Bug#878811: dummy interface in bridge sticks in "configuring", leading to degraded system

2017-10-16 Thread Marc Haber
On Tue, Oct 17, 2017 at 12:11:07AM +0200, Michael Biebl wrote: > Control: > Am 16.10.2017 um 21:57 schrieb Marc Haber: > > Package: systemd > > Version: 235-2.0~zgSID+1 > > Seems the bts is not happy with that version. > For proper version tracking, which version is affected by this? > Is this a

Bug#878841: clips FTBFS: uudecode: not found

2017-10-16 Thread Adrian Bunk
Source: clips Version: 6.30-1 Severity: serious https://buildd.debian.org/status/package.php?p=clips=sid ... cd doc && /usr/bin/make -f Makefile all make[1]: Entering directory '/<>/doc' uudecode -o advanced_programming_guide.pdf

Bug#878209: apcupsd: please provide a split package without X11 deps

2017-10-16 Thread Daniel Schaal
Source: apcupsd Followup-For: Bug #878209 Attached is a patch to split the gui from the main package into apcupsd-gui. It also installs the desktop file and pixmaps for gapcmon. -- System Information: Debian Release: buster/sid APT prefers unstable-debug APT policy: (500, 'unstable-debug'),

Bug#828475: openssh: Please migrate to openssl1.1 in Buster

2017-10-16 Thread Russ Allbery
Sebastian Andrzej Siewior writes: > Well, one way sure. You get features from the fork which upstream does > not provide and the Debian version does not have. I had a brief look > into debian patch queue and there was something regarding ldap and the > fork mentioned

Bug#878840: icu: CVE-2017-14952: Double free in i18n/zonemeta.cpp

2017-10-16 Thread Salvatore Bonaccorso
Source: icu Version: 57.1-6 Severity: grave Tags: patch security upstream Hi, the following vulnerability was published for icu. CVE-2017-14952[0]: | Double free in i18n/zonemeta.cpp in International Components for | Unicode (ICU) for C/C++ through 59.1 allows remote attackers to | execute

Bug#878839: optipng: global-buffer-overflow bug while parsing GIF file

2017-10-16 Thread Joonun Jang
Package: optipng Version: 0.7.6-1 Severity: normal Dear Maintainer, global-buffer-overflow bug while parsing GIF file Running 'optipng' with the attached file raises global-buffer-overflow bug, which may allow a remote attacker to cause a denial-of-service attack or other unspecified impact

Bug#878812: [pkg-gnupg-maint] Bug#878812: hits bug_at when encrypting to 1A6F3E639A4467E8C3476525DF6D76C44D696F6B

2017-10-16 Thread NIIBE Yutaka
Guido Günther wrote: >> > #4 0x556a0f29306f bug_at (gpg) >> > #5 0x556a0f243c1e do_we_trust (gpg) >> > #6 0x556a0f243fff find_and_check_key (gpg) >> > #7 0x556a0f2455b6 find_and_check_key (gpg)

Bug#821839: golang-github-gosuri-uitable: changing from RFP to ITP

2017-10-16 Thread Nobuhiro Iwamatsu
retitle 821839 ITP: golang-github-gosuri-uitable -- Go library for tabular terminal output owner 821839 ! thanks Hi, I am intrested in this package, I am going to package this. Best regards, Nobuhiro

Bug#878838: Please add foolproof warning distribution=UNRELEASED

2017-10-16 Thread Hideki Yamane
Package: lintian Severity: minor Hi, Sometimes stupid maintainer (=me) forgets about changing from UNRELEASED distribution to unstable at build with cowbuilder. Could you add foolproof warning to lintian? And I've tried to check it with .changes file, below warning seems to not work. >$ head

Bug#878837: sambamba: FTBFS with ldc 1.4.0

2017-10-16 Thread Nobuhiro Iwamatsu
Package: sambamba Version: 0.6.6-1 Severity: serious Tags: buster sid Justification: FTBFS on amd64 Hi, Dear Maintainer, sambamba FTBFS with ldc 1.4.0 on sid. https://buildd.debian.org/status/fetch.php?pkg=sambamba=amd64=0.6.6-1%2Bb1=1507088043=0 - [1/74] ldc2 -Isambamba@exe -I. -I..

Bug#878836: ifupdown: ifquery only reports the first stanza for each interface

2017-10-16 Thread Peter.Chubb
Package: ifupdown Version: 0.8.25 Severity: normal Dear Maintainer, With the attached /etc/network/interfaces file, ifquery reports only ipv6 configuration for each interface. I expect it to show both ipv4 and ipv6 info --- the same interface has two address classes. -- Package-specific

Bug#878792: Upstream patch

2017-10-16 Thread Eric Desrochers
The PR has been approved/merged in the lshw primary devel site (ezix upstream) https://ezix.org/src/pkg/lshw/commit/7b99d35064230f908551ba65c29264d90f49f246

Bug#878835: transition: hypre

2017-10-16 Thread Drew Parsons
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: transition I'd like to push hypre 2.11.2 into unstable. This is a routine upgrade, but does affect the soname. It brings a fix for #877054 which stabilises hypre and reverse-dependencies in

Bug#878834: freetype: Upgrade to 2.8.1 breaks font rendering in various applications

2017-10-16 Thread Christian Weeks
Source: freetype Version: 2.8.1-0.1 Severity: important Dear Maintainer, I upgraded freetype from 2.8.0 to 2.8.1 today and font rendering in both thunderbird and discord took a really steep nosedive. Freetype 2.8.0: https://imgur.com/8QLHYDK Freetype 2.8.1: https://imgur.com/TtDN0pE Thanks

Bug#878833: tbb: FTBFS on m68k: static assertion about atomics failed

2017-10-16 Thread Aaron M. Ucko
Source: tbb Version: 2017~U7-8 Severity: important Tags: upstream Justification: fails to build from source (but built successfully in the past) User: debian-m...@lists.debian.org Builds of tbb for m68k (admittedly not a release architecture) have been failing lately: In file included from

Bug#878832: tbb: FTBFS on hppa: rml::pool_* undefined

2017-10-16 Thread Aaron M. Ucko
Source: tbb Version: 2017~U7-8 Severity: important Tags: upstream Justification: fails to build from source (but built successfully in the past) User: debian-h...@lists.debian.org Builds of tbb for hppa (admittedly not a release architecture) have been failing lately, per the below excerpt from

Bug#878831: tbb: FTBFS on alpha: test_malloc_whitebox fails

2017-10-16 Thread Aaron M. Ucko
Source: tbb Version: 2017~U7-8 Severity: important Tags: upstream Justification: fails to build from source (but built successfully in the past) User: debian-al...@lists.debian.org Builds of tbb for alpha (admittedly not a release architecture) have been failing lately: sh ../gdb_shell.sh

Bug#754513: RFP: libressl -- SSL library, forked from OpenSSL

2017-10-16 Thread Michael Stone
On Tue, Oct 17, 2017 at 12:05:30AM +0200, Guus Sliepen wrote: despite fears of OpenBSD only caring about themselves, I have found that it is easier to compile LibreSSL for various platforms (even non-POSIX ones) than OpenSSL. And that APIs might be broken more easily by LibreSSL is ridiculous,

Bug#878830: opencv: FTBFS w/tbb 4.x: has_trivial_copy_constructor missing

2017-10-16 Thread Aaron M. Ucko
Source: opencv Version: 3.2.0+dfsg-2 Severity: important Justification: fails to build from source (but built successfully in the past) User: debian-...@lists.debian.org Thanks again for looking into #878705. Builds for x32 now do slightly better, but still fail:

Bug#683772: gpscorrelate: provide a --force option to overwrite existing GPS tags

2017-10-16 Thread Tim Connors
Hi Mònica, A patch has been supplied for this bug a long time ago, but hasn't been acknowledged yet. Are you able to look at this please? -- Tim Connors

Bug#878732: ufraw-batch: NULL pointer dereference when runningwith --conf option

2017-10-16 Thread 장준언
Hello, I reported 3 bugs (878732, 878733, 878745) In fact, 878745 is a duplicate of 878732. But I should have reported it again because I attached wrong poc file in 878732. So you can regenerate this bug using the attached file in 878745. And after analyzing this issue, I thought that two bugs

Bug#878732: ufraw-batch: NULL pointer dereference when running with --conf option

2017-10-16 Thread Hubert Chathi
On Mon, 16 Oct 2017 18:48:16 +0900, Joonun Jang said: > Package: ufraw-batch > Version: 0.22-1.1 > Severity: normal > Running 'ufraw-batch --conf' with the attached file raises a NULL > pointer dereference, which may allow a denial-of-service attack of a > malicious

Bug#839879: mtr FTCBFS: uses build architecture tools

2017-10-16 Thread Robert Woodcock
On 10/15/2017 01:18 PM, Robert Woodcock wrote: > On 10/15/2017 10:50 AM, Samuel Henrique wrote: >> ​Hello everyone, >> >> I've just applied an updated version of Helmut's patch on another >> branch[1] >> But as you can see (if you build that branch), we have a problem >> because the packages will

Bug#878829: initramfs-tools: system freezes at boot with MODULES=dep

2017-10-16 Thread Christoph Anton Mitterer
Package: initramfs-tools Version: 0.130 Severity: important Hi. The following is a quite strange problem, and it may actually be a kernel bug. Few days ago, I got a new notebook (a Fujitsu U757), before I removed the HDD from the old one, I changed MODULES=most on the old and updated the

Bug#878828: snmpd: PID file missing

2017-10-16 Thread Rob Gibson
Package: snmpd Version: 5.7.3+dfsg-1.7 Severity: minor Dear Maintainer, I have been trying to use 'monit' to monitor the local daemons on this system, and I have had issues since upgrading from Jessie to Stretch. Apparently, the new systemd service file does not specify creating a pid file,

Bug#871619: ZFS/SPL 0.7.2 Packaging

2017-10-16 Thread Antonio Russo
The two repositories github.com/aerusso/pkg-zfsonlinux-spl github.com/aerusso/pkg-zfsonlinux-zfs include patches from the stable branches of upstream, as well as Fabian's zfs-test packaging, which was suggested was important for a release. I also believe this addresses the issues regarding FHS

Bug#878827: Auto-login no longer works as of 3.26.0-1 [Regression]

2017-10-16 Thread Jason Wittlin-Cohen
Package: gdm3 Version: 3.26.1-3 Severity: normal Dear Maintainer, * What led up to the situation? I noticed that auto-login stopped working in GDM after the package was updated from 3.25.90.1-2 to 3.26.0-1. I did not make any configuration changes between versions. * What exactly did you

Bug#878826: libapache2-mod-python: Double free in mod_python

2017-10-16 Thread Peter Chubb
Package: libapache2-mod-python Version: 3.3.1-11 Severity: important Dear Maintainer, I upgraded from Jessie to Stretch; now my website doesn't work at all. Blank pages are returned. /var/log/apache2/error.log shows: *** Error in `/usr/sbin/apache2': double free or corruption (!prev):

Bug#878825: vagrant: Does not detect that `nfs-kernel-server` is sufficient

2017-10-16 Thread Paul "LeoNerd" Evans
Package: vagrant Version: 1.9.8+dfsg-1 Severity: normal When trying to start a machine using NFS, when I have `nfs-kernel-server` installed and available, it complains that It appears your machine doesn't support NFS, or there is not an adapter to enable NFS on this machine for Vagrant.

Bug#754513: RFP: libressl -- SSL library, forked from OpenSSL

2017-10-16 Thread Guus Sliepen
On Mon, Oct 16, 2017 at 05:29:09PM +0100, Colin Watson wrote: > > * Package name: libressl [...] > Furthermore, the OpenSSL maintainers in Debian now want to drop their > 1.0 compatibility packages, which the Debian OpenSSH packages rely on. > I can't exactly fault them for wanting to reduce

Bug#878811: dummy interface in bridge sticks in "configuring", leading to degraded system

2017-10-16 Thread Michael Biebl
Control: Am 16.10.2017 um 21:57 schrieb Marc Haber: > Package: systemd > Version: 235-2.0~zgSID+1 Seems the bts is not happy with that version. For proper version tracking, which version is affected by this? Is this a regression in v235 or (given your comment) is not a regression and happens with

Bug#867921: Closing the bug

2017-10-16 Thread Thomas Goirand
Hi, The issue is probably in openstack-debian-images rather than in cloud-init. I'm therefore reassigning the bug. The directive really is "source" and not "include" as you wrote. In the default OpenStack image from cdimage.d.o, there is already that source directive, so it should work by

Bug#849077: Please adjust the BTS version tracking info

2017-10-16 Thread Francesco Poli
Control: fixed -1 wpa/2:2.4-1 Control: found -1 wpa/2:2.6-4 On Sat, 16 Sep 2017 23:54:10 +0200 Francesco Poli wrote: > On Sat, 9 Sep 2017 19:17:12 +0200 Francesco Poli wrote: > > > On Sat, 1 Jul 2017 23:32:28 +0200 Francesco Poli wrote: > > > > > Dear Debian wpasupplicant Maintainers, > > > I

Bug#258096: ITP: glom -- A database designer and user interface

2017-10-16 Thread Jeremy Bicha
Control: retitle -1 ITP: glom -- A database designer and user interface Control: owner -1 jbi...@debian.org I am looking into maintaining glom under the Debian GNOME team. See also these 2 ITPs https://bugs.debian.org/878822 (goocanvasmm2.0) https://bugs.debian.org/878823 (libgdamm5.0) Thanks,

Bug#878824: [FIXED UPSTREAM] xfce4-diskperf-plugin: Unable to get performance statistics for devices with major number > 255

2017-10-16 Thread Paul-Antoine Arras
Package: xfce4-diskperf-plugin Version: 2.5.5-1 Severity: important Tags: upstream Reported and fixed upstream in 2.6.1. Packaged and tested in my environment. Upstream bug report: https://bugzilla.xfce.org/show_bug.cgi?id=13281 Upstream fix commit:

Bug#878823: ITP: libgdamm5.0 -- C++ wrappers for libgda5

2017-10-16 Thread Jeremy Bicha
Package: wnpp Severity: wishlist X-Debbugs-CC: debian-de...@lists.debian.org Owner: jbi...@debian.org Package Name: libgdamm Version: 4.99.11 Upstream Authors : Murray Cumming License : LGPL-2.1+. Some files are GPL-2+ Programming Lang: C++ Description: C++ wrappers for libgda5 libgdamm is a

Bug#878806: debug-file-with-no-debug-symbols: mention lack of -g as common cause

2017-10-16 Thread Chris Lamb
tags 878806 + pending thanks Applied in Git; many thanks! https://anonscm.debian.org/git/lintian/lintian.git/commit/?id=9db324c2487ad26d07eb42f71c33141deab837bb Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Bug#878812: hits bug_at when encrypting to 1A6F3E639A4467E8C3476525DF6D76C44D696F6B

2017-10-16 Thread Guido Günther
Hi, On Mon, Oct 16, 2017 at 10:35:15PM +0200, Guido Günther wrote: > Hi, > On Mon, Oct 16, 2017 at 10:02:09PM +0200, Guido Günther wrote: > > Package: gnupg > > Version: 2.2.1-2 > > Severity: normal > > > > Encrypting to 1A6F3E639A4467E8C3476525DF6D76C44D696F6B makes GPG here > > segfault like: >

Bug#878822: ITP: goocanvasmm-2.0 -- C++ bindings for GooCanvas

2017-10-16 Thread Jeremy Bicha
Package: wnpp Severity: wishlist X-Debbugs-CC: debian-de...@lists.debian.org Owner: jbi...@debian.org Package Name: goocanvasmm Version: 1.90.11 Upstream Authors : Murray Cumming and others License : LGPL-2.1+. Some files are GPL-2 or GPL-2+ Programming Lang: C++ Description: C++ bindings for

Bug#643277: python-opencv: Cannot read video anymore after upgrading to 2.1.0-7

2017-10-16 Thread Antoine Sirinelli
Hi Mattia, On Mon, Oct 16, 2017 at 09:06:45PM +0200, Mattia Rizzolo wrote: > On Fri, Sep 30, 2011 at 09:06:53PM +0100, Antoine Sirinelli wrote: > > You can find an example video (very short): > > http://www.monte-stello.com/test.avi > > This seems to not be reachable anymore. I am not sure I

Bug#878696: Debian mirror mirror.nbtelecom.com.br: broken mirror

2017-10-16 Thread Peter Palfrader
On Mon, 16 Oct 2017, Pedro Alves wrote: >    Sorry, i had to move to one other disk/mount dir and i forgot to fix the > Apache dir. > >     Can you check again ? Less broken, but very out of date. Mirrors should update every 6 hours to match the update frequency of the archive. The latest

Bug#878798: lintian: Please accept and recommend new vcs-mtn mtn:// uri format

2017-10-16 Thread Chris Lamb
tags 878798 + pending thanks Fixed in Git: https://anonscm.debian.org/git/lintian/lintian.git/commit/?id=678ea00d7b63997e22d09735bdc66ea7ea04ad0d Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Bug#878819: Patch

2017-10-16 Thread Ben Howard
Tags: patch The following patch fixes the problem: diff --git a/debian/control b/debian/control index 4aac4ad2..721f801f 100644 --- a/debian/control +++ b/debian/control @@ -41,11 +41,13 @@ Homepage: https://launchpad.net/cloud-init Package: cloud-init Architecture: all Depends: +

Bug#878821: ITP: norm -- NACK-Oriented Reliable Multicast (NORM) library

2017-10-16 Thread Luca Boccassi
Package: wnpp Severity: wishlist Owner: Luca Boccassi * Package name: norm   Version : 1.5r6   Upstream Author : Naval Research Laboratory (NRL) * URL : https://www.nrl.navy.mil/itd/ncs/products/norm * License : NSL (BSD-2-clause lookalike)  

Bug#876561: transition: gdal

2017-10-16 Thread Manuel A. Fernandez Montecelo
Hi! 2017-10-05 18:19 Sebastiaan Couwenberg: Thanks for the osgearth NMU on amd64, for the uncoordinated openscenegraph-3.4 transition it also needs to be NMUed on i386 & ppc64el (and powerpc). Sorry about that, I intended [1] to upload to experimental but failed miserably :( [1]

Bug#878820: python-skbio FTBFS with Python 3.6 as default

2017-10-16 Thread Adrian Bunk
Source: python-skbio Version: 0.5.1-3 Severity: serious https://tests.reproducible-builds.org/debian/rb-pkg/unstable/amd64/python-skbio.html ... Exception occurred: File "/build/1st/python-skbio-0.5.1/.pybuild/pythonX.Y_3.5/build/skbio/metadata/_interval.py", line 13, in from

Bug#878819: cloud-init has undeclared dependencies

2017-10-16 Thread Ben Howard
Package: cloud-init Version: 0.7.9-2 Cloud-init relies on both cloud-guest-utils and locales, however both are undeclared.

Bug#878818: ovito: FTBFS - Testsuite fails because executed with python3.5 instead of 3.6

2017-10-16 Thread Gilles Filippini
Source: ovito Version: 2.9.0+dfsg1-2 Severity: serious Tags: patch Justification: FTBFS -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, With the ongoing python3.6 transition ovito is built with both python3.5 and 3.6. The latter being the defaut. This makes the testsuite fails with:

Bug#853658: Forwarded upstream

2017-10-16 Thread Gilles Filippini
Control: tags -1 + patch fixed-upstream Hi, On Fri, 18 Aug 2017 17:33:47 +0100 Ghislain Vaillant wrote: > On 18/08/17 17:26, Sebastiaan Couwenberg wrote: > > On Mon, 7 Aug 2017 08:49:19 +0100 Ghislain Vaillant wrote: > >> control: forwarded -1

Bug#878812: Segfaults when encrypting to certain keys

2017-10-16 Thread Guido Günther
Hi, On Mon, Oct 16, 2017 at 10:02:09PM +0200, Guido Günther wrote: > Package: gnupg > Version: 2.2.1-2 > Severity: normal > > Encrypting to 1A6F3E639A4467E8C3476525DF6D76C44D696F6B makes GPG here > segfault like: > > $ coredumpctl dump >PID: 21438 (gpg) >UID: 1000 (agx) >

Bug#861736: closed by Andreas Tille <ti...@debian.org> (Bug#861736: fixed in nexus 4.3.2-svn1921-5)

2017-10-16 Thread Gilles Filippini
Control: tags -1 + patch Hi, On Fri, 12 May 2017 08:32:28 +0200 Marc Rosanes wrote: > Hi, > > We have found that python-nxs is still affected by problems: > > The following piece of code fails on stretch + the lastest nexus from > unstable: > > ``` > import nxs > f =

Bug#878817: luajit: Please drop mips64el again

2017-10-16 Thread Adrian Bunk
Source: luajit Version: 2.1.0~beta3+dfsg-5 Severity: serious Control: affects -1 src:neovim src:knot-resolver neovim and knot-resolver FTBFS with luajit 2.1.0~beta3+dfsg-5: https://buildd.debian.org/status/logs.php?pkg=neovim=mips64el

Bug#878816: stretch-pu: package lttng-modules/2.9.0-1+deb9u1

2017-10-16 Thread Michael Jeanson
Package: release.debian.org Severity: normal Tags: stretch User: release.debian@packages.debian.org Usertags: pu Hi, The attached diff fixes a build failure of the dkms modules on the linux-rt flavor of the debian linux kernel. This was reported at:

Bug#853351: comet-ms: ftbfs with GCC-7

2017-10-16 Thread pini
Control: tags -1 + patch Hi, On Tue, 31 Jan 2017 09:30:22 + Matthias Klose wrote: > Package: src:comet-ms > Version: 2014022-3 > Severity: normal > Tags: sid buster > User: debian-...@lists.debian.org > Usertags: ftbfs-gcc-7 > > Please keep this issue open in the bug

Bug#877700: [Help] Exclusion did not worked (Was: Bug#877419: Bug#877700: RM: pandas [arm64 armel armhf mips mips64el mipsel s390x] ...)

2017-10-16 Thread Andreas Tille
Hi, On Mon, Oct 16, 2017 at 12:03:49PM +0100, James Clarke wrote: > On 16 Oct 2017, at 11:08, Andreas Tille wrote: > > On Sun, Oct 15, 2017 at 08:21:46PM +0100, Rebecca N. Palmer wrote: > >>> raise nose.SkipTest("known failure of test_stata on non-little > >>> endian")

Bug#878813: g2clib FTBFS with libopenjp2-7-dev 2.3.0-1

2017-10-16 Thread Adrian Bunk
Source: g2clib Version: 1.6.0-8 Severity: serious https://tests.reproducible-builds.org/debian/rb-pkg/unstable/amd64/g2clib.html ... jpeg2000_openjpeg.c:10:10: fatal error: openjpeg.h: No such file or directory #include "openjpeg.h" ^~~~ compilation terminated. makefile:103:

Bug#878814: fails to install in a chroot

2017-10-16 Thread Emanuele Aina
Package: blueman Version: 2.0.5-1+b1 Severity: normal In debian/postinst the blueman package calls `invoke-rc.d dbus reload` but does not ignore the return value, so the maintscript will fail in chroot environments where dbus cannot be reloaded: $ sudo debootstrap sid /tmp/scratch/debian $ sudo

Bug#878815: qsstv FTBFS with libopenjp2-7-dev 2.3.0-1

2017-10-16 Thread Adrian Bunk
Source: qsstv Version: 9.2.4+repack-2 Severity: serious https://tests.reproducible-builds.org/debian/rb-pkg/unstable/amd64/qsstv.html ... In file included from widgets/imageviewer.cpp:28:0: utils/jp2io.h:3:10: fatal error: openjpeg.h: No such file or directory #include "openjpeg.h"

Bug#878812: Segfaults when encrypting to certain keys

2017-10-16 Thread Guido Günther
Package: gnupg Version: 2.2.1-2 Severity: normal Encrypting to 1A6F3E639A4467E8C3476525DF6D76C44D696F6B makes GPG here segfault like: $ coredumpctl dump PID: 21438 (gpg) UID: 1000 (agx) GID: 1000 (agx) Signal: 6 (ABRT) Timestamp: Mon 2017-10-16

Bug#754513: RFP: libressl -- SSL library, forked from OpenSSL

2017-10-16 Thread Sebastian Andrzej Siewior
On 2017-10-16 17:29:09 [+0100], Colin Watson wrote: > [I won't quote everything, but people replying to this should probably > read the bug log in the BTS first.] It was a lot to read and "they" stumbled over details. > While there does exist a skeletal compatibility layer linked from the >

Bug#878810: sox: CVE-2017-15370: heap-buffer-overflow src/ima_rw.c:126 in ImaExpandS

2017-10-16 Thread Salvatore Bonaccorso
Source: sox Version: 14.4.1-5 Severity: important Tags: security upstream Hi, the following vulnerability was published for sox. CVE-2017-15370[0]: | There is a heap-based buffer overflow in the ImaExpandS function of | ima_rw.c in Sound eXchange (SoX) 14.4.2. A Crafted input will lead to a |

Bug#878811: dummy interface in bridge sticks in "configuring", leading to degraded system

2017-10-16 Thread Marc Haber
Package: systemd Version: 235-2.0~zgSID+1 Severity: normal Tags: upstream patch Forwarded: https://github.com/systemd/systemd/issues/6961 This is upstream issue 6961, where a dummy interface configured into a bridge gets stuck in "configuring" state, with the usual consequences of the network

Bug#878809: sox: CVE-2017-15371

2017-10-16 Thread Salvatore Bonaccorso
Source: sox Version: 14.4.1-5 Severity: important Tags: security upstream Hi, the following vulnerability was published for sox. CVE-2017-15371[0]: | There is a reachable assertion abort in the function | sox_append_comment() in formats.c in Sound eXchange (SoX) 14.4.2. A | Crafted input will

Bug#878807: wpasupplicant: Please port the security fixes to 2.6 also

2017-10-16 Thread Eric Valette
Package: wpasupplicant Version: 2:2.6-4 Severity: grave Tags: upstream security Justification: user security hole Upstream patches patches for 2.6 are here http://w1.fi/security/2017-1/ -- System Information: Debian Release: buster/sid APT prefers unstable APT policy: (500, 'unstable'), (1,

Bug#878808: sox: CVE-2017-15372: stack-buffer-overflow src/adpcm.c:126 in lsx_ms_adpcm_block_expand_i

2017-10-16 Thread Salvatore Bonaccorso
Source: sox Version: 14.4.1-5 Severity: important Tags: security upstream Hi, the following vulnerability was published for sox. CVE-2017-15372[0]: | There is a stack-based buffer overflow in the | lsx_ms_adpcm_block_expand_i function of adpcm.c in Sound eXchange (SoX) | 14.4.2. A Crafted input

Bug#878805: More kernel log output

2017-10-16 Thread Jesse Szwedko
More interesting kern.log output from when touchpad was erratic: Oct 16 09:36:39 jesse-thinkpad kernel: [ 353.981729] psmouse serio1: TouchPad at isa0060/serio1/input0 lost synchronization, throwing 5 bytes away. Oct 16 09:36:39 jesse-thinkpad kernel: [ 354.526319] psmouse serio1: resync

Bug#864562: No ethernet link on Olimex A20-Olinuxino Micro Rev. J, possibly PHY driver problem

2017-10-16 Thread Jean-Louis Mounier
Hello Karsten, for some reasons, I changed my mail configuration and I discovered your last request very recently (!) Sorry for the delay. Now I keep an eye on the bug thru the bug web page. I discovered a new installer release but the bug is still present. Now the test : => gpio clear

Bug#877470: Question about strip-nondeterminism in bsh

2017-10-16 Thread Chris Lamb
Jathan, > include /usr/share/dpkg/pkg-info.mk > > export SOURCE_DATE_EPOCH = $(call > dpkg_late_eval,SOURCE_DATE_EPOCH,dpkg-parsechangelog -STimestamp) > or > export SOURCE_DATE_EPOCH = $(shell dpkg-parsechangelog -STimestamp) I fear you are confused here — if you include include

Bug#878806: debug-file-with-no-debug-symbols: mention lack of -g as common cause

2017-10-16 Thread Adrian Bunk
Package: lintian Version: 2.5.55 Severity: minor Tags: patch Mention the most (?) common cause of debug-file-with-no-debug-symbols: diff --git a/checks/binaries.desc b/checks/binaries.desc index 73f789a59..708ad263a 100644 --- a/checks/binaries.desc +++ b/checks/binaries.desc @@ -424,6 +424,8 @@

Bug#878805: linux-image-4.13.0-1-amd64: Integrated synaptic touchpad and keyboard not working after kernel upgrade

2017-10-16 Thread Jesse Szwedko
Package: src:linux Version: 4.13.4-2 Severity: important Dear Maintainer, Recently upgraded the kernel from 4.12 to 4.13 whereafter the touchpad of my Thinkpad Yoga 11e began behaving very erratically (slow, jumpy, and often freezing). dmesg reported issues syncing with the touchpad (not shown

Bug#833057: extlinux: cannot boot from ext4 filesystems with 64bit feature enabled

2017-10-16 Thread Lukas Schwaighofer
Control: retitle -1 extlinux: cannot boot from ext4 filesystems with 64bit feature enabled Control: tags -1 - moreinfo + confirmed upstream Hi, thanks for reporting and working on this issue. I'm certain the experienced problem is due to the 64bit feature in ext4, which is set by default when

Bug#878804: RFS: shotwell/0.26.3-1

2017-10-16 Thread Jörg Frings-Fürst
Package: sponsorship-requests Severity: normal Dear mentors, I am looking for a sponsor for my package "shotwell" Package name: shotwell Version : 0.26.3-1 Upstream Author : Jim Nelson URL : https://wiki.gnome.org/Apps/Shotwell License

Bug#874118: CVE-2017-14039: Heap-based buffer overflow in opj_t2_encode_packet function in lib/openjp2/t2.c

2017-10-16 Thread Mathieu Malaterre
Hi Salvatore, This is the second time you /saved/ me (sorry for my limited Spanish) :) On Mon, Oct 16, 2017 at 7:12 PM, Salvatore Bonaccorso wrote: > Hello Mathieu, > > On Mon, Oct 16, 2017 at 06:12:30PM +0200, Mathieu Malaterre wrote: >> Control: severity -1 important >> >>

Bug#878803: ITP: ppx-derivers -- interoperability of ppx-deriving and ppx-type-conv

2017-10-16 Thread Ralf Treinen
Package: wnpp Severity: wishlist Owner: Ralf Treinen * Package name: ppx-derivers Version : 1.0 Upstream Author : Jérémie Dimino * URL : https://github.com/diml/ppx_derivers * License : BSD3 Programming Lang: OCaml

Bug#119911: still worked in

2017-10-16 Thread PICCORO McKAY Lenz
hi andy, i worked and send the files to debian also i have the repository but feedback does not are received i still waiting for that feedback , my workand packages are ready to .. but now noted that many was changed at game-data.packager, i not haveclear how now put the files.. i'll revise

Bug#643277: python-opencv: Cannot read video anymore after upgrading to 2.1.0-7

2017-10-16 Thread Mattia Rizzolo
Control: tags -1 = moreinfo On Fri, Sep 30, 2011 at 09:06:53PM +0100, Antoine Sirinelli wrote: > You can find an example video (very short): > http://www.monte-stello.com/test.avi This seems to not be reachable anymore. > This video is played by my script with the 2.1.0-6 version of OpenCV

Bug#877470: Question about strip-nondeterminism in bsh

2017-10-16 Thread jathan
On 09/10/17 10:47, Chris Lamb wrote: > [Adding 877...@bugs.debian.org to CC] > > Hi jathan, > >> Also I want to ask you what does it mean you actually use >> /usr/share/dpkg/pkg-info.mk for SOURCE_DATE_EPOCH > > See, for example: > >

Bug#594543: Addendum: UniBrain Fire-i works correctly with OpenCV 2.1

2017-10-16 Thread Mattia Rizzolo
Control: tag -1 moreinfo Hi! On Fri, Aug 27, 2010 at 01:58:21AM +0200, Raphael Wimmer wrote: > I just tested with a UniBrain Fire-i camera (color). > This one seems to work correctly. > As OpenCV automatically chooses a video mode for the camera (a real > annoyance), I suspect that it chooses

Bug#828475: openssh: Please migrate to openssl1.1 in Buster

2017-10-16 Thread Sebastian Andrzej Siewior
On 2017-10-15 22:06:35 [+0100], Colin Watson wrote: > What? You've entirely misunderstood me. OpenSSH upstream *already* This got cleared up in the meantime. > > I've been pointed out to another way to go I hope you like it: There is > > PKIX-SSH [0]. > > I dislike the idea of switching to a

Bug#833035: linux-image-3.16.0-4-amd64: Keyspan USB serial adapter USA-49WLC failed to load firmware

2017-10-16 Thread Paul Fox
ben, chris -- regarding this bug: Bug#833035: linux-image-3.16.0-4-amd64: Keyspan USB serial adapter USA-49WLC failed to load firmware whatever became of the proposed patch. i'm running ubuntu 16.04.3, kernel 4.4.0-97-generic, and the failure is still present there. paul

Bug#878802: xonix: Widgets are missing labels

2017-10-16 Thread Andrej Mernik
Package: xonix Version: 1.4-31 Severity: normal Dear Maintainer, the game Widgets are missing label values (see screenshot). The values are easy to guess, but their absence makes the game look broken. Best Regards, Andrej Mernik -- System Information: Debian Release: 9.1 APT prefers stable

Bug#610400: [Pkg-scicomp-devel] Bug#610400: opencv: usage of external lapack breaks cvCalibrateCamera2

2017-10-16 Thread Mattia Rizzolo
Control: tag -1 moreinfo On Tue, Feb 08, 2011 at 04:49:47PM +0100, Sven Geggus wrote: > > > Do you check on i386? I checked on amd64, but I could not get > > > Segmentation fault. > > > > Yes, this is a 32 bit machine. > > Just cross checked on 64bit squeeze. No segfault there! I do not have

Bug#763838: libopencv-highgui2.4: Webcam capture failures

2017-10-16 Thread Mattia Rizzolo
Control: tag -1 moreinfo On Fri, Oct 03, 2014 at 03:48:36AM +, Richard Allen wrote: > It appears webcam capture is broken. I tried a PS3 Eye(RGB/YUV) > and a PS2 Eyetoy(JPG). On AMD64 both result in garbage. On another > jessie box, this time i386, both cameras crash. Nobuhiro reported (in a

Bug#878801: zulupolkit should probably have a dependency relationship with polkit

2017-10-16 Thread Simon McVittie
Package: zulupolkit Version: 5.2.0-2 Severity: normal zulupolkit appears to be something to do with polkit prompting for zulucrypt (I don't use it and am purely going by the package description). If that's true, it should probably have a Depends, or at least Recommends or Suggests, on

Bug#878584: [libevas-dev] Missing dependency for libecore-dev

2017-10-16 Thread Andreas Metzler
On 2017-10-15 Ross Vandegrift wrote: > On Sun, Oct 15, 2017 at 01:20:05PM +0200, Andreas Metzler wrote: > > Ross, could you apply and push the attached patch? [...] > 2) Upstream doesn't really support builds against part of EFL (and > hasn't since the library merge before

Bug#876308: libxml2 FTBFS: rename: "Unknown option: vf"

2017-10-16 Thread Manuel A. Fernandez Montecelo
Hi, 2017-10-15 13:24 GMT+02:00 Mattia Rizzolo : > On Sun, Oct 15, 2017 at 12:41:53PM +0200, Manuel A. Fernandez Montecelo wrote: >> >> libxslt needed also to add "rename" as B-D, which I added in a recent >> >> NMU. >> > >> > About that, next time please consider using the

Bug#878754: Plinth fail to start at boot - import_from_gi('NM', '1.0') fail

2017-10-16 Thread Petter Reinholdtsen
Control: forcemerge -1 862758 This is actually the same as #862758, and is fixed by installing gir1.2-nm-1.0. -- Happy hacking Petter Reinholdtsen

Bug#878796: anjuta: crash when compiler is starting

2017-10-16 Thread Michael Biebl
Control: tags -1 - patch Am 16.10.2017 um 19:12 schrieb Francesco: > Package: anjuta > Version: 2:3.22.0-3 > Severity: important > Tags: patch > > Dear Maintainer, > > The program crash when the 'start compiling' option is selected. > > When the 'run without debug' option is selected instead

Bug#878800: jgit-cli: IllegalStateException: Cannot set value to a final field 'org.eclipse.jgit.pgm.Daemon.enable'

2017-10-16 Thread Jonathan Nieder
Package: jgit-cli Version: 3.7.1-4 Tags: upstream patch fixed-upstream Severity: important Justification: renders feature unusable Steps to reproduce: git clone https://kernel.googlesource.com/pub/scm/git/git cd git make -j8 cd t ./t5512-ls-remote.sh -v -i Expected result: test passes

Bug#878799: CVE-2017-1000256/LSN-2017-0002: TLS certificate verification disabled for clients

2017-10-16 Thread Guido Günther
Source: libvirt Version: CVE-2017-1000256/LSN-2017-0002: TLS certificate verification disabled for clients Severity: important Tags: security Description --- The default_tls_x509_verify (and related) parameters in qemu.conf control whether the TLS servers in QEMU request & verify

Bug#878798: lintian: Please accept and recommend new vcs-mtn mtn:// uri format

2017-10-16 Thread Nicolas Boulenguez
Package: lintian Severity: wishlist Tags: patch The monotone version control system has deprecated the "mtn host branch" syntax for years. We should recommend the new "mtn mtn://host?branch" instead. Please consider the attached suggestion when checking the VCS-Mtn control field. ---

Bug#878797: Shellinabox not working on Stretch

2017-10-16 Thread Jeff Burns
Package: shellinabox Version: 2.20+b1 On a fresh Debian Stretch install I cannot get shellinabox to respond, seems the web server side of it isn’t responding or providing a pool of connections. I reused a working configuration from Debian Jessie with no luck. See configuration details below.

Bug#754513: RFP: libressl -- SSL library, forked from OpenSSL

2017-10-16 Thread Michael Stone
On Mon, Oct 16, 2017 at 05:29:09PM +0100, Colin Watson wrote: Out of all of these, I think the option that I think has the fewest downsides overall is to convince people to package LibreSSL, but I'm not myself in a position to contribute to that effort. Does anyone have thoughts or other

Bug#754513: [Pkg-openssl-devel] Bug#754513: RFP: libressl -- SSL library, forked from OpenSSL

2017-10-16 Thread Kurt Roeckx
On Mon, Oct 16, 2017 at 05:29:09PM +0100, Colin Watson wrote: > > While there does exist a skeletal compatibility layer linked from the > upstream wiki [1], the OpenSSL developers explicitly don't want to > maintain this properly [2], and the OpenSSH developers say that it is > "unversioned,

Bug#869995: fixed in systemd 235-1

2017-10-16 Thread Michael Biebl
Control: tags -1 - fixed-upstream Am 16.10.2017 um 18:58 schrieb Marc Haber: > found #869995 235-1 > thanks > > I regret to inform you that the fix given in this bug report didn't make > it into upstream 235. The issue reappears after the update to systemd > 235, the patches do still apply to

Bug#878796: anjuta: crash when compiler is starting

2017-10-16 Thread Francesco
Package: anjuta Version: 2:3.22.0-3 Severity: important Tags: patch Dear Maintainer, The program crash when the 'start compiling' option is selected. When the 'run without debug' option is selected instead the program do nothing. -- System Information: Debian Release: 9.2 Architecture: amd64

Bug#874118: CVE-2017-14039: Heap-based buffer overflow in opj_t2_encode_packet function in lib/openjp2/t2.c

2017-10-16 Thread Salvatore Bonaccorso
Hello Mathieu, On Mon, Oct 16, 2017 at 06:12:30PM +0200, Mathieu Malaterre wrote: > Control: severity -1 important > > While I understand the this generic heap based buffer overflow ought > to be fixed in Debian stable, I fail to see why it is marked as > affecting stretch. [...] In my initial

Bug#869995: fixed in systemd 235-1

2017-10-16 Thread Marc Haber
found #869995 235-1 thanks I regret to inform you that the fix given in this bug report didn't make it into upstream 235. The issue reappears after the update to systemd 235, the patches do still apply to the code (with some fuzz, but without rejection), the issue disappears with the patched

Bug#831414: systemd: learns IPv6 prefix from its own RAs and configures IP address on wrong interface

2017-10-16 Thread Michael Biebl
Version: 234-1 Am 16.10.2017 um 18:52 schrieb Marc Haber: > Hi, > > stumbling upon this again. The system behaves now, so the issue as at > least fixed in systemd 234. Ah, perfect. Thanks for reporting back. Closing the bug report for that version then. Michael -- Why is it that all of the

Bug#831414: systemd: learns IPv6 prefix from its own RAs and configures IP address on wrong interface

2017-10-16 Thread Marc Haber
Hi, stumbling upon this again. The system behaves now, so the issue as at least fixed in systemd 234. Greetings Marc -- - Marc Haber | "I don't trust Computers. They | Mailadresse im Header Leimen, Germany

  1   2   3   >