Bug#611787: Two new security issues

2011-02-01 Thread Moritz Muehlenhoff
Package: mediawiki Severity: grave Tags: security Please see http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_16_2/phase3/RELEASE-NOTES Cheers, Moritz -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@l

Bug#600206: marked as done (libcompass-ruby: compass apparently completely broken)

2011-02-01 Thread Debian Bug Tracking System
Your message dated Wed, 02 Feb 2011 04:47:14 + with message-id and subject line Bug#600206: fixed in libcompass-ruby 0.10.6~dfsg-1 has caused the Debian Bug report #600206, regarding libcompass-ruby: compass apparently completely broken to be marked as done. This means that you claim that the

Processed: your mail

2011-02-01 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > found 600667 2.11.2-8 Bug #600667 [eglibc] eglibc: cve-2010-3847 dynamic linker expands $ORIGIN in setuid library search path There is no source info for the package 'eglibc' at version '2.11.2-8' with architecture '' Unable to make a source ver

Processed: Fw: re: eglibc: cve-2010-3847 dynamic linker expands $ORIGIN in setuid library search path

2011-02-01 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > reopen 600667 Bug #600667 {Done: "Florian Weimer,,," } [eglibc] eglibc: cve-2010-3847 dynamic linker expands $ORIGIN in setuid library search path 'reopen' may be inappropriate when a bug has been closed with a version; you may need to use 'found

Bug#600667: Fw: re: eglibc: cve-2010-3847 dynamic linker expands $ORIGIN in setuid library search path

2011-02-01 Thread Michael Gilbert
reopen 600667 thanks Maybe I'm reading things wrong, or maybe Mitre's information is actually incorrect, but it looks like the fixes claimed for CVE-2010-3847 in 2.11.2-8 actually address CVE-2010-3856 [0] instead. It looks like CVE-2010-3847 [1] is still unfixed. The original fix in -7 may have

Processed: your mail

2011-02-01 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > unarchive 600667 Bug #600667 {Done: "Florian Weimer,,," } [eglibc] eglibc: cve-2010-3847 dynamic linker expands $ORIGIN in setuid library search path Unarchived Bug 600667 > thanks Stopping processing here. Please contact me if you need assistan

Bug#611389: Please unblock videolink/1.2.9-2.1 NMU for #611389 and #611427

2011-02-01 Thread Nobuhiro Iwamatsu
On Wed, Feb 02, 2011 at 09:03:35AM +0900, Nobuhiro Iwamatsu wrote: > Hi, > > On Tue, Feb 01, 2011 at 06:35:15AM +, Adam D. Barratt wrote: > > Hi Nobuhiro, > > > > On Sun, 2011-01-30 at 07:24 +0900, Nobuhiro Iwamatsu wrote: > > > We lacked defined of the XPCOM_GLUE_USE_NSPRB. > > > I attached

Bug#611427: Bug#611389: videolink: FTBFS: error: 'struct nsID' has no member named

2011-02-01 Thread Nobuhiro Iwamatsu
Dear maintainer, I've prepared an NMU for videolink (version 1.2.9-2.1) and uploaded it to DELAYED/2. Please see changelog for more details. videolink (1.2.9-2.1) unstable; urgency=high * Non-maintainer upload. * Update debian/control. Add quilt to Build-Depends. * Add patches/611389.p

Bug#611427: Bug#611389: videolink: FTBFS: error: 'struct nsID' has no member named

2011-02-01 Thread Nobuhiro Iwamatsu
Hi, On Tue, Feb 01, 2011 at 06:35:15AM +, Adam D. Barratt wrote: > Hi Nobuhiro, > > On Sun, 2011-01-30 at 07:24 +0900, Nobuhiro Iwamatsu wrote: > > We lacked defined of the XPCOM_GLUE_USE_NSPRB. > > I attached the patch which revised this problem. > > Thanks for your work on these bugs. Wou

Processed: DD Address

2011-02-01 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > submitter 344136 ! Bug #344136 [ogmtools] ogmmerge Aborts and corrupts comments when given many comments Changed Bug submitter to 'Stefano Rivera ' from 'Stefano Rivera ' > submitter 391824 ! Bug #391824 [ez-ipupdate] Everydns support patch Chan

Processed: Re: Bug#611720: crack: apt purge does not remove /var/run/Crack/ and contents

2011-02-01 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > user release.debian@packages.debian.org Setting user to release.debian@packages.debian.org (was a...@adam-barratt.org.uk). > usertag 611720 + squeeze-can-defer Bug#611720: crack: apt purge does not remove /var/run/Crack/ and contents Ther

Bug#611720: crack: apt purge does not remove /var/run/Crack/ and contents

2011-02-01 Thread Adam D. Barratt
user release.debian@packages.debian.org usertag 611720 + squeeze-can-defer tag 611720 + squeeze-ignore thanks On Tue, 2011-02-01 at 11:49 +, Sam wrote: > 1) install crack (aptitude install crack) > 2) run crack (e.g. sudo Crack /etc/passwd) > 3) purge crack (aptitude purge crack) > > Expe

Bug#607193: document various download options/locations for Squeeze CD images

2011-02-01 Thread Simon Paillard
On Tue, Feb 01, 2011 at 11:10:01PM +0100, Julien Cristau wrote: > On Wed, Dec 15, 2010 at 15:32:50 +0100, Stefano Zacchiroli wrote: > > Package: www.debian.org > > Severity: important [..] > > We should document that on the website before the Squeeze release, obviously > > the prominent links shoul

Bug#611698: nodejs: conflicts with package node needlessly

2011-02-01 Thread Jérémy Lal
Hi, not having /usr/bin/node as nodejs binary path will without any doubt render nodejs package unuseful for a vast majority of users. It simply makes them use another package than the one in debian, and most of them, if not all, don't even take care of the possibility of name conflict between /sbi

Bug#603552: marked as done (update theme for squeeze)

2011-02-01 Thread Debian Bug Tracking System
Your message dated Tue, 01 Feb 2011 22:17:18 + with message-id and subject line Bug#603552: fixed in syslinux-themes-debian 5-1 has caused the Debian Bug report #603552, regarding update theme for squeeze to be marked as done. This means that you claim that the problem has been dealt with. If

Bug#607193: document various download options/locations for Squeeze CD images

2011-02-01 Thread Julien Cristau
On Wed, Dec 15, 2010 at 15:32:50 +0100, Stefano Zacchiroli wrote: > Package: www.debian.org > Severity: important > > Starting with Debian Squeeze, there will be (more) download options/locations > for CD images, be them netinst/complete/etc. In particular, users of specific > pieces of hardware

Bug#598101: marked as done (update syslinux theme for squeeze)

2011-02-01 Thread Debian Bug Tracking System
Your message dated Tue, 01 Feb 2011 23:05:26 +0100 with message-id <4d4883a6.8000...@debian.org> and subject line has caused the Debian Bug report #598101, regarding update syslinux theme for squeeze to be marked as done. This means that you claim that the problem has been dealt with. If this is

Bug#611142: Processed: tagging 611142

2011-02-01 Thread Julien Cristau
On Tue, Feb 1, 2011 at 17:54:09 +, Debian Bug Tracking System wrote: > Processing commands for cont...@bugs.debian.org: > > > tags 611142 + squeeze > Bug #611142 {Done: Filippo Rusconi } [massxpert] > massxpert: Program crashes when clicking left of first monomer vignette > Added tag(s) squ

Processed: Bug#608791: syslog-ng: dir_group not effective

2011-02-01 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > severity 608791 grave Bug #608791 {Done: Laszlo Boszormenyi (GCS) } [syslog-ng] syslog-ng: dir_group not effective Ignoring request to change severity of Bug 608791 to the same value. > End of message, stopping processing here. Please contact me

Bug#608791: marked as done (syslog-ng: dir_group not effective)

2011-02-01 Thread Debian Bug Tracking System
Your message dated Tue, 01 Feb 2011 19:32:07 + with message-id and subject line Bug#608791: fixed in syslog-ng 3.1.3-3 has caused the Debian Bug report #608791, regarding syslog-ng: dir_group not effective to be marked as done. This means that you claim that the problem has been dealt with. I

Bug#606340: This bug not completely fixed in 2:2.13.0-5

2011-02-01 Thread Alan W. Irwin
To follow up on my previous report, I have now had success with xserver-xorg-video-intel/2:2.13.0-5 on the 32-bit 945GME system. To recount the sequence of events, I originally encountered the error with the 2:2.13.0-5 version when trying to use "apt-get install xserver-xorg-video-intel" on a wor

Bug#611722: ndb: FTBFS: Fills up entire disk.

2011-02-01 Thread Kurt Roeckx
I get: make[3]: Entering directory `/build/buildd-nbd_2.9.20-1~1-i386-3DNXFh/nbd-2.9.20' gcc -DHAVE_CONFIG_H -I.-g -O2 -I/usr/include/glib-2.0 -I/usr/lib/glib-2.0/include -g -O2 -c -o nbd_tester_client-nbd-tester-client.o `test -f 'nbd-tester-client.c' || echo './'`nbd-tester-client.c gcc

Processed: Re: syslog-ng and dir_owner() + dir_group()

2011-02-01 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > severity 608791 grave Bug #608791 [syslog-ng] syslog-ng: dir_group not effective Severity set to 'grave' from 'normal' > End of message, stopping processing here. Please contact me if you need assistance. -- 608791: http://bugs.debian.org/cgi-b

Processed: tagging 611142

2011-02-01 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tags 611142 + squeeze Bug #611142 {Done: Filippo Rusconi } [massxpert] massxpert: Program crashes when clicking left of first monomer vignette Added tag(s) squeeze. > thanks Stopping processing here. Please contact me if you need assistance. --

Processed: found 611142 in 2.3.6-1

2011-02-01 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > found 611142 2.3.6-1 Bug #611142 {Done: Filippo Rusconi } [massxpert] massxpert: Program crashes when clicking left of first monomer vignette Bug Marked as found in versions massxpert/2.3.6-1. > thanks Stopping processing here. Please contact me

Processed: Changing severity

2011-02-01 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > severity 607372 grave Bug #607372 [phpunit] phpunit: Tries to use nonexisting file Severity set to 'grave' from 'important' > thanks Stopping processing here. Please contact me if you need assistance. -- 607372: http://bugs.debian.org/cgi-bin/b

Bug#611701: coffeescript: should no longer patch nodejs executable but instead depend on nodeje >= 0.2.6

2011-02-01 Thread Julien Cristau
On Tue, Feb 1, 2011 at 03:30:03 +0100, Jonas Smedegaard wrote: > Package: coffeescript > Version: 1.0.0-1 > Severity: grave > Justification: renders package unusable > > Nodejs packaging for Debian stopped renaming the executable since the > 0.2.6 release. So as subject says, coffeescript shoul

Bug#611698: nodejs: conflicts with package node needlessly

2011-02-01 Thread Julien Cristau
On Tue, Feb 1, 2011 at 01:43:27 +, brian m. carlson wrote: > Package: nodejs > Version: 0.2.6-1 > Severity: serious > Tags: experimental > > It appears that nodejs in experimental has acquired a Conflicts with > node. According to the changes file for that release: > >* Use upstream bi

Bug#602853: Workaround documented in errata

2011-02-01 Thread Julien Cristau
On Tue, Feb 1, 2011 at 08:14:05 +, Jurij Smakov wrote: > Thanks for providing a patch, it has been on my todo list for a while, > however I was not able to find time to take care of it so far. > > One of the users affected by this problem has confirmed that booting > with 'video=atyfb:off'

Bug#611725: chromium-browser: FTBFS on armel: selected processor does not support `smulbb ..'

2011-02-01 Thread Hector Oron
Package: chromium-browser Version: 9.0.597.83~r72435-1 Severity: serious Tags: sid Hello, Your package fails to build from source with assembler errors: CXX(target) out/Release/obj.target/skia_opts/third_party/skia/src/opts/SkBlitRow_opts_arm.o {standard input}: Assembler messages: {stand

Bug#611722: nbd: FTBFS: make check-TESTS failure

2011-02-01 Thread Hector Oron
Package: nbd Version: 1:2.9.20-1~1 Severity: serious Tags: sid Hello, Your package nbd fails to build from source in different arches: armel, powerpc, s390, .. On armel: make check-TESTS make[3]: Entering directory `/build/buildd-nbd_2.9.20-1~1-armel-i5VBn3/nbd-2.9.20' 4096+0 records in

Bug#611720: Acknowledgement (crack: apt purge does not remove /var/run/Crack/ and contents)

2011-02-01 Thread sam penny
I noticed that my purge hadn't also purged the auto-installed "crack-common" package, which I suspected might have been a part of the story, but I just purged that too and the /var/run/Crack/ directory is still there and still contains various files... Cheers & God bless Sam "SammyTheSnake" Penn

Bug#611720: crack: apt purge does not remove /var/run/Crack/ and contents

2011-02-01 Thread Sam
Package: crack Version: 5.0a-9.1 Severity: serious Justification: Policy 6.8 Steps to reproduce: 1) install crack (aptitude install crack) 2) run crack (e.g. sudo Crack /etc/passwd) 3) purge crack (aptitude purge crack) Expected results: crack is completely removed from the system Actual result

Bug#536376: [Pkg-e-devel] Bug#536376: evas: Not suitable for testing yet

2011-02-01 Thread Alexander Kurtz
Hi, Am Sonntag, den 08.08.2010, 23:31 +0200 schrieb Albin Tonnerre: > Given that Testing just got frozen, I guess it'll have to wait. By the time > Squeeze releases, things should have gotten closer to a release, and I'll > reconsider letting it go into testing. Well, Squeeze will release in a fe

Bug#609371: linux-image-2.6.37-trunk-sparc64: module scsi_mod: Unknown relocation: 36

2011-02-01 Thread Jesper Nilsson
On Tue, Feb 01, 2011 at 06:11:16AM +0100, David Miller wrote: > Jesper, could you please review this? Looks good! Acked-by: Jesper Nilsson > > klist: Fix object alignment on 64-bit. > > Commit c0e69a5bbc6fc74184aa043aadb9a53bc58f953b ("klist.c: bit 0 in > pointer can't be

Bug#602853: Workaround documented in errata

2011-02-01 Thread Jurij Smakov
Thanks for providing a patch, it has been on my todo list for a while, however I was not able to find time to take care of it so far. One of the users affected by this problem has confirmed that booting with 'video=atyfb:off' provides a workaround for this issue [0]. It has now been (or should