Bug#503037: ssl-cert snakeoil generation completely broken in hurd

2008-10-26 Thread Stefan Fritsch
On Wednesday 22 October 2008, Will wrote: > When installing ssl-cert on GNU/Hurd i386, the package fails the > postinst. Upon further inspection, I found that the bash script > never actually queries debconf for the hostname parameter it needs > to config the package. It uses the output from `hos

Bug#494768: sendfile bails out with error

2008-10-14 Thread Stefan Fritsch
On Tuesday 14 October 2008, [EMAIL PROTECTED] wrote: > linux-image-2.6.24-etchnhalf.1-amd64 2.6.24-6~etchnhalf.5 > linux-image-2.6.25-1-amd64 2.6.25-1 > linux-image-2.6.25-2-amd64 2.6.25-6 > linux-image-2.6.25-2-amd64 2.6.25-7 > > and none of them resolved the problem. This is a bi

Bug#501403: (no subject)

2008-10-08 Thread Stefan Fritsch
On Tuesday 07 October 2008, Allard Hoeve wrote: > We run clusters of about 15 webservers that are reloaded for new > configs about twenty times per day. This results in the following > error about once per day per cluster: > > apache2: nscd_helper.c:133: __nscd_unmap: Assertion mapped->counter > ==

Bug#499191: apache2-suexec-custom: Allow execution of programs owned by root

2008-10-06 Thread Stefan Fritsch
On Thursday 02 October 2008, Alexander Prinsier wrote: > > Apart from that, allowing scripts owned by root to be executed as > > any user would certainly create (local) security issues. Using a > > dedicated user might be possible, though. > > Why would running a root-owned script as a local user c

Bug#501362: libpoppler-glib3: uses all memory

2008-10-06 Thread Stefan Fritsch
Package: libpoppler-glib3 Version: 0.8.7-1 Severity: normal Hi, a user on #debian-security ("schmidt") reported that the pdf linked from this page http://de.wikipedia.org/wiki/Bild:WikiReader_Digest_2005-17.pdf uses all memory when nautilus tries to create the thumbnail via evince-thumbnailer

Bug#501347: mp3gain: impossible to use with non-alphanum filenames

2008-10-06 Thread Stefan Fritsch
On Monday 06 October 2008, Xavier Bestel wrote: > mp3gain doesn't use popt, so it doesn't support filenames with > spaces or strange chars. It also doesn't support "--" to stop > option parsing, so each time it sees a dash "-" it thinks it's a > new option. It works for me: $ mp3gain -a -a.mp3 -a

Bug#499842: CVE-2008-2940/-2941: security issues in hplip

2008-10-03 Thread Stefan Fritsch
fixed 499842 2.8.6-1 thanks Both issues affect 1.6.10-3etch1 in etch. Of the three patches, this one https://bugzilla.redhat.com/attachment.cgi?id=312880 introduces a new config file /etc/hp/alerts.conf . I am not sure if this is good for a stable security update, but it may be ok if the feat

Bug#500558: apache2.2-common: Apache fails to start on boot after upgrade Etch -> Lenny

2008-10-01 Thread Stefan Fritsch
On Wednesday 01 October 2008, you wrote: > >> I wonder why Apache is able to start without these explicitly > >> added addresses after boot has finished. What's the difference? > > > > Yes, that's strange. What is the output from > > > > cat /proc/sys/net/ipv4/ip_nonlocal_bind > > > > after boot? >

Bug#500558: apache2.2-common: Apache fails to start on boot after upgrade Etch -> Lenny

2008-10-01 Thread Stefan Fritsch
On Wednesday 01 October 2008, Micha Lenk wrote: > I wonder why Apache is able to start without these explicitly added > addresses after boot has finished. What's the difference? Yes, that's strange. What is the output from cat /proc/sys/net/ipv4/ip_nonlocal_bind after boot? -- To UNSUBSCRIBE

Bug#494768: sendfile bails out with error

2008-09-30 Thread Stefan Fritsch
On Tuesday 30 September 2008, Chad Feller wrote: > You'll have to tell me where I can get older Debian kernels as I > don't have anything older than 2.6.26-* in the > /var/cache/apt/archives on that machine (or any other AMD64 Debian > machine for that matter). Normally on snapshot.debian.net, but

Bug#500558: apache2.2-common: Apache fails to start on boot after upgrade Etch -> Lenny

2008-09-29 Thread Stefan Fritsch
On Monday 29 September 2008, Micha Lenk wrote: > recently I upgraded from Etch to Lenny. Now apache2 doesn't start > on boot any more. With "-x" in /etc/init.d/apache2 I get following > output on boot (partial only, typos possible due to screenshot > taken by a camera and typed in afterwards): > S

Bug#494768: sendfile bails out with error

2008-09-28 Thread Stefan Fritsch
On Monday 29 September 2008, Bastian Blank wrote: > The given strace shows that sendfile returns a proper error for the > sendfile invocation (EOVERFLOW). apache must not ignore errors > returned by syscalls. This is not the issue here, apache works as documented. The point is that, according to

Bug#411623: /usr/bin/zrun: If run as zsomeprog, zrun someprog

2008-09-27 Thread Stefan Fritsch
tags 411623 patch thanks The attached patch implements this feature (and adds support for lzma and lzo).--- /usr/bin/zrun 2008-06-29 05:22:20.0 +0200 +++ zrun 2008-09-27 23:07:42.0 +0200 @@ -17,6 +17,11 @@ This is a quick way to run a command that does not itself support compre

Bug#500114: CVE-2008-4182: XSS in turba2

2008-09-25 Thread Stefan Fritsch
Package: turba2 Version: 2.1.3-1 Severity: important Tags: security Hi, the following CVE (Common Vulnerabilities & Exposures) id was published for turba2. CVE-2008-4182[0]: | Cross-site scripting (XSS) vulnerability in imp/test.php in Horde | Turba Contact Manager H3 2.2.1, and possibly other Ho

Bug#500115: CVE-2008-4106: WordPress allows remote attackers to change an arbitrary user's password to a random value

2008-09-25 Thread Stefan Fritsch
Package: wordpress Version: 2.0.10-1 Severity: grave Tags: security Hi, the following CVE (Common Vulnerabilities & Exposures) id was published for wordpress. CVE-2008-4106[0]: | WordPress before 2.6.2 does not properly handle MySQL warnings about | insertion of username strings that exceed the m

Bug#500086: CVE-2008-4125: phpbb2 leaks state of php random number generator

2008-09-25 Thread Stefan Fritsch
I have also filed http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=500087 for php5. If that one gets fixed for lenny, phpbb2 would not need to be changed. -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Bug#500087: CVE-2008-4107: The rand and mt_rand functions in PHP produce weak random numbers

2008-09-24 Thread Stefan Fritsch
Package: php5 Version: 5.2.6-3 Severity: important Tags: security >From CVE-2008-4107: The (1) rand and (2) mt_rand functions in PHP 5.2.6 do not produce cryptographically strong random numbers, which allows attackers to leverage exposures in products that rely on these functions for security-rel

Bug#500086: CVE-2008-4125: phpbb2 leaks state of php random number generator

2008-09-24 Thread Stefan Fritsch
Package: phpbb2 Version: 2.0.21-7 Severity: grave Tags: security Hi, the following CVE (Common Vulnerabilities & Exposures) id was published for phpbb2. CVE-2008-4125[0]: | The search function in phpBB 2.x provides a search_id value that | leaks the state of PHP's PRNG, which allows remote attack

Bug#499942: CVE-2008-3663: Squirrelmail: Session hijacking vulnerability

2008-09-23 Thread Stefan Fritsch
Package: squirrelmail Version: 2:1.4.9a-2 Severity: grave Tags: security Justification: user security hole Squirrelmail does not set the secure flag for its session cookie when accessed over https. See http://int21.de/cve/CVE-2008-3663-squirrelmail.html -- To UNSUBSCRIBE, email to [EMAIL PRO

Bug#499842: CVE-2008-2940/-2941: security issues in hplip

2008-09-22 Thread Stefan Fritsch
Package: hplip Version: 1.6.10-3 Severity: important Tags: security Hi, the following CVE (Common Vulnerabilities & Exposures) ids were published for hplip. CVE-2008-2940[0]: | The alert-mailing implementation in HP Linux Imaging and Printing | (HPLIP) 1.6.7 allows local users to gain privileges

Bug#499841: CVE-2008-3970: does not verify mountpoint and source ownership before mounting a user-defined volume

2008-09-22 Thread Stefan Fritsch
Package: libpam-mount Version: 0.18-3 Severity: grave Tags: security Hi, the following CVE (Common Vulnerabilities & Exposures) id was published for libpam-mount. CVE-2008-3970[0]: | pam_mount 0.10 through 0.45, when luserconf is enabled, does not | verify mountpoint and source ownership before m

Bug#499191: apache2-suexec-custom: Allow execution of programs owned by root

2008-09-22 Thread Stefan Fritsch
Hi, On Wednesday 17 September 2008, Alexander Prinsier wrote: > I'm using apache2 together with fastcgi, suexec and php. To > configure php I'm using a wrapper script to set PHPRC, which then > exec's php itself. > > I don't want users to set their own PHPRC, so they could modify the > php.ini for

Bug#489242: googleearth-package: Building 4.3.7204.836 results in non-functioning executable

2008-09-21 Thread Stefan Fritsch
Hi Ron, with 4.3.7284.3916, the resulting package works for me. But googleearth takes quite a long time to start (20s) and it crashes when exiting (this is also mentioned in #478785). In what way did the executable fail for you? Was there an error message? Can you retry with the newer version?

Bug#496080: apache2 ceased to correctly serve foo.html.es files as spanish text/html and changed to serve as text/ecmascript

2008-09-12 Thread Stefan Fritsch
Since I don't think this is RC, I fear this will not be fixed in lenny. I will add a hint to README.Debian how to work around the problem. -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Bug#488924: release team opinion on big diffs

2008-09-12 Thread Stefan Fritsch
On Friday 12 September 2008, Kurt B. Kaiser wrote: > OK, here is a cherry-picked version with minimal changes. Good. I will upload this. -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Bug#498624: release-notes: Document apache2 changes requiring manual config changes

2008-09-11 Thread Stefan Fritsch
Package: release-notes Severity: normal Since apt-listchanges is still priority optional and not installed by default, I think the following information should be added to the release notes: The apache2 default configuration has changed in some ways that may require manual changes to your conf

Bug#496080: apache2 ceased to correctly serve foo.html.es files as spanish text/html and changed to serve as text/ecmascript

2008-09-11 Thread Stefan Fritsch
Forwarding the answer to the bug report. On Thursday 11 September 2008, Noel David Torres Taño wrote: > > Noel, are you sure it fixed the problem for you? Did you edit > > /etc/mime.types, too? > > > > RemoveType doesn't seem to act on the types loaded from > > mime.types. There is an open bug rep

Bug#496080: apache2 ceased to correctly serve foo.html.es files as spanish text/html and changed to serve as text/ecmascript

2008-09-11 Thread Stefan Fritsch
On Thursday 11 September 2008, W. Martin Borgert wrote: > On 2008-09-05 23:42, Noel David Torres Taño wrote: > > > this was changed in /etc/mime.types in the mime-support > > > package. Can you please try if adding > > > > > > RemoveType es > > > > > > to /etc/apache2/mods-available/mime.conf fixe

Bug#497307: apache2.2-common: /etc/logrotate.d/apache2 should reload, not restart

2008-09-09 Thread Stefan Fritsch
On Friday 05 September 2008, Stefan Fritsch wrote: > Some apache child processes may hang on reload. After many reloads, > you may run into the max number of apache childs or exhaust your > server's memory. > > The problem affects prefork and itk MPMs, but only if you use more

Bug#489077: bug #489077: wxwidgets2.8: FTBFS

2008-09-07 Thread Stefan Fritsch
I will NMU Matt's patch soon unless somebody tells me a good reason why I shouldn't. -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Bug#497307: apache2.2-common: /etc/logrotate.d/apache2 should reload, not restart

2008-09-05 Thread Stefan Fritsch
On Friday 05 September 2008, Mark Hedges wrote: > > It has been decided that this won't be changed in etch > > (because reload had different problems at the time). > > However, the problem and the fix is already documented in > > README.Debian. > > Indeed it is. Which is what I figured out to do.

Bug#496080: apache2 ceased to correctly serve foo.html.es files as spanish text/html and changed to serve as text/ecmascript

2008-09-05 Thread Stefan Fritsch
Hi, On Friday 22 August 2008, Noel Torres wrote: > I used to have an index.html.es and an index.html.en in each > directory, to use mod_negotiation to serve the adequate one. It > worked until the upgrade. Now, all *.html.es files are served as > mimetype text/ecmascript which made them absolutely

Bug#497307: apache2.2-common: /etc/logrotate.d/apache2 should reload, not restart

2008-09-05 Thread Stefan Fritsch
On Sunday 31 August 2008, Mark Hedges wrote: > etch version of /etc/logrotate.d/apache2 should use reload, not > restart. > > Otherwise a site with an SSL cert that uses a passphrase will not > restart. > > This renders SSL certificates with passphrases useless under > default config. > > This is f

Bug#489957: Why not move /etc/apache2/envvars to /etc/default/apache2 ?

2008-09-05 Thread Stefan Fritsch
On Wednesday 09 July 2008, Stefanos Harhalakis wrote: > /etc/apache2/envvars contains the lines: > > export APACHE_RUN_USER=www-data > export APACHE_RUN_GROUP=www-data > export APACHE_PID_FILE=/var/run/apache2.pid > > Correct me if I'm wrong but don't these belong to > /etc/default/apache2 ? The i

Bug#488924: dspam-webfrontend and apache2-suexec

2008-09-02 Thread Stefan Fritsch
Sorry this answer took so long. First the usual disclaimer: I am not a release team member. On Sunday 17 August 2008, Kurt B. Kaiser wrote: > > Lenny is frozen, the release team will never accept so many > > changes to go into Lenny. > I understand your feeling about this. However, I think you

Bug#497534: apache2.2-common: /etc/init.d/apache2 / apache2ctl not reporting error return code when apache2 segfaults

2008-09-02 Thread Stefan Fritsch
On Tuesday 02 September 2008, Olivier Berger wrote: > Whenever apache2 segfaults on start (for example as experienced > when #497453), there's no error return code propagated to > apache2ctl nor /etc/init.d/apache2's exit values... In this case, the segfault happens after apache has gone into the

Bug#497038: Speed improvements are not warrantied

2008-08-30 Thread Stefan Fritsch
On Saturday 30 August 2008, Emmanuel Rodriguez wrote: > In systems with a low buffer cache (low RAM) using the original > compressed files yields faster results as the program has to read > the whole file each time from the disk. Although, if a system has > enough memory to cache the input files th

Bug#497065: Please build two binaries, one with inflated depends and one without

2008-08-29 Thread Stefan Fritsch
On Friday 29 August 2008, Daniel Baumann wrote: > Therefore, please build two binary packages out of apr-util, one > which is build against the db backends, and one without (and apache > depends against it them conditionally). Otherwise, this is a > serious regression from the admin point of view f

Bug#485769: [pkg-wpa-devel] Bug#485769: wpasupplicant crashes: not with 32bit kernel

2008-08-26 Thread Stefan Fritsch
On Tuesday 26 August 2008, Julien Cristau wrote: > Sounds like an issue with handling of compat ioctl paths (when the > kernel is 64bit and the userland 32bit)… That's probably one part of the issue. Jouni Malinen is looking at the wpasupplicant crash (he contacted me by private mail). -- To U

Bug#485769: wpasupplicant crashes: not with 32bit kernel

2008-08-24 Thread Stefan Fritsch
Hrm. It works with linux-image-2.6.25-2-686. Maybe the severity is not grave after all. But wpasupplicant should not crash. -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Bug#485769: wpasupplicant crashes

2008-08-24 Thread Stefan Fritsch
severity 485769 grave retitle 485769 wpasupplicant crashes thanks wpasupplicant crashes for me always. I have recompiled 0.6.4-1 with nostrip and created a back trace for the case when it is started directly. The configuration is rather simple: ctrl_interface=DIR=/var/run/wpa_supplicant GROUP

Bug#496127: slash ignored

2008-08-23 Thread Stefan Fritsch
On Saturday 23 August 2008, Thijs Kinkhorst wrote: > > Why was my slash ignored? The man page gives no clue. > > This was done to address #483624. I've documented this now in the > manpage. I think it is more like a regression introduced by the fix for #483624. I will look at it. -- To UNSUB

Bug#495519: apt-file search only seems to work as root

2008-08-18 Thread Stefan Fritsch
Probably the directory /var/cache/apt/apt-file has the wrong permissions. It is created correctly on new installs since 2.1.0 but the permissions are not fixed on upgrades. Try if sudo chmod og+rx /var/cache/apt/apt-file fixes the problem. Alternatively, you could also remove the package with

Bug#493573: Backtrace on 'hung' apache2 (while trying to stop service)

2008-08-18 Thread Stefan Fritsch
On Monday 18 August 2008, Chris Horn wrote: > Chris Horn wrote: > > I'm not really a programmer (so this may be obvious from the > > backtrace), but disabling the PHP5 module completely solves the > > problem. > > Sorry for so much traffic, but I bring good news. I just upgraded > all of my MySQL

Bug#493573: Backtrace on 'hung' apache2 (while trying to stop service)

2008-08-17 Thread Stefan Fritsch
On Saturday 16 August 2008, you wrote: > Stefan Fritsch wrote: > > On Friday 15 August 2008, Chris Horn wrote: > >> To re-create normal situation: > >> 1. /etc/init.d/apache2 start > >> 2. /etc/init.d/apache2 stop > >> 3. apache2 is now hung &g

Bug#493573: Backtrace on 'hung' apache2 (while trying to stop service)

2008-08-16 Thread Stefan Fritsch
On Friday 15 August 2008, Chris Horn wrote: > To re-create normal situation: > 1. /etc/init.d/apache2 start > 2. /etc/init.d/apache2 stop > 3. apache2 is now hung Does this happen for you always or only sometimes? Does it only happen after apache processed some requests? I cannot reproduce it. C

Bug#493573: Backtrace on 'hung' apache2 (while trying to stop service)

2008-08-16 Thread Stefan Fritsch
Hi, does anybody have an idea what is going wrong here or how to debug this? On Friday 15 August 2008, Chris Horn wrote: > (gdb) bt full > #0 0xb7e630ee in __lll_lock_wait_private () from > /lib/libpthread.so.0 No symbol table info available. > #1 0xb7e606e1 in _L_lock_23 () from /lib/libpthre

Bug#494768: sendfile and CIFS

2008-08-16 Thread Stefan Fritsch
retitle 494768 sendfile no longer works with CIFS reassign 494768 linux-2.6 thanks On Friday 15 August 2008, [EMAIL PROTECTED] wrote: > I am using "EnableSendfile Off" on a per dir basis, namely the CIFS > mounted dirs (I alluded to that in my original post as the > "adequate workaround"), however

Bug#494768: strace

2008-08-15 Thread Stefan Fritsch
On Thursday 14 August 2008, [EMAIL PROTECTED] wrote: > Here is the trimmed strace. (I assume you aren't interested in all > the startup and shutdown garbage.) Thanks for the strace. But I am a bit confused now. Was this done with "EnableSendfile off" set? The strace shows sendfile being called.

Bug#488924: [Pkg-dspam-misc] Bug#488924: dspam-webfrontend and apache2-suexec

2008-08-15 Thread Stefan Fritsch
On Thursday 14 August 2008, Kurt B. Kaiser wrote: > On Wed, Aug 13 2008, Stefan Fritsch wrote: > > dspam-webfrontend does not depend on apache2, it just suggests it > > (via mod-perl). It should also suggest apache2-suexec. Will there > > be an upload soon or should I do a NMU

Bug#489208: bug #489208: fml incompatible with perl 5.10

2008-08-13 Thread Stefan Fritsch
fml has a rather low popcon count and the maintainer doesn't seem to be active anymore. Maybe it would make sense to remove the package? -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Bug#488924: dspam-webfrontend and apache2-suexec

2008-08-13 Thread Stefan Fritsch
On Wednesday 16 July 2008, Kurt B. Kaiser wrote: > tags 488924 + pending > thanks > > The reversion in apache2 is going into testing today (2.2.9-5), so > the UID issue is gone. > > However, we need to add apache2-suexec as a dependency for > dspam-webfrontend. dspam-webfrontend does not depend o

Bug#494768: narrowed version range

2008-08-12 Thread Stefan Fritsch
Hi, it is extremely unlikely that this problem is due to any apache change. The changes between 2.2.9-4 and -6 were very small and not in any way related to such core functionality. Libapr/libaprutil haven't changed in testing since 7/10, either. It is more likely that this is a kernel issue.

Bug#493573: apache2: Restart and reload does not work

2008-08-07 Thread Stefan Fritsch
Hi, On Thursday 07 August 2008, Vladislav Kurz wrote: > we did some more testing and googling and foud thet this issue is > discussed on apache-dev mailing list. They mention that the problem > is related to proxy setting, and yes, we use mod_proxy too. There > are some patches too. > > http://www

Bug#493573: apache2: Restart and reload does not work

2008-08-03 Thread Stefan Fritsch
On Sunday 03 August 2008, Vladislav Kurz wrote: > Log for restart says this: > > [error] child process 27290 still did not exit, sending a SIGKILL > [error] child process 27291 still did not exit, sending a SIGKILL > [error] child process 27292 still did not exit, sending a SIGKILL > [error] child

Bug#493142: apache2.2-common: init.d stop does not wait for Apache to stop

2008-08-02 Thread Stefan Fritsch
> The current init.d script for Apache2 calls the function > apache_stop when using /etc/init.d/apache2 stop, and the function > apache_sync_stop when using /etc/init.d/apache2 restart. > > So, when executing > /etc/init.d/apache2 stop ; /etc/init.d/apache2 start > it does not always restart apache

Bug#482946: apache2-mpm-itk FTBFS in experimental chroot

2008-07-28 Thread Stefan Fritsch
clone 482946 -1 reassign -1 libmysqlclient-dev retitle -1 libmysqlclient-dev is missing libmysqlclient_r.la found -1 5.1.26rc-1 thanks > > Which versions of libapr1-dev, libaprutil1-dev, and > > libmysqlclient15-dev do you have installed (if any)? > > > >   > +++--===

Bug#492295: apr_1.3.2-1(mips/experimental): FTBFS: test failure

2008-07-28 Thread Stefan Fritsch
The only real problems are hppa and powerpc. powerpc === testrand issues: https://issues.apache.org/bugzilla/show_bug.cgi?id=45389 very wild guess: /dev/urandom not in chroot??? amd64: == > testsock            :  Line 85: Problem getting ftp service (2): No > such file or directory /e

Bug#482946: apache2-mpm-itk FTBFS in experimental chroot

2008-07-28 Thread Stefan Fritsch
On Monday 28 July 2008, peter green wrote: > > ...which I'm pretty sure has been fixed now, so I'm closing it. > > I just updated my experimental amd64 chroot and tried to build the > latest version of apache2-mpm-itk and it failed with the same error > as before. Which versions of libapr1-dev, li

Bug#492532: apt-get also removes apache2 when i just wanted to remove mysql-server

2008-07-27 Thread Stefan Fritsch
Hi, apache2 depends on libaprutil1 which depends on libmysqlclient15off which depends on mysql-common. If you tell apt to remove mysql-common, apache2 will be removed. This is not a bug. Cheers, Stefan -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? C

Bug#492463: apache2.2-common: Please enable mod_deflate by default

2008-07-26 Thread Stefan Fritsch
On Saturday 26 July 2008, Steinar H. Gunderson wrote: > Please consider enabling mod_deflate by default. For most sites, > this is a reasonable default in that it conserves bandwidth without > eating undue amounts of CPU (only HTML and the likes is compressed > -- in today's AJAX-heavy world you ma

Bug#492282: "seahorse-agent --execute" leaks file descriptors

2008-07-26 Thread Stefan Fritsch
On Friday 25 July 2008, Josselin Mouette wrote: > > This explains why this bug hasn't been found before. I use KDE > > and no KDE desktop process seems to clean up the file > > descriptors. Therefore for me, every bash started in every > > terminal has those file descriptors. > > That’s bad indeed.

Bug#492295: hppa segfaults

2008-07-25 Thread Stefan Fritsch
hppa: testdso : /bin/sh: line 2: 13552 Segmentation fault ./$prog s390: Failed TestsTotal FailFailed % === testsock8 1 12.50% testsockets 7 1 14.29% powerpc:

Bug#492282: "seahorse-agent --execute" leaks file descriptors

2008-07-25 Thread Stefan Fritsch
> Indeed, this can easily be confirmed by looking at gnome-session�s file > descriptors. > > However it seems that gnome-session itself correctly closes the file > descriptors before spawning anything else, so they are not leaked > further. What makes you think all desktop processes will inherit

Bug#492282: "seahorse-agent --execute" leaks file descriptors

2008-07-24 Thread Stefan Fritsch
Package: seahorse Version: 2.22.3-1 Severity: normal Tags: security Seahorse leaks file descriptors to processes started with "seahorse-agent --execute", including the gpg agent listening socket. For the default setup, this means that all processes started from the desktop inherit those FDs and ca

Bug#485525: [hardening-discuss] -DFORTIFY_SOURCE seems to cause SIGBUS on sparc

2008-07-19 Thread Stefan Fritsch
Hi Kees, On Thursday 19 June 2008, Kees Cook wrote: > On Thu, Jun 19, 2008 at 08:38:33PM +0200, Stefan Fritsch wrote: > > I had this bug report which seems to point to gcc doing something > > wrong on sparc with -DFORTIFY_SOURCE and causing SIGBUS: > > > > htt

Bug#485525: Same bug with 2.2.9-2

2008-07-15 Thread Stefan Fritsch
On Friday 04 July 2008, BERTRAND Joël wrote: > > If the errors are not new, you could try to rebuild the > > subversion packages and replace libsvn1 and libapache2-svn with > > the rebuilt versions. Rebuilding the same versions could help > > because the libapr1-dev that was used to build 1.4.6dfsg

Bug#490859: bug #490859: libaprutil1 Depends libmysqlclient15off >= 5.0.27-1 is wrong

2008-07-15 Thread Stefan Fritsch
On Tuesday 15 July 2008, you wrote: > From: "Stefan Fritsch" <[EMAIL PROTECTED]> > Sent: Tuesday, July 15, 2008 10:11 PM > > > What do you mean with defunct? Does top show the process as > > "defunct" or is it just doing nothing? If the latte

Bug#490859: bug #490859: libaprutil1 Depends libmysqlclient15off >= 5.0.27-1 is wrong

2008-07-15 Thread Stefan Fritsch
> My complete system is debian unstable with MySQL 5.1.25rc1 from > experimental But that shouldn't matter libmysqlclient15off is still > from 5.0.x The MySQL Client library from 5.1 has 16 not 15off The mysql home page lists some incompatibilities. It would be very interesting to know if this pr

Bug#481976: libaprutil1: do we really need mysql stuff

2008-07-15 Thread Stefan Fritsch
On Saturday 12 July 2008, Justin B Rye wrote: > Just sticking my nose in to point out (in case it hasn't been > noticed) that this new dependency means there is now a hard > dependency chain all the way from apache2 to mysql-common. > This seems a bit much. mysql-common adds 136k to libmysqlclien

Bug#490801: apache2-mpm-prefork: mod_dbd /w mysql support gives: [error] (20014)Internal, error: DBD: failed to initialiseIt

2008-07-15 Thread Stefan Fritsch
It works for me with 2.2.9-3, and there is no difference to 2.2.9-2 that should affect mod_dbd. You could try - disabling mod_security - strace'ing apache to see what goes wrong Cheers, Stefan -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [E

Bug#405927: apt-file: Please add a cron entry for resynchronizing the package contents

2008-07-10 Thread Stefan Fritsch
On Thursday 10 July 2008, Thijs Kinkhorst wrote: > > Could you please add a cron entry for resynchronizing the > > packages contents from their sources every days? > > I don't think this is a good idea. For systems running (old)stable, > the Contents lists hardly change over the lifetime of t

Bug#443728: "apt-file update" should not have to be run as root

2008-07-10 Thread Stefan Fritsch
On Thursday 10 July 2008, Thijs Kinkhorst wrote: > The idea behind storing this centrally is that not every individual > user needs to download the large Contents files, but that these are > in one place. I think this is very similar to 'apt-get update' > which also requires root, even though thing

Bug#489899: apache2-utils htpasswd bogus compromised md5 factor

2008-07-08 Thread Stefan Fritsch
Hi, On Tuesday 08 July 2008, Mark Hedges wrote: > Does this restrict the hash space so it can be more easily cracked? Yes, but even the reduced hash space is enough to prevent dictionary / rainbow table attacks for some time to come. This is not a severe issue. See also the thread at [1]. When

Bug#489215: after upgrade, cannot access virtualhosts

2008-07-05 Thread Stefan Fritsch
On Friday 04 July 2008, Hideki Yamane wrote: > Hi, > > > I've updated apache2 package, added symlinks to > > /etc/apache2/sites-enabled is gone... (and just say "It works!" > > with browser ;-) > > No, it's my fault. I saw other host, sorry. > > But a problem remains. I cannot saw all virtualhos

Bug#485525: Same bug with 2.2.9-2

2008-07-05 Thread Stefan Fritsch
On Friday 04 July 2008, BERTRAND Joël wrote: > OK, I have tried, but dpkg-buildpackage returns an error : > Any idea ? Not really. Wait for subversion to migrate from unstable (will take at least 5 more days), or get all subversions packages from unstable now. Cheers, Stefan --

Bug#485525: Same bug with 2.2.9-2

2008-07-03 Thread Stefan Fritsch
Hi Joel, can you tell if the errors started after you did some upgrade (e.g. apache or subversion)? Have they just started or have they occured for some weeks now? If the errors are not new, you could try to rebuild the subversion packages and replace libsvn1 and libapache2-svn with the rebui

Bug#488821: DSpam example

2008-07-02 Thread Stefan Fritsch
On Wednesday 02 July 2008, Adrien Clerc wrote: > and since I'm on testing, I'll have to wait or use another web > server. You can manually download and install just the apache2-suexec package from unstable. No need to upgrade the rest of apache. Cheers, Stefan -- To UNSUBSCRIBE, email to [EM

Bug#485525: Same bug with 2.2.9-2

2008-07-02 Thread Stefan Fritsch
On Wednesday 02 July 2008, BERTRAND Joël wrote: > Root rayleigh:[~] > dpkg-query -l apache2* | grep ^ii > ii apache2 2.2.9-2 > Apache HTTP Server metapackage > ii apache2-mpm-prefork 2.2.9-2 > Apache HTT

Bug#488821: apache2-suexec: suexec configuration change demands extensive system changes

2008-07-02 Thread Stefan Fritsch
Hi Michael, On Wednesday 02 July 2008, Michael Alan Dorman wrote: > First, I would like to apologize for my rather terse initial > message---it took me a while to figure out that I needed to install > a new package (perhaps it warrants a recommends or at least > suggests, so it shows up somewhere?

Bug#488821: apache2-suexec: suexec configuration change demands extensive system changes

2008-07-01 Thread Stefan Fritsch
On Tuesday 01 July 2008, Michael Alan Dorman wrote: > Your decision to suddenly change the minimum userid that suexec > will allow breaks existing installations of totally unrelated > software. Nearly every configuration change in apache will break some system somewhere. That does not make this a

Bug#450831: apache2-mpm-prefork: apache does not start with: No space left on device: mod_rewrite: could not create rewrite_log_lock error

2008-06-30 Thread Stefan Fritsch
Hi, sorry for the late response. On Sunday 11 November 2007, Alessandro Polverini wrote: > Today on my box apache was down and did not start any more, this > was the error from the logs: > > [crit] (28)No space left on device: mod_rewrite: could not create > rewrite_log_lock Configuration Failed

Bug#341022: default apache2.conf file should deny access to /

2008-06-30 Thread Stefan Fritsch
2.2.9-3 will contain the config block, but commented out. It would currently break at least (there might be others) docbookwiki jpoker lxr-cvs mahara-apache2 movabletype-opensource phpicalendar sympa which I think is too much so close to the freeze. Let's activate this in lenny+1. -- To UNS

Bug#414193: Bug still present in etch.

2008-06-21 Thread Stefan Fritsch
On Saturday 21 June 2008, Michael Loftis wrote: > > You can change the grep in the init script to suite your needs > > and the change will not be overwritten on upgrades since the init > > script is a config file. I think that is an acceptable solution > > for people who use a non-standard setup of

Bug#486629: apache2 refusing to restart

2008-06-20 Thread Stefan Fritsch
Hi Paul, it seems if there is a large number of child processes, apache can take a long time to close all the listening sockets. If this is your problem, then apache should die some time after an unsuccessful restart. In this case, you could try to increase the wait time in the init script (th

Bug#414193: Bug still present in etch.

2008-06-20 Thread Stefan Fritsch
Hi Michael, On Tuesday 27 May 2008, Michael Loftis wrote: > Can we please get an update/backport of the fix into etch whatever > it was? The fix used in testing/unstable is too invasive for a stable point release. > I can think of atleast one better way, /etc/apache2/*.conf > /etc/apache2/conf

Bug#432753: CVE-2006-7211 to 7214 : unfixed in firebird1.5

2008-06-20 Thread Stefan Fritsch
reassign 432753 firebird2-server-common thanks On Friday 20 June 2008, Martin Michlmayr wrote: > > These issues are reported to be fixed in 2.0, but I can't find > > any references in the changelogs that they are fixed in 1.5: > > I cannot find firebird1.5 in Debian anymore. Can this bug be > clo

Bug#486629: apache2 refusing to restart

2008-06-19 Thread Stefan Fritsch
On Thursday 19 June 2008, Paul wrote: > Is there any traces or dumps I can do to provide more information. Maybe the output of sudo lsof -nP -i tcp:80 sudo sh -x /etc/init.d/apache2 restart sudo lsof -nP -i tcp:80 can give more information. You might have to install lsof first. Which apache2-m

Bug#477772: marked as done (subversion: Segfaults during operation)

2008-06-18 Thread Stefan Fritsch
ugh. wrong bug number. Should have been #486850 -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Bug#486629: apache2 refusing to restart

2008-06-18 Thread Stefan Fritsch
On Tuesday 17 June 2008, Paul wrote: > Some times I have noticed the system is abit sluggish when I > restart apache, the main problem is with apache, it creates lots > of child processes that refuse to die, the biggest problem is it > then locks up the ports it is using and the only way to kill a

Bug#481737: [php-maint] Bug#481737: Bug#481737: FTBFS on arm

2008-06-18 Thread Stefan Fritsch
On Tuesday 17 June 2008, Stefan Fritsch wrote: > I will do a rebuild with the most current gcc next. With up-to-date chroot and gcc-4.3 4.3.1-2 the build of 5.2.6-1 still fails with the known error. -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe&q

Bug#481737: [php-maint] Bug#481737: Bug#481737: FTBFS on arm

2008-06-17 Thread Stefan Fritsch
> > BTW, for both builds I had gcc-4.3 4.3.0-4 installed, which is > > not current anymore but it's the same version that was used by > > the arm buildd. I did yet another test build. This time php5 5.2.5-3 from testing in the same (by now outdated) unstable chroot as the other builds. This buil

Bug#486629: apache2 refusing to restart

2008-06-17 Thread Stefan Fritsch
Hi, On Tue, 17 Jun 2008, Paul wrote: Why does apache2 refuse to restart or reload the configuration and if you attempt it then the whole system needs to be rebooted. Any package that dies bad enough to require a reboot has something badly broken in it. Please be more verbose. What happens ex

Bug#307298: tagging 465283, tagging 307298

2008-06-14 Thread Stefan Fritsch
# Automatically generated email from bts, devscripts version 2.10.29 # needs to go upstream first tags 465283 - patch # needs to go upstream first tags 307298 - patch -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Bug#485413: apache2: Apache crashes system due to exessive memory allocation

2008-06-14 Thread Stefan Fritsch
severity 485413 important thanks Until it is verified that this is not one of the memleaks fixed by php 5.2.6, it should not be considered RC for apache. -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Bug#463338: "/etc/init.d/apache2 restart" fails

2008-06-14 Thread Stefan Fritsch
On Thursday 31 January 2008, Martin Sebald wrote: > when I or a script (like logrotate) tries to restart Apache2 with > the > > command "/etc/init.d/apache2 restart" it fails printing out the following: > > Restarting web server: apache2(98)Address already in use: > > make_sock: could not bind to

Bug#486078: ssl-cert: Too hastily written debconf nonte contains trailing spaces

2008-06-13 Thread Stefan Fritsch
Hi Christian, > The debconf note that was added in the latest upload of ssl-cert > unfortunately contains trailing spaces in some lines in the original > templates file. > > The consequence are double spaces in strings. > > You'll then get updates by translators but if you fix the trailing spaces

Bug#486081: ssl-cert: Debconf abuse: is there *really* a need to stop installation to tell users about certificate replacement?

2008-06-13 Thread Stefan Fritsch
> Critical level debconf notes should be kept for things that users *must > absolutely see*. > > The text of the note you added in the last release of the package says > thatthe note can be ignored if one does not know what it is about. > > It means that the package will handle the certificate

Bug#485525: apache2 crashing with SIGBUS

2008-06-11 Thread Stefan Fritsch
Hi Nathaniel, On Tue, 10 Jun 2008, Nathaniel W Filardo wrote: No, 2.2.8-3 did not have this problem (at least, to judge from my log files). I think it would be helpful if you could confirm that it was the apache upgrade (as opposed to some other library upgrade that you did in the meantime

Bug#485413: apache2: Apache crashes system due to exessive memory allocation

2008-06-10 Thread Stefan Fritsch
Hi Nico, On Tuesday 10 June 2008, Nico Schottelius wrote: > > Php 5.2.6 fixes some memory leaks. You could try 5.2.6-1 from > > Debian unstable. > > Hmm, have to wait until it is in testing, as I don't want > to mix up testing/unstable. Is there a way to get notified, > as soon as it is available?

<    4   5   6   7   8   9   10   11   12   13   >