Bug#341807: libqt4-debug: the debug libraries are the same as the release ones

2005-12-03 Thread Christian Welzel
Package: libqt4-debug Version: 4.0.1-5 Severity: important The debug libraries of qt4 are the same as the ones in the release version because of a broken upstream build skript. (see http://www.trolltech.com/developer/tasktracker.html?method=entryid=90812) Thats why Qt4 does not print warning

Bug#398576: RM: typo3-site-installer -- RoM; abandoned upstream; broken

2006-11-14 Thread Christian Welzel
Package: ftp.debian.org Severity: normal The programm is not developed anymore by upstream and misses basic functionality. So please remove this package from archive. -- MfG, Christian Welzel GPG-Key: http://www.camlann.de/key.asc Fingerprint: 4F50 19BF 3346 36A6 CFA9 DBDC C268 6D24

Bug#394452: RM: typo3-src-3.7

2006-10-21 Thread Christian Welzel
Package: ftp.debian.org Please remove the package typo3-src-3.7 from unstable because it is superceeded by typo3-src-4.0. -- MfG, Christian Welzel GPG-Key: http://www.camlann.de/key.asc Fingerprint: 4F50 19BF 3346 36A6 CFA9 DBDC C268 6D24 70A1 AD15 -- To UNSUBSCRIBE, email

Bug#310742: while updating the pdns package, the file /etc/powerdns/pdns.conf is overwritten without question.

2005-05-25 Thread Christian Welzel
Package: pdns Version: 2.9.17-12 Severity: critical Justification: causes serious data loss during update of the packages the installer overwrites the /etc/powerdns/pdns.conf file which is the main config file of powerdns. this is not a problem when using the prebuild packages from sarge. but

Bug#438991: incorrect depends

2007-08-21 Thread Christian Welzel
standalone, graphicsmagick through the imagemagick interface and graphicsmagick standalone. So the OR of all three in the depends list is correct. The only ooption would be to drop the dependency on graphicsmagick-imagemagick-compat. -- MfG, Christian Welzel GPG-Key: http://www.camlann.de

Bug#438991: incorrect depends

2007-08-25 Thread Christian Welzel
on graphicmagic would do, as graphicsmagick-imagemagick-compat depends it anyway :) graphicsmagick-imagemagick-compat is there for easier backporting to older systems. On debian lenny it would be enough to depend on graphicsmagick or imagemagick. -- MfG, Christian Welzel GPG-Key: http

Bug#421205: Could not reproduce

2007-08-25 Thread Christian Welzel
Hi there i tryed to reproduce this bugreport on a freshly installed debian etch and there was no error shown. Could you please provide more information and/or a solution how you fixed this bug? -- MfG, Christian Welzel GPG-Key: http://www.camlann.de/key.asc Fingerprint: 4F50 19BF 3346

Bug#397458: Won't fix that bugs

2006-12-16 Thread Christian Welzel
Hi there! As the package typo3-site-installer is to be removed from the debian archive completely. i will not fix that bug reports. Please see bug #398576 for reasons. -- MfG, Christian Welzel GPG-Key: http://www.camlann.de/key.asc Fingerprint: 4F50 19BF 3346 36A6 CFA9 DBDC C268 6D24

Bug#403419: typo3-src-4.0: Completely broken: Cannot find tslib/

2006-12-17 Thread Christian Welzel
Am Sonntag, 17. Dezember 2006 01:11 schrieb clayton: Cannot find tslib/. Please set path by defining $configured_tslib_path in index.php. Check if the link /var/lib/typo3-dummy/typo3_src points to /usr/share/typo3/typo3_src-4.0 . If not, change that link accordingly. -- MfG, Christian

Bug#403419: typo3-src-4.0: Completely broken: Cannot find tslib/

2006-12-18 Thread Christian Welzel
/localconf.php. -- MfG, Christian Welzel GPG-Key: http://www.camlann.de/key.asc Fingerprint: 4F50 19BF 3346 36A6 CFA9 DBDC C268 6D24 70A1 AD15 -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Bug#415566: typo3-dummy: Import Extension fails

2007-03-21 Thread Christian Welzel
either in .htaccess/apache.conf or in localconf.php. I do not know if php ignores the setting in localconf.php if some limit is set in apache.conf. So please to try to set the limit only in one place. -- MfG, Christian Welzel GPG-Key: http://www.camlann.de/key.asc Fingerprint: 4F50 19BF

Bug#412019: TYPO3 Security Bulletin 20070221-1: Email header injection

2007-02-22 Thread Christian Welzel
Package: typo3-src There is a security flaw in the current TYPO3 packages: TYPO3 Security Bulletin 20070221-1: Email header injection Further information can be found here: http://typo3.org/teams/security/security-bulletins/typo3-20070221-1/ -- MfG, Christian Welzel GPG-Key: http

Bug#412023: RM: typo3-dummy from tpu

2007-02-22 Thread Christian Welzel
Package: ftp.debian.org Please remove the packages typo3-dummy 4.0.2-3 and 4.0.2-4 from testing proposed updates. They were uploaded to fix some issues but didn't get acceped by release team. -- MfG, Christian Welzel GPG-Key: http://www.camlann.de/key.asc Fingerprint: 4F50 19BF 3346

Bug#485814: typo3-src-4.0: Security Issue: TYPO3 Security Bulletin TYPO3-20080611-1: Multiple vulnerabilities in TYPO3 Core

2008-06-11 Thread Christian Welzel
5.2.5-3+lenny1 MySQL module for php5 ii poppler-utils [xpdf-util 0.6.4-1 PDF utilitites (based on libpopple pn typo3-dummy none (no description available) -- MfG, Christian Welzel GPG-Key: http://www.camlann.de/key.asc Fingerprint: 4F50 19BF

Bug#485815: typo3-src-4.0: the typo3 backend is not usable in Firefox3

2008-06-11 Thread Christian Welzel
, Christian Welzel GPG-Key: http://www.camlann.de/key.asc Fingerprint: 4F50 19BF 3346 36A6 CFA9 DBDC C268 6D24 70A1 AD15 -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Bug#485814: Patch

2008-06-12 Thread Christian Welzel
Here is the patch to this issue. -- MfG, Christian Welzel GPG-Key: http://www.camlann.de/key.asc Fingerprint: 4F50 19BF 3346 36A6 CFA9 DBDC C268 6D24 70A1 AD15 04-SecBull-TYPO3-20080611-1.dpatch Description: application/shellscript

Bug#485815: Patch

2008-06-12 Thread Christian Welzel
This is the patch to this issue. -- MfG, Christian Welzel GPG-Key: http://www.camlann.de/key.asc Fingerprint: 4F50 19BF 3346 36A6 CFA9 DBDC C268 6D24 70A1 AD15 05-firefox3-fix.dpatch Description: application/shellscript

Bug#421205: Confirmed with lenny

2008-03-08 Thread Christian Welzel
Am Donnerstag 07 Februar 2008 schrieb Rouven Homann: I can confirm this error message with the latest lenny package version. Did you move the typo3 installation from http://server/typo3 http://server/ ? What i mean... did you change the document root of the webserver? -- MfG, Christian

Bug#591969: status update?

2010-12-09 Thread Christian Welzel
typo3-svn. player.swf came from pixelout player 1.2 All actionscript 3 code is not buildable within debian because debian has no as3 compiler. Perhaps flex-sdk will be available in some time (see #602499) but until then no as3-swf can be build from source. -- MfG, Christian Welzel GPG-Key

Bug#611387: typo3-dummy: Missing dependency on apache2.2-common

2011-01-29 Thread Christian Welzel
) | libapache2-mod-php5filter (= 5.3.3-7) | php5-cgi (= 5.3.3-7) So at least one of those packages must have been installed. -- MfG, Christian Welzel GPG-Key: http://www.camlann.de/de/pgpkey.html Fingerprint: 4F50 19BF 3346 36A6 CFA9 DBDC C268 6D24 70A1 AD15 -- To UNSUBSCRIBE, email to debian

Bug#611387: typo3-dummy: Missing dependency on apache2.2-common

2011-01-29 Thread Christian Welzel
) is used. Depending on apache2.2-common would force other users to install half an apache installation, what i do not want. Perhaps i will provide some typo3-dummy-apache2 and typo3-dummy-nginx etc packages in the future. I put it into Suggestens: until then. -- MfG, Christian Welzel GPG-Key

Bug#612145: RM: typo3-dummy -- ROM; merged into typo3-src

2011-02-06 Thread Christian Welzel
Package: ftp.debian.org Hello ftp-masters, please remove the source package typo3-dummy from unstable. It has been merged with typo3-src in unstable using new source format 3.0-quilt. The binary package typo3-dummy is now build by typo3-src. -- MfG, Christian Welzel GPG-Key: http

Bug#614135: typo3-dummy: Does not provide a user and password

2011-02-23 Thread Christian Welzel
this in 4.3. And i'm not sure, how to fix this in stable release. In this state, the package is completely unusable. No, its not. You can always generate admin user accounts using the install tool of typo3. But you found that already :) -- MfG, Christian Welzel GPG-Key: http://www.camlann.de

Bug#614133: typo3-database: Text during configuration badly worded

2011-02-23 Thread Christian Welzel
the database is handled by the package dbcommon-config. I do not have access to the wording which is shown to the user. Or at least i have no idea how to change it. Perhaps some lines of documentation in README.debian would help on this one? -- MfG, Christian Welzel GPG-Key: http://www.camlann.de

Bug#614133: typo3-database: Text during configuration badly worded

2011-03-02 Thread Christian Welzel
Am 23.02.2011 22:37, schrieb Daniel Skorka: If the text can't be changed, than yes, that would help to clarify things. Did you have a look into typo3-dummy/README.Debian? There are some notes about installing the database packages. -- MfG, Christian Welzel GPG-Key: http

Bug#614133: typo3-database: Text during configuration badly worded

2011-03-02 Thread Christian Welzel
Am 23.02.2011 22:37, schrieb Daniel Skorka: If the text can't be changed, than yes, that would help to clarify things. What i meant to write: Did you have a look into typo3-database/README.Debian? There are some notes about installing the database packages. -- MfG, Christian Welzel GPG

Bug#606790: typo3-dummy: package fails to upgrade properly from lenny

2010-12-15 Thread Christian Welzel
know the cause) and that leeds to the failure that dbconfig-common cannot set up the database. Please make sure, that mysql-server is running when typo3-database is configured and try again. -- MfG, Christian Welzel GPG-Key: http://www.camlann.de/de/pgpkey.html Fingerprint: 4F50 19BF

Bug#606740: typo3-src-4.5: Menu in GLUECK template rendered incorrectly

2010-12-15 Thread Christian Welzel
: This seems to be a bug in the upstream distribution. Could you please file a bug in the TYPO3 bugtracker: http://bugs.typo3.org -- MfG, Christian Welzel GPG-Key: http://www.camlann.de/de/pgpkey.html Fingerprint: 4F50 19BF 3346 36A6 CFA9 DBDC C268 6D24 70A1 AD15 -- To UNSUBSCRIBE, email

Bug#607286: TYPO3 Security Bulletin TYPO3-SA-2010-022: Multiple vulnerabilities in TYPO3 Core

2010-12-16 Thread Christian Welzel
escapeStrForLike() is failing to properly quote user input, making it is possible to inject wildcards into a LIKE query. This could potentially disclose a set of records that are meant to be kept in secret. -- MfG, Christian Welzel GPG-Key: http://www.camlann.de/de/pgpkey.html Fingerprint: 4F50

Bug#505324: typo3-src: Cross-Site Scripting (XSS) in BE module fileadmin

2008-11-11 Thread Christian Welzel
Package: typo3-src Version: 4.2.2 Severity: grave Tags: security Justification: user security hole the version 4.2.2 of typo3 is vulnerable to a xss attack in the backend modul fileadmin. -- System Information: Debian Release: lenny/sid APT prefers testing APT policy: (650, 'testing'), (600,

Bug#505325: typo3-src-4.2: Cross-Site Scripting (XSS) in sysext felogin

2008-11-11 Thread Christian Welzel
Package: typo3-src-4.2 Version: 4.2.0 4.2.1 4.2.2 Severity: grave Tags: security Justification: user security hole typo3 backend is vulnerable to a xss attack in the system extension felogin which handles frontend user logins to restricted areas of a webpage. -- System Information: Debian

Bug#505326: typo3-src: User account passwords cannot be changed in backend

2008-11-11 Thread Christian Welzel
Package: typo3-src Version: 4.2.1 4.2.2 Severity: grave Justification: renders package unusable This bug replaces all content entered into a password field in the backend by the string unknown. This leads to the problem, that passwords cannot be changed anymore by users or admins. -- System

Bug#505325: (no subject)

2008-11-13 Thread Christian Welzel
This bug is now officially announced as TYPO3 Security Bulletin TYPO3-20081113-2: Cross-Site Scripting vulnerability in TYPO3 Core See this url for more information: http://typo3.org/teams/security/security-bulletins/typo3-20081113-2/ -- MfG, Christian Welzel GPG-Key: http

Bug#505324: (no subject)

2008-11-13 Thread Christian Welzel
This bug is now officially announced as TYPO3 Security Bulletin TYPO3-20081113-1: Cross-Site Scripting vulnerability in TYPO3 Core See this url for more information: http://typo3.org/teams/security/security-bulletins/typo3-20081113-1/ -- MfG, Christian Welzel GPG-Key: http

Bug#460678: Same problem here

2009-01-28 Thread Christian Welzel
to 0/0 Jan 28 13:20:34 projektserver cnid_dbd[30338]: Startup, DB dir /daten/print_share/.AppleDB Jan 28 13:20:35 projektserver cnid_dbd[30338]: error writing message : Broken pipe Version of netatalk: 2.0.4~beta2-4 -- MfG, Christian Welzel GPG-Key: http://www.camlann.de/key.asc

Bug#460678: Same problem here

2009-01-28 Thread Christian Welzel
]: ipc_read: command: 2, pid: 30326, len: 24 Jan 28 13:20:14 projektserver afpd[30316]: Setting clientid (len 16) for 30326, boottime 754D8049 Jan 28 13:20:14 projektserver afpd[30316]: ipc_get_session: len: 24, idlen 16, time 754d8049 [...] -- MfG, Christian Welzel GPG-Key: http

Bug#514713: Information disclosure and XSS vulnerabilities in TYPO3

2009-02-10 Thread Christian Welzel
to exploit this vulnerability. The vulnerability allows to read any file, the web server user account has access to. Problem Description 2: Failing to sanitize user input, three fields in the backend is open to Cross-Site Scripting (XSS). -- MfG, Christian Welzel GPG-Key: http

Bug#514713: Information disclosure and XSS vulnerabilities in TYPO3

2009-02-10 Thread Christian Welzel
-src_4.0.2+debian-8.dsc -- MfG, Christian Welzel GPG-Key: http://www.camlann.de/key.asc Fingerprint: 4F50 19BF 3346 36A6 CFA9 DBDC C268 6D24 70A1 AD15 -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas

Bug#529581: typo3-src-4.2: Should depend on libnusoap-php instead of shipping it

2010-05-04 Thread Christian Welzel
there ? I'm here, but when i looked into this some time ago, i had the impression that the files are not identical. I had no time to investigate this futher and wrote it on the todo-if-nothing- more-important-is-available-list. -- MfG, Christian Welzel GPG-Key: http://www.camlann.de/de/pgpkey.html

Bug#574655: typo3: Backend page is not displayed after initial installation

2010-03-22 Thread Christian Welzel
versions and therefor on 4.3.0. Please enable debugging output in your php-installation and look for errors in the php error log. -- MfG, Christian Welzel GPG-Key: http://www.camlann.de/de/pgpkey.html Fingerprint: 4F50 19BF 3346 36A6 CFA9 DBDC C268 6D24 70A1 AD15 -- To UNSUBSCRIBE

Bug#574655: typo3: Backend page is not displayed after initial installation

2010-03-24 Thread Christian Welzel
for the session management are broken. Is the file content right? Is /usr/share/typo3/typo3_src-4.3 the right place to place the .htaccess file? the right location would be /var/lib/typo3-dummy -- MfG, Christian Welzel GPG-Key: http://www.camlann.de/de/pgpkey.html Fingerprint: 4F50 19BF 3346

Bug#574655: typo3: Backend page is not displayed after initial installation

2010-03-29 Thread Christian Welzel
reinstalling the stuff! -- MfG, Christian Welzel GPG-Key: http://www.camlann.de/de/pgpkey.html Fingerprint: 4F50 19BF 3346 36A6 CFA9 DBDC C268 6D24 70A1 AD15 -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas

Bug#574655: typo3: Backend page is not displayed after initial installation

2010-03-29 Thread Christian Welzel
installation seems to be broken. Try googling for Failed to initialize storage module: files. There are some hits, but there are several solutions. You have to try out which one helps on your system. Otherwise try reinstalling the whole PHP/Typo3 bundle. -- MfG, Christian Welzel GPG-Key: http

Bug#574655: typo3: Backend page is not displayed after initial installation

2010-04-22 Thread Christian Welzel
not configured and redirects to the install tool. i hadn't time yet to investigate this. -- MfG, Christian Welzel GPG-Key: http://www.camlann.de/de/pgpkey.html Fingerprint: 4F50 19BF 3346 36A6 CFA9 DBDC C268 6D24 70A1 AD15 -- To UNSUBSCRIBE, email to debian-bugs-dist-requ

Bug#605249: unblock: typo3-src/4.3.8+dfsg1-1

2010-11-28 Thread Christian Welzel
Am 28.11.2010 16:36, schrieb Holger Levsen: so this seems like it would break each of the callers? Stupid me! The return $script; should not have been commented out. I uploaded a fixed version to mentors.d.n Christian? -- MfG, Christian Welzel GPG-Key: http://www.camlann.de/de

Bug#595099: typo3-src: typo3 backend stops working due to backported security patches

2010-09-05 Thread Christian Welzel
Am 01.09.2010 01:56, schrieb Fabian Ruff: the patch 06-SecBull-TYPO3-SA-2010-012.dpatch introduces the usage of a non existing function: t3lib_div::sanitizeLocalUrl A fixed pakage awaits upload on mentors. Until uploaded you can find it here: http://typo3.camlann.de/ -- MfG, Christian

Bug#591969: typo3-src: does not build .swf files from source

2010-09-02 Thread Christian Welzel
in the world has them). -- MfG, Christian Welzel GPG-Key: http://www.camlann.de/de/pgpkey.html Fingerprint: 4F50 19BF 3346 36A6 CFA9 DBDC C268 6D24 70A1 AD15 -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas

Bug#602250: typo3-src-4.3: jsmin.php is non-DFSG

2010-11-04 Thread Christian Welzel
Thank you in advance. Sure this doesn't suffice to be a license change, does it? I asked him to change the license more offically on his website and now i'm waiting for some reply. -- MfG, Christian Welzel GPG-Key: http://www.camlann.de/de/pgpkey.html Fingerprint: 4F50 19BF 3346

Bug#599334: TYPO3 Security Bulletin TYPO3-SA-2010-020: Multiple vulnerabilities in TYPO3 Core

2010-10-06 Thread Christian Welzel
/A:N/E:F/RL:OF/RC:C Problem Description: The normalisation feature of the RemoveXSS function was incomplete, allowing an attacker to inject arbitrary JavaScript code. -- MfG, Christian Welzel GPG-Key: http://www.camlann.de/de/pgpkey.html Fingerprint: 4F50 19BF 3346 36A6 CFA9 DBDC C268

Bug#588518: Where?

2010-10-20 Thread Christian Welzel
Hi there, i could not find the mentioned ablities. where is this spelling error? -- MfG, Christian Welzel GPG-Key: http://www.camlann.de/de/pgpkey.html Fingerprint: 4F50 19BF 3346 36A6 CFA9 DBDC C268 6D24 70A1 AD15 -- To UNSUBSCRIBE, email to debian-bugs-dist-requ

Bug#512626: typo3-dummy: typo3 cannot send emails

2009-01-22 Thread Christian Welzel
Package: typo3-dummy Version: 4.2.3-1 Severity: grave Justification: renders package unusable The config set by apache.conf includes the wrong value for the sendmail_path php_value. Thereby sendmail does not accepts emails send by typo3 core. -- System Information: Debian Release: 5.0 APT

Bug#512624: typo3-dummy: Safe-Mode breaks access to javascript libraries

2009-01-22 Thread Christian Welzel
Package: typo3-dummy Version: 4.2.3 Severity: grave Justification: renders package unusable In PHP safe mode, the backend of typo3 cannot access the javascript libaries. This is because these libraries are symlinked to /usr/share/... but this directories are missing in the open_basedir setting.

Bug#586285: typo3-dummy: General update after the debconf review process

2010-07-20 Thread Christian Welzel
do. -- MfG, Christian Welzel GPG-Key: http://www.camlann.de/de/pgpkey.html Fingerprint: 4F50 19BF 3346 36A6 CFA9 DBDC C268 6D24 70A1 AD15 -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas

Bug#590719: TYPO3 Security Bulletin TYPO3-SA-2010-012: Multiple vulnerabilities in TYPO3 Core

2010-07-28 Thread Christian Welzel
installation in the mail header. -- MfG, Christian Welzel GPG-Key: http://www.camlann.de/de/pgpkey.html Fingerprint: 4F50 19BF 3346 36A6 CFA9 DBDC C268 6D24 70A1 AD15 -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact

Bug#552020: TYPO3 Security Bulletin TYPO3-SA-2009-016: Multiple vulnerabilities in TYPO3 Core

2009-10-22 Thread Christian Welzel
.org/teams/security/security-bulletins/typo3-sa-2009-016/ -- MfG, Christian Welzel GPG-Key: http://www.camlann.de/key.asc Fingerprint: 4F50 19BF 3346 36A6 CFA9 DBDC C268 6D24 70A1 AD15 -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe

Bug#619642: Current version?

2011-03-25 Thread Christian Welzel
Package: libjs-extjs Are there any plans to package ExtJS in its current version (3.2.x)? I would need that for the typo3-src package. -- MfG, Christian Welzel GPG-Key: http://www.camlann.de/de/pgpkey.html Fingerprint: 4F50 19BF 3346 36A6 CFA9 DBDC C268 6D24 70A1 AD15

Bug#630412: typo3-src-4.3: scheduler cronjob creates unnecessary alerts in syslog

2011-06-23 Thread Christian Welzel
this is related to a job provided by an extension. -- MfG, Christian Welzel GPG-Key: http://www.camlann.de/de/pgpkey.html Fingerprint: 4F50 19BF 3346 36A6 CFA9 DBDC C268 6D24 70A1 AD15 -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble

Bug#627199: typo3-dummy: cronjob throws error messages

2011-06-23 Thread Christian Welzel
. -- MfG, Christian Welzel GPG-Key: http://www.camlann.de/de/pgpkey.html Fingerprint: 4F50 19BF 3346 36A6 CFA9 DBDC C268 6D24 70A1 AD15 -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#641682: TYPO3 Security Bulletin TYPO3-CORE-SA-2011-002: Potential SQL injection vulnerability in TYPO3 Core

2011-09-15 Thread Christian Welzel
. -- MfG, Christian Welzel GPG-Key: http://www.camlann.de/de/pgpkey.html Fingerprint: 4F50 19BF 3346 36A6 CFA9 DBDC C268 6D24 70A1 AD15 -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#641683: TYPO3 Security Bulletin TYPO3-CORE-SA-2011-003: Improper error handling could lead to cache flooding in TYPO3 Core

2011-09-15 Thread Christian Welzel
an attacker to easily flood the caching tables of TYPO3. -- MfG, Christian Welzel GPG-Key: http://www.camlann.de/de/pgpkey.html Fingerprint: 4F50 19BF 3346 36A6 CFA9 DBDC C268 6D24 70A1 AD15 -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject

Bug#619642: Current version?

2011-08-05 Thread Christian Welzel
, Christian, you are willing to help maintaining extjs and/or extplorer, I can help here and there, but i'm busy with other projects besides debian, so i cannot do so much. -- MfG, Christian Welzel GPG-Key: http://www.camlann.de/de/pgpkey.html Fingerprint: 4F50 19BF 3346 36A6 CFA9 DBDC C268

Bug#635937: TYPO3 Security Bulletin TYPO3-CORE-SA-2011-001: Multiple vulnerabilities in TYPO3 Core

2011-07-29 Thread Christian Welzel
is not applied on ExtDirect calls. This allows arbitrary BE users to consume any available ExtDirect endpoint service. -- MfG, Christian Welzel GPG-Key: http://www.camlann.de/de/pgpkey.html Fingerprint: 4F50 19BF 3346 36A6 CFA9 DBDC C268 6D24 70A1 AD15 -- To UNSUBSCRIBE, email to debian

Bug#591969: status

2012-06-02 Thread Christian Welzel
This is AS3, but as3compile cannot compile it because of missing features in as3compile. Source code is included in source package. -- MfG, Christian Welzel GPG-Key: pub 4096R/5117E119 2011-09-19 Fingerprint: 3688 337C 0D3E 3725 94EC E401 8D52 CDE9 5117 E119 -- To UNSUBSCRIBE, email

Bug#591969: status

2012-06-03 Thread Christian Welzel
too. -- MfG, Christian Welzel GPG-Key: pub 4096R/5117E119 2011-09-19 Fingerprint: 3688 337C 0D3E 3725 94EC E401 8D52 CDE9 5117 E119 -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#609110: packaged

2012-05-17 Thread Christian Welzel
and not flash-swfupload. The package uses as3compile from swftools for compiling the swf from source, so some more testing of the functionality would be welcome. -- MfG, Christian Welzel GPG-Key: pub 4096R/5117E119 2011-09-19 Fingerprint: 3688 337C 0D3E 3725 94EC E401 8D52 CDE9 5117 E119

Bug#673438: RFS: libjs-swfupload/2.2.0.1-1 [ITP]

2012-05-18 Thread Christian Welzel
visit the following URL: http://mentors.debian.net/package/libjs-swfupload Alternatively, one can download the package with dget using this command: dget -x http://mentors.debian.net/debian/pool/main/libj/libjs-swfupload/libjs-swfupload_2.2.0.1-1.dsc -- MfG, Christian Welzel GPG-Key

Bug#673438: RFS: libjs-swfupload/2.2.0.1-1 [ITP]

2012-05-22 Thread Christian Welzel
a problem for me. I made a new package which removes the swfupload.swf and moves its build to a tmp-dir, now rebuilding works flawlessly. http://mentors.debian.net/debian/pool/main/libj/libjs-swfupload/libjs-swfupload_2.2.0.1+ds1-1.dsc -- MfG, Christian Welzel GPG-Key: pub 4096R/5117E119

Bug#681323: libjs-swfupload: XSS via ExternalInterface.call

2012-07-12 Thread Christian Welzel
Package: libjs-swfupload Version: 2.2.0.1+ds1-1 Severity: grave Tags: security Justification: user security hole Dear Maintainer, libjs-swfupload contains a XSS security vulnarability that allows attackers to inject javascript code into the context of the current webpage. As a Flash applet can be

Bug#691516: RFP: python-cef -- Module that emits CEF logs

2012-10-26 Thread Christian Welzel
Package: wnpp Severity: wishlist * Package name: python-cef Version : 0.5 Upstream Author : Mozilla Services team * URL : http://pypi.python.org/pypi/cef * License : MPL Programming Lang: Python Description : Module that emits CEF logs Most Mozilla

Bug#691518: RFP: python-wsgiproxy -- HTTP proxying tools for WSGI apps

2012-10-26 Thread Christian Welzel
Package: wnpp Severity: wishlist * Package name: python-wsgiproxy Version : 0.2.2 Upstream Author : Ian Bicking * URL : http://pypi.python.org/pypi/WSGIProxy/0.2.2 * License : MIT Programming Lang: Python Description : HTTP proxying tools for WSGI apps

Bug#691524: RFP: python-metlog -- Metrics Logging

2012-10-26 Thread Christian Welzel
Package: wnpp Severity: wishlist * Package name: python-metlog Version : 0.9.8 Upstream Author : Rob Miller * URL : http://pypi.python.org/pypi/metlog-py/ * License : MPL Programming Lang: Python Description : Metrics Logging metlog-py is a Python

Bug#691014: marked as done (RFS: swftools/0.9.2+ds1-3 [RC])

2012-10-29 Thread Christian Welzel
Am 29.10.2012 21:47, schrieb David Prévot: The package was uploaded. Looks like it wasn't. It was: http://packages.qa.debian.org/s/swftools.html But its currently waiting for its 10 days quarantine to be over. -- MfG, Christian Welzel GPG-Key: pub 4096R/5117E119 2011-09-19

Bug#691918: RFP: libas-osmf -- The Open Source Media Framework

2012-10-31 Thread Christian Welzel
Package: wnpp Severity: wishlist * Package name: libas-osmf Version : 2.0 Upstream Author : Adobe * URL : http://sourceforge.net/projects/osmf.adobe/ * License : MPL 1.1 Programming Lang: ActionScript Description : The Open Source Media Framework Open

Bug#691919: RFP: libas-tlf -- Text Layout Framework

2012-10-31 Thread Christian Welzel
Package: wnpp Severity: wishlist * Package name: libas-tlf Version : 3.0 Upstream Author : Adobe * URL : http://sourceforge.net/projects/tlf.adobe/ * License : MPL 1.1 Programming Lang: ActionScript Description : Text Layout Framework The Text Layout

Bug#692775: TYPO3-CORE-SA-2012-005: Several Vulnerabilities in TYPO3 Core

2012-11-08 Thread Christian Welzel
v2.0: AV:N/AC:M/Au:S/C:N/I:P/A:N/E:P/RL:O/RC:C Problem Description: Failing to properly encode user input, the function menu API is susceptible to Cross-Site Scripting. A valid backend login is required to exploit this vulnerability. -- MfG, Christian Welzel GPG-Key: http://www.camlann.de

Bug#690146: unblock: typo3-src/4.5.19+dfsg1-2

2012-10-10 Thread Christian Welzel
@@ +typo3-src (4.5.19+dfsg1-2) unstable; urgency=low + + * Added rsaauth and saltedpasswords to the list of installed extensions and +change owner and permissions of generated localconf.php in postinst. +(Closes: 689329) + + -- Christian Welzel gaw...@camlann.de Wed, 10 Oct 2012 15:09:57 +0200

Bug#690236: libjs-swfupload ftbfs in testing/unstable on i386

2012-10-18 Thread Christian Welzel
tags 690236 pending tags 690237 pending Segmentation fault (core dumped) make: *** [build] Error 139 A fixed version of swftools was uploaded to mentors.d.n. -- MfG, Christian Welzel GPG-Key: pub 4096R/5117E119 2011-09-19 Fingerprint: 3688 337C 0D3E 3725 94EC E401 8D52 CDE9 5117

Bug#691014: RFS: swftools/0.9.2+ds1-3 [RC]

2012-10-20 Thread Christian Welzel
the package libjs-swfupload from build on i386. -- MfG, Christian Welzel GPG-Key: 4096R/5117E119 2011-09-19 Fingerprint: 3688 337C 0D3E 3725 94EC E401 8D52 CDE9 5117 E119 -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact

Bug#691194: unblock: swftools/0.9.2+ds1-3

2012-10-22 Thread Christian Welzel
:34.0 +0200 +++ swftools-0.9.2+ds1/debian/changelog 2012-10-22 11:28:11.0 +0200 @@ -1,3 +1,9 @@ +swftools (0.9.2+ds1-3) unstable; urgency=low + + * Added fix for segfault on i386. (Closes: 690237) + + -- Christian Welzel gaw...@camlann.de Mon, 22 Oct 2012 12:42:54 +0100 + swftools

Bug#602499: Progress?

2012-10-23 Thread Christian Welzel
Hi there, some time ago Apache Flex® 4.8.0 was released. Is there any progress in packaging this one for main? -- MfG, Christian Welzel GPG-Key: pub 4096R/5117E119 2011-09-19 Fingerprint: 3688 337C 0D3E 3725 94EC E401 8D52 CDE9 5117 E119 -- To UNSUBSCRIBE, email to debian-bugs

Bug#602499: Progress?

2012-10-23 Thread Christian Welzel
Am 23.10.2012 16:51, schrieb Joey Parrish: It should be much easier to build a proper package from sources for inclusion in main now that it's an Apache project, but someone else will have to take on packaging it. Can your work be found somewhere? -- MfG, Christian Welzel GPG-Key

Bug#685492: unblock: typo3-src/4.5.19+dfsg1-1

2012-08-21 Thread Christian Welzel
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock Please unblock package typo3-src Hello there, some days ago there was an announcment by TYPO3 upstream, that there are some security issues in the current version. I filed a bug report

Bug#685011: TYPO3-CORE-SA-2012-004: Several Vulnerabilities in TYPO3 Core

2012-08-15 Thread Christian Welzel
Suggested CVSS v2.0: AV:N/AC:H/Au:S/C:P/I:P/A:N/E:F/RL:O/RC:C Problem Description: Failing to properly sanitize user input, the Install Tool is susceptible to Cross-Site Scripting. -- MfG, Christian Welzel GPG-Key: http://www.camlann.de/de/pgpkey.html Fingerprint: 4F50 19BF 3346 36A6 CFA9

Bug#591969: status

2012-06-04 Thread Christian Welzel
Am 04.06.2012 12:55, schrieb Holger Levsen: On Sonntag, 3. Juni 2012, Christian Welzel wrote: These files directly correlate to some of TYPO3 content elements. Removing the swf would mean to patch TYPO3 core too. so you would like to get this bugged tagged wheezy-ignore again? If thats

Bug#657058: flowplayer

2012-01-23 Thread Christian Welzel
Flowplayer is an Open Source (GPL 3) video player for the web. Use it to embed video streams into your web pages. Built for site owners, developers, hobbyists, businesses, and serious programmers. -- MfG, Christian Welzel GPG-Key: http://www.camlann.de/de/pgpkey.html Fingerprint: 4F50

Bug#657065: libjs-videojs

2012-01-23 Thread Christian Welzel
the fallback to Flash or other playback technologies when HTML5 video isn't supported, and also provides a consistent JavaScript API for interacting with the video. -- MfG, Christian Welzel GPG-Key: http://www.camlann.de/de/pgpkey.html Fingerprint: 4F50 19BF 3346 36A6 CFA9 DBDC C268 6D24

Bug#467288: same problem here

2012-03-11 Thread Christian Welzel
af10f93e31e2a6a809fdf24e34f6c6bf3a71606f | (cd '/tmp/pristine-tar.aLUBc5aaTJ' tar x) -- MfG, Christian Welzel GPG-Key: pub 4096R/5117E119 2011-09-19 Fingerprint: 3688 337C 0D3E 3725 94EC E401 8D52 CDE9 5117 E119 -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject

Bug#467288: same problem here

2012-03-15 Thread Christian Welzel
? -- MfG, Christian Welzel GPG-Key: pub 4096R/5117E119 2011-09-19 Fingerprint: 3688 337C 0D3E 3725 94EC E401 8D52 CDE9 5117 E119 -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#583982: packaging work

2012-02-11 Thread Christian Welzel
on this issue. current (broken) packages can be found here: http://typo3.camlann.de/swftools/ all programs exept pdf2swf should work normal. -- MfG, Christian Welzel GPG-Key: pub 4096R/5117E119 2011-09-19 Fingerprint: 3688 337C 0D3E 3725 94EC E401 8D52 CDE9 5117 E119 -- To UNSUBSCRIBE

Bug#602253: Duplicate

2012-02-01 Thread Christian Welzel
Hi there, this is a duplicate of 609110. -- MfG, Christian Welzel -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#650837: RFP: svgweb

2011-12-03 Thread Christian Welzel
then that is used, though you can override this and have the SVG Web toolkit handle things instead. No downloads or plugins are necessary other than Flash 10 which is used for the actual rendering, so it's very easy to use and incorporate into an existing web site. -- Viele Grüße, Christian Welzel schech.net

Bug#651960: php-http-request2

2011-12-13 Thread Christian Welzel
requests with data and file uploads, basic and digest authentication, cookies, managing cookies across requests, proxies, gzip and deflate encodings, redirects, monitoring the request progress with Observers. -- MfG, Christian Welzel GPG-Key: http://www.camlann.de/de/pgpkey.html Fingerprint

Bug#651961: php-http-request2

2011-12-13 Thread Christian Welzel
into their constituent parts (scheme, host, path etc.), URL generation, and resolving of relative URLs. -- MfG, Christian Welzel GPG-Key: http://www.camlann.de/de/pgpkey.html Fingerprint: 4F50 19BF 3346 36A6 CFA9 DBDC C268 6D24 70A1 AD15 -- To UNSUBSCRIBE, email to debian-bugs-dist

Bug#651963: libjs-extjs4

2011-12-13 Thread Christian Welzel
Ext JS 4 is the next major advancement in our JavaScript framework. Featuring expanded functionality, plugin-free charting, and a new MVC architecture it's the best Ext JS yet. Create incredible web apps for every browser. -- MfG, Christian Welzel GPG-Key: http://www.camlann.de/de

Bug#651128: Wrong symbolic link

2011-12-13 Thread Christian Welzel
Am 07.12.2011 08:50, schrieb Andreas Rittershofer: The problem is caused due to a wrong symbolic link to prototype.js. After correcting this symbolic link, TYPO3 runs fine. What exactly caused that wrong symlink? My tests worked well and all symlinks are correct. -- MfG, Christian Welzel

Bug#652365: TYPO3 Security Bulletin TYPO3-CORE-SA-2011-004: Remote Code Execution in TYPO3 Core

2011-12-16 Thread Christian Welzel
will allow an attacker to load PHP code from an external source and to execute it on the TYPO3 installation. -- MfG, Christian Welzel GPG-Key: http://www.camlann.de/de/pgpkey.html Fingerprint: 4F50 19BF 3346 36A6 CFA9 DBDC C268 6D24 70A1 AD15 -- To UNSUBSCRIBE, email to debian-bugs-dist

Bug#668553: RFS: swftools/0.9.2+ds1-1 [ITP]

2012-04-12 Thread Christian Welzel
:0.3.0-11.1 as all versions in debian are later than this one. * Updated watch file. -- MfG, Christian Welzel GPG-Key: pub 4096R/5117E119 2011-09-19 Fingerprint: 3688 337C 0D3E 3725 94EC E401 8D52 CDE9 5117 E119 -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org

Bug#720194: TYPO3-CORE-SA-2013-002: Cross-Site Scripting and Remote Code Execution Vulnerability in TYPO3 Core

2013-08-19 Thread Christian Welzel
/I:C/A:C/E:F/RL:O/RC:C CVE: CVE-2013-4250 -- MfG, Christian Welzel GPG-Key: pub 4096R/5117E119 2011-09-19 Fingerprint: 3688 337C 0D3E 3725 94EC E401 8D52 CDE9 5117 E119 -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact

Bug#665981: debian-maintainers: Please add Christian Welzel as Debian Maintainer

2012-03-27 Thread Christian Welzel
Package: debian-maintainers Severity: normal Dear Maintainer, Please add Christian Welzel gaw...@camlann.de to the Debian Maintainer keyring. Find the corresponding jetring changeset attached. Thanks a lot, -- MfG, Christian Welzel GPG-Key: pub 4096R/5117E119 2011-09-19 Fingerprint

Bug#666074: TYPO3 Security Bulletin TYPO3-CORE-SA-2012-001: Several Vulnerabilities in TYPO3 Core

2012-03-28 Thread Christian Welzel
crafted HTML injections, thus is susceptible to Cross-Site Scripting. -- MfG, Christian Welzel GPG-Key: http://www.camlann.de/de/pgpkey.html Fingerprint: 4F50 19BF 3346 36A6 CFA9 DBDC C268 6D24 70A1 AD15 -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org

  1   2   >