Bug#1009636: ruby-devise-two-factor: CVE-2021-43177 - possible reuse of OTP due to incomplete fix for CVE-2015-7225

2022-04-13 Thread Neil Williams
On Wed, 13 Apr 2022 11:18:50 +0100 Neil Williams wrote: > Source: ruby-devise-two-factor > Version: 4.0.2-1 > Severity: important > Tags: security > X-Debbugs-Cc: codeh...@debian.org, Debian Security Team > > > Hi, > > The following vulnerability was published for ruby-devise-two-factor. > > C

Bug#1009636: ruby-devise-two-factor: CVE-2021-43177 - possible reuse of OTP due to incomplete fix for CVE-2015-7225

2022-04-13 Thread Neil Williams
Source: ruby-devise-two-factor Version: 4.0.2-1 Severity: important Tags: security X-Debbugs-Cc: codeh...@debian.org, Debian Security Team Hi, The following vulnerability was published for ruby-devise-two-factor. CVE-2021-43177[0]: | As a result of an incomplete fix for CVE-2015-7225, in versi

Bug#1004171: bash: Replace add-shell/remove-shell with declarative shells.d trigger

2022-04-13 Thread Johannes Schauer Marin Rodrigues
Hi, Quoting Johannes Schauer Marin Rodrigues (2022-01-22 09:25:43) > the attached patch replaces add-shell/remove-shell with the declarative > shells.d trigger from debianutils. > > For details about this new mechanism see https://bugs.debian.org/990440. > > This further reduces the number of ma

Bug#1009635: trousers init script fails with systemd if /dev/tpm* is absent

2022-04-13 Thread Marc Haber
Package: trousers Version: 0.3.15-0.1 Severity: normal Hi, upgrading the trousers package fails: [20/5013]mh@fan:~ $ sudo apt upgrade Reading package lists... Done Building dependency tree... Done Reading state information... Done Calculating upgrade... Done 0 upgraded, 0 newly installed, 0 to r

Bug#1009634: img2pdf: Does not work at all error: Can't convert ObjectHelper (or subclass) to Object implicitly. Use .obj to get access the underlying object.

2022-04-13 Thread Andreas Metzler
Package: img2pdf Version: 0.4.2-2 Severity: serious Justification: 1 Hello, this bug is mainly for documentation purposes. (I will close it once it has a number.) img2pdf currently in testing does not work at all. Taking any two jpegs (e.g. two from gimp) produces an error and empty output. ---

Bug#1009528: [Pkg-javascript-devel] Bug#1009528: node-temporary: FTBFS: dh_auto_test: error: /bin/sh -ex debian/tests/pkg-js/test returned exit code 2

2022-04-13 Thread Yadd
On 12/04/2022 21:22, Lucas Nussbaum wrote: Source: node-temporary Version: 1.1.0-2 Severity: serious Justification: FTBFS Tags: bookworm sid ftbfs User: lu...@debian.org Usertags: ftbfs-20220412 ftbfs-bookworm Hi, During a rebuild of all packages in sid, your package failed to build on amd64.

Bug#1009633: keepassxc: segfault with synced group

2022-04-13 Thread Sergey Spiridonov
Package: keepassxc Version: 2.6.2+dfsg.1-1 Severity: normal got segfault when open a file in a shared folder from 2 hosts at the same time with synced group on the same shared folder that is probably bad idea, but it should not segfault $ keepassxc QObject::startTimer: Timers cannot be started

Bug#1009632: The QPA plugin package contains the TLS backends

2022-04-13 Thread Robert Griebl
Package: qt6-qpa-plugins Version: 6.2.2 The new Qt6 plugins for the TLS backend (QSslSocket) got packaged with the QPA plugins, which is a bit awkward if you have a headless daemon that needs to download from https:// URLs, because you are now pulling in a lot of X11 and OpenGL dependencies.

Bug#1009631: lnav: FTBFS with glibc 2.34

2022-04-13 Thread Graham Inggs
Source: lnav Version: 0.9.0-2 Severity: important Tags: ftbfs fixed-upstream Hi Maintainer Your package used a vendored copy of doctest. It will FTBFS once glibc is upgraded to 2.34 due to MINSIGSTKSZ and SIGSTKSZ no longer being defined as constants. This was already fixed upstream [1]. Regar

Bug#1009630: /etc/tcsd.conf set to wrong owner in postinst

2022-04-13 Thread Marc Haber
Package: trousers Version: 0.3.15-0.1 Severity: important Hi, /var/lib/dpkg/info/trousers.postinst does chown tss:tss /etc/tcsd.conf However, the daemon complains that /etc/tcsd.conf must be root:tss: Apr 13 11:32:41 fan TCSD[540257]: TrouSerS ERROR: TCSD config file (/etc/tcsd.conf) must be u

Bug#1009629: live-tools: postinst generates two update-rc.d warnings

2022-04-13 Thread Daniel Lewart
Source: live-tools Version: 1:20190831 Severity: normal Tags: patch Live System Maintainers, $ sudo apt install live-tools ... Setting up live-tools (1:20190831) ... update-rc.d: warning: start and stop actions are no longer supported; falling back to defaults update-rc.d: warning: start runleve

Bug#1009473: claws-mail: FTBFS: perl.h:736:25: error: expected expression before ‘do’

2022-04-13 Thread Ricardo Mones
control: tags -1 confirmed fixed pending control: affects 1009149 claws-mail Hi Lucas, On Tue, Apr 12, 2022 at 07:45:18PM +0200, Lucas Nussbaum wrote: > Source: claws-mail > Version: 4.0.0-3 > Severity: serious > Justification: FTBFS > Tags: bookworm sid ftbfs > User: lu...@debian.org > Usertags:

Bug#1009628: linux-image-5.16.0-6-amd64: Wrong initial state of microphone muted LED on Thinkpad E14 (Gen 2)

2022-04-13 Thread Steven
Package: src:linux Version: 5.16.18-1 Severity: normal X-Debbugs-Cc: steven3k+deb...@gmail.com Dear Maintainer, I'd like to report that the initial status of the "microphone muted" LED on the F4 key of a Thinkpad E14 (Gen 2) laptop is incorrectly set to on on boot, even though the microphone is in

Bug#1009415: [Debichem-devel] Bug#1009415: gemmi: FTBFS: cif.hpp:40:30: error: ‘analysis’ in namespace ‘gemmi::cif::pegtl’ does not name a type

2022-04-13 Thread Andrius Merkys
Control: retitle -1 gemmi: FTBFS with tao-pegtl v3 Control: tags -1 + confirmed Hello, On 2022-04-12 20:45, Lucas Nussbaum wrote: >> /usr/include/tao/pegtl/match.hpp:57:34: error: incomplete type >> ‘gemmi::cif::rules::str_stop’ used in nested name specifier >>57 | -> decltype( Rule

Bug#1009626: android-platform-frameworks-base: CVE-2021-39796 - possible to trick victim to install harmful app due to a tapjacking/overlay attack

2022-04-13 Thread Neil Williams
Source: android-platform-frameworks-base Version: 1:10.0.0+r36-3 Severity: important Tags: security X-Debbugs-Cc: codeh...@debian.org, Debian Security Team Hi, The following vulnerability was published for android-platform-frameworks-base. CVE-2021-39796[0]: | In HarmfulAppWarningActivity of H

Bug#1009462: I think we can remove pyqi (Was: Bug#1009462: pyqi: FTBFS: Only Python 3.8 and 3.9 are supported.E: pybuild pybuild:369: configure: plugin distutils failed with: exit code=1: python3.10 s

2022-04-13 Thread Andreas Tille
Hi, if I remember correctly pyqi was packaged for qiime 1.x. It has no rdepends any more and I think we should remove it. Does anybody think differently? Kind regards Andreas. - Weitergeleitete Nachricht von Lucas Nussbaum - Date: Tue, 12 Apr 2022 20:44:37 +0200 From: Lucas N

Bug#1009625: RM: laszip -- ROM; Dead upstream

2022-04-13 Thread Bas Couwenberg
Package: ftp.debian.org Severity: normal X-Debbugs-Cc: pkg-grass-de...@lists.alioth.debian.org Control: block -1 by 1009624 Please remove laszip from the archive, it's literally dead upstream and should not be in Debian any longer. It was packaged for pdal which is also going to be removed (#100

Bug#1009385: libldns3 1.7.1-2.1 changes output of ldns-key2ds, causing FTBFS on dns-root-data [was: Re: Bug#1009385: dns-root-data: FTBFS: root-anchors.ds root.ds differ]

2022-04-13 Thread Michael Tokarev
13.04.2022 10:09, Michael Tokarev wrote: .. But let's try. How this utility is used in building of dns-root-data?  Lemme take a look at this package.  If you can provide me some minimal testcase to produce just the DS record which differs, it will be nice. I don't have time for this today. Th

Bug#1007131: facet-analyser: Don't depend on PDAL

2022-04-13 Thread Sebastiaan Couwenberg
On 3/11/22 19:09, Bas Couwenberg wrote: Your package build depends on PDAL, which is going to be removed. The attached patch fixes the issue by dropping the package from the build dependencies. paraview (5.10.1-1) dropped the pdal (build) dependencies, that should unblock the fix in facet-an

Bug#1009624: RM: pdal -- ROM; Should not be in Debian

2022-04-13 Thread Bas Couwenberg
Package: ftp.debian.org Severity: normal X-Debbugs-Cc: pkg-grass-de...@lists.debian.org As reported in #1006910 pdal should be removed from Debian. facet-analyser still has a build dependency on libpdal-dev and a patch for this is available in #1007131. The package hasn't seen any activity since

Bug#1009428: gitlabracadabra: FTBFS: dh_auto_test: error: pybuild --test -i python{version} -p "3.9 3.10" returned exit code 13

2022-04-13 Thread Mathieu Parent
Control: tag -1 upstream Control: forwarded -1 https://gitlab.com/gitlabracadabra/gitlabracadabra/-/merge_requests/240 On Tue, Apr 12, 2022 at 8:53 PM Lucas Nussbaum wrote: > > Source: gitlabracadabra > Version: 1.4.0 > Severity: serious > Justification: FTBFS > Tags: bookworm sid ftbfs > User: l

Bug#1009623: ITP: python-hazwaz -- a python3 library to write command line scripts.

2022-04-13 Thread Elena ``of Valhalla''
Package: wnpp Severity: wishlist Owner: Elena ``of Valhalla'' X-Debbugs-Cc: debian-de...@lists.debian.org * Package name: python-hazwaz Version : 0.0.1 Upstream Author : Elena ``of Valhalla'' Grandi * URL : https://sr.ht/~valhalla/hazwaz/ * License : AGPLv3+

Bug#1009385: libldns3 1.7.1-2.1 changes output of ldns-key2ds, causing FTBFS on dns-root-data [was: Re: Bug#1009385: dns-root-data: FTBFS: root-anchors.ds root.ds differ]

2022-04-13 Thread Michael Tokarev
13.04.2022 09:50, Daniel Kahn Gillmor wrote: Control: reassign 1009385 libldns3 1.7.1-2.1 Control: retitle 1009385 libldns3 1.7.1-2.1 changes output of ldns-key2ds, causing FTBFS on dns-root-data Control: affects 1009385 + dns-root-data X-Debbugs-Cc: Michael Tokarev Control: tags 1009385 + help

<    1   2