduit-dev (<< 1.5) but sid has 1.5.1-1

2017-11-01 Thread Andreas Beckmann
Source: haskell-xml-hamlet Version: 0.4.1-1 Severity: serious Justification: fails to build from source (but built successfully in the past) Hi, haskell-xml-hamlet cannot be built in sid anymore since haskell-xml-conduit was upgraded to 1.5.1. Andreas

Bug#880516: RFP : qtscxml-opensource-src bug

2017-11-01 Thread laurent Trinques
Package: wnpp Severity: RFP Dear mentors, I am looking for a sponsor to package and/or upload "qtscxml" https://doc.qt.io/qt-5/qscxmlc.html Thanks for your consideration.

  1   2   >