Bug#731155: arpwatch consumes excessive CPU with libpcap0.8 1.5.1-1

2014-02-12 Thread Carlos Alberto Lopez Perez
On 12/02/14 22:58, Arthur Marsh wrote: > > > Florian Schlichting wrote, on 13/02/14 07:48: >> Hi Arthur, Carlos, >> >> the issue you reportied looks a lot like >> https://github.com/the-tcpdump-group/libpcap/issues/333 or >> https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=733747, which was >> f

Bug#737629: FTBFS on powerpc and armhf

2014-02-04 Thread Carlos Alberto Lopez Perez
Source: util-vserver Version: 0.30.216-pre3038-1 Severity: important util-vserver (0.30.216-pre3038-1) fails to build from source on powerpc and armhf architectures: https://buildd.debian.org/status/logs.php?pkg=util-vserver&ver=0.30.216-pre3038-1&suite=sid signature.asc Description: OpenPGP d

Bug#731155: arpwatch consumes excessive CPU

2014-01-21 Thread Carlos Alberto Lopez Perez
severity 731155 grave thanks I'm raising the severity level. The rationale is that this bug not only makes arpwatch unusable, but also can break the system. A rogue process eating the 100% of the CPU in an endless loop can cause the system to seriously overheat or malfunction. I have deleted a

Bug#735927: general: X *always* crashes when 5 youtube video opened

2014-01-18 Thread Carlos Alberto Lopez Perez
On 18/01/14 19:37, moli wrote: >* What exactly did you do (or not do) that was effective (or > ineffective)? > > I started chrome and opened 5 youtube 10 hour long videoes (i was planning to > test my cooling solution). The processor load was at 80% (!! not 100%!), the > ram was at ~90%.

Bug#661154: Bug#712050: aa-status does not show loaded profiles / aa-genprof is unusable

2014-01-16 Thread Carlos Alberto Lopez Perez
fixed 712050 2.8.0-1 fixed 661154 2.8.0-1 fixed 712050 2.8.0-5 fixed 661154 2.8.0-5 thanks On 15/01/14 19:24, intrigeri wrote: > Control: tag -1 + moreinfo > > Carlos Alberto Lopez Perez wrote (15 Jan 2014 18:12:36 GMT) : >> I'm running apparmor=2.8.0-5 on Debian/sid AMD

Bug#661154: aa-status does not show loaded profiles / aa-genprof is unusable

2014-01-15 Thread Carlos Alberto Lopez Perez
notfixed 712050 2.8.0-1 notfixed 661154 2.8.0-1 found 712050 2.8.0-5 found 661154 2.8.0-5 thanks Hi, I'm experimenting this bug(s). I'm running apparmor=2.8.0-5 on Debian/sid AMD64 with Debian's 3.9 kernel. $ dpkg -l | grep apparmor | awk '{print $1,$2,$3}' ii apparmor 2.8.0-5 ii apparmor-pro

Bug#731155: arpwatch uses 100% cpu

2013-12-12 Thread Carlos Alberto Lopez Perez
Same here. After upgrading libpcap0.8 to 1.5.2-1 (AMD64) arpwatch started to consume CPU like crazy. I tried to manually execute it with the debug flag, but it won't start properly. It will enter in the infinite loop before writing something to stderr. Looking at ltrace output it hangs in a ca

Bug#694405: Theme in settings.ini is ignored

2013-11-05 Thread Carlos Alberto Lopez Perez
On 31/01/13 18:15, Michael Biebl wrote: > Do you have gnome-settings-daemon running? > What does > gsettings get org.gnome.desktop.interface gtk-theme > say? > Which desktop environment is this? > > Michael > I can confirm this bug also. I'm my case I'm running XFCE desktop, and all GTK3 appli

Bug#368297: Does OpenLDAP has any GPLv2 dependency?

2013-11-05 Thread Carlos Alberto Lopez Perez
On 24/04/12 17:25, Thorsten Glaser wrote: > Hi all, > > this bug has been brought to my attention by my boss today. > If I understand the situation correctly, the problem is: > > • OpenLDAP links against GnuTLS (gnutls26) > • gnutls26 links against gcrypt, which has the bug > • gnutls28 links aga

Bug#727708: Re: Bug#727708: tech-ctte: Decide which init system to default to in Debian.

2013-11-04 Thread Carlos Alberto Lopez Perez
On 02/11/13 04:11, Russ Allbery wrote: > I think the right way to put this is that systemd has significant > development resources behind it and is working in fairly close cooperation > with both kernel developers and GNOME developers to make available new > kernel functionality and to provide impl

Bug#727708: tech-ctte: Decide which init system to default to in Debian.

2013-10-29 Thread Carlos Alberto Lopez Perez
On 28/10/13 20:14, Christoph Anton Mitterer wrote: > For those who haven't seen it, Lennart has posted some of his comments > about all this on G+: > https://plus.google.com/u/0/115547683951727699051/posts/8RmiAQsW9qf And here is the reply from Gentoo developer Patrick Lauer: http://gentooexperim

Bug#648160: util-vserver sponsorship request [was: Re: Bug#648160: util-vserver: wheezy vserver guests don't start]

2013-10-12 Thread Carlos Alberto Lopez Perez
On 26/08/13 22:03, Carlos Alberto Lopez Perez wrote: > On 26/08/13 17:51, micah wrote: >> Hi Carlos! >> >> A quick reply because I do not have very much time. I wanted to let you >> know that I am happy to have a look and sponsor it, but I wont have time >> until f

Bug#700092: flashplugin-nonfree: please include a cronjob for automatic security upgrades

2013-10-06 Thread Carlos Alberto Lopez Perez
On 06/10/13 07:09, Bart Martens wrote: > Still the same reason as back in 2008 : > http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=475580 > Quoting your reason back in 2008: [1] > Only the local sysadmin can decide on how frequently he/she wants to > check for newer versions, and on whether/whe

Bug#725446: Please build the vegas browser plugin

2013-10-05 Thread Carlos Alberto Lopez Perez
Package: totem Version: 3.8.2-3 Severity: wishlist Please enable the vegas browser plugin. I would suggest to build it on a new binary package, for example: totem-mozilla-vegas, and register the plugin as a flash alternative with update-alternatives like the packages browser-plugin-gnash and b

Bug#707201: Unable to initialize /machine cgroup: Invalid argument

2013-08-29 Thread Carlos Alberto Lopez Perez
This is a me-too report. I have just upgraded from 1.0.3-1 to 1.1.1-1 of libvirt-bin and when I tried to start a VM from virt-manager I got the following error: Error starting domain: internal error: Missing '/' separator in cgroup mount '' Traceback (most recent call last): File "/usr/share

Bug#648160: util-vserver sponsorship request [was: Re: Bug#648160: util-vserver: wheezy vserver guests don't start]

2013-08-26 Thread Carlos Alberto Lopez Perez
On 26/08/13 17:51, micah wrote: > Hi Carlos! > > A quick reply because I do not have very much time. I wanted to let you > know that I am happy to have a look and sponsor it, but I wont have time > until first week of Sept. > > Sorry I can't do it quicker, but I will! > > micah No problem. The

Bug#648160: util-vserver sponsorship request [was: Re: Bug#648160: util-vserver: wheezy vserver guests don't start]

2013-08-25 Thread Carlos Alberto Lopez Perez
Hi Micah! As we discussed some months ago, I would like to take care of the package util-vserver. I have migrated the repository to git [1], and I have prepared a new upload that fixes the this bug (#648160) as also #605473 and #586510 This new upload sets me as the new maintainer of the packag

Bug#706739: Asterisk do not log source IP for Fake auth rejection

2013-06-14 Thread Carlos Alberto Lopez Perez
Forwarded 706739 https://issues.asterisk.org/jira/browse/ASTERISK-21908 thanks signature.asc Description: OpenPGP digital signature

Bug#706739: Asterisk do not log source IP for Fake auth rejection

2013-06-14 Thread Carlos Alberto Lopez Perez
On 04/05/13 05:43, Dominik Strnad wrote: > Details: When using alwaysauthreject=yes in sip.conf, then source IP of > attacker is not logged when rejecting INVITES from not registered > devices trying to authenticate at call beginning (only asterisk server > IP itself is logged). > > Solution: As D

Bug#712062: Please enable X86_INTEL_PSTATE (P state power scaling driver)

2013-06-12 Thread Carlos Alberto Lopez Perez
Source: linux Version: 3.9.5-1 Severity: wishlist Please consider enabling X86_INTEL_PSTATE on 3.9 or superior This is a new CPU power scaling driver specially optimized for the latest Intel CPUs (Sandy Bridge and Ivy Bridge) https://lwn.net/Articles/536017/ Thanks! signature.asc Descripti

Bug#711855: RFS: aircrack-ng/1:1.1-6

2013-06-11 Thread Carlos Alberto Lopez Perez
On 12/06/13 03:28, Paul Wise wrote: > On Wed, 2013-06-12 at 03:10 +0200, Carlos Alberto Lopez Perez wrote: > >> Which package contains such oui file? Is there any package shipping >> generic oui files to be shared or is every package shipping just his own >> oui file? >

Bug#711855: RFS: aircrack-ng/1:1.1-6

2013-06-11 Thread Carlos Alberto Lopez Perez
On 11/06/13 02:47, Paul Wise wrote: > On Tue, Jun 11, 2013 at 12:48 AM, Carlos Alberto Lopez Perez wrote: > >> I'm not sure if beta versions are welcome on Debian or should be avoided >> if possible. My understanding is that it should be avoided if possible. > > Th

Bug#711855: RFS: aircrack-ng/1:1.1-6

2013-06-10 Thread Carlos Alberto Lopez Perez
On 10/06/13 14:50, أحمد المحمودي wrote: > Hello, > > Why not work on aircrack-ng 1.2~beta1 instead ? > That's a good question. I'm not sure if beta versions are welcome on Debian or should be avoided if possible. My understanding is that it should be avoided if possible. I was thinking in up

Bug#711855: RFS: aircrack-ng/1:1.1-6

2013-06-10 Thread Carlos Alberto Lopez Perez
On 10/06/13 15:18, أحمد المحمودي wrote: > On Mon, Jun 10, 2013 at 02:12:02PM +0200, Carlos Alberto Lopez Perez wrote: >> * Remove unused Build-Depends on obsolete libnl-dev (Closes: #688158) > ---end quoted text--- > > Why is netlink support disabled ? > 1.1 don'

Bug#711855: RFS: aircrack-ng/1:1.1-6

2013-06-10 Thread Carlos Alberto Lopez Perez
Package: sponsorship-requests Severity: normal Dear mentors, I am looking for a sponsor for my package "aircrack-ng" * Package name: aircrack-ng Version : 1:1.1-6 Upstream Author : Thomas d'Otreppe * URL : http://www.aircrack-ng.org * License : GPL-

Bug#573483: linux-headers-3.9-1-amd64 : Depends: linux-kbuild-3.9 but it is not installable

2013-06-03 Thread Carlos Alberto Lopez Perez
And again... $ sudo apt-get install linux-headers-3.9-1-amd64 Reading package lists... Done Building dependency tree Reading state information... Done Some packages could not be installed. This may mean that you have requested an impossible situation or if you are using the unstable di

Bug#688158: unused Build-Depends on obsolete libnl-dev

2013-05-15 Thread Carlos Alberto Lopez Perez
On 16/05/13 00:18, Michael Biebl wrote: > Hi, > > I'd like to proceed with the removal of libnl1 soon. > > What's the current status of this bug report? > > Michael > -- I was waiting for a major bug to fix or a new upstream release in order to upload a new version of the package and seize tha

Bug#694257: fdk-aac: who knows more?

2013-05-10 Thread Carlos Alberto Lopez Perez
On 10/05/13 07:41, Arto Jantunen wrote: > The difference between the GPL and the LGPL does solve the problem if > the program you are developing wants to link to both LGPL licensed and > GPL incompatible libraries, assuming that the license of the program > itself is not either GPL or LGPL. Parts o

Bug#694257: fdk-aac: who knows more?

2013-05-09 Thread Carlos Alberto Lopez Perez
On 09/05/13 23:27, Adam M. Costello wrote: > Fabian Greffrath : > >> Is fdk-aac finally the first *free* high-quality AAC encoder or is it >> just the next *non-free* one after FAAC? > > From what I've read, FAAC is not a high-quality AAC encoder. As far as > I know, fdk-aac is the only high-qua

Bug#707275: Ansible causes noise in server logs

2013-05-08 Thread Carlos Alberto Lopez Perez
Package: ansible Version: 1.1+dfsg-1 Severity: normal When executing the ping module on server: ansible servername -c ssh -m ping It causes a log entry on the target server # grep -r servername /var/log/ /var/log/messages:May 8 15:09:07 servername ansible-ping: Invoked with data=None /v

Bug#706637: Re: Please include AppArmor profiles

2013-05-06 Thread Carlos Alberto Lopez Perez
On 06/05/13 21:54, Daniel Baumann wrote: > tag 706637 - security > thanks > > at this point, the apparmor profiles are not really usable yet. once > that has happened, and the ubuntu people have have mainlined their > apparmor profiles, we'll have that in debian too automatically. > > Could you

Bug#706985: ITP: opensmtpd -- Simple Mail Transfer Protocol daemon

2013-05-06 Thread Carlos Alberto Lopez Perez
On 06/05/13 18:42, Lars Wirzenius wrote: > On Mon, May 06, 2013 at 05:10:17PM +0100, Daniel Walrond wrote: >> Package: wnpp >> Severity: wishlist >> Owner: Daniel Walrond >> >> >> * Package name: opensmtpd >> Version : 5.3.1p1 >> Upstream Author : OpenBSD >> * URL : htt

Bug#700411: git-buildpackage: git-import-orig should filter the upstream debian directory

2013-05-05 Thread Carlos Alberto Lopez Perez
tags 700411 patch thanks On 12/02/13 14:37, Raphaël Hertzog wrote: > > git-import-orig will happily import upstream tarballs that contain a > debian directory and when the upstream debian dir changes, git-import-orig > will try to merge those changes in the real debian packaging available on > th

Bug#706637: Please include AppArmor profiles

2013-05-02 Thread Carlos Alberto Lopez Perez
Package: lxc Severity: wishlist Tags: security Please include and enable AppArmor profiles on the LXC package. The AppArmor profiles are available in the Ubuntu repository: https://bazaar.launchpad.net/~ubuntu-lxc/lxc/github-staging-packaging/files/head:/debian/apparmor/ Thanks! signature.

Bug#648160: util-vserver: wheezy vserver guests don't start

2013-05-01 Thread Carlos Alberto Lopez Perez
On 01/05/13 17:32, micah wrote: > Carlos Alberto Lopez Perez writes: > >> On 28/04/13 02:50, micah wrote: >>>> I will happily sign for that. However I would like to migrate the >>>> package scm from svn to git. I have not experience packaging with svn >&g

Bug#648160: util-vserver: wheezy vserver guests don't start

2013-05-01 Thread Carlos Alberto Lopez Perez
On 28/04/13 02:50, micah wrote: >> I will happily sign for that. However I would like to migrate the >> package scm from svn to git. I have not experience packaging with svn >> and learning to do that now will be a backwards step IMHO. > > As I mentioned on IRC, I think that is a fantastic idea. >

Bug#695323: Re: Bug#695323: Icedove: Debian patch breaks forwarding of "simple" messages

2013-04-29 Thread Carlos Alberto Lopez Perez
On 22/04/13 17:05, Frank Otto wrote: > Hello Carsten, > > On Sun, Apr 14, 2013 at 2:10 PM, Carsten Schoenert > wrote: >> >> Where did you get this backport for 17.0.4 ? >> I though this is a missunderstanding on your side. :) Anyway ... > > 17.0.4 is from http://mozilla.debian.net/ (Icedove vers

Bug#695323: icedove: error occurred while creating a message compose window

2013-04-29 Thread Carlos Alberto Lopez Perez
Hi! I have hit the same problem. I'm running icedove=17.0.5-1 and when I try to forward a given message (it only happens on certain messages, not all). I get the same error: "An error occurred while creating a message compose window. Please try again." On the error console (tools->error console

Bug#706160: general: it should be easier for ordinary developers to work with Debian packages

2013-04-26 Thread Carlos Alberto Lopez Perez
On 27/04/13 01:46, James Cloos wrote: >>>>>> "CALP" == Carlos Alberto Lopez Perez writes: > > CALP> This can be even more simple: > > CALP> dh_make -f ../foo-1.tar.gz > CALP> dpkg-buildpackage > > And where does one find dh_make? >

Bug#648160: util-vserver: wheezy vserver guests don't start

2013-04-26 Thread Carlos Alberto Lopez Perez
On 26/04/13 16:38, micah wrote: > Carlos Alberto Lopez Perez writes: >> I don't think this is an appropriate approach to deal with this problem. >> I rather would ask you to remove the package util-vserver from Debian >> sid completely than to have it in a broken state.

Bug#706160: general: it should be easier for ordinary developers to work with Debian packages

2013-04-26 Thread Carlos Alberto Lopez Perez
On 25/04/13 19:18, Wouter Verhelst wrote: >> Gentoo: >> > - vim foo-1.ebuild; ebuild foo-1.ebuild manifest; emerge foo >> > - That may look like oversimplification, but the contents of >> > foo-1.ebuild really are very simple. > By that rationale, building a Debian package s

Bug#648160: util-vserver: wheezy vserver guests don't start

2013-04-25 Thread Carlos Alberto Lopez Perez
On 25/04/13 20:23, micah wrote: > > Hi Carlos, > > Carlos Alberto Lopez Perez writes: > >> So please: update the package to a newer upstream version. > > util-vserver was removed from wheezy as was the kernel support. It is > not surprising that this version doe

Bug#648160: util-vserver: wheezy vserver guests don't start

2013-04-25 Thread Carlos Alberto Lopez Perez
retitle 648160 wheezy vserver guests don't start found 648160 0.30.216-pre2864-2.1 found 648160 0.30.216-pre2864-2+b1 severity 648160 serious thanks justification: renders the package mostly unusable for Debian. Hi. After creating a Debian/wheezy vserver guest with the bootstrap method, the vse

Bug#368297: About the libgcrypt and OpenLDAP issue

2013-04-20 Thread Carlos Alberto Lopez Perez
On 20/04/13 20:18, Carlos Alberto Lopez Perez wrote: > So, we have the following chain of successes: ^ events > > sudo/passwd/su/etc -> libpam ---(if system==PAM/LDAP)--> libpam-ldap -> > libldap ---(if URI==ldaps://)--> gnutls ->

Bug#368297: About the libgcrypt and OpenLDAP issue

2013-04-20 Thread Carlos Alberto Lopez Perez
On 20/04/13 02:04, Werner Koch wrote: > On Sat, 20 Apr 2013 01:35, clo...@igalia.com said: > >> I think it would be a good idea to add this feature to libgcrypt. > > See attached patch against master. It is not tested, though. You may > backport it to 1.5 and use it like this: > > #if GCRYPT_V

Bug#368297: About the libgcrypt and OpenLDAP issue

2013-04-19 Thread Carlos Alberto Lopez Perez
On 20/04/13 00:08, Werner Koch wrote: >> At least, I think that you should consider adding a new flag to >> > libgcrypt that allows the application/library developer to complete >> > disable the dropping privileges feature. Perhaps something like: > That was my suggesttion. Shall we go for that? >

Bug#368297: About the libgcrypt and OpenLDAP issue

2013-04-19 Thread Carlos Alberto Lopez Perez
On 19/04/13 20:56, Werner Koch wrote: > Having said this, I don't see a reason why not to put the > responsibilities in the hands of the suid program authors. They anyway > wake up every night due to a nightmare telling them to check this and > that and - oh - I am using a library I didn't checked

Bug#368297: About the libgcrypt and OpenLDAP issue

2013-04-19 Thread Carlos Alberto Lopez Perez
On 19/04/13 10:22, Werner Koch wrote: > While we are in the business of refreshing our URL memories, let me > follow up with: > > http://thread.gmane.org/gmane.comp.encryption.gpg.libgcrypt.devel/2198 > > Florian Weimer comes to the same conclusion regarding the PAM > architecture but also asked

Bug#368297: About the libgcrypt and OpenLDAP issue

2013-04-19 Thread Carlos Alberto Lopez Perez
On 19/04/13 19:25, Julien Cristau wrote: > On Fri, Apr 19, 2013 at 19:07:02 +0200, Werner Koch wrote: > >> What about my suggestion on how to solve the problem? >> > If that "solution" is to have sudo itself call into libgcrypt, that > doesn't sound like a solution at all. sudo doesn't know how l

Bug#368297: About the libgcrypt and OpenLDAP issue

2013-04-19 Thread Carlos Alberto Lopez Perez
On 19/04/13 10:22, Werner Koch wrote: > On Fri, 19 Apr 2013 02:52, mgilb...@debian.org said: >>> 1.a) Patch libgcrypt to revert commit >>> d769529a71ccda4e833f919f3c5693d25b005ff0 >>> >> >>> >> Urgs. That is a short sighted fix. >> > >> > That seems to be the solution the rest of th

Bug#368297: About the libgcrypt and OpenLDAP issue

2013-04-18 Thread Carlos Alberto Lopez Perez
On 18/04/13 20:24, Adam D. Barratt wrote: > On Thu, 2013-04-18 at 18:58 +0200, Werner Koch wrote: >> On Tue, 16 Apr 2013 20:37, a...@adam-barratt.org.uk said: >> >>> libgcrypt maintainers - any thoughts on this? >> >> Did anything change since my comments from 2010? >> >> OpenLDAP needs to get it r

Bug#705221: ITP: pcapfix -- repair broken pcap files

2013-04-12 Thread Carlos Alberto Lopez Perez
On 12/04/13 10:00, Ansgar Burchardt wrote: > Could this be made part of pcaputils instead? From the package > description it looks like it might fit in there. How such things could be done? It will require both upstreams to merge? Or do you can create a Debian package that merges two upstreams tar

Bug#705184: "git hg clone" aborts with "Invalid raw date"

2013-04-11 Thread Carlos Alberto Lopez Perez
found 705184 20120921-1~exp1 thanks I tested also with the version from experimental (20120921-1~exp1) and gives the same error. signature.asc Description: OpenPGP digital signature

Bug#705184: "git hg clone" aborts with "Invalid raw date"

2013-04-10 Thread Carlos Alberto Lopez Perez
Package: hg-fast-export Version: 20120618-1 Severity: important Hi! I have tried to "git hg" clone the following repository: $ git hg clone ssh://ano...@hg.illumos.org/illumos-gate And after a long while it aborts with: master: Exporting simple delta revision 7370/14007 with 2/9/0 added/ch

Bug#368297: About the libgcrypt and OpenLDAP issue

2013-04-03 Thread Carlos Alberto Lopez Perez
On 03/04/13 16:09, Jack Bates wrote: > Hi, here is a blog post about this issue: > > http://jdbates.blogspot.ca/2013/04/its-crazy-how-much-time-and-effort-one.html > Really very interesting stuff. Thanks for sharing Now I'm convinced that the right fix for this is to revert upstream d769529a71

Bug#704283: Hurd: fix calculation of elapsed time

2013-04-01 Thread Carlos Alberto Lopez Perez
Just only a comment to say that I tested Pino's patch on Debian/Hurd (I just dropped it on debian/patches and rebuilt the package) and it works like a charm. Before this patch time was reporting weird things on Hurd: # /usr/bin/time sleep 1 0.00user 0.00system 4:37:46elapsed 0%CPU (0avgtext+0avgd

Bug#553999: grub-pc: Difficult to remove os-prober menu entries

2013-03-23 Thread Carlos Alberto Lopez Perez
FYI: You can disable os-prober by setting on /etc/default/grub the line: GRUB_DISABLE_OS_PROBER=true After that just reconfigure grub-pc dpkg-reconfigure grub-pc signature.asc Description: OpenPGP digital signature

Bug#702729: valgrind: build on kfreebsd-amd64

2013-03-16 Thread Carlos Alberto Lopez Perez
On 15/03/13 17:53, Alessandro Ghedini wrote: > On Fri, Mar 15, 2013 at 07:30:11AM -0500, Jeff Epler wrote: >> > On Thu, Mar 14, 2013 at 06:30:43PM +0100, Alessandro Ghedini wrote: >>> > > I'll have a look as soon as I have some free time. I was also thinking >>> > > that the >>> > > patch may be a

Bug#448638: RFP: i2p -- I2P is an anonymizing network

2013-03-12 Thread Carlos Alberto Lopez Perez
retitle 448638 RFP: i2p -- I2P is an anonymizing network noowner 448638 thanks Hi Given the timeline, I think is pretty clear that nobody is working on this package. In the mean time another ITP was filled for this package #665450 (now merged on this one). So I'm retitling this bug to RFP to ea

Bug#702669: reopen 702669

2013-03-10 Thread Carlos Alberto Lopez Perez
On 10/03/13 23:43, Adam D. Barratt wrote: > Please don't do that; you just marked the bug as no longer fixed in > unstable. > > The BTS is quite capable of tracking the status of the bug across > multiple suites. Having it closed with appropriate versions as soon as > any of them is fixed is the c

Bug#702669: reopen 702669

2013-03-10 Thread Carlos Alberto Lopez Perez
reopen 702669 thanks I'm reopening it because the fix was only uploaded to unstable (as far as I can see). signature.asc Description: OpenPGP digital signature

Bug#702669: TYPO3-CORE-SA-2013-001: SQL Injection and Open Redirection in TYPO3 Core

2013-03-09 Thread Carlos Alberto Lopez Perez
On 09/03/13 22:43, Carlos Alberto Lopez Perez wrote: > It has been discovered that TYPO3 Core is susceptible to SQL Injection > and Open Redirection. > > Here is the relevant information: > > https://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2013-001/

Bug#702669: TYPO3-CORE-SA-2013-001: SQL Injection and Open Redirection in TYPO3 Core

2013-03-09 Thread Carlos Alberto Lopez Perez
Package: typo3 Version: 4.3.9+dfsg1-1+squeeze7 Severity: grave Tags: security, upstream Hi, It has been discovered that TYPO3 Core is susceptible to SQL Injection and Open Redirection. Here is the relevant information: https://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-

Bug#702314: checkinstall aborts with illegal instruction on kFreeBSD

2013-03-04 Thread Carlos Alberto Lopez Perez
Package: checkinstall Severity: grave Version: 1.6.2-3 Justification: Renders the package unusable. On a Debian/kFreeBSD AMD64 machine running sid, checkinstall aborts with illegal instruction when trying to build a package. # checkinstall --install=no checkinstall 1.6.2, Copyright 2009 Felipe

Bug#701812: Please include the time-limit patch

2013-02-27 Thread Carlos Alberto Lopez Perez
Package: rsync Version: 3.0.9-4 Severity: wishlist There is a time-limit patch which adds the following options to rsync: --stop-at=y-m-dTh:m Stop rsync at year-month-dayThour:minute --time-limit=MINS Stop rsync after MINS minutes have elapsed This is very useful when rsyncing a

Bug#423458: Status of dnscap ITP?

2013-02-22 Thread Carlos Alberto Lopez Perez
On 26/10/12 00:19, Andrew Ruthven wrote: > On Thu, 2012-10-25 at 15:00 +0200, Marc Haber wrote: >> On Tue, Feb 07, 2012 at 12:39:18AM +, Andrew Ruthven wrote: >>> Our git repo for dnscap is here: >>> >>> http://git.catalyst.net.nz/dnscap.git >>> >>> I'm waiting for a minor update to a patch w

Bug#595790: hostid: useless unless fixed

2013-02-20 Thread Carlos Alberto Lopez Perez
On 21/02/13 00:14, Michael Stone wrote: > Short version: > > My inclination is to simply better document that hostid is an interface > without clear semantics which exists for compatability with legacy > systems and should not be used in new applications. > > Longer version: > > What is the reas

Bug#595790: hostid: useless unless fixed

2013-02-20 Thread Carlos Alberto Lopez Perez
On 20/02/13 03:01, Carlos Alberto Lopez Perez wrote: > On 06/09/10 19:35, martin f krafft wrote: >> Package: coreutils >> Version: 8.5-1 >> Severity: normal >> File: /usr/bin/hostid >> Tags: upstream >> >> I have never come across a (Debian) system w

Bug#595790: hostid: useless unless fixed

2013-02-19 Thread Carlos Alberto Lopez Perez
On 06/09/10 19:35, martin f krafft wrote: > Package: coreutils > Version: 8.5-1 > Severity: normal > File: /usr/bin/hostid > Tags: upstream > > I have never come across a (Debian) system where /usr/bin/hostid > didn't print 007f0101. That is because Debian uses /etc/hosts to map > 127.0.1.1 to the

Bug#387327: SELinux policy for Exim already included on package selinux-policy-default

2013-02-17 Thread Carlos Alberto Lopez Perez
FYI: Package selinux-policy-default=2:2.20110726-12 already includes an Exim policy (/usr/share/selinux/default/exim.pp). signature.asc Description: OpenPGP digital signature

Bug#686447: [RFC] First release of spl-dkms and zfs-linux packages for Debian

2013-02-15 Thread Carlos Alberto Lopez Perez
Hi! An update here. I was a bit busy later. Today I was talking with Aron on IRC and we agreed that we will push your repository on Alioth in order to keep the full history. In fact is already there: http://anonscm.debian.org/gitweb/?p=pkg-zfsonlinux/zfs.git http://anonscm.debian.org/gitweb/?p=

Bug#700092: Please include a cronjob for automatic security upgrades

2013-02-08 Thread Carlos Alberto Lopez Perez
Package: flashplugin-nonfree Version: 1:3.2 Severity: wishlist Hi, Today I have been notified of dangerous security vulnerabilities on flash being exploited in the wild. https://www.adobe.com/support/security/bulletins/apsb13-04.html I'm very glad to check that you already provided the update

Bug#647939: RFP: certwatch -- generate SSL certificate expiry warnings

2013-02-05 Thread Carlos Alberto Lopez Perez
#! /bin/bash # # Designed to be run weekly and send mail reports for certificates going # to expire in the next 30 days. # # Configure the variables mailto, includedirs and excludedirs and drop # it into /etc/cron.weekly # # -- Carlos Alberto Lopez Perez # # set -o noclobber # Where to send warnin

Bug#658739: merging with 368297 and re-assigning to openldap

2013-02-04 Thread Carlos Alberto Lopez Perez
reassign 658739 libldap-2.4-2 2.4.31-1 forcemerge 368297 658739 thanks This bug is the same than #368297 and others. I have attached a very small patch for openldap that solves the issue for Wheezy. It's here: http://bugs.debian.org/658896#104 signature.asc Description: OpenPGP digital sign

Bug#658896: LDAP, GnuTLS/libgcrypt

2013-01-28 Thread Carlos Alberto Lopez Perez
On 25/01/13 03:00, Howard Chu wrote: >> Hi! >> >> >> I have been digging on this issue and I found the ultimate cause of this >> problem. >> >> >> When sudo/su/passwd/ on >> a system configured with PAM/LDAPs it chains into libldap, which uses >> GnuTLS/libgcrypt to manage the TLS channel. >> >> >>

Bug#697346: Fix spelling on manpages of aircrack-ng

2013-01-26 Thread Carlos Alberto Lopez Perez
forcemerge 697346 698036 severity 697346 minor forwarded 697346 http://trac.aircrack-ng.org/ticket/1018 tags 697346 +fixed-upstream thanks Hi! Thanks for reporting this. I just discovered that lintian won't show this warnings by default (you have to use the -I option). All spelling errors wer

Bug#368297: [PATCH] Fix dropping privileges issue on setuid programs on systems with PAM/LDAP and GnuTLS/libgcrypt

2013-01-24 Thread Carlos Alberto Lopez Perez
ngelog @@ -1,3 +1,14 @@ +openldap (2.4.31-1.1) unstable; urgency=low + + * Non-maintainer upload. + + [ Carlos Alberto Lopez Perez ] + * debian/patches/fix-dropping-privileges-by-libgcrypt-secmem.diff: +Ensure that we don't use secure memory when libgcrypt is initialized. + Avoids drop

Bug#658896: Please apply patch no_global_init_during_thread_callbacks.diff

2013-01-23 Thread Carlos Alberto Lopez Perez
On 23/01/13 19:48, Andreas Metzler wrote: > On 2013-01-23 Carlos Alberto Lopez Perez wrote: >> On 23/01/13 19:04, Andreas Metzler wrote: >>> On 2013-01-23 Carlos Alberto Lopez Perez wrote: > ..] >>>> I'm attaching the debdiff. I rebuilt libgcrypt11

Bug#658896: Please apply patch no_global_init_during_thread_callbacks.diff

2013-01-23 Thread Carlos Alberto Lopez Perez
On 23/01/13 19:30, Carlos Alberto Lopez Perez wrote: > On 23/01/13 19:04, Andreas Metzler wrote: >> On 2013-01-23 Carlos Alberto Lopez Perez wrote: >>> severity 658896 serious >>> thanks >>> justification: Breaks unrelated software. It renders sudo un

Bug#658896: Please apply patch no_global_init_during_thread_callbacks.diff

2013-01-23 Thread Carlos Alberto Lopez Perez
On 23/01/13 19:04, Andreas Metzler wrote: > On 2013-01-23 Carlos Alberto Lopez Perez wrote: >> severity 658896 serious >> thanks >> justification: Breaks unrelated software. It renders sudo unusable on >> systems with LDAP/PAM > [...] > >> What

Bug#658739: Re: Bug#658739: Broken su/sudo/whatever - breaks systems - up goes the severity

2013-01-23 Thread Carlos Alberto Lopez Perez
On 03/11/12 17:46, Andreas Metzler wrote: > On 2012-10-24 Joerg Jaspert wrote: > [...] >> Maybe the rebuild without gcrypt is a solution. I don't know, I have >> no idea what other functionality then might be missing. > > Hello, > It is not possible currently for Debian to use nettle instead of >

Bug#658896: Please apply patch no_global_init_during_thread_callbacks.diff

2013-01-23 Thread Carlos Alberto Lopez Perez
/changelog 2013-01-23 12:56:44.0 +0100 @@ -1,3 +1,11 @@ +libgcrypt11 (1.5.0-3.1) unstable; urgency=low + + * Non-maintainer upload. + * debian/patches/13_no_global_init_during_thread_callbacks.diff +Closes: #658896 + + -- Carlos Alberto Lopez Perez Wed, 23 Jan 2013 12:49:54 +0100 +

Bug#698650: Use of uninitialized value when verifying DKIM signatures

2013-01-21 Thread Carlos Alberto Lopez Perez
Package: libmail-dkim-perl Version: 0.38-1 Hello, On a mailserver running spamassassin (Debian/Squeeze), I started to see this kind of logs a couple of days ago: Jan 21 18:06:08 mailserver spamd[17151]: Use of uninitialized value $prms{"Selector"} in concatenation (.) or string at /usr/shar

Bug#698428: ITP: ansible -- Configuration management, deployment,

2013-01-18 Thread Carlos Alberto Lopez Perez
Great! I was looking forward to test ansible, and having it packaged within Debian would help. Thanks for the effort! signature.asc Description: OpenPGP digital signature

Bug#658896: sudo: setresuid(ROOT_UID, ROOT_UID, ROOT_UID): Operation not permitted

2013-01-15 Thread Carlos Alberto Lopez Perez
found 658896 1.8.5p2-1 severity 658896 serious thanks justification: Renders the package unusable on systems with LDAP/PAM Hi! I can confirm this bug. On a Wheezy system with nscd and libnss-ldap is impossible to use sudo. # apt-cache policy sudo sudo: Installed: 1.8.5p2-1 Candidate: 1.8.

Bug#697871: dma generated headers misses the domain part (violates section-3.4.1 of rfc2822)

2013-01-10 Thread Carlos Alberto Lopez Perez
Package: dma Severity: grave Justification: violates section-3.4.1 of rfc2822, therefore could make unrelated software on the system to break or cause data loss (missing/bounced e-mails) DMA should append the system mailname (/etc/mailname), or the system hostname when the mailname is not avai

Bug#214566: dpkg-checkbuilddeps: please consider adding option to format output

2013-01-07 Thread Carlos Alberto Lopez Perez
tags 214566 patch thanks Any chance of fixing this bug? The attached patch is 3 years old! I found an old discussion about this here: http://lists.debian.org/debian-dpkg/2009/12/msg0.html IMHO this would be a nice improvement. Many times I find myself running dpkg-checkbuilddeps and c

Bug#686447: [RFC] First release of spl-dkms and zfs-linux packages for Debian

2012-12-15 Thread Carlos Alberto Lopez Perez
Hi! Finally found some time to work on the spl-dkms and zfs-linux packages. I started with debian helpers from Darik Horn and I ended rewriting many things. Hope all looks ok O:-) You have a summary of the most relevant changes on the commit message [1] Keep in mind that the packages are still i

Bug#640499: libxvmc: please add multiarch support

2012-12-06 Thread Carlos Alberto Lopez Perez
On 06/12/12 22:57, Julien Cristau wrote: > On Thu, Dec 6, 2012 at 20:36:25 +0100, Carlos Alberto Lopez Perez wrote: > >> Shouldn't this bug be marked as RC ? >> > No. > >> Please _maintainers_: just upload the damn fix! >> > https://lists.debian.org

Bug#640499: libxvmc: please add multiarch support

2012-12-06 Thread Carlos Alberto Lopez Perez
I can confirm this issue. $ uname -m x86_64 $ sudo aptitude install libxvmc1:i386 The following NEW packages will be installed: libxvmc1:i386{b} 0 packages upgraded, 1 newly installed, 0 to remove and 8 not upgraded. Need to get 24,0 kB of archives. After unpacking 76,8 kB will be used. The fo

Bug#695298: Please strip files under /etc/cron* from the google earth tarball

2012-12-06 Thread Carlos Alberto Lopez Perez
Package: googleearth-package Version: 0.7.0 Severity: important Tags: security Hello, The package google-earth-stable that googleearth-package builds includes a file under /etc/cron.daily that tries to import a GPG key and also tires to include google repositories into the system ones. Please,

Bug#617898: default PATH of cron should include /sbin and /usr/sbin for root user.

2012-12-04 Thread Carlos Alberto Lopez Perez
On 04/12/12 13:34, Javier Fernandez-Sanguino wrote: > n 4 December 2012 13:02, Carlos Alberto Lopez Perez wrote: >> I have recently just discovered this. I started digging why one of my >> scripts was failing and at the end I discovered that this was caused >> because cron

Bug#617898: default PATH of cron should include /sbin and /usr/sbin for root user.

2012-12-04 Thread Carlos Alberto Lopez Perez
retitle 617898 default PATH of cron should include /sbin and /usr/sbin for root user. thanks Hi! I have recently just discovered this. I started digging why one of my scripts was failing and at the end I discovered that this was caused because cron was setting the PATH for my script to be: PA

Bug#694257: RFP: libfdk-aac -- The Fraunhofer FDK AAC Codec Library

2012-11-24 Thread Carlos Alberto Lopez Perez
Package: wnpp Severity: wishlist X-Debbugs-CC: pkg-multimedia-maintain...@lists.alioth.debian.org, maril...@free.fr, mar...@martin.st * Package name: libfdk-aac Version : 0.1.1 Upstream Author : Martin Storsjo * URL : http://opencore-amr.git.sourceforge.net/git/gitwe

Bug#660862: initscripts: symlink /etc/nologin points to non existent file:

2012-11-23 Thread Carlos Alberto Lopez Perez
reassign 660862 initscripts retitle 660862 initscripts: symlink /etc/nologin points to non existent file: thanks Same here. Such symlink was created by an upgrade of the package initscripts on a system running Debian/Squeeze. Here is the relevant part: $ grep -C3 /etc/nologin sysvinit-2.88

Bug#658783: Re: MATE Desktop Environment in Debian

2012-11-15 Thread Carlos Alberto Lopez Perez
On 21/10/12 01:15, Josselin Mouette wrote: > Most issues people have with GNOME 3 “classic” usually boil down to “the > panel is black instead of grey”. > > Anyway, you’re welcome to package MATE in Debian. Just fix all the code > duplication stupidity before. So far no one has volunteered to do s

Bug#693183: Please include ignore.d.server rules for DMA

2012-11-13 Thread Carlos Alberto Lopez Perez
Package: logcheck-database Version: 1.3.15 Severity: wishlist Tags: patch X-Debbugs-CC: r...@ringlet.net Hello, After deploying DMA, I found that logcheck is not filtering the typical notification messages of mail delivery that any mailer daemon generates. Here is one example of the logcheck m

Bug#693048: Gajim fails to handle invalid certificates

2012-11-12 Thread Carlos Alberto Lopez Perez
Package: gajim Version: 0.15-1.1 Severity: grave Tags: security, upstream Forwarded: https://trac.gajim.org/ticket/7252 Gajim does not seem to properly handle invalid/broken/expired certificates. The _ssl_verify_callback function in tls_nb.py is called by OpenSSL for every certificate in the cer

Bug#692375: approx-gc should ignore lost+found directory

2012-11-05 Thread Carlos Alberto Lopez Perez
On 05/11/12 17:56, Eric Cooper wrote: > On Mon, Nov 05, 2012 at 02:25:25PM +0100, Carlos Alberto Lopez Perez wrote: >> I have an ext3 separated partition for the directory /var/cache/approx and >> I'm receiving this errors from the cron daemon: > > See the very fir

Bug#692375: approx-gc should ignore lost+found directory

2012-11-05 Thread Carlos Alberto Lopez Perez
Package: approx Version: 4.5-1+squeeze1 Severity: normal I have an ext3 separated partition for the directory /var/cache/approx and I'm receiving this errors from the cron daemon: Original Message From: root@localhost (Cron Daemon) To: root@localhost Subject: Cron test -x /

<    1   2   3   4   >