Bug#993705: freeorion: 'PythonAI failed to initialize' when starting singleplayer game with AI

2021-09-05 Thread Markus Koschany
Control: tags -1 moreinfo Hello, On Sun, 5 Sep 2021 03:36:44 +0200 (CEST) joyfulma...@tutanota.com wrote: > Package: freeorion > Version: 0.4.10.2-1 > Severity: normal > > Dear Maintainer, > >    * What led up to the situation? >    In the unstable version, starting a game with AI fails to

Bug#993224: buster-pu: package ublock-origin/1.37.0+dfsg-1~deb10u1

2021-09-02 Thread Markus Koschany
Hi, Am Donnerstag, dem 02.09.2021 um 22:29 +0100 schrieb Adam D. Barratt: > On Sat, 2021-08-28 at 22:52 +0200, Markus Koschany wrote: > > Fixing CVE-2021-36773 in Buster and updating various filter lists. > > > > The changelog appears to include a conflict marker: >

Bug#993225: bullseye-pu: package ublock-origin/1.37.0+dfsg-1~deb11u1

2021-08-28 Thread Markus Koschany
Package: release.debian.org Severity: normal Tags: bullseye User: release.debian@packages.debian.org Usertags: pu X-Debbugs-Cc: a...@debian.org [ Reason ] Fixing CVE-2021-36773 in Bullseye and updating various filter lists. [ Impact ] CVE-2021-36773 would be unfixed. [ Tests ] I have

Bug#993224: buster-pu: package ublock-origin/1.37.0+dfsg-1~deb10u1

2021-08-28 Thread Markus Koschany
Package: release.debian.org Severity: normal Tags: buster User: release.debian@packages.debian.org Usertags: pu X-Debbugs-Cc: a...@debian.org [ Reason ] Fixing CVE-2021-36773 in Buster and updating various filter lists. [ Impact ] CVE-2021-36773 would be unfixed. [ Tests ] I have tested

Bug#992599: buster-pu: package commons-io/2.6-2

2021-08-20 Thread Markus Koschany
ut not further above (thus "limited" path traversal), if the calling code +would use the result to construct a path value. + + -- Markus Koschany Fri, 20 Aug 2021 22:25:28 +0200 + commons-io (2.6-2) unstable; urgency=medium * Team upload. diff -Nru commons-io-2.6/debian/patches

Bug#991885: unblock: xmlgraphics-commons/2.4-1

2021-08-04 Thread Markus Koschany
by the XMPParser. By using a +specially-crafted argument, an attacker could exploit this vulnerability to +cause the underlying server to make arbitrary GET requests. +(Closes: #984949) + + -- Markus Koschany Mon, 02 Aug 2021 07:48:42 +0200 + xmlgraphics-commons (2.4-1) unstable

Bug#991881: buster-pu: package xmlgraphics-commons/2.3-1

2021-08-04 Thread Markus Koschany
exploit this vulnerability to +cause the underlying server to make arbitrary GET requests. +(Closes: #984949) + + -- Markus Koschany Wed, 04 Aug 2021 13:31:34 +0200 + xmlgraphics-commons (2.3-1) unstable; urgency=medium * Team upload. diff -Nru xmlgraphics-commons-2.3/debian/patches/CVE

Bug#991614: apache-directory-server: CVE-2021-33900

2021-08-01 Thread Markus Koschany
On Wed, 28 Jul 2021 17:44:49 +0200 Salvatore Bonaccorso wrote: > Hi, > > The following vulnerability was published for apache-directory-server. > > CVE-2021-33900[0]: Hi Salvatore, are you sure CVE-2021-33900 corresponds to apache-directory-server as well? To me it seems the vulnerability

Bug#991279: unblock: jetty9/9.4.39-3

2021-07-19 Thread Markus Koschany
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock X-Debbugs-Cc: a...@debian.org Please unblock package jetty9 [ Reason ] jetty9 in Bullseye is vulnerable to CVE-2021-34429. https://bugs.debian.org/991188 [ Tests ] I have backported all

Bug#991188: jetty9: CVE-2021-34429

2021-07-16 Thread Markus Koschany
Control: owner -1 ! Hi, Am Freitag, dem 16.07.2021 um 21:16 +0200 schrieb Salvatore Bonaccorso: > Source: jetty9 > Version: 9.4.39-2 > Severity: grave > Tags: security upstream > X-Debbugs-Cc: car...@debian.org, Debian Security Team > > > Hi, > > The following vulnerability was published for

Bug#990368: Regarding SuperTuxKart in Debian main

2021-07-16 Thread Markus Koschany
Hello, we have a dedicated bug report for this problem, please keep 990...@bugs.debian.org in CC. Am Freitag, dem 16.07.2021 um 14:34 +1000 schrieb GumballForAPenny: > Hi all, > > (I am a user and contributor of SuperTuxKart, not any staff member of > the project.) > > It has recently come

Bug#991054: unblock: xarchiver/1:0.5.4.17-2

2021-07-13 Thread Markus Koschany
to David Harte for the report and Ingo Brückl for the patch. + + -- Markus Koschany Tue, 13 Jul 2021 14:02:25 +0200 + xarchiver (1:0.5.4.17-1) unstable; urgency=medium * New upstream version 0.5.4.17. diff -Nru xarchiver-0.5.4.17/debian/patches/debian-bug-990906.patch xarchiver-0.5.4.17/debian

Bug#990906: Xarchiver Debian bug 990906

2021-07-13 Thread Markus Koschany
Control: tags -1 pending Am Dienstag, dem 13.07.2021 um 13:41 +0200 schrieb Ingo Brückl: > Hi, > > I believe that the bug you reported is fixed in the current master of > xarchiver: > > https://github.com/ib/xarchiver/commit/949854e9a74489d8d977aac7a8428ecadd526ff1 Confirmed. Thanks for the

Bug#990906: Xarchiver Debian bug 990906

2021-07-11 Thread Markus Koschany
Hi Ingo, I have received a bug report from David Harte (Debian bug #990906) and I can reproduce the behavior. https://bugs.debian.org/990906 It makes no difference if the linked directory is on a ntfs or ext4 file system though. If you follow all steps and open the archive with xarchiver and

Bug#990711: unblock: debian-games/4

2021-07-05 Thread Markus Koschany
.qtopengl + + -- Markus Koschany Sun, 04 Jul 2021 08:50:03 +0200 + debian-games (3.3) unstable; urgency=medium * arcade: Remove fofix from Suggests. @@ -15,7 +33,7 @@ - board: kgames - rpg: openmw - rpg: openmw-cs -- arcarde: pinball-table-gnu +- arcade: pinball-table-gnu

Bug#990710: unblock: jetty9/9.4.39-1

2021-07-05 Thread Markus Koschany
. This can result in an +application used on a shared computer being left logged in. + +Thanks to Salvatore Bonaccorso for the report. (Closes: #98, #990578) + + -- Markus Koschany Sat, 03 Jul 2021 19:09:58 +0200 + jetty9 (9.4.39-1) unstable; urgency=high * New upstream release

Bug#987896: GUI drawing error due to Dsun.java2d.opengl=true

2021-05-01 Thread Markus Koschany
Control: severity -1 normal Hello, On Sat, 1 May 2021 17:14:57 + (UTC) Alexis PM wrote: > Package: sweethome3d > Version: 6.1.2+dfsg-2 > Severity: grave > Justification: package unusable > > Widespread GUI drawing errors (entire sections of the window appear black when interacting with

Bug#944431: Salzburg BSP

2021-04-28 Thread Markus Koschany
Hi Philip, thank you for the reminder and the debdiff. Indeed I wanted to fix this issue in Buster too but it seems I forgot to do it. I have requested a buster-pu (#987719) and already uploaded the package. Cheers, Markus signature.asc Description: This is a digitally signed message part

Bug#987719: buster-pu: package berusky2/0.10-7

2021-04-28 Thread Markus Koschany
-7+deb10u1) buster; urgency=medium + + [ Phil Wyett ] + * Add fix segfault at startup patch. +- 944431-avoid-no-return-statement-in-function-returning-non-void.patch + Thanks to Bernhard Übelacker . (Closes: #944431) + + -- Markus Koschany Wed, 28 Apr 2021 13:14:06 +0200 + berusky2

Bug#987583: unblock: mgba/0.8.4+dfsg-2 (pre-approval)

2021-04-28 Thread Markus Koschany
Control: tags -1 -moreinfo On Mon, 26 Apr 2021 15:42:34 +0200 Graham Inggs wrote: [...] > > The full diff is attached. May I upload it to unstable? > > Please go ahead and upload, and remove the moreinfo tag once the new > version is available in unstable. Hi, I have just uploaded mgba for

Bug#972230: Bug#976477 marked as pending in jruby

2021-04-18 Thread Markus Koschany
Hi, I'm just investigating the current open RC bugs for the debian-java maintained packages. You have marked #976477 and #977979 in jruby as pending. Could you clarify why there hasn't been an upload yet? There also seems to be another RC bug, #972230. Do you have any suggestions how we can

Bug#987099: ITP: openrefine-opencsv -- CSV parser library for Java

2021-04-17 Thread Markus Koschany
Package: wnpp Severity: wishlist Owner: Markus Koschany X-Debbugs-Cc: debian-de...@lists.debian.org, debian-j...@lists.debian.org, a...@debian.org * Package name: openrefine-opencsv Version : 2.4 Upstream Author : Bytecode Pty Ltd, Kyle Miller * URL : https

Bug#987098: ITP: httpcomponents-client5 -- HTTP/1.1 and HTTP/2 compliant HTTP agent implementation

2021-04-17 Thread Markus Koschany
Package: wnpp Severity: wishlist Owner: Markus Koschany X-Debbugs-Cc: debian-de...@lists.debian.org, debian-j...@lists.debian.org, a...@debian.org * Package name: httpcomponents-client5 Version : 5.0.3 Upstream Author : The Apache Software Foundation * URL : https

Bug#987097: ITP: httpcomponents-core5 -- set of low level HTTP transport components for Java

2021-04-17 Thread Markus Koschany
Package: wnpp Severity: wishlist Owner: Markus Koschany X-Debbugs-Cc: debian-de...@lists.debian.org, debian-j...@lists.debian.org, a...@debian.org * Package name: httpcomponents-core5 Version : 5.0.3 Upstream Author : The Apache Software Foundation * URL : https

Bug#986926: ITP: libsweble-common-java -- common classes for sweble projects

2021-04-14 Thread Markus Koschany
Package: wnpp Severity: wishlist Owner: Markus Koschany X-Debbugs-Cc: debian-de...@lists.debian.org, debian-j...@lists.debian.org, a...@debian.org * Package name: libsweble-common-java Version : 3.0.8 Upstream Author : The Open Source Research Group

Bug#986924: ITP: libsweble-wikitext-java -- parser for MediaWiki's wikitext

2021-04-14 Thread Markus Koschany
Package: wnpp Severity: wishlist Owner: Markus Koschany X-Debbugs-Cc: debian-de...@lists.debian.org, debian-j...@lists.debian.org, a...@debian.org * Package name: libsweble-wikitext-java Version : 3.1.9 Upstream Author : The Open Source Research Group

Bug#986922: ITP: libxtc-rats-java -- parser generator written in Java

2021-04-14 Thread Markus Koschany
Package: wnpp Severity: wishlist Owner: Markus Koschany X-Debbugs-Cc: debian-de...@lists.debian.org, debian-j...@lists.debian.org, a...@debian.org * Package name: libxtc-rats-java Version : 1.15.0 Upstream Author : Robert Grimm, New York University, Princeton University

Bug#986921: ITP: maven-jflex-plugin -- Maven plugin to generate Lexer code in Java

2021-04-14 Thread Markus Koschany
Package: wnpp Severity: wishlist Owner: Markus Koschany X-Debbugs-Cc: debian-de...@lists.debian.org, debian-j...@lists.debian.org, a...@debian.org * Package name: maven-jflex-plugin Version : 1.7.0 Upstream Author : Gerwin Klein, Steve Rowe, Régis Décamps * URL

Bug#986857: ITP: librdfa-java -- SAX-based Java RDFa parser

2021-04-12 Thread Markus Koschany
Package: wnpp Severity: wishlist Owner: Markus Koschany * Package name: librdfa-java Version : 1.0.0~BETA1 Upstream Author : The University of Bristol * URL : https://github.com/iteggmbh/java-rdfa * License : BSD-3-clause Programming Lang: Java Description

Bug#986797: unblock: sauerbraten/0.0.20201227-1

2021-04-12 Thread Markus Koschany
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock X-Debbugs-Cc: a...@debian.org Dear release team, [ Reason ] Please unblock the sauerbraten content package for the cube2 engine in testing. The current version of sauerbraten in testing

Bug#986681: ITP: libodfdom-java -- OpenDocument Format (ODF) framework

2021-04-09 Thread Markus Koschany
Package: wnpp Severity: wishlist Owner: Markus Koschany X-Debbugs-Cc: debian-de...@lists.debian.org, debian-j...@lists.debian.org, a...@debian.org * Package name: libodfdom-java Version : 0.9.0~RC2 Upstream Author : The Document Foundation * URL : https

Bug#986680: ITP: libsecondstring-java -- approximate string-matching routines

2021-04-09 Thread Markus Koschany
Package: wnpp Severity: wishlist Owner: Markus Koschany X-Debbugs-Cc: debian-de...@lists.debian.org, debian-j...@lists.debian.org, a...@debian.org * Package name: libsecondstring-java Version : 0.1 Upstream Author : 2003 Carnegie Mellon University * URL : https

Bug#986679: ITP: openrefine-vicino -- near-neighbor search tool for Java

2021-04-09 Thread Markus Koschany
Package: wnpp Severity: wishlist Owner: Markus Koschany X-Debbugs-Cc: debian-de...@lists.debian.org, debian-j...@lists.debian.org, a...@debian.org * Package name: openrefine-vicino Version : 1.2 Upstream Author : 2006-2010 Massachusetts Institute of Technology and Contributors

Bug#986678: ITP: openrefine-arithcode -- Java implementation of arithmetic coding and PPM compression

2021-04-09 Thread Markus Koschany
Package: wnpp Severity: wishlist Owner: Markus Koschany X-Debbugs-Cc: debian-de...@lists.debian.org, debian-j...@lists.debian.org, a...@debian.org * Package name: openrefine-arithcode Version : 1.2 Upstream Author : Bob Carpenter * URL : https://github.com/bob

Bug#986677: ITP: libmarc4j-java -- API for working with MARC and MARCXML in Java

2021-04-09 Thread Markus Koschany
Package: wnpp Severity: wishlist Owner: Markus Koschany X-Debbugs-Cc: debian-de...@lists.debian.org, debian-j...@lists.debian.org, a...@debian.org * Package name: libmarc4j-java Version : 2.9.1 Upstream Author : Robert Haschart, Bas Peters, Bill Dueber, et.al. * URL

Bug#986611: ITP: openrefine-butterfly -- modular web application framework

2021-04-07 Thread Markus Koschany
Package: wnpp Severity: wishlist Owner: Markus Koschany X-Debbugs-Cc: debian-de...@lists.debian.org, debian-j...@lists.debian.org, a...@debian.org * Package name: openrefine-butterfly Version : 1.1.1 Upstream Author : Stefano Mazzocchi * URL : https://github.com

Bug#986609: ITP: libdexx-java -- immutable, persistent collection classes for Java

2021-04-07 Thread Markus Koschany
Package: wnpp Severity: wishlist Owner: Markus Koschany X-Debbugs-Cc: debian-de...@lists.debian.org, debian-j...@lists.debian.org, a...@debian.org * Package name: libdexx-java Version : 0.7 Upstream Author : Andrew O'Malley * URL : https://github.com/andrewoma/dexx

Bug#986608: ITP: liblessen-java -- lightweight CSS+LESS parser written in Java

2021-04-07 Thread Markus Koschany
Package: wnpp Severity: wishlist Owner: Markus Koschany X-Debbugs-Cc: debian-de...@lists.debian.org, debian-j...@lists.debian.org, a...@debian.org * Package name: liblessen-java Version : 1.0 Upstream Author : David Huynh * URL : https://search.maven.org/artifact

Bug#986605: ITP: apache-jena -- Java framework for building Semantic Web applications

2021-04-07 Thread Markus Koschany
Package: wnpp Severity: wishlist Owner: Markus Koschany X-Debbugs-Cc: debian-de...@lists.debian.org, a...@debian.org * Package name: apache-jena Version : 3.17.0 Upstream Author : Apache Software Foundation * URL : https://jena.apache.org * License : Apache

Bug#986604: ITP: openrefine -- powerful tool for working with messy data

2021-04-07 Thread Markus Koschany
Package: wnpp Severity: wishlist Owner: Markus Koschany X-Debbugs-Cc: debian-de...@lists.debian.org, debian-j...@lists.debian.org, a...@debian.org * Package name: openrefine Version : 3.5 Upstream Author : OpenRefine contributors * URL : https://openrefine.org

Bug#986435: ITP: libthrift-java -- Java language support for Thrift

2021-04-05 Thread Markus Koschany
Package: wnpp Severity: wishlist Owner: Markus Koschany X-Debbugs-Cc: debian-de...@lists.debian.org, 938...@bugs.debian.org, debian-j...@lists.debian.org, a...@debian.org * Package name: libthrift-java Version : 0.13.0 Upstream Author : Apache Software Foundation * URL

Bug#986008: libpdfbox2-java: CVE-2021-27906

2021-04-05 Thread Markus Koschany
Hi tony, Am Sonntag, den 04.04.2021, 21:05 -0700 schrieb tony mancill: > On Sat, Mar 27, 2021 at 07:54:11PM +0100, Salvatore Bonaccorso wrote: > > Source: libpdfbox2-java > > Version: 2.0.22-1 > > Severity: important > > Tags: security upstream > > Forwarded:

Bug#981088: pacemaker: crm shell can't be executed due to a library error

2021-03-26 Thread Markus Koschany
I'm dropping the bug submitter from CC because I believe the discussion is no longer relevant for him. Am Freitag, den 26.03.2021, 21:08 +0100 schrieb wf...@niif.hu: > Markus Koschany writes: [...] > > Yes, exactly. There should be a versioned dependency on > > pacemaker-cli-u

Bug#981088: pacemaker: crm shell can't be executed due to a library error

2021-03-26 Thread Markus Koschany
Hello Feri, Am Freitag, den 26.03.2021, 16:37 +0100 schrieb wf...@niif.hu: > Control: reassign -1 libpe-status10 1.1.24-0+deb9u1 > Control: severity -1 serious > > Thorsten Rehm writes: > > > In my opinion the crmsh package should be more strict with the > > pacemaker-cli-utils package > >

Bug#985604: sweethome3d svg export bug

2021-03-22 Thread Markus Koschany
Am Montag, den 22.03.2021, 07:55 +0200 schrieb Andrius Merkys: > Control: severity 985604 important > Control: tags 985604 + confirmed > > Hello, > > On 2021-03-20 18:05, Антон Скрипка wrote: > > When export to SVG: > > > > Java 3D: implicit antialiasing enabled > >

Bug#984673: patch for solarwolf

2021-03-12 Thread Markus Koschany
Am Freitag, den 12.03.2021, 11:48 +0700 schrieb Judit Foglszinger: > Hi, > > wanted to play solarwolf tonight and stumbled over #984673 ;) > So just did what you said in the bug report and replaced isAlive with > is_alive, > what made it work for me. > Not sure, if the patch is actually useful

Bug#984886: buster-pu: package xcftools/1.0.7-6

2021-03-09 Thread Markus Koschany
and xcf2pnm binaries of +xcftools. An integer overflow can occur while walking through tiles that +could be exploited to corrupt memory and execute arbitrary code. In order +to trigger this vulnerability, a victim would need to open a specially +crafted XCF file. + + -- Markus Koschany

Bug#984673: solarwolf: Thread object has no attribute isAlive

2021-03-06 Thread Markus Koschany
Package: solarwolf Version: 1.5+dfsg1-2 Severity: grave X-Debbugs-Cc: a...@debian.org solarwolf fails to start because of an AttributeError: Thread object has no attribute isAlive. The funtion was removed in Python 3.9. The new one appears to be is_alive(). I try to prepare a patch for solarwolf

Bug#984672: oneisenough: AttributeError: module 'time' has no attribute 'clock'

2021-03-06 Thread Markus Koschany
Package: oneisenough Version: 0.40-5 Severity: grave X-Debbugs-Cc: a...@debian.org oneisenough fails to start because the function time.clock() has been removed in Python 3.8. I believe time.process_time() is the new equivalent but I have not tested the patch yet. Markus -- System

Bug#983807: spring builds with -march=native on amd64

2021-03-01 Thread Markus Koschany
Control: severity -1 normal Am Dienstag, den 02.03.2021, 01:32 +0200 schrieb Adrian Bunk: [...] > > I would really like to understand what the current drawback is for our > > users. > > If you could provide the build flags with march=native and march=x86-64 and > > then prove that march=x86-64

Bug#983807: spring builds with -march=native on amd64

2021-03-01 Thread Markus Koschany
Control: severity -1 normal Am Dienstag, den 02.03.2021, 01:02 +0200 schrieb Adrian Bunk: > On Mon, Mar 01, 2021 at 11:39:00PM +0100, Markus Koschany wrote: > > Am Montag, den 01.03.2021, 23:53 +0200 schrieb Adrian Bunk: > > > Source: spring > > > Version: 105.0.1+dfs

Bug#983807: spring builds with -march=native on amd64

2021-03-01 Thread Markus Koschany
Am Montag, den 01.03.2021, 23:53 +0200 schrieb Adrian Bunk: > Source: spring > Version: 105.0.1+dfsg-1 > Severity: serious > Tags: patch > > spring builds with -march=native on amd64, which makes spring > only work on machines compatible with whatever buildd built it. What Policy violation

Bug#800983: Reopen bug 800983 and 982001

2021-02-27 Thread Markus Koschany
Control: tags 800983 pending Control: tags 982001 pending On second thought, let's fix this now. signature.asc Description: This is a digitally signed message part

Bug#800983: Reopen bug 800983 and 982001

2021-02-27 Thread Markus Koschany
Control: reopen 800983 982001 I'm reopening bug 800983 and 982001 because they were not properly fixed. I let the current version in unstable migrate to testing and then I fix those remaining issues. Markus signature.asc Description: This is a digitally signed message part

Bug#945317: xcftools NMU for CVE-2019-5086 and CVE-2019-5087

2021-02-25 Thread Markus Koschany
Hello security team, hello Hugo, I hope you are doing well! I have just uploaded a NMU for xcftools fixing CVE-2019-5086 and CVE-2019-5087. The new patch also addresses the 32 bit portability issues. The basic idea behind it is to limit possible values of width and height (which can only be

Bug#982671: Supporting unbound in stretch by upgrading to 1.9

2021-02-22 Thread Markus Koschany
Control: tags -1 wontfix Hello, thanks for the report. There is no plan to continue support for the Python bindings of unbound in Stretch. The official support ended last year. See also DSA-4694-1. [1] We have resumed support a few weeks ago but only for the unbound server itself, as well as

Bug#983124: RM: fretsonfire -- ROM; rc-buggy and unmaintained

2021-02-19 Thread Markus Koschany
Package: ftp.debian.org Severity: normal X-Debbugs-Cc: a...@debian.org Dear ftp team, please remove fretsonfire from Debian. The package is rc-buggy and unmaintained. [1] I have raised this issue on the debian-devel-games mailing list [2] and nobody objected against the removal. Regards,

Bug#983123: RM: kiki-the-nano-bot -- ROM; rc-buggy and unmaintained

2021-02-19 Thread Markus Koschany
Package: ftp.debian.org Severity: normal X-Debbugs-Cc: a...@debian.org Dear ftp team, please remove kiki-the-nano-bot from Debian. The package is rc-buggy and unmaintained. [1] I have raised this issue on the debian-devel-games mailing list [2] and nobody objected against the removal. Regards,

Bug#983122: RM: jugglemaster -- ROM; rc-buggy and unmaintained

2021-02-19 Thread Markus Koschany
Package: ftp.debian.org Severity: normal X-Debbugs-Cc: a...@debian.org Dear ftp team, please remove jugglemaster from Debian. The package is rc-buggy and unmaintained. [1] I have raised this issue on the debian-devel-games mailing list [2] and nobody objected against the removal. Regards,

Bug#983119: RM: adanaxisgpl -- ROM; rc-buggy and unmaintained upstream

2021-02-19 Thread Markus Koschany
Package: ftp.debian.org Severity: normal X-Debbugs-Cc: a...@debian.org Dear ftp team, please remove adanaxisgpl from Debian. The package is rc-buggy and unmaintained. [1] I have raised this issue on the debian-devel-games mailing list [2] and nobody objected against the removal. Regards,

Bug#982671: Supporting unbound in stretch by upgrading to 1.9

2021-02-18 Thread Markus Koschany
Am Donnerstag, den 18.02.2021, 11:40 +0200 schrieb Andrei POPESCU: [...] > Hello, > > This appears to be the case. A side effect of this is that unless dealt > with manually these bugs will just linger in the BTS. > > https://bugs.debian.org/cgi-bin/pkgreport.cgi?maint= > > Please either close

Bug#982671: Supporting unbound in stretch by upgrading to 1.9

2021-02-17 Thread Markus Koschany
Am Mittwoch, den 17.02.2021, 15:21 -0500 schrieb Robert Edmonds: > Markus Koschany wrote: [...] > > Please feel free to reassign and/or adjust the bug report as necessary. > > I get the following error message from the BTS. Do I need to do > "reassign 982671 unbound1.9&quo

Bug#982671: Supporting unbound in stretch by upgrading to 1.9

2021-02-17 Thread Markus Koschany
Hello, Am Mittwoch, den 17.02.2021, 14:09 -0500 schrieb Robert Edmonds: > Hi, > > #982671 / #982672 is incorrectly reported against the python-unbound > package. It should instead be against the unbound binary package because > this functionality is in the unbound daemon. Please feel free to

Bug#982671: Supporting unbound in stretch by upgrading to 1.9

2021-02-17 Thread Markus Koschany
Hi, Am Mittwoch, den 17.02.2021, 12:43 -0500 schrieb Robert Edmonds: [...] > Hi, > > It looks like #982671 / #982672 was assigned by the BTS to src:unbound > rather than src:unbound1.9. I attempted to re-assign the bug to > src:unbound1.9 with notfound/found but I don't think that worked since I

Bug#982580: netty: CVE-2021-21290

2021-02-12 Thread Markus Koschany
Control: owner -1 ! Hi Salvatore, Am Freitag, den 12.02.2021, 07:42 +0100 schrieb Salvatore Bonaccorso: > Source: netty > Version: 1:4.1.48-1 > Severity: important > Tags: security upstream > X-Debbugs-Cc: car...@debian.org, Debian Security Team < > t...@security.debian.org> > Control: found -1

Bug#945317: xcftools NMU for CVE-2019-5086 and CVE-2019-5087

2021-02-10 Thread Markus Koschany
Hi Salvatore, Am Mittwoch, den 10.02.2021, 22:03 +0100 schrieb Salvatore Bonaccorso: [...] > > I'm not fully in favor to have all the (build-)rdeps forced out of > Debian, that would likely not be a benefit as seems unfair to the > castle-game-engine, game-data-packager and neurodebian packages,

Bug#945317: xcftools NMU for CVE-2019-5086 and CVE-2019-5087

2021-02-10 Thread Markus Koschany
Hello Salvatore, Am Mittwoch, den 10.02.2021, 06:30 +0100 schrieb Salvatore Bonaccorso: [...] > Question back on this. > > Is it confirmed that it fixes both CVE-2019-5086 (TALOS-2019-0878, > https://github.com/j-jorge/xcftools/issues/12) and CVE-2019-5087 > (TALOS-2019-0879,

Bug#945317: xcftools NMU for CVE-2019-5086 and CVE-2019-5087

2021-02-09 Thread Markus Koschany
this vulnerability, a victim would need to open a specially +crafted XCF file. + + -- Markus Koschany Tue, 9 Feb 2021 23:15:22 +0100 + xcftools (1.0.7-6) unstable; urgency=medium * Team upload (collab-maint) diff -Nru xcftools-1.0.7/debian/patches/CVE-2019-5086-and-CVE-2019-5087.patch xcftools

Bug#981731: bullet: Provide a multithreaded bullet packages

2021-02-03 Thread Markus Koschany
Hey, Am Mittwoch, den 03.02.2021, 12:23 +0100 schrieb Bret Curtis: > Package: bullet > Severity: normal > > Dear Maintainer, > > Multhreaded bullet has been available since 2014, yet is still not packaged. > Since bullet already ships with single and double precision packages, it > seems not

Bug#954487: barrage: man page misses comand line options and crashes when using f to switch from/to fullscreen

2021-01-30 Thread Markus Koschany
Hello, On Sun, 22 Mar 2020 07:41:37 +0100 treaki wrote: [...] > Please add all avaivable command line options to the man page, i found out following by guessing: [...] I have added the missing command line options to the man page. You can also find more information at

Bug#947844: also affected by libservlet3.1-java: 8.5.50-0+deb9u1 breaks upgrades to Buster, fix not in proposed-updates

2021-01-29 Thread Markus Koschany
Am Freitag, den 29.01.2021, 14:25 +0200 schrieb Modestas: > The bug is still not fixed as I tried updating LMDE3 to LMDE4 based on debian > 9 to 10. The bug was fixed eight months ago. Without more information, nobody can investigate your problem. Regards, Markus Koschany signatu

Bug#981088: pacemaker: crm shell can't be executed due to a library error

2021-01-28 Thread Markus Koschany
Hello Thorsten, Am Donnerstag, den 28.01.2021, 14:52 +0100 schrieb Thorsten Rehm: > Hi Markus, > > thank you for your reply. > I've installed a fresh Debian Stretch and I think I know why I had > such a problem. I believe it's a dependency problem, but I let you > decide, if this is the case. >

Bug#981088: pacemaker: crm shell can't be executed due to a library error

2021-01-27 Thread Markus Koschany
Hello, On Tue, 26 Jan 2021 08:24:19 +0100 Thorsten Rehm wrote: > Package: pacemaker > Version: 1.1.24-0+deb9u1 > Severity: normal > > Dear Maintainer, > > thank you for the effort and the update. > Unfortunately there are still some problems with the updated version. > > I've just updated the

Bug#980922: debian-games: please move to the new name udd-mirror.debian.net

2021-01-24 Thread Markus Koschany
Control: severity -1 normal Hello, Am Sonntag, den 24.01.2021, 13:22 +0100 schrieb Mattia Rizzolo: [...] > As announced in https://lists.debian.org/debian-qa/2020/11/msg00011.html > we don't plan to remove public-udd-mirror.xvm.mit within less than a > year. > > I'm filing this bug as RC, as I

Bug#894312: rrootage: New upstream version 0.24

2021-01-23 Thread Markus Koschany
I have pushed my preliminary work for 0.24 to the experimental branch of https://salsa.debian.org/games-team/rrootage The sources are targeted for the Windows platform and I had to rebase the patches. There are still some issues with the path to /usr/share/games/rrootage because upstream

Bug#980816: Clarify requirement for safe default typing?

2021-01-22 Thread Markus Koschany
Hi Moritz, Am Freitag, den 22.01.2021, 21:03 +0100 schrieb Moritz Muehlenhoff: > Source: jackson-databind > Severity: important > X-Debbugs-Cc: car...@debian.org, a...@debian.org > > Starting with 2.10 (and thus in Bullseye) upstream makes safe default > typing required, the absense is no longer

Bug#938509: Intent to request the removal from Debian

2021-01-17 Thread Markus Koschany
Hi, thanks for the patch. I have pushed your changes to https://salsa.debian.org/games-team/snowballz/-/tree/experimental However I can't build the package as is. The build system seems to require python-distutils instead of pybuild and all the dependencies haven't been updated yet. Regards,

Bug#938509: Intent to request the removal from Debian

2021-01-16 Thread Markus Koschany
Hello, Am Samstag, den 16.01.2021, 14:13 -0300 schrieb Caleb Marshall: [...] > Hello Markus, > Last October I tried to port snowballz to python 3. I have it mostly > working except for the GUI, which flickers when I move the mouse. If you > could advise me on where to send a tar or diff I could

Bug#979733: teg: FTBFS on several architectures

2021-01-10 Thread Markus Koschany
Package: teg Version: 0.12.0-1 Severity: serious teg 0.12.0-1 FTBFS on several architectures. We are aware of the problem which has been reported upstream. https://github.com/wfx/teg/issues/25

Bug#978745: Server buffer overflow when reading tailored score log

2020-12-31 Thread Markus Koschany
Hi, Am Donnerstag, den 31.12.2020, 10:36 +0200 schrieb Marko Lindqvist: > Package: freeciv > Version: 2.6.2.1-2 > Tags: Security > > Freeciv server has a buffer overflow vulnerability, if it reads > tailored score log file. > Score log functionality is not enabled by default, and it's rarely

Bug#974563: Security update of pacemaker

2020-12-27 Thread Markus Koschany
Hello, I have prepared a new security update of pacemaker, the latest version in the 1.1.x series. The update will fix CVE-2018-16877, CVE-2018-16878 and CVE-2020- 25654. I would appreciate it if you could test this version before it is uploaded to stretch-security again. You can find all Debian

Bug#697615: Intent to request the removal from Debian

2020-12-21 Thread Markus Koschany
Hi, as previously announced on debian-devel-games [1] I intend to request the removal of this source or binary package from Debian at the end of January 2021. If you are interested in fixing this bug, please let me know in time to avoid the removal from Debian. Markus [1]

Bug#976548: This package only builds Arch:all binary packages

2020-12-14 Thread Markus Koschany
Control: severity -1 normal The package is arch:all and builds fine on amd64 but FTBFS on other supported architectures. Apparently one or two arch-dependent tests fail which is the root cause of this failure. I'm downgrading the severity to normal as discussed on the debian-java list. This is

Bug#976915: service-wrapper-java: FTBFS on ppc64el: [exec] wrapper.c:(.text+0x3598): undefined reference to `pow'

2020-12-12 Thread Markus Koschany
On Wed, 9 Dec 2020 09:41:34 +0100 Lucas Nussbaum wrote: > Source: service-wrapper-java > Version: 3.5.30-1 > Severity: serious > Justification: FTBFS on ppc64el > Tags: bullseye sid ftbfs > Usertags: ftbfs-20201209 ftbfs-bullseye ftbfs-ppc64el > > Hi, > > During a rebuild of all packages in

Bug#976948: jnr-unixsocket: FTBFS on ppc64el (arch:all-only src pkg): dh_auto_test: error: /usr/lib/jvm/default-java/bin/java -noverify -cp /usr/share/maven/boot/plexus-classworlds-2.x.jar -Dmaven.hom

2020-12-12 Thread Markus Koschany
Control: severity -1 normal I'm lowering the severity to normal as discussed on the debian-java mailing list. The package builds fine on amd64 but it appears a test fails on ppc64el. Markus signature.asc Description: This is a digitally signed message part

Bug#938927: #938927: patch available

2020-12-08 Thread Markus Koschany
Control: block 941480 by -1 Hi, On Thu, 5 Sep 2019 18:30:33 +0300 mer...@debian.org wrote: > control: tags -1 + patch > > Hello, > > Please find attached a patch to build libthrift-java. > > Best wishes, > Andrius What is the status of this bug report? I also need libthrift-java for

Bug#976545: Build failures on arm64 are release critical now

2020-12-05 Thread Markus Koschany
Control: severity -1 normal Hello, The package builds fine on amd64. I don't think it is correct to use severity serious in this case because ufoai-maps is an arch:all package. The same is true for Java packages. If we want to make this a release goal (making arch all packages buildable on all

Bug#976219: zsh uninstallable due to partial oldstable security update

2020-12-01 Thread Markus Koschany
Hello, zsh 5.3.1-4+deb9u4 was sucessfully uploaded to stretch-security thirteen hours ago but it still remains in status "uploaded" for all supported architectures except arch all. Who can "install" the packages into the archive or is another upload necessary? Regards, Markus signature.asc

Bug#976060: Migrate to udd-mirror.debian.net

2020-11-30 Thread Markus Koschany
Thanks for the patch Asheesh! signature.asc Description: This is a digitally signed message part

Bug#973695: buster-pu: package ublock-origin/1.22.2+dfsg-1~deb10u1

2020-11-22 Thread Markus Koschany
Am Sonntag, den 22.11.2020, 18:37 + schrieb Adam D. Barratt: [...] > Assuming that's the only required change, please go ahead. Thanks. Reverting the debhelper bump to 12 was the only packaging change. I have uploaded ublock-origin 1.30.0 a few minutes ago. Regards, Markus signature.asc

Bug#975405: wabt: Please build wabt.js

2020-11-22 Thread Markus Koschany
Hi, Am Samstag, den 21.11.2020, 18:45 +0100 schrieb Xavier Guimard: > Package: wabt > Version: 1.0.20-1 > Severity: important > X-Debbugs-Cc: pkg-javascript-de...@lists.alioth.debian.org > > Hi, > > wabt.js upstream repository is a minified file built from wabt. This > package is a reverse

Bug#975148: freeciv: FTBFS: canvas.cpp:265:16: error: aggregate ‘QPainterPath path’ has incomplete type and cannot be defined

2020-11-19 Thread Markus Koschany
Am Donnerstag, den 19.11.2020, 12:01 +0200 schrieb Marko Lindqvist: > On Thu, 19 Nov 2020 at 11:50, Marko Lindqvist wrote: > > Upstream fix: https://www.hostedredmine.com/issues/868060, upstream > > 2.6.2.1 release with the fix included coming soon (likely 28.11) > > In case you decide not to

Bug#926423: webext-https-everywhere: Possible issue with https-everywhere crashing Firefox-ESR tabs.

2020-11-18 Thread Markus Koschany
Control: tags -1 moreinfo signature.asc Description: This is a digitally signed message part

Bug#974563: corosync unable to communicate with pacemaker 1.1.16-1+deb9u1 which contains the fix for CVE-2020-25654

2020-11-17 Thread Markus Koschany
Control: severity -1 normal Am Montag, den 16.11.2020, 09:22 -0300 schrieb Alejandro Taboada: > Hi Markus, > > Sorry for the delay. With this patch works when is applied only to 1 node. > The services restart and the arm resources are up. > The problem appears again when I install the patch on a

Bug#974563: corosync unable to communicate with pacemaker 1.1.16-1+deb9u1 which contains the fix for CVE-2020-25654

2020-11-13 Thread Markus Koschany
Am Freitag, den 13.11.2020, 23:13 -0300 schrieb Alejandro Taboada: > Hello Markus, > > It doesn’t work. The output log is quite different. I throws a timeout and > just at the end the “unprivileged client crmd”. > See attached log. I'm sorry but I uploaded an older version that missed a do_reply

Bug#974563: corosync unable to communicate with pacemaker 1.1.16-1+deb9u1 which contains the fix for CVE-2020-25654

2020-11-13 Thread Markus Koschany
Am Donnerstag, den 12.11.2020, 15:50 -0300 schrieb Alejandro Taboada: > Hi ! > > Just tested v1.1 and the issue persists. The problem is quiet local > connection when using with corosync Hello, I believe I have found and fixed the problem. The refactored code in lrmd.c caused the regression.

Bug#974563: corosync unable to communicate with pacemaker 1.1.16-1+deb9u1 which contains the fix for CVE-2020-25654

2020-11-12 Thread Markus Koschany
Hi, Am Donnerstag, den 12.11.2020, 18:21 +0100 schrieb Pallai Roland: > Hi Markus, > > The problem is still the same here: Thanks for your debug log. I have looked at every line of code again and compared the original upstream patch from here

Bug#974563: corosync unable to communicate with pacemaker 1.1.16-1+deb9u1 which contains the fix for CVE-2020-25654

2020-11-12 Thread Markus Koschany
Thanks for reporting. This is a permission problem. I assume your clients are local and not remote and you don't use the tls_backend. I have prepared another update that should grant the local hacluser clients the necessary privileges. You can download the source and binary files from

Bug#973125: pdfsam: stackoverflow error when closing the application

2020-11-07 Thread Markus Koschany
Control: forwarded -1 https://github.com/torakiki/pdfsam/issues/431 signature.asc Description: This is a digitally signed message part

Bug#964195: guacamole-client: CVE-2020-9497 and CVE-2020-9498

2020-11-06 Thread Markus Koschany
+++ guacamole-server-0.9.9/debian/patches/CVE-2020-9497-and-CVE-2020-9498.patch 2020-11-06 22:44:56.0 +0100 @@ -0,0 +1,355 @@ +From: Markus Koschany +Date: Tue, 3 Nov 2020 13:45:20 +0100 +Subject: CVE-2020-9497 and CVE-2020-9498 + +Bug-Debian: https://bugs.debian.org/964195 +Origin: https

<    1   2   3   4   5   6   7   8   9   10   >