Bug#772277: Re: [Packaging] Bug#772277: munin-async: bashism in /bin/sh script

2014-12-06 Thread Raphael Geissert
Control: severity -1 minor On Saturday 06 December 2014 14:48:33 Holger Levsen wrote: Hi Raphael, thanks for your fix-bashism campaigns! On Samstag, 6. Dezember 2014, Raphael Geissert wrote: checkbashisms' output: possible bashism in ./etc/init.d/munin-async line 82 (sleep only takes

Bug#690648: 4store: bashism in /bin/sh script

2014-12-05 Thread Raphael Geissert
hurry to get this fixed for jessie. Hints about how to fix bashisms can be found at: https://wiki.ubuntu.com/DashAsBinSh Thanks in advance, Raphael Geissert -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas

Bug#771932: libgl1-mesa-glx: please drop the OS ABI tag

2014-12-03 Thread Raphael Geissert
/26663 Thanks a lot in advance. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#771934: libc-bin: multi-arch paths for /usr/local

2014-12-03 Thread Raphael Geissert
Package: libc-bin Version: 2.13-38 Severity: wishlist Hi, Would it be possible to have /usr/local/lib-equivalents configured by libc.conf, but with multi-arch paths? E.g. /usr/local/lib/x86_64-linux-gnu/ /usr/local/lib/i386-linux-gnu/ Thanks in advance. Cheers, -- Raphael Geissert - Debian

Bug#771932: Re: Bug#771932: libgl1-mesa-glx: please drop the OS ABI tag

2014-12-03 Thread Raphael Geissert
On Wednesday 03 December 2014 19:51:56 Julien Cristau wrote: On Wed, Dec 3, 2014 at 17:23:17 +0100, Raphael Geissert wrote: Would it be possible to remove the 2.4.20 OS ABI tag from libGL in the next wheezy point release? It prevents /etc/ld.so.conf from doing its thing when multiple

Bug#771665: nvidia-support: bashism in check-for-conflicting-opengl-libraries

2014-12-01 Thread Raphael Geissert
... is a bashism and basically prevents the script from checking /usr/lib/triplet Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#751408: linux-3.2: xhci_hcd: ERR: no room for command on command ring

2014-10-08 Thread Raphael Geissert
. HTH. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#763148: Re: Bug#763148: Prevent migration to jessie

2014-10-05 Thread Raphael Geissert
: given your apparent lack of understanding of the situation and way of communicating it only makes me wonder on the ability to work with you as the maintainer of such a security- sensitive package that ffmpeg is. I truly hope you understand the implications of such an impediment. Regards, -- Raphael

Bug#762839: Re: Bug#762839: bash without importing shell functions from the environment

2014-09-28 Thread Raphael Geissert
On Friday 26 September 2014 18:48:37 Matthias Urlichs wrote: [...] In any case, adding -p to any #!/bin/bash shebang line looks like a very good idea. Shall we add a Lintian check for this? No. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE

Bug#760029: systemd: doesn't initialise RANDOM_SEED upon installation

2014-08-30 Thread Raphael Geissert
into the systemd package - which I personally consider it to be a regression. Could you please then initialise RANDOM_SEED at the package installation time? TIA. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ

Bug#755969: acpi-support: Upgrade to 0.140-5+deb7u1 breaks suspend to RAM: forced shutdown after return

2014-08-04 Thread Raphael Geissert
pgrep needs the -f option, then the script works and power button behaves as expected. The use of -f changes the matching behaviour, and as such it is going to try to match to whatever $pid says its argv[0] is, not what was actually exec'ed. Cheers, -- Raphael Geissert - Debian Developer

Bug#749584: libusb-1.0-0: crashes pcscd, sporadically, on usb plugging on xhci-driven devices

2014-07-28 Thread Raphael Geissert
. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#753686: Re: Bug#753686: squeeze-pu: package mobile-broadband-provider-info/20140317-1~deb6u1

2014-07-09 Thread Raphael Geissert
On Wednesday 09 July 2014 20:10:10 Adam D. Barratt wrote: Please go ahead, bearing in mind that the window for acceptance closes over the coming weekend. Thanks, uploaded. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs

Bug#753686: squeeze-pu: package mobile-broadband-provider-info/20140317-1~deb6u1

2014-07-04 Thread Raphael Geissert
. Will be sending the debdiff later today. Actual packaging difference to make the backport is a downgrade of debhelper compat level (and the b-d) from 9 to 8. TIA and apologies for sending the mail until now. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net

Bug#751408: linux-3.2: xhci_hcd: ERR: no room for command on command ring

2014-06-16 Thread Raphael Geissert
On 12 June 2014 16:59, Raphael Geissert geiss...@debian.org wrote: [...] So, searching a bit on the git log leads to the following commits: xhci: Reset reserved command ring TRBs on cleanup. - likely to fix the no room for command bug https://github.com/torvalds/linux/commit

Bug#749584: libusb-1.0-0: crashes pcscd, sporadically, on usb plugging on xhci-driven devices

2014-06-16 Thread Raphael Geissert
On 28 May 2014 15:30, Aurelien Jarno aurel...@aurel32.net wrote: On Wed, May 28, 2014 at 03:20:24PM +0200, Raphael Geissert wrote: On 28 May 2014 15:03, Aurelien Jarno aurel...@aurel32.net wrote: On Wed, May 28, 2014 at 12:31:00PM +0200, Raphael Geissert wrote: [...] With a backtrace

Bug#697963: linux-image-3.2.0-4-amd64: xhci_hcd breaks suspend

2014-06-12 Thread Raphael Geissert
that commit. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#751408: linux-3.2: xhci_hcd: ERR: no room for command on command ring

2014-06-12 Thread Raphael Geissert
expansion - likely to fix other bugs, and maybe help on this one https://github.com/torvalds/linux/commit/8dfec6140fc617b932cf9a09ba46d0ee3f3a7d87 I intend to test those, but sending the report in advance. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net

Bug#750764: packages.debian.org: please include squeeze-lts suite

2014-06-08 Thread Raphael Geissert
. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#750757: wheezy-pu: package mobile-broadband-provider-info/20140317-1~deb7u1

2014-06-06 Thread Raphael Geissert
://bugs.debian.org/cgi-bin/bugreport.cgi?bug=641469 Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net mobile-broadband-provider-info_20140317-1~deb7u1.debdiff Description: Binary data

Bug#750550: pm-utils: pm-is-supported should not exit with 0 if hibernation is not setup

2014-06-04 Thread Raphael Geissert
to basically an unclean reboot. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#750551: pm-utils: pm-is-supported _is_ used by upower, in spite of the claim from the manpage

2014-06-04 Thread Raphael Geissert
://sources.debian.net/src/upower/0.9.23-2/src/linux/up-backend.c?hl=385#L377 Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas

Bug#749584: libusb-1.0-0: crashes pcscd, sporadically, on usb plugging on xhci-driven devices

2014-05-28 Thread Raphael Geissert
the lifetime of pcscd is enough to reproducibly trigger the bug Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#749584: libusb-1.0-0: crashes pcscd, sporadically, on usb plugging on xhci-driven devices

2014-05-28 Thread Raphael Geissert
On 28 May 2014 15:03, Aurelien Jarno aurel...@aurel32.net wrote: On Wed, May 28, 2014 at 12:31:00PM +0200, Raphael Geissert wrote: [...] I don't really understand the version part. You mean it works on 1.0.8 and 1.0.11, but crashes with 1.0.17 and 1.0.18? Yes Did you change only the libusb

Bug#694143: php5-ffmpeg: FTBFS because of deprecated functions

2014-05-13 Thread Raphael Geissert
once and then to sponsor the package. Will be filing the removal request later today. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas

Bug#747952: RM: ffmpeg-php -- RoM; Unmaintained upstream, incompatible with libav 10

2014-05-13 Thread Raphael Geissert
Package: ftp.debian.org Hi, Please remove ffmpeg-php, it's been dead upstream for a while and it needs somebody with some time to keep up with all the libav transitions. Thanks in advance. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE

Bug#746306: dpkg: CVE-2014-0471 fix introduces the vulnerability into squeeze

2014-04-30 Thread Raphael Geissert
hit the sec archive. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#746306: dpkg: CVE-2014-0471 fix introduces the vulnerability into squeeze

2014-04-29 Thread Raphael Geissert
need to be added to all versions so that e.g. wheezy's dpkg can't be used with squeeze's patch * if handling both behaviors, it should also apply to both releases. Unless I missed something, of course. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net

Bug#745836: wget: certificate revocation is not checked

2014-04-28 Thread Raphael Geissert
[...] It is not a bug, it is a missing feature. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#745837: curl should use a Certificate Revocation List by default

2014-04-28 Thread Raphael Geissert
support and/or OCSP stapling support would be nice but they are false solutions. Please bring up the subject on -devel before mass bug filing, it would have avoided it (in its current form at least). Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE

Bug#746245: installation-reports: Jessie daily amd64 netinst from 25/04/2014 won't even load

2014-04-28 Thread Raphael Geissert
it works fine. [1] 2014-04-25 12:24:12.0 +0200 5f7af8ca7220e1ea659869f0f99c6ea8 debian-testing-amd64-netinst.iso Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject

Bug#694143: php5-ffmpeg: FTBFS because of deprecated functions

2014-04-28 Thread Raphael Geissert
! The missing declaration of time_t was puzzling me. Thanks, I will take a look at the other bugs to get the package back in shape. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject

Bug#745259: ITP: apt-transport-tor -- APT transport for anonymous package downloads via Tor

2014-04-22 Thread Raphael Geissert
Hi, By using curl you are basically allowing the mirror (or anyone who can intercept the clear text) to tell normal and tor users apart. Think of targeted attacks. Just saying... Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email

Bug#744187: xulrunner-24.0-dbg: dependencies on nss and nspr not needed when LESS_SYSTEM_LIBS

2014-04-11 Thread Raphael Geissert
. Thanks in advance. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#743883: Is it realy fixed?

2014-04-11 Thread Raphael Geissert
*) and restart applications as soon as possible. [emphasis is mine] We did mention it. -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas

Bug#744197: ecryptfs-utils: unix_chkpwd should not be used

2014-04-11 Thread Raphael Geissert
Package: ecryptfs-utils Severity: important Version: 103-3 Tags: security Hi, ecryptfs-setup-private calls unix_chkpwd, but according to the latter's manpage it should not be called by anything other than libpam-unix. Cheers, -- Raphael Geissert - Debian Developer www.debian.org

Bug#744027: Revocation Policy

2014-04-10 Thread Raphael Geissert
the library what they want it to check for. From a previous look at the openssl-using applications in Debian, those cases are rare. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject

Bug#744027: Please remove StartCom Certification Authority root certificate

2014-04-09 Thread Raphael Geissert
, if they desire. Agreed, so marking it as wontfix. If anything changes upstream, it will be reflected here. For those reading at home don't waste your time, nor ours, sending arguments or +1s. If anywhere, do it on mozilla's bugzilla - all the while respecting their policies. Cheers, -- Raphael Geissert

Bug#744027: data point

2014-04-09 Thread Raphael Geissert
. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#741952: linux: Possible bug in 3.2's cifs/file.c, use of uninitialized variable

2014-04-07 Thread Raphael Geissert
) - total_written = rc; - break; } /* get length and number of kvecs of the next write */ Looks good to me. Thanks, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs

Bug#734238: Patch for CVE-2013-6045

2014-04-07 Thread Raphael Geissert
and upload to security-master.d.o. Can you do that? Thanks. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#741958: [PATCH 3.2 17/18] cifs: ensure that uncached writes handle unmapped areas correctly

2014-04-07 Thread Raphael Geissert
, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#641469: mobile-broadband-provider-info: Please provide updates for stable distribution, somehow

2014-04-03 Thread Raphael Geissert
Hi, Has any progress been made towards doing old/stable updates? Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#718434: fixed in ca-certificates 20140223

2014-03-26 Thread Raphael Geissert
posted or wants to post) want to say that it is not strictly within the topic of this report, please refrain yourself from writing it here and send it elsewhere. Thanks. -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ

Bug#741952: linux: Possible bug in 3.2's cifs/file.c, use of uninitialized variable

2014-03-17 Thread Raphael Geissert
/cifs/file.c#L2183 [4]http://sources.debian.net/src/linux/3.2.54-2/fs/cifs/file.c#L2197 Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas

Bug#741955: linux: ssize_t casted to unsigned int in fs/cifs/file.c when CONFIG_CIFS_STATS is set

2014-03-17 Thread Raphael Geissert
/3.2.54-2/fs/cifs/file.c#L2204 [2]http://sources.debian.net/src/linux/3.2.54-2/fs/cifs/file.c#L2219 Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact

Bug#741958: linux: CVE-2014-0069: cifs: incorrect handling of bogus user pointers during uncached writes

2014-03-17 Thread Raphael Geissert
Source: linux Version: 3.2.51-1 Tags: patch security X-debbugs-cc: j...@debian.org Hi, Attached patch is what I believe would be the correct backport for 3.2 of the specific fix for CVE-2014-0069, which is 5d81de8e8667da7135d3a32a964087c0faf5483f. Cheers, -- Raphael Geissert - Debian Developer

Bug#718434: ca-certificates: should CAcert.org be included?

2014-03-14 Thread Raphael Geissert
by Gandi. Once the transition is finished we are very likely going to also drop the SPI root certificate. P.S. as a gentle reminder, a decision has been made by the maintainers. The result can be found in the archive. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net

Bug#720013: make p11-kit multiarch

2014-03-14 Thread Raphael Geissert
-gnu/pkcs11/p11-kit-trust.so lrwxrwxrwx root/root 0 2014-03-14 16:32 ./usr/lib/x86_64-linux-gnu/p11-kit-proxy.so - libp11-kit.so.0.0.0 Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net From da22bc26e804e4a18b33fef04b7945c307d29fc3 Mon Sep 17 00:00:00 2001 From

Bug#741561: No longer ship cacert certificates

2014-03-13 Thread Raphael Geissert
or that doesn't require a special parameter to connect to any server for which it can not verify the validity of the certificate should be fixed. Don't hesitate to file a bug report against those tools. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE

Bug#718434: ca-certificates: should CAcert.org be included?

2014-03-13 Thread Raphael Geissert
Hi, On Thursday 13 March 2014 23:09:48 Axel Beckert wrote: Christoph Anton Mitterer wrote: I doubt that the removal of CAcert was a good decision... A quite bad decision in my view, too. Thanks for sharing your thoughts. Cheers, -- Raphael Geissert - Debian Developer www.debian.org

Bug#741346: lintian: check the name of modules config in /etc/pkcs11/modules

2014-03-12 Thread Raphael Geissert
On 11 March 2014 14:36, Raphael Geissert geiss...@debian.org wrote: [...] An example of a package triggering the warning by p11-kit (from jessie or wheezy-bpo) is wheezy's gnome-keyring. And now that I take a better look at how things are done in sid, the directory is now usr/share/p11-kit

Bug#741346: lintian: check the name of modules config in /etc/pkcs11/modules

2014-03-11 Thread Raphael Geissert
, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net From 1e197a7baf40d1e7c5874cf02335af4c53f8844d Mon Sep 17 00:00:00 2001 From: Raphael Geissert geiss...@debian.org Date: Tue, 11 Mar 2014 11:39:44 +0100 Subject: [PATCH] Check for the naming convention of etc/pkcs11/modules files

Bug#739490: iceweasel: compiled extensions can not be built with version in wheezy-sec

2014-03-11 Thread Raphael Geissert
On 7 March 2014 11:29, Raphael Geissert geiss...@debian.org wrote: On 5 March 2014 23:01, Mike Hommey m...@glandium.org wrote: What about pkg-config --cflags libxul? Could you also share your built -dev package? -I/usr/include/xulrunner-24.0 A quick and dirty workaround is to symlink the nss

Bug#738199: Access to the oval generation script ?

2014-03-11 Thread Raphael Geissert
? It's in www team's webwml CVS repository, one of the scripts being: webwml/english/security/oval/parseDsa2Oval.py but there are a few other under oval/ Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ

Bug#741299: freetype: CVE-2014-2240, CVE-2014-2241: stack OOB read/write, DoS

2014-03-10 Thread Raphael Geissert
, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#741199: RFP: libmaxminddb -- library for working with MaxMind DB files

2014-03-09 Thread Raphael Geissert
the geoip maintainer in case he wants to take this RFP as this is basically the continuation of what he is maintining. [1]https://github.com/maxmind/libmaxminddb Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ

Bug#741005: iceweasel: using p11-kit to replace nssckbi?

2014-03-07 Thread Raphael Geissert
is there that I might be missing? Thanks in advance. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#739490: iceweasel: compiled extensions can not be built with version in wheezy-sec

2014-03-07 Thread Raphael Geissert
, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#588953: file: poor detection of avr32 ELF objects

2014-03-06 Thread Raphael Geissert
Hi, On 1 March 2014 22:08, Christoph Biedl debian.a...@manchmal.in-ulm.de wrote: Raphael Geissert wrote... Running file(1) against an avr32 ELF object prints the following: ELF 32-bit MSB shared object, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.18, stripped

Bug#739490: iceweasel: compiled extensions can not be built with version in wheezy-sec

2014-03-05 Thread Raphael Geissert
On 24 February 2014 09:58, Mike Hommey m...@glandium.org wrote: On Wed, Feb 19, 2014 at 10:33:09AM +0100, Raphael Geissert wrote: Package: iceweasel Version: 24.3.0esr-1~deb7u1 Severity: important Hi, As mentioned in a private email, binary extensions fail to build with the backported

Bug#729203: Packaging for FFmpeg avoiding conflicts with libav

2014-02-22 Thread Raphael Geissert
libavfilter? Seems like a bug in lintian. It complains because it has detected a copy of libavfilter in a package which is none of the ones it knows that are the source of it. So arguably, yes, it's a bug. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net

Bug#739490: iceweasel: compiled extensions can not be built with version in wheezy-sec

2014-02-19 Thread Raphael Geissert
. It fails to find the mozilla-nspr pkg-config file, which results in a series of missing files and the build failure. There's also a cannot find -lmozglue error from the linker. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs

Bug#739490: iceweasel: compiled extensions can not be built with version in wheezy-sec

2014-02-19 Thread Raphael Geissert
Hi Sylvestre, On 19 February 2014 11:26, Sylvestre Ledru sylves...@mozilla.com wrote: [...] I wasn't in cc of the private email. Do you have a build log with the error? Sure, attached is the relevant part of the log. HTH. Cheers, -- Raphael Geissert - Debian Developer www.debian.org

Bug#739236: libanyevent-http-perl: doesn't separate connection tokens with comma

2014-02-16 Thread Raphael Geissert
thanks if somebody prepares a backport with the fix :)! Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net --- unpacked/usr/share/perl5/AnyEvent/HTTP.pm 2012-11-14 23:22:00.0 +0100 +++ /usr/share/perl5/AnyEvent/HTTP.pm 2013-11-17 16:08:10.0 +0100

Bug#731860: libtar: CVE-2013-4420: directory traversal when extracting archives

2014-02-14 Thread Raphael Geissert
of .. will yield the desired result, but the even ..s will be missed. Ah, yes, indeed. Nice catch. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble

Bug#738785: aptitude: (remote) changelogs is broken after packages.d.o move to https

2014-02-13 Thread Raphael Geissert
switching worked. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#738785: aptitude: (remote) changelogs is broken after packages.d.o move to https

2014-02-13 Thread Raphael Geissert
On Thursday 13 February 2014 22:07:37 David Kalnischkies wrote: On Thu, Feb 13, 2014 at 07:52:38PM +0100, Julien Cristau wrote: On Thu, Feb 13, 2014 at 10:27:47 +0100, Raphael Geissert wrote: On 13 February 2014 00:26, Julien Cristau jcris...@debian.org wrote: [...] // Do

Bug#738785: aptitude: (remote) changelogs is broken after packages.d.o move to https

2014-02-12 Thread Raphael Geissert
APT's http method from the redirection, but they'd like this issue to be fixed. Hence this email. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact

Bug#731860: libtar: CVE-2013-4420: directory traversal when extracting archives

2014-02-11 Thread Raphael Geissert
contains an entry called ../../../empty-file tar tf should print a warning message and list the full path, while libtar should simply print it as 'empty-file'. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net triple-double-dot.tar Description: Unix tar archive

Bug#738173: security-tracker: detect some fixed version inconsistencies

2014-02-08 Thread Raphael Geissert
that either the release-specific tag is incorrect, or the fixed version is incorrect. One sample was fixed with r25293 Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject

Bug#737738: htop: please provide ioprio_get information (aka ionice)

2014-02-06 Thread Raphael Geissert
in htop 1.0.2. Ah, indeed! great. It appears to have issues understanding the idle class, but it appears to work for best-effort. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject

Bug#737738: htop: please provide ioprio_get information (aka ionice)

2014-02-05 Thread Raphael Geissert
Package: htop Version: 1.0.1-1 Severity: wishlist Hi, It would be great if htop could also display the I/O priority (and/or the class?) of the processes as another column. This can be obtained via the ioprio_get syscall. Thanks! Cheers, -- Raphael Geissert - Debian Developer www.debian.org

Bug#737534: vlc: unsafe use of libtar

2014-02-03 Thread Raphael Geissert
that is about to be extracted that none contains a ../, and something similar for symlinks. Alternatively, vlc could just use tar(1) to unpack the tarballs, or drop support for skins or skins in tarballs. What do you think? This should probably be forwarded to upstream. Cheers, -- Raphael Geissert

Bug#736958: [oss-security] CVE request: temporary file issue in Passenger rubygem

2014-01-29 Thread Raphael Geissert
On 29 January 2014 09:57, Raphael Geissert geiss...@debian.org wrote: [...] One thing to notice, however, is that there's a race condition between the stat check introduced in 34b1087870c2. The following sequence still triggers the bogus behaviour: user mkdir $dir phusion lstat

Bug#736425: poppler-glib: incorrect password error bypasses GError

2014-01-23 Thread Raphael Geissert
at SecurityHandler.cc I see that there are other cases for which error() is called, and assuming there's no race condition in the trapping of error() to GError, it would mean that there are several error conditions which entirely bypass GError. Thanks in advance. Cheers, -- Raphael Geissert - Debian

Bug#735292: libstrongswan: configuring strongswan.conf with file snippets (aka strongswan.conf.d)

2014-01-17 Thread Raphael Geissert
though? Done in attached mbox. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net From a2431a1cdab1a5fa72df9c4ca734d2ea75dcba1d Mon Sep 17 00:00:00 2001 From: Raphael Geissert geiss...@debian.org Date: Tue, 14 Jan 2014 14:51:01 +0100 Subject: [PATCH] Support configuration

Bug#731111: augeas: CVE-2013-6412

2014-01-15 Thread Raphael Geissert
Control: tag -1 patch Attached are patches fixing the issues for squeeze and wheezy. Also attached is an additional patch needed in squeeze to be able to run the test-save.c test. Could you please coordinate with the release team to fix these issues via O/SPU? Thanks, -- Raphael Geissert

Bug#735292: libstrongswan: configuring strongswan.conf with file snippets (aka strongswan.conf.d)

2014-01-14 Thread Raphael Geissert
or a configuration management system) to drop a file to modify the configuration without touching the main strongswan.conf LTDR: Please consider git-am'ing the attached mbox. Thanks! Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net From a281d077254db5fd86001896300d3fa356f0f6ca

Bug#735305: strongswan: should the padlock plugin be disabled?

2014-01-14 Thread Raphael Geissert
Package: strongswan Version: 4.2.4-4 Hi, Given everything that was revealed last year, the openssl package has now disabled support for the VIA Padlock. Given that in strongswan the plugin is compiled and enabled, I wonder what you or upstream think about disabling it. Cheers, -- Raphael

Bug#734238: Fix for CVE-2013-6045 breaks decoding of chroma-subsampled images

2014-01-06 Thread Raphael Geissert
to memory outside the allocated buffer. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#732963: ssh fails with OpenSSL version mismatch. Built against 1000105f, you have 10001060

2013-12-23 Thread Raphael Geissert
Known bug in openssh. Merging. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#732966: [openssl] Update to openssl 1.0.1e-5 renders X unusable

2013-12-23 Thread Raphael Geissert
mismatch. Built against 1000105f, you have 10001060 That's openssh. If there's anything else that's breaking your DM or something else then it might be another bug in a different package, but not in openssl. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net

Bug#732841: cicero: TypeError: exceptions must be old-style classes or derived from BaseException, not str

2013-12-22 Thread Raphael Geissert
14.4.1-3 Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#732144: Bug#731357: opu: package librsvg/2.26.3-2

2013-12-20 Thread Raphael Geissert
Hi again, Found another case where it didn't work as expected. Updated, attached, patch should do it. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net Index: librsvg-2.26.3/rsvg-image.c === --- librsvg

Bug#731357: opu: package librsvg/2.26.3-2

2013-12-19 Thread Raphael Geissert
Control: tag 732144 patch Attached patch should correctly handle URIs and non-URIs. I've tested it with a few applications using relative and absolute paths, and URIs. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net Index: librsvg-2.26.3/rsvg-image.c

Bug#731357: opu: package librsvg/2.26.3-2

2013-12-18 Thread Raphael Geissert
, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#732464: manpages-dev: mcheck(3) typo in compiler flag

2013-12-18 Thread Raphael Geissert
Package: manpages-dev Version: 3.44-1 Severity: minor Hi, mcheck(3) reads: linking the program with -mcheck inserts an implicit Whereas it should read: linking the program with -lmcheck inserts an implicit Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net

Bug#731860: libtar: CVE-2013-4420: directory traversal when extracting archives

2013-12-10 Thread Raphael Geissert
) id in your changelog entry. For further information see: [0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4420 http://security-tracker.debian.org/tracker/CVE-2013-4420 Attached is a proposed patch that makes libtar work similarly to tar. Cheers, -- Raphael Geissert - Debian

Bug#718434: Bug#731463: Bug#718434: ca-certificates: should CAcert.org be included?

2013-12-07 Thread Raphael Geissert
be managed. With nss' ckbi store you can ship a certificate and indicate no trust setting for a specific use, distrust, etc. No trust setting can be determined from /etc/ssl/certs, losing important information. Do you know if there's already a plan to address that shortcoming? Cheers, -- Raphael

Bug#718434: ca-certificates: should CAcert.org be included?

2013-12-05 Thread Raphael Geissert
/95_add_spi+cacert_ca_certs.patch That said, I think it is time to start discontinuing the certificate. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble

Bug#731237: openjpeg: CVE-2013-1447 CVE-2013-6045 CVE-2013-6052 CVE-2013-6054

2013-12-03 Thread Raphael Geissert
Hi, There are also some other issues that are specific to 1.5.1 (or at least they do not affect 1.3): CVE-2013-6053: information leaks CVE-2013-6887: DoS All the patches will be available as soon as I forward to oss-sec the messages I sent to the distros list. Cheers, -- Raphael Geissert

Bug#731132: augeas: CVE-2012-0786, CVE-2012-0787

2013-12-02 Thread Raphael Geissert
with the release team? Attached tarballs contain patches for the corresponding release. Note, however, that #73 is introduced by them and should also be fixed :) Thanks in advance. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net squeeze.tar.gz Description

Bug#724741: librsvg: CVE-2013-1881

2013-11-28 Thread Raphael Geissert
; use_data_uris_for_symbolic_icons.patch does the same for the version in wheezy. Could you please prepare packages for O/SPU and coordinate with the release team? TIA. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net Index: librsvg-2.26.3/rsvg-image.c

Bug#730615: mirrors: Index for wheezy-proposed-updates/contrib contents is out of sync.

2013-11-27 Thread Raphael Geissert
-i386.diff/ is: 2013-09-25-0234.41.gz 2013-10-12-1445.32.gz Index Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#730637: gtk+3.0: FTBFS when building with -j8

2013-11-27 Thread Raphael Geissert
/shared' make[1]: *** [all] Error 2 make[1]: Leaving directory `/tmp/buildd/gtk+3.0-3.4.2/debian/build/shared' make: *** [debian/stamp-makefile-build/shared] Error 2 dpkg-buildpackage: error: debian/rules build gave error exit status 2 I haven't tried with the version in sid. Cheers, -- Raphael

Bug#730637: gtk+3.0: FTBFS when building with -j8

2013-11-27 Thread Raphael Geissert
the severity back to serious. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#730637: gtk+3.0: FTBFS when building with -j8

2013-11-27 Thread Raphael Geissert
On Wednesday 27 November 2013 22:35:31 Raphael Geissert wrote: I believe that debhelper does that for you: Sigh, wrong reference, and now that I think about it it's very likely that cdbs is the one using the value of DEB_BUILD_OPTIONS=parallel=8 class/langcore.mk defines DEB_PARALLEL, which

Bug#692606: Marking as done in recent versions

2013-10-28 Thread Raphael Geissert
correctly tracked as fixed in later versions. I'll coordinate with SRM for uploading a fix to stable. Are you available to test a tentatively fixed package before upload? The change is trivial, but sure. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net

Bug#727052: RFP: libanyevent-gearman-perl -- Asynchronous Gearman client/worker module for AnyEvent applications

2013-10-21 Thread Raphael Geissert
be very thankful if the oh so mighty perl group could package this module :-) Would it be possible? Thanks in advance! Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe

<    1   2   3   4   5   6   7   8   9   10   >