Bug#913164: CVE-2018-18897

2018-11-07 Thread Moritz Muehlenhoff
Source: poppler Severity: normal Tags: security This was assigned CVE-2018-18897: https://gitlab.freedesktop.org/poppler/poppler/issues/654 Cheers, Moritz

Bug#913166: CVE-2018-17095

2018-11-07 Thread Moritz Muehlenhoff
Source: audiofile Severity: important Tags: security Please see https://security-tracker.debian.org/tracker/CVE-2018-17095 Cheers, Moritz

Bug#879786: apt-secure man page needs to provide useful pointers for Release file info changes

2018-11-07 Thread Jesse Hathaway
> IMO, the right answer would be to run "apt update" and confirm the > change when asked. I find it strange to recommend another tool, when there is a flag to confirm the change with apt-get. If the intent is to deprecate using apt-get interactively entirely, then that should be done at a more

Bug#912740: ruby2.3: FTBFS on mips and armhf in stretch

2018-11-07 Thread Steve McIntyre
On Sat, Nov 03, 2018 at 11:36:04AM +0100, Salvatore Bonaccorso wrote: >Source: ruby2.3 >Version: 2.3.3-1+deb9u3 >Severity: serious >Justification: FTBFS >Control: found -1 2.3.3-1+deb9u4 >Control: affects -1 release.debian.org,security.debian.org > >Hi > >There is a regression for rub2.3 in

Bug#913175: minitube sources exposes google API key

2018-11-07 Thread Pablo De Napoli
Package: miniube Version: version 2.9 Tags: security Dear mantainer: The file /debian/rules from the debian sources exposes a google API key, This is sensitive information. That key should be considered compromised, and could be potentially be abused by others. Is there no better solution than

Bug#913179: libprelude: FTBFS with glibc 2.28; cherrypicked patches attached

2018-11-07 Thread Adam Conrad
Package: libprelude Version: 4.1.0-4.1 Severity: normal Tags: patch User: ubuntu-de...@lists.ubuntu.com Usertags: origin-ubuntu disco ubuntu-patch In Ubuntu, the attached patch was applied to achieve the following: * 014-fix-glibc-gnulib.patch: Cherrypick gnulib fixes for glibc 2.28. This

Bug#913182: poppler: CVE-2018-19060

2018-11-07 Thread Salvatore Bonaccorso
Source: poppler Version: 0.69.0-2 Severity: normal Tags: patch security upstream Forwarded: https://gitlab.freedesktop.org/poppler/poppler/issues/660 Hi, The following vulnerability was published for poppler. CVE-2018-19060[0]: | An issue was discovered in Poppler 0.71.0. There is a NULL

Bug#913160: ITP: node-serialize-javascript -- Serialize JavaScript to a superset of JSON.

2018-11-07 Thread Nicolas Mora
package: node-serialize-javascript Severity: whishlist Owner: 'Nicolas Mora' *Package Name : node-serialize-javascript Version : 1.5.0 Upstream Author : Eric Ferraiuolo *URL : https://github.com/yahoo/serialize-javascript *License : BSD-3-Clause *Description : Serialize JavaScript to a

Bug#913156: [pkg-wicd-maint] Bug#913156: UnicodeDecodeError: 'ascii' codec can't decode byte 0xe2

2018-11-07 Thread Axel Beckert
Hi Bryce, Bryce Handerson wrote: > After some debugging myself it seems to happen when I have my iPhone's > hotspot on with the iw scan SSID below > > SSID: Bryce\xe2\x80\x99s iPhone Thanks! So it's not an unexpected encoding as I suspected but correct UTF-8. "\xe2\x80\x99" is actually the

Bug#873838: hobbit-plugins: libs test gives false positive with mysql/mariadb installed

2018-11-07 Thread Damien Martins
Hi Axel, Unfortunately, I'm using the version provided for Debian stretch (hobbit-plugins 20170219). So let consider this is the main reason of my issue. So this bug can be closed. Indeed, I did whitelist /[aio] file, but I escaped the special characters ;) Thank you for the reminder of

Bug#913173: gettext: CVE-2018-18751

2018-11-07 Thread Salvatore Bonaccorso
Source: gettext Version: 0.19.8.1-8 Severity: minor Tags: security upstream Hi Santiago, The following vulnerability was published for gettext, and as discussed already this has negligable security impact if at all. But still filling the bug for tracking purpose so we can update the tracker

Bug#913176: [gnutls28] Please backport for Stretch

2018-11-07 Thread Dererk
Package: gnutls28 Version: 3.5.19-1 Severity: wishlist Dear gnutls team! I've come across #857436 on ssmtp package version for Stretch. This issue prevents ssmtp from working on recent installations that do not support <= tlsv1.1, which by today standards, is reasonably unsafe. Just for the

Bug#913157: ITP: node-jest-worker -- Module for executing heavy tasks under forked processes in parallel

2018-11-07 Thread Nicolas Mora
package: node-jest-worker Severity: whishlist Owner: 'Nicolas Mora' *Package Name : node-jest-worker Version : 23.2.0 Upstream Author : Facebook Inc. *URL : https://github.com/facebook/jest/tree/master/packages/jest-worker *License : Expat *Description : Module for executing heavy tasks

Bug#913158: The system encountered an error

2018-11-07 Thread Harald Dunkel
Package: gerbera Version: 1.1.0+dfsg-2+b2 If I wipe out gerbera's database and start it with ui enabled="yes", then Firefox shows me a tiny popup at the bottom edge saying "The system encountered an error". If I click on "Add some files", then nothing happens. The logfile: 2018-11-07 18:56:51

Bug#913163: CVE-2018-14626 CVE-2018-10851

2018-11-07 Thread Moritz Muehlenhoff
Source: pdns Severity: grave Tags: security Please see: CVE-2018-10851: https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2018-03.html https://downloads.powerdns.com/patches/2018-03/ CVE-2018-14626:

Bug#913162: CVE-2018-10851 CVE-2018-14626 CVE-2018-14644

2018-11-07 Thread Moritz Muehlenhoff
Package: pdns-recursor Severity: grave Tags: security Please see CVE-2018-10851: https://doc.powerdns.com/recursor/security-advisories/powerdns-advisory-2018-04.html https://downloads.powerdns.com/patches/2018-04/ CVE-2018-14626:

Bug#907837: Please give more hints for net booting from UEFI

2018-11-07 Thread Holger Wansing
Control: tags -1 + pending Holger Wansing wrote: > Hi, > > Vincent McIntyre wrote: > > Not quite sure about the wording, but a first try: > > > > diff --git a/en/install-methods/install-tftp.xml > > b/en/install-methods/install-tftp.xml > > index 868c70155..7236fa836 100644 > > ---

Bug#913170: ITP: tryton-modules-account-dunning-email -- Account Dunning Email Module for the Tryton Application Platform

2018-11-07 Thread Mathias Behrle
X-Debbugs-CC: debian-de...@lists.debian.org Package: wnpp Severity: wishlist Owner: Debian Tryton Maintainers * Package name: tryton-modules-account-dunning-email Version : 5.0.0 Upstream Author : Tryton project (www.tryton.org) * URL :

Bug#913172: ITP: tryton-modules-edocument-unece -- EDocument UNECE Module for the Tryton Application Platform

2018-11-07 Thread Mathias Behrle
X-Debbugs-CC: debian-de...@lists.debian.org Package: wnpp Severity: wishlist Owner: Debian Tryton Maintainers * Package name: tryton-modules-edocument-unece Version : 5.0.0 Upstream Author : Tryton project (www.tryton.org) * URL : http://downloads.tryton.org/5.0/ *

Bug#913169: ITP: tryton-modules-account-fr-chorus -- Account FR Chorus Module for the Tryton Application Platform

2018-11-07 Thread Mathias Behrle
X-Debbugs-CC: debian-de...@lists.debian.org Package: wnpp Severity: wishlist Owner: Debian Tryton Maintainers * Package name: tryton-modules-account-fr-chorus Version : 5.0.0 Upstream Author : Tryton project (www.tryton.org) * URL : http://downloads.tryton.org/5.0/ *

Bug#910917: RFA: apache2 -- Apache HTTP Server

2018-11-07 Thread Stefan Fritsch
Hi Jason, sorry for the late response. I forgot to subscribe to the wnpp report and did not get your mail. On Saturday, 20 October 2018 04:50:50 CET Jason Vigil wrote: > To be honest, I'm not terribly experienced with Apache HTTPD nor Debian > packaging, but I am fairly experienced as a Debian

Bug#913171: ITP: tryton-modules-edocument-uncefact -- EDocument UN/CEFACT Module for the Tryton Application Platform

2018-11-07 Thread Mathias Behrle
X-Debbugs-CC: debian-de...@lists.debian.org Package: wnpp Severity: wishlist Owner: Debian Tryton Maintainers * Package name: tryton-modules-edocument-uncefact Version : 5.0.0 Upstream Author : Tryton project (www.tryton.org) * URL : http://downloads.tryton.org/5.0/

Bug#913168: ITP: tryton-modules-account-es -- Financial and Accounting Module for Spain for the Tryton Application Platform

2018-11-07 Thread Mathias Behrle
X-Debbugs-CC: debian-de...@lists.debian.org Package: wnpp Severity: wishlist Owner: Debian Tryton Maintainers * Package name: tryton-modules-account-es Version : 5.0.0 Upstream Author : Tryton project (www.tryton.org) * URL : http://downloads.tryton.org/5.0/ *

Bug#913167: ITP: tryton-modules-sale-subscription -- Sale Subscription Module for the Tryton Application Platform

2018-11-07 Thread Mathias Behrle
X-Debbugs-CC: debian-de...@lists.debian.org Package: wnpp Severity: wishlist Owner: Debian Tryton Maintainers * Package name: tryton-modules-sale-subscription Version : 5.0.0 Upstream Author : Tryton project (www.tryton.org) * URL : http://downloads.tryton.org/5.0/ *

Bug#913183: "/etc/cryptsetup-initramfs/conf-hook", add the possibility to include at least one header file

2018-11-07 Thread 21naown
Package: cryptsetup Version: 2:1.7.3-4 Severity: normal Key files can be included in the initramfs image through the variable "KEYFILE_PATTERN", it would be very appreciable if at least one header file could be included in a similar manner through for example the variable

Bug#905388: Devuan has working packages, but they need work wrt systemd

2018-11-07 Thread Mark Hindley
owner ! retitle ITP: elogind -- The systemd project's "logind", extracted to a standalone package thanks I am working on packaging elogind 239.1 for Debian based on my work for Devuan, so I am happy to take ownership of this bug. The WIP git repro is at

Bug#913154: Please move /etc/init.d/skeleton

2018-11-07 Thread Michael Biebl
Package: initscripts Severity: normal Hi, please consider moving the skeleton init script from /etc/init.d to a different place. My proposal would be /usr/share/doc/initscripts/examples/ Being installed in /etc/init.d has several undesirable consequences a/ it's marked as a conffile when it

Bug#913159: task-kannada-desktop: uninstallable on mips and mipsel

2018-11-07 Thread Ivo De Decker
Control: found -1 3.39 Hi On Wed, Nov 07, 2018 at 07:19:21PM +0100, Ivo De Decker wrote: > version: 3.47 As kibi noted on IRC, this also affects the version in stretch. Ivo

Bug#818544: Re[2]: Bug#818544: libsane-dev: arch-dependent file in "Multi-Arch: same" package

2018-11-07 Thread Anton Vorobyov
I am using debian testing, libsane-dev version 1.0.25-4.1. I suppose it's fixed in unstable and stable, but not old enough to migrate to testing?

Bug#913045: [Pkg-alsa-devel] Bug#913045: libasound2: ALSA lib pcm_dmix.c:1099:(snd_pcm_dmix_open) unable to open slave

2018-11-07 Thread Pedro Silva
On Tue, 6 Nov 2018 12:16:18 +0100 Elimar Riesebieter wrote: > * Ryan Lue [2018-11-06 18:51 +0800]: > > > Package: libasound2 > > Version: 1.1.7-1 > > Severity: important > > > > Dear Maintainer, > > > > Please forgive my lack of familiarity with ALSA. > > > > I use sox in a script to play an mp3

Bug#913180: poppler: CVE-2018-19059

2018-11-07 Thread Salvatore Bonaccorso
Source: poppler Version: 0.69.0-2 Severity: normal Tags: patch security upstream Forwarded: https://gitlab.freedesktop.org/poppler/poppler/issues/661 Hi, The following vulnerability was published for poppler. CVE-2018-19059[0]: | An issue was discovered in Poppler 0.71.0. There is a

Bug#913004: python-gnupg: should not fail on fingerprint collisions

2018-11-07 Thread W. Martin Borgert
I almost forgot, that there was a Debian bug report by Dominik, too: https://bugs.debian.org/850751

Bug#913129: [Pkg-openssl-devel] Bug#913129: openssl: TLS error (error 403 4.7.0 TLS handshake failed in sendmail logs)

2018-11-07 Thread Kurt Roeckx
On Wed, Nov 07, 2018 at 11:21:44AM +0100, BERTRAND Joël wrote: > Nov 7 09:17:31 rayleigh sm-mta[10148]: ruleset=try_tls, > arg1=smtp-in.orange.fr, relay=smtp-in.orange.fr, reject=550 5.7.1 > ... do not try TLS with smtp-in.orange.fr [80.12.242.9] > Nov 7 09:17:31 rayleigh sm-mta[10148]:

Bug#879786: apt-secure man page needs to provide useful pointers for Release file info changes

2018-11-07 Thread Julian Andres Klode
On Wed, Nov 07, 2018 at 10:50:05AM -0600, Jesse Hathaway wrote: > Just ran into this issue with chrome package from Google: > > E: Repository 'http://dl.google.com/linux/chrome/deb stable > Release' changed its 'Origin' value from 'Google, Inc.' to 'Google > LLC' > N: This must be

Bug#879786: apt-secure man page needs to provide useful pointers for Release file info changes

2018-11-07 Thread Julian Andres Klode
On Wed, Nov 07, 2018 at 12:21:01PM -0600, Jesse Hathaway wrote: > On Wed, Nov 7, 2018 at 12:12 PM Julian Andres Klode wrote: > > > > On Wed, Nov 07, 2018 at 10:50:05AM -0600, Jesse Hathaway wrote: > > > Just ran into this issue with chrome package from Google: > > > > > > E: Repository

Bug#906643: transition: php7.3

2018-11-07 Thread Ondřej Surý
I solved the doctrine bug, but php-symfony-polyfill 1.10.0 turned out to be harder nut to crack: For reference: 1. I removed references for Normalizer::NONE as they were testing if the code would "assert" (whatever that means in this context) 2. There was mismatch between declaration of

Bug#905388: Devuan has working packages, but they need work wrt systemd

2018-11-07 Thread Mark Hindley
owner #905388 ! retitle #905388 ITP: elogind -- The systemd project's "logind", extracted to a standalone package thanks

Bug#913155: ITP: node-rollup-plugin-uglify -- Rollup plugin to minify generated bundle.

2018-11-07 Thread Nicolas Mora
package: node-rollup-plugin-uglify Severity: whishlist Owner: 'Nicolas Mora' *Package Name : node-rollup-plugin-uglify Version : 6.0.0 Upstream Author : Bogdan Chadkin *URL : https://github.com/TrySound/rollup-plugin-uglify#readme *License : Expat *Description : Uses UglifyJS under the

Bug#913156: [pkg-wicd-maint] Bug#913156: UnicodeDecodeError: 'ascii' codec can't decode byte 0xe2

2018-11-07 Thread Axel Beckert
Hi Bryce, Bryce Handerson wrote: > Trying to run wicd-curses results in a traceback, I have an `iw scan` log > that was taken at the time of trying to run wicd-curses that I can attach > if needed. Thanks for the bug report. Yes, the iw scan log would likely be helpful as I expect some ESSID

Bug#910917: RFA: apache2 -- Apache HTTP Server

2018-11-07 Thread Stefan Fritsch
Hi Mosab, sorry for the late response. I forgot to subscribe to the wnpp report and did not get your mail. On Thursday, 18 October 2018 10:47:34 CET Mosab Ibrahim wrote: > I don't have experience with packaging, but I do have experience with using > Apache HTTP Server, and I am a quick learner.

Bug#913177: poppler: CVE-2018-19058

2018-11-07 Thread Salvatore Bonaccorso
Source: poppler Version: 0.69.0-2 Severity: important Tags: security upstream Forwarded: https://gitlab.freedesktop.org/poppler/poppler/issues/659 Hi, The following vulnerability was published for poppler. CVE-2018-19058[0]: | An issue was discovered in Poppler 0.71.0. There is a reachable

Bug#913178: ITP: node-react-audio-player -- A simple React wrapper on the HTML5 audio tag

2018-11-07 Thread Nicolas Mora
package: node-react-audio-player Severity: whishlist Owner: 'Nicolas Mora' *Package Name : node-react-audio-player Version : 0.11.0 Upstream Author : Justin McCandless *URL : https://github.com/justinmc/react-audio-player#readme *License : Expat *Description : This is a light React wrapper

Bug#873838: hobbit-plugins: libs test gives false positive with mysql/mariadb installed

2018-11-07 Thread Axel Beckert
Control: tag -1 + moreinfo Hi Damien, Damien Martins wrote: > Le 22/08/2018 à 10:59, Damien Martins a écrit : > > I installed libs test from hobbit-plugins_20180711_all.deb on a > > Debian 9.5. The issue is still pending. > > A workaround is to whitelist /[aio] file in /etc/xymon/libs.yaml file

Bug#879786: apt-secure man page needs to provide useful pointers for Release file info changes

2018-11-07 Thread Jesse Hathaway
On Wed, Nov 7, 2018 at 12:12 PM Julian Andres Klode wrote: > > On Wed, Nov 07, 2018 at 10:50:05AM -0600, Jesse Hathaway wrote: > > Just ran into this issue with chrome package from Google: > > > > E: Repository 'http://dl.google.com/linux/chrome/deb stable > > Release' changed its 'Origin'

Bug#838356: fixed in jboss-annotations-1.2-api 1.0.0-1

2018-11-07 Thread Timo Aaltonen
On 6.11.2018 18.35, Emmanuel Bourg wrote: > Hi Timo, > > We already have the javax.annotation API in the > geronimo-annotation-1.3-spec package. Is it really necessary to > duplicate it? I had no idea it was packaged and jboss-annotations is a dupe, I just followed what Fedora did. I'd need to

Bug#913161: nrss: pressing almost all keys has no effect

2018-11-07 Thread s3v
Package: nrss Version: 0.3.9-1+b3 Severity: grave Dear maintainer, I have created this content for ~/.nrss/config as suggested by the manpage: default_rate "5" default_show "30" default_maxitems "50" add "http://rss.slashdot.org/Slashdot/slashdotMain; "Slashdot" (Slashdot feed URL is

Bug#913156: [pkg-wicd-maint] Bug#913156: UnicodeDecodeError: 'ascii' codec can't decode byte 0xe2

2018-11-07 Thread Bryce Handerson
After some debugging myself it seems to happen when I have my iPhone's hotspot on with the iw scan SSID below SSID: Bryce\xe2\x80\x99s iPhone When I turn off the hotspot it opens correctly, However the weird thing. is I can open wicd-curses with the hotspot on and connect to it (which the

Bug#913174: globs: GL_shadow and GL_smoke segmentation fault

2018-11-07 Thread Witold Baryluk
Package: globs Version: 0.2.0~svn50-5 Severity: important GL_shadow and GL_smoke immediately segfaults I am guessing this is related to textures loaded from the .png files. If I run gl_smoke manually, with current directory being random, it says can't load a texture and shows gray smoke. But if

Bug#913156: UnicodeDecodeError: 'ascii' codec can't decode byte 0xe2

2018-11-07 Thread Bryce Handerson
Package: wicd-curses Version: 1.7.4+tb2-4 Severity: important Dear Maintainer, Trying to run wicd-curses results in a traceback, I have an `iw scan` log that was taken at the time of trying to run wicd-curses that I can attach if needed. The wicd, service is enabled and started, and seems to be

Bug#884635: transition: libupnp

2018-11-07 Thread Emilio Pozuelo Monfort
On 07/11/2018 12:03, Uwe Kleine-König wrote: > Hello James, > > On 11/5/18 6:58 PM, James Cowgill wrote: >> Hi, >> >> On 05/11/2018 17:28, Uwe Kleine-König wrote: >>> Hello Emilio, >>> >>> [adding jcowgill to recipients] >>> >>> On 11/05/2018 04:37 PM, Emilio Pozuelo Monfort wrote: Please

Bug#913159: task-kannada-desktop: uninstallable on mips and mipsel

2018-11-07 Thread Ivo De Decker
package: task-kannada-desktop version: 3.47 severity: serious Hi, task-kannada-desktop depends on 'firefox-esr-l10n-kn | firefox-l10n-kn', which is not installable on mips and mipsel, because the latest firefox doesn't build there (yet). Please move this dependency to recommends, as is done

Bug#913165: CVE-2018-7727 CVE-2018-7726 CVE-2018-7725

2018-11-07 Thread Moritz Muehlenhoff
Source: zziplib Severity: important Tags: security Please see https://security-tracker.debian.org/tracker/CVE-2018-7727 https://security-tracker.debian.org/tracker/CVE-2018-7726 https://security-tracker.debian.org/tracker/CVE-2018-7725 Cheers, Moritz

Bug#913181: ruby2.5: FTBFS with tzdata >= 2018f; patch attached

2018-11-07 Thread Adam Conrad
Package: ruby2.5 Version: 2.5.1-6 Severity: serious Tags: patch Justification: fails to build from source (but built successfully in the past) User: ubuntu-de...@lists.ubuntu.com Usertags: origin-ubuntu disco ubuntu-patch In Ubuntu, the attached patch was applied to achieve the following: *

Bug#913185: redis-server: Lua scripts cannot use cjson

2018-11-07 Thread Nicolas Le Manchet
Package: redis-server Version: 5:5.0.0-2~bpo9+1 Severity: important Dear Maintainer, After upgrading from Redis 4 to Redis 5, lua scripts cannot use the cjson library anymore. Expected: $ redis-cli EVAL 'cjson.decode("{}")' 0 (nil) Actual: $ redis-cli EVAL 'cjson.decode("{}")' 0

Bug#913099: Possible triage

2018-11-07 Thread Adam D. Barratt
On Tue, 2018-11-06 at 14:49 -0800, Felix Lechner wrote: > Thank you for identifying the offending commit. The error you are > seeing could be caused by the second assignment in: By default, nnn...@bugs.debian.org does not get sent to the submitter - you'll need to CC them explicitly. Regards,

Bug#911712: fixed in tigervnc 1.9.0+dfsg-2

2018-11-07 Thread Ivo De Decker
Control: reopen -1 Hi, On Mon, Oct 29, 2018 at 10:06:50AM +, Mike Gabriel wrote: >[ Christoph Biedl ] >* Add missing dependency on libunwind-dev. (Closes: #911712). Libunwind isn't used on every architecture, so on some architectures, the dependency is unnecessary. On s390x (and on

Bug#913196: netmrg: Debain/watch and debian/copyright point to spam site

2018-11-07 Thread Snahil Singh
Package: netmrg Version: 0.20-7.2 Severity: normal Dear Maintainer, Debian/watch and debian/copyright of netmrg points to spam site. Kindly update these to point to https://github.com/balleman/netmrg. PLease let me know if you have questions regarding this. Thank you Snahil Singh -- System

Bug#912426: git-debrebase: mangled conversion from base64

2018-11-07 Thread Ian Jackson
David Bremner writes ("Bug#912426: git-debrebase: mangled conversion from base64"): > A workaround seems to be round trip the patches via gbp-pq; this > switched the encoding to 8bit from base64. I tried this and it does just the same thing as git-debrebase does, as I would have predicted. That

Bug#881490: sysvinit-core: shutdown should default to -h

2018-11-07 Thread Jonathan de Boyne Pollard
Jesse Smith: 881490 (Feature requests asks that, when user provides no valid action for shutdown that we immediately power off, killing any running processes. This sounds terrible/dangerous and we will not implement it upstream. Report can be closed.) This is a wildly inaccurate

Bug#913204: ITP: node-i18next-xhr-backend -- backend layer for i18next using browsers xhr

2018-11-07 Thread Nicolas Mora
package: node-i18next Severity: whishlist Owner: 'Nicolas Mora' *Package Name : node-i18next Version : 1.5.1 Upstream Author : Jan Mühlemann *URL : https://github.com/i18next/i18next-xhr-backend *License : Expat *Description : This is a simple i18next backend to be used in the browser. It

Bug#903163: Adding OpenPGP smartcard support to LUKS

2018-11-07 Thread Kyle Rankin
On Tue, Nov 06, 2018 at 10:49:36PM +0100, Guilhem Moulin wrote: > On Tue, 06 Nov 2018 at 11:15:57 -0800, Kyle Rankin wrote: > > On Sun, Nov 04, 2018 at 02:38:29PM +0100, Guilhem Moulin wrote: > >> On Sun, 04 Nov 2018 at 05:35:44 -0500, Chris Lamb wrote: > >

Bug#911732: hiredis: Please backport 0.14.0 to stretch-backports

2018-11-07 Thread Chris Lamb
tags 911732 + pending retitle 911732 Please backport 0.14.0 to stretch-backports thanks This is now pending: 2018-11-07 11:35:55,814 - dput[31196]: uploader.invoke_dput - Uploading hiredis_0.14.0-3~bpo9+1.dsc 2018-11-07 11:35:56,515 - dput[31196]: uploader.invoke_dput - Uploading

Bug#912297: ansible: CVE-2018-16837

2018-11-07 Thread Chris Lamb
Hi Moritz, > > > From the upstream changelog for 2.7.1+dfsg-1 (already in unstable): > > [..] > > > - user module - do not pass ssh_key_passphrase on cmdline > > > (CVE-2018-16837) […] > We can fix that one in a DSA, but should also fix CVE-2018-10875 > and CVE-2018-10874, then. Cool. I will

Bug#911441: xfce4-systemload-plugin: High I/O read/writes causing I/O contention across the xfce desktop

2018-11-07 Thread ewe2
Hi, Upon further investigation, I've tracked the issue down to xfsettingsd constantly writing settings, and not systemload-plugin. I request that this bug be closed and I will log a bug against xfsettingsd. -- I love deadlines. I love the whooshing noise they make as they go by.

Bug#913120: cups-filters: please favor graphicsmagick-imagemagick-compat over imagemagick

2018-11-07 Thread Samuel Thibault
Hello, Moritz Mühlenhoff, le mer. 07 nov. 2018 23:04:55 +0100, a ecrit: > In this specific case other, more promising hardening options would be: > - IM is only used for the braille support, so this could be split into > a separate binary package, reducing the attack footprint for the

Bug#913141: [Pkg-opencl-devel] Bug#913141: beignet: Segmentation fault while running opencv_perf_dnn

2018-11-07 Thread Rebecca N. Palmer
That's a crash while trying to compile something. Is this bug present in LLVM 7? LLVM 3.9 has just been removed, so isn't an option. Do any of the tests (/usr/lib/x86_64-linux-gnu/beignet/utest_run from the beignet-dev package) also crash? Please install libllvm6.0-dbgsym and

Bug#586709: closed by Thomas Goirand

2018-11-07 Thread Ian Jackson
Control: reopen -1 Jesse Smith writes ("Bug#586709: closed by Thomas Goirand"): > Both of these assertions are mistaken. /etc/init.d/halt gets called as > part of the shutdown process. That's where it is getting run and the > script runs halt, passing the necessary parameters to match the

Bug#913205: python-urllib3: mythtv ttvdb.py fails with latest python-urllib3

2018-11-07 Thread James Bottomley
Package: python-urllib3 Version: 1.24-1 Severity: important Mythtv version 29.1+fixes20180821.gite5fc66e822-dmo2 is failing with mythtv@vito:~$ /usr/share/mythtv/metadata/Television/ttvdb.py -B Superstore Traceback (most recent call last): File "/usr/share/mythtv/metadata/Television/ttvdb.py",

Bug#913187: FTBFS on s390x

2018-11-07 Thread Sean Whitton
Package: haskell-dbus Version: 1.0.1-3 Severity: serious Tags: ftbfs Dear maintainer, haskell-dbus is failing to build on build on s390x. This is blocking at least git-annex from building on the buildds and then migrating to buster. [11 of 11] Compiling DBus.TH ( lib/DBus/TH.hs,

Bug#913192: qtwebengine5-examples: Instructions on how to compile the examples must be provided

2018-11-07 Thread Salvo Tomaselli
Package: qtwebengine5-examples Severity: grave Justification: renders package unusable Dear Maintainer, this packages provides source examples, and a binary that supposedly is compiled from them. However, there is no README, the usual qmake . && make won't work. So a package with examples that

Bug#913193: buildd.debian.org: Assign a mipsel/mips64el builder to *-backports

2018-11-07 Thread Emmanuel Bourg
Package: buildd.debian.org Severity: normal Hi, The mipsel/mips64el build queues for stretch-backports currently have a backlog of 97 packages, the last package was built 38 days ago. The builders have been busy with the sid/experimental uploads for over a month. It would be nice if at least

Bug#586709: closed by Thomas Goirand

2018-11-07 Thread Jesse Smith
On 11/7/18 7:04 PM, Jonathan de Boyne Pollard wrote: > > Jesse Smith is saying that invoking "halt -p" runs /sbin/halt, and > that works as designed and as documented in the halt(8) manual page.  > Whereas it does not invoke /etc/init.d/halt.  If "halt -p" runs > /etc/init.d/halt for you, then

Bug#913195: netmrg: Make netmrg reproducible

2018-11-07 Thread Snahil Singh
Package: netmrg Version: 0.20-7.2 Severity: important Tags: patch Dear Maintainer, While working on Reproducible Builds effort[0], I found that netmrg could not be built reproducibly because in the var/lib/rrd/Makefile.am, rrdtool is picking current time to create the database. So, in order to

Bug#913198: osmo-trx: Please enable LimeSDR support

2018-11-07 Thread Sebastian Reichel
Package: osmo-trx Version: 0.4.0-1 Severity: wishlist Hi, Please enable LimeSDR support (--with-lms). -- Sebastian

Bug#913202: ITP: node-i18next -- i18next internationalization framework

2018-11-07 Thread Nicolas Mora
package: node-i18next Severity: whishlist Owner: 'Nicolas Mora' *Package Name : node-i18next Version : 12.0.0 Upstream Author : Jan Mühlemann *URL : http://i18next.com *License : Expat *Description : i18next is a very popular internationalization framework for browser or any other

Bug#903163: Adding OpenPGP smartcard support to LUKS

2018-11-07 Thread Guilhem Moulin
On Wed, 07 Nov 2018 at 13:05:17 -0800, Kyle Rankin wrote: > I've tested these debs and can confirm everything works. Awesome, thanks for the feedback! > I was also able to add this support to an existing LUKS root partition > by just using luksAddKey and making sure the crypttab was updated and

Bug#912617: Fwd: Re: Bug#912617: libsdl2-image: CVE-2018-3977: do_layer_surface code execution vulnerability

2018-11-07 Thread Chris Lamb
(Forwarding for completeness) - Original message - From: Moritz Mühlenhoff To: Chris Lamb Cc: "Manuel A. Fernandez Montecelo" , t...@security.debian.org Subject: Re: Bug#912617: libsdl2-image: CVE-2018-3977: do_layer_surface code execution vulnerability Date: Wed, 7 Nov 2018 23:07:52

Bug#909682: Bug #909682: Memory leak with gst_tag_list_add_id3_image

2018-11-07 Thread Bernhard Übelacker
Now really with the mentioned file. # snapshot deb [check-valid-until=no] http://192.168.178.25:/debian-10-buster-snapshot.debian.org/ buster main deb-src [check-valid-until=no] http://192.168.178.25:/debian-10-buster-snapshot.debian.org/ buster main deb [check-valid-until=no]

Bug#714770: Still a problem on Ubuntu 18.04.1 LTS

2018-11-07 Thread Brent W. Baccala
Hi - I had a problem with this on Ubuntu 18.04.1 LTS (bionic). After installing the packages postfix and sasl2-bin, I then (after at least an hour of debugging), ended up putting in a symlink from /var/run/saslauthd to /var/spool/postfix/var/run/saslauthd. I didn't change much from the standard

Bug#909682: Bug #909682: Memory leak with gst_tag_list_add_id3_image

2018-11-07 Thread Bernhard Übelacker
Dear Maintainer, hello Anthony DeRobertis, I just tried to reproduce this issue in a buster amd64 qemu VM with a uptodate buster at 2018-09-27. On Wed, 26 Sep 2018 13:42:01 -0400 Anthony DeRobertis wrote: > Package: clementine > Version: 1.3.1+git565-gd20c2244a+dfsg-1 > Severity: normal > >

Bug#912297: ansible: CVE-2018-16837

2018-11-07 Thread Moritz Mühlenhoff
On Tue, Oct 30, 2018 at 12:35:05AM -0400, Chris Lamb wrote: > Hi Ivo, > > > From the upstream changelog for 2.7.1+dfsg-1 (already in unstable): > [..] > > - user module - do not pass ssh_key_passphrase on cmdline > > (CVE-2018-16837) > > Thanks for providing this and no problem that this

Bug#913190: bash-completion: Update 'java' completion to support '.java' files

2018-11-07 Thread Emmanuel Bourg
Package: bash-completion Version: 1:2.8-2 Severity: wishlist User: debian-j...@lists.debian.org Usertags: default-java11 .java files used to be compiled into .class files with 'javac' and then executed with 'java', but starting with Java 11 the explicit compilation can be skipped and the file

Bug#913189: /usr/bin/tclsh8.6: `file delete' can produce EFAULT

2018-11-07 Thread Ian Jackson
Package: tcl8.6 Version: 8.6.6+dfsg-1+b1 Severity: normal File: /usr/bin/tclsh8.6 To reproduce: $ rm -rf d $ mkdir d $ cd d $ rm -rf ../d $ env - pwd pwd: couldn't find directory entry in '..' with matching i-node $ tclsh8.6 % file delete spong error deleting "spong": bad address in system call

Bug#912730: RM: useragentswitcher/0.7.3-3

2018-11-07 Thread Moritz Mühlenhoff
On Wed, Nov 07, 2018 at 06:22:58AM +0100, Julien Aubin wrote: > On Sat, 03 Nov 2018 10:45:33 +0100 Moritz Muehlenhoff wrote: > > Package: release.debian.org > > Severity: normal > > User: release.debian@packages.debian.org > > Usertags: rm > > > > Broken with Firefox 60, please remove from

Bug#913191: override: libnids1.21/libs

2018-11-07 Thread Marcos Fouces
Package: ftp.debian.org Please move the libnids1.21 package to "libs" section. It was wrongly tagged as "libdevel". d/control file has already been updated and the proper package had also been uploaded. Greetings, Marcos

Bug#913200: laptop-mode-tools: major performance issues on battery with kernels >=4.18.9 and intel ahci

2018-11-07 Thread Tomas Ebenlendr
Package: laptop-mode-tools Version: 1.72-2 Severity: important Tags: patch Laptop-mode-tools puts SATA drives in DEVSLP on battery. Waking drives then takes several seconds, rendering all disk-using applications (web browser, Vim editor, ...) unresponsive for few seconds every often. Reason is

Bug#912426: git-debrebase: mangled conversion from base64

2018-11-07 Thread Ian Jackson
Control: reassign -1 git-buildpackage 0.8.12.2 Hi Guido. This is another weirdness with gbp pq conversion. To reproduce: git clone https://salsa.debian.org/bremner/nullmailer cd nullmailer git checkout -b bug912426 debian/1%2.1-7 less

Bug#549550: Clear patch tag

2018-11-07 Thread Gabriel F. T. Gomes
Control: tags -1 - patch After such a long time, the patch provided for this bug is no longer accessible, and even if it was, I doubt it would apply.

Bug#630521: Update tags

2018-11-07 Thread Gabriel F. T. Gomes
Control: tags -1 = unreproducible It looks like the bug is gone, so I'm setting it to unreproducible. After some time, if no one oposes, I'll close it. $ ls '!' file1 file2 file3 $ vi file file1 file2 file3 Michal, do you still see this problem?

Bug#913184: libsdl2-dev: Compiled applications see one keypress as two

2018-11-07 Thread Nicholas Ricciuti
Package: libsdl2-dev Version: 2.0.5+dfsg1-2 Severity: important Tags: newcomer Dear Maintainer, *** Reporter, please consider answering these questions, where appropriate *** * What led up to the situation? I was compiling various sdl2-based doom engines.Namely: eternity engine, crispy-doom,

Bug#913185: redis-server: Lua scripts cannot use cjson

2018-11-07 Thread Nicolas Le Manchet
Sorry for the incomplete bug report, I hit send too quickly. After upgrading from Redis 4 to Redis 5, lua scripts cannot use the cjson library anymore. Expected: $ redis-cli EVAL 'cjson.decode("{}")' 0 (nil) Actual: $ redis-cli EVAL 'cjson.decode("{}")' 0 (error) ERR Error

Bug#903603: ssh upgrade breaks in some openvz container

2018-11-07 Thread Joey Hess
Following up to this, I was running testing under this same openvz kernel, and I noticed that su displayed a similar message about setrlimit, and failed. So perhaps the problem is really in PAM? Or multiple things just don't work with that openvz kernel. -- see shy jo signature.asc

Bug#913194: virsh net-create fails if firewalld is installed, but not running

2018-11-07 Thread Martin Pitt
Package: libvirt-client Version: 4.7.0-1+b1 Version of firewalld: 0.6.3-1 When firewalld is installed, but not running, creating a libvirt network fails. Apparently libvirt is detecting that firewalld is installed, and then fails to talk to it: # systemctl status firewalld ● firewalld.service -

Bug#913153: img2pdf: Corrupted PDF with some PNG files

2018-11-07 Thread Johannes Schauer
Hi, Quoting Rogério Brito (2018-11-07 17:43:00) > First of all, thank you so very much for img2pdf. Once I found out about it, > I started using it extensively. > > Unfortunately, I found a bug when trying to convert a PNG file that I > acquired with Gnome's Simple Scan (I further optimized it

Bug#913188: new upstream version: 0.7.1

2018-11-07 Thread Hans-Christoph Steiner
Package: ruby-libvirt Version: 0.7.0-1 There is a new upstream version available with a bug fix. I'm happy to do an NMU on this, since I'm also helping to maintain vagrant-libvirt. https://libvirt.org/git/?p=ruby-libvirt.git;a=summary https://libvirt.org/ruby/download/ruby-libvirt-0.7.1.tgz

Bug#913120: cups-filters: please favor graphicsmagick-imagemagick-compat over imagemagick

2018-11-07 Thread Moritz Mühlenhoff
On Wed, Nov 07, 2018 at 08:44:25AM +0100, Jonas Smedegaard wrote: > Source: cups-filters > Version: 1.21.3-2 > Severity: important > Tags: security > > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA512 > > Graphicsmagick is a drop-in replacement for imagemagick which - apart > from being faster

Bug#913018: Update: bug is probably in laptop-mode-tools (linux-image-4.18.0-2-amd64: Chromium repeatedly freezes for few seconds on battery power after upgrade to 4.18.0-2)

2018-11-07 Thread ebik
By git bisect on linux-stable kernel tree I got to commit 0c8b7991f40d ata: libahci: Correct setting of DEVSLP register This suggested future research and I realized, that laptop-mode-tools sets drivers to lowest power mode which has setting BATT_SATA_POLICY=min_power in

Bug#913199: linux: Please enable CONFIG_DRM_DP_CEC on x86

2018-11-07 Thread Sebastian Reichel
Source: linux Version: 4.19~rc7-1~exp1 Severity: wishlist Hi, Please enable CONFIG_DRM_DP_CEC on x86, which can be used with some Displayport to HDMI adapters. -- Sebastian

Bug#913203: ITP: node-i18next-browser-languagedetector -- language detector used in browser environment for i18next

2018-11-07 Thread Nicolas Mora
package: node-i18next-browser-languagedetector Severity: whishlist Owner: 'Nicolas Mora' *Package Name : node-i18next-browser-languagedetector Version : 2.2.3 Upstream Author : Jan Mühlemann *URL : https://github.com/i18next/i18next-browser-languageDetector *License : Expat *Description :

Bug#821397: ITP: sway -- i3-compatible Wayland compositor

2018-11-07 Thread Jeremy Bicha
Sean, did you see the full email that added the pending tag? https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=821397;msg=56 Thanks, Jeremy Bicha

  1   2   3   >