Bug#942154: z3: Incomplete debian/copyright?

2019-10-10 Thread Chris Lamb
way exhaustive so please check over the entire package carefully and address these on your next upload. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Bug#942056: openvswitch: Incomplete debian/copyright?

2019-10-10 Thread Chris Lamb
Hi Thomas, > My last upload, which fixes it, goes again through NEW, as we (re-)added > the support for ipsec. This was just ACCEPTED. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org πŸ₯ chris-lamb.co.uk `-

Bug#942056: openvswitch: Incomplete debian/copyright?

2019-10-09 Thread Chris Lamb
in no way exhaustive so please check over the entire package carefully and address these on your next upload. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Bug#940973: libarchive-zip-perl breaks strip-nondeterminism autopkgtest: error: becoming Archive::Zip::DirectoryMember

2019-10-08 Thread Chris Lamb
tags 940973 + fixed-upstream thanks This has apparently been fixed (again) upstream in version 1.67: https://github.com/redhotpenguin/perl-Archive-Zip/issues/51#issuecomment-539679696 Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Bug#941474: networkx: Incomplete debian/copyright?

2019-10-01 Thread Chris Lamb
entire package carefully and address these on your next upload. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Bug#940973: libarchive-zip-perl breaks strip-nondeterminism autopkgtest: error: becoming Archive::Zip::DirectoryMember

2019-09-23 Thread Chris Lamb
notfound 940973 strip-nondeterminism/1.6.0-1 affects 940973 + strip-nondeterminism tags 940973 + fixed-upstream forwarded 940973 https://github.com/redhotpenguin/perl-Archive-Zip/issues/51 thanks Chris Lamb wrote: > Will investigate soon. This appears to be happening as libarchive-zip-perl 1

Bug#940973: libarchive-zip-perl breaks strip-nondeterminism autopkgtest: error: becoming Archive::Zip::DirectoryMember

2019-09-22 Thread Chris Lamb
://bugs.debian.org/858431 https://salsa.debian.org/reproducible-builds/strip-nondeterminism/issues/4 https://bugs.debian.org/931730 Will investigate soon. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org πŸ₯ chris-lamb.co.uk `-

Bug#830726: Regrabbing (was: Re: Bug#830726: xtrlock: CVE-2016-10894: xtrlock does not block multitouch events)

2019-09-22 Thread Chris Lamb
eper is awry given that locks persist beyond the end of the process. Best wishes, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org πŸ₯ chris-lamb.co.uk `-

Bug#940645: marked as pending in diffoscope

2019-09-18 Thread Chris Lamb
Control: tag -1 pending Hello, Bug #940645 in diffoscope reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/reproducible-builds/diffoscope/commit/7ddebfdc67a7f8ec5

Bug#940471: diffoscope: test failures

2019-09-17 Thread Chris Lamb
ed at the entire log > 2) test being skipped when ocaml-nox is not installed This is the route we have taken elsewhere and I have committed it in: https://salsa.debian.org/reproducible-builds/diffoscope/commit/bf83651d62a9717feba892a4b01d8d7ec28bac49 Best wishes, -- ,'&#x

Bug#940471: marked as pending in diffoscope

2019-09-17 Thread Chris Lamb
Control: tag -1 pending Hello, Bug #940471 in diffoscope reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/reproducible-builds/diffoscope/commit/bf83651d62a9717fe

Bug#940471: diffoscope: test failures

2019-09-16 Thread Chris Lamb
lc': 'ocamlc' This does not make immediate sense to me - ocamlc is provided by the ocaml-nox package which is listed in the Build-Depends and in the autopkgtest debian/tests/control file. Any ideas? Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org πŸ₯ chris-lamb.co.uk `-

Bug#940015: minder: Incomplete debian/copyright?

2019-09-11 Thread Chris Lamb
carefully and address these on your next upload. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Bug#940017: crypto-policies: Incomplete debian/copyright?

2019-09-11 Thread Chris Lamb
please check over the entire package carefully and address these on your next upload. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Bug#830726: Regrabbing(was: Re: Bug#830726: xtrlock: CVE-2016-10894: xtrlock does not block multitouch events)

2019-09-10 Thread Chris Lamb
eper is awry given that locks persist beyond the end of the process. Best wishes, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org πŸ₯ chris-lamb.co.uk `-

Bug#830726: xtrlock: CVE-2016-10894: xtrlock does not block multitouch events

2019-09-08 Thread Chris Lamb
4 days from right now so that we fallback to a previous iteration as you outline regardless of whether I get around to this or they fruitfully reply. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org πŸ₯ chris-lamb.co.uk `-

Bug#830726: xtrlock: CVE-2016-10894: xtrlock does not block multitouch events

2019-09-08 Thread Chris Lamb
t the maintainers of the Input Extension and see if they have any insight. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org πŸ₯ chris-lamb.co.uk `-

Bug#939659: golang-github-paypal-gatt: Incomplete debian/copyright?

2019-09-07 Thread Chris Lamb
least linux/socket/*. This is in no way exhaustive so please check over the entire package carefully and address these on your next upload. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Bug#939658: printrun: Incomplete debian/copyright?

2019-09-07 Thread Chris Lamb
posterity and not on this bug report. This is in no way exhaustive so please check over the entire package carefully and address these on your next upload. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Bug#939569: icingaweb2-module-statusmap: Incomplete debian/copyright?

2019-09-06 Thread Chris Lamb
, Robert Kieffer and Andrei Mackenzie. This is in no way exhaustive so please check over the entire package carefully and address these on your next upload. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Bug#939568: icingaweb2-module-graphite: Incomplete debian/copyright?

2019-09-06 Thread Chris Lamb
is in no way exhaustive so please check over the entire package carefully and address these on your next upload. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Bug#934026: python-django: CVE-2019-14232 CVE-2019-14233 CVE-2019-14234 CVE-2019-14235

2019-09-02 Thread Chris Lamb
Chris Lamb wrote: > > > +python-django (1:1.11.23-1~deb10u1) buster-security; urgency=high > > > > Thanks, these both look good; please upload to security-master. > > Both uploaded to security-master. There is now a 1.11.24 (ie. 1:1.11.24-1~deb10u1) upstream: htt

Bug#830726: xtrlock: CVE-2016-10894: xtrlock does not block multitouch events

2019-08-22 Thread Chris Lamb
hing that would want to try a few moments to avoid... (ignore that I'm using "xinput" per se) Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org πŸ₯ chris-lamb.co.uk `-

Bug#830726: xtrlock: CVE-2016-10894: xtrlock does not block multitouch events

2019-08-22 Thread Chris Lamb
ck: fprintf(stderr, "grabbing\n"); … at the top of the the handle_multitouch function and see whether that's even called when it gets re-enabled? Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org πŸ₯ chris-lamb.co.uk `-

Bug#830726: xtrlock: CVE-2016-10894: xtrlock does not block multitouch events

2019-08-21 Thread Chris Lamb
Chris Lamb wrote: > I've been working on an updated patch that detects new devices and > blocks them too. However, "grabbing" devices during the processing of > these "device hierarchy changed" events appears to do something funny > and actually disables a

Bug#830726: xtrlock: CVE-2016-10894: xtrlock does not block multitouch events

2019-08-20 Thread Chris Lamb
obviously doing something wrong and I'll have another run at it ASAP. Best wishes, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org πŸ₯ chris-lamb.co.uk `-

Bug#830726: xtrlock: CVE-2016-10894: xtrlock does not block multitouch events

2019-08-16 Thread Chris Lamb
Chris Lamb wrote: > Patch attached that works for me on my Dell XPS 13 Antoine, does the patch attached to: https://bugs.debian.org/830726#43 … also work for you? If so, I will go ahead and upload. Best wishes, -- ,''`. : :' : Chris Lamb `. `'

Bug#934034: Bug#934775: stretch-pu: package monkeysphere/0.41-1+deb9u1

2019-08-16 Thread Chris Lamb
loading agent-transfer-dbgsym_0.41-1+deb9u1_amd64.deb Uploading agent-transfer_0.41-1+deb9u1_amd64.deb Uploading monkeysphere_0.41-1+deb9u1_all.deb Uploading monkeysphere_0.41-1+deb9u1_amd64.buildinfo Uploading monkeysphere_0.41-1+deb9u1_amd64.changes $ echo $? 0 Best wishes, --

Bug#830726: xtrlock: CVE-2016-10894: xtrlock does not block multitouch events

2019-08-16 Thread Chris Lamb
tags 830726 + patch thanks Chris Lamb wrote: > CVE-2016-10894[0]: > | xtrlock through 2.10 does not block multitouch events. Consequently, > | an attacker at a locked screen can send input to (and thus control) > | various programs such as Chromium via events such as pan scrolling

Bug#934034: monkeysphere: FTBFS in stretch

2019-08-14 Thread Chris Lamb
underlying reasons for insisting on such a process. > Thanks for considering to fix bugs in stretch. No problem; thank you for your advice and patient guidance. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org πŸ₯ chris-lamb.co.uk `-

Bug#934034: monkeysphere: FTBFS in stretch

2019-08-13 Thread Chris Lamb
egards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org πŸ₯ chris-lamb.co.uk `-diff --git a/debian/control b/debian/control index 95750f4..19c4dbb 100644 --- a/debian/control +++ b/debian/control @@ -9,7 +9,7 @@ Build-Depends: cpio, debhelper (>=

Bug#934034: monkeysphere: FTBFS in stretch

2019-08-13 Thread Chris Lamb
egards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org πŸ₯ chris-lamb.co.uk `-diff --git a/debian/control b/debian/control index 95750f4..19c4dbb 100644 --- a/debian/control +++ b/debian/control @@ -9,7 +9,7 @@ Build-Depends: cpio, debhelper (>= 10~), d

Bug#934034: monkeysphere: FTBFS randomly (failing tests)

2019-08-10 Thread Chris Lamb
tags 934034 + patch tags 861457 - patch thanks [Adding 934...@bugs.debian.org to CC] Hi Santiago, > Maybe you mean #934034 instead of #861457? Wrong bug indeed. Fixing... Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.

Bug#934026: python-django: CVE-2019-14232 CVE-2019-14233 CVE-2019-14234 CVE-2019-14235

2019-08-10 Thread Chris Lamb
curity-master. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org πŸ₯ chris-lamb.co.uk `-

Bug#934026: python-django: CVE-2019-14232 CVE-2019-14233 CVE-2019-14234 CVE-2019-14235

2019-08-09 Thread Chris Lamb
(… although it's not a "re"-build of anything; 1.11.23 won't be in any other suite… :p) Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org πŸ₯ chris-lamb.co.uk `-

Bug#934026: python-django: CVE-2019-14232 CVE-2019-14233 CVE-2019-14234 CVE-2019-14235

2019-08-08 Thread Chris Lamb
nfirm the version we should use? > > 1:1.11.23-1~deb10u1? > > Looks good! Updated debdiff attached. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org πŸ₯ chris-lamb.co.uk `-diff --git a/Django.egg-info/PKG-INFO b/Django.egg-info/

Bug#934026: python-django: CVE-2019-14232 CVE-2019-14233 CVE-2019-14234 CVE-2019-14235

2019-08-08 Thread Chris Lamb
m my PoV Lintian should probably just waive that check > unless the target distro for the upload is "unstable". I took a different approach (to mirror similar existing logic) here: https://salsa.debian.org/lintian/lintian/commit/bcded0a16c1094ae55afdd65caca7f598e3be7fc Regard

Bug#934026: python-django: CVE-2019-14232 CVE-2019-14233 CVE-2019-14234 CVE-2019-14235

2019-08-08 Thread Chris Lamb
, given that > we agreed to follow 1.11.x in buster, shouldn't we rather use that one? D'oh, that makes more sense. Okay, I can prepare a debdiff for that -- however, can you just confirm the version we should use? 1:1.11.23-1~deb10u1? Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org πŸ₯ chris-lamb.co.uk `-

Bug#934026: python-django: CVE-2019-14232 CVE-2019-14233 CVE-2019-14234 CVE-2019-14235

2019-08-08 Thread Chris Lamb
ta about existing releases? How does it > know that 1:1.11.22-1 is missing? debian/changelog. Lintian, as a strict rule, does not query external sources. (I should probably clarify; missing *sequential* releases.) Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org πŸ₯ chris-lamb.co.uk `-

Bug#934026: python-django: CVE-2019-14232 CVE-2019-14233 CVE-2019-14234 CVE-2019-14235

2019-08-08 Thread Chris Lamb
.conf for new debian/buster branch. -- Chris Lamb Wed, 03 Jul 2019 15:18:13 -0300 … and that I've tentatively versioned the updated version to address these new CVEs as 1:1.11.22-1+deb10u1 (ie. with a plus, not a tilde). I mention it specifically as I'm not 100% confident this is corre

Bug#934026: python-django: CVE-2019-14232 CVE-2019-14233 CVE-2019-14234 CVE-2019-14235

2019-08-06 Thread Chris Lamb
[Adding t...@security.debian.org to CC] Chris Lamb wrote: > The following vulnerabilities were published for python-django. > > CVE-2019-14232[0]: > CVE-2019-14233[1]: > CVE-2019-14234[2]: > CVE-2019-14235[3]: I have just fixed this in sid and will fix this in jessie LTS

Bug#934026: marked as pending in python-django

2019-08-06 Thread Chris Lamb
Control: tag -1 pending Hello, Bug #934026 in python-django reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/python-team/modules/python-django/commit/0aa461b77c8

Bug#934026: python-django: CVE-2019-14232 CVE-2019-14233 CVE-2019-14234 CVE-2019-14235

2019-08-06 Thread Chris Lamb
?name=CVE-2019-14235 Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Bug#932339: marked as pending in lintian

2019-07-19 Thread Chris Lamb
ned-off-by: Chris Lamb (this message was generated automatically) -- Greetings https://bugs.debian.org/932339

Bug#931730: marked as pending in strip-nondeterminism

2019-07-15 Thread Chris Lamb
recursively depends on an XS binary Perl module which creates build cycle issues for Perl transitions. Use Sub::Override instead as it has no dependencies outside Perl core. Signed-off-by: Chris Lamb (this message was

Bug#931730: marked as pending in strip-nondeterminism

2019-07-15 Thread Chris Lamb
Control: tag -1 pending Hello, Bug #931730 in strip-nondeterminism reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/reproducible-builds/strip-nondeterminism/comm

Bug#931730: libfile-stripnondeterminism-perl: build dependency cycle with libsub-identify-perl

2019-07-15 Thread Chris Lamb
ations to your commit message as well as replaced the reference to "Monkey::Patch" in the Makefile.PL too. I added some comments to the "upstream" bug here: https://salsa.debian.org/reproducible-builds/strip-nondeterminism/issues/8#note_95760 Thanks again. Regards, --

Bug#931730: marked as pending in strip-nondeterminism

2019-07-15 Thread Chris Lamb
recursively depends on an XS binary Perl module which creates build cycle issues for Perl transitions. Use Sub::Override instead as it has no dependencies outside Perl core. Signed-off-by: Chris Lamb (this message was

Bug#931730: libfile-stripnondeterminism-perl: build dependency cycle with libmonkey-patch-perl

2019-07-12 Thread Chris Lamb
forwarded 931730 https://salsa.debian.org/reproducible-builds/strip-nondeterminism/issues/8 thanks I've "forwarded" this upstream here: https://salsa.debian.org/reproducible-builds/strip-nondeterminism/issues/8 Regards, -- ,''`. : :' :

Bug#931881: marked as pending in diffoscope

2019-07-12 Thread Chris Lamb
Control: tag -1 pending Hello, Bug #931881 in diffoscope reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/reproducible-builds/diffoscope/commit/372346e4990114f63

Bug#931881: diffoscope: undeclared versioned dependency on file

2019-07-12 Thread Chris Lamb
_FAIL_TESTS_ON_MISSING_TOOLS="foo bar" β†’ Fails; the required version is missing and unlisted. * DIFFOSCOPE_FAIL_TESTS_ON_MISSING_TOOLS="foo bar file" β†’ Skipped correctly. What am I missing here? :) (Note that I renamed this variable in d5b9daf04). Best wishes, --

Bug#931881: diffoscope: undeclared versioned dependency on file

2019-07-11 Thread Chris Lamb
TESTS_FAIL_ON_MISSING_TOOLS is not set. I think we need to add "file" to the DIFFOSCOPE_TESTS_MISSING_TOOLS list in debian/tests/pytest. Mattia, can you confirm? Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org πŸ₯ chris-lamb.co.uk `-

Bug#931730: libfile-stripnondeterminism-perl: build dependency cycle with libsub-identify-perl

2019-07-11 Thread Chris Lamb
would be best developed upstream. Archive-Zip seems > to be alive if quiet. But a bug against libarchive-zip-perl would be a > good start (with or without a patch). Nod. I'll work on a proper patch to libarchive-zip-perl over the next few days. Regards, -- ,''`. : :&#x

Bug#917847: ipsec-tools is unsuitable for inclusion in Debian

2019-07-11 Thread Chris Hofstaedtler
Hey Noah, * Noah Meyerhans [190711 14:17]: > If you disagree that ipsec-tools should be removed from future Debian > releases, please say so now. As we haven't really heard from anyone, should I go ahead and ask for final removal via ftpmaster? Cheers, Chris

Bug#931625: redis: CVE-2019-10192 CVE-2019-10193

2019-07-10 Thread Chris Lamb
9u3_amd64.changes * redis_5.0.3-4+deb10u1_amd64.changes Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org πŸ₯ chris-lamb.co.uk `-

Bug#931625: redis: CVE-2019-10192 CVE-2019-10193

2019-07-10 Thread Chris Lamb
rds, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Bug#931730: libfile-stripnondeterminism-perl: build dependency cycle with libsub-identify-perl

2019-07-09 Thread Chris Lamb
a restriction be of use to you? Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org πŸ₯ chris-lamb.co.uk `-

Bug#931709: marked as pending in diffoscope

2019-07-09 Thread Chris Lamb
Control: tag -1 pending Hello, Bug #931709 in diffoscope reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/reproducible-builds/diffoscope/commit/8e811480e6e8a8ee7

Bug#931625: redis: CVE-2019-10192 CVE-2019-10193

2019-07-08 Thread Chris Lamb
.org/tracker/CVE-2019-10193 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10193 Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Bug#922027: Bug#931316: python-django: CVE-2019-12308: Incorrect HTTP detection with reverse-proxy connecting via HTTPS

2019-07-02 Thread Chris Lamb
ed. It builds for me (with all tests passing) in a stretch chroot. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org πŸ₯ chris-lamb.co.uk `-diff --git a/debian/changelog b/debian/changelog index fa89c8b21..5bb1d6625 100644 --- a

Bug#931316: python-django: CVE-2019-12308: Incorrect HTTP detection with reverse-proxy connecting via HTTPS

2019-07-01 Thread Chris Lamb
stable? Best wishes, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org πŸ₯ chris-lamb.co.uk `-

Bug#931316: marked as pending in python-django

2019-07-01 Thread Chris Lamb
Control: tag -1 pending Hello, Bug #931316 in python-django reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/python-team/modules/python-django/commit/f3e2052b9d0

Bug#931097: installing python3.4 fails

2019-06-26 Thread Chris Lamb
reassign 931097 python3.4 forcemerge 931044 931097 thanks Thanks for filing this. However it was already filed as #931044 and the issue itself was fixed in python3.4 3.4.2-1+deb8u4. Hope that helps. Regards, -- ,''`. : :' : Chris Lamb `. `'` la..

Bug#907135: [Box Backup] Debian now requires 2048bit RSA keys

2019-06-10 Thread Chris Wilson
e 4.5 months to fix the issue from when you reported it to me, so unless a package has at least one full-time developer, a month simply isn't enough to fix this issue. Not even close for a hobbyist like myself. Thanks, Chris. On Sun, 9 Jun 2019 at 23:26, Reinhard Tartler wrote: > Agreed

Bug#907135: [Box Backup] Debian now requires 2048bit RSA keys

2019-06-09 Thread Chris Wilson
carefully whether this course of action was really in the best interests of its users. Thanks, Chris. Sent from my iPhone > On 7 Jun 2019, at 22:26, Reinhard Tartler wrote: > > > >> On Wed, Jun 5, 2019 at 7:46 PM Chris Wilson wrote: >> Hi Reinhard, >> >>

Bug#907135: [Box Backup] Debian now requires 2048bit RSA keys

2019-06-05 Thread Chris Wilson
Hi Reinhard, Could you have a look at this patch <https://github.com/boxbackup/boxbackup/compare/debian_10_fix_ssl> (documented here <https://github.com/boxbackup/boxbackup/wiki/WeakSSLCertificates#workaround-2>) to see if it's something like what you were hoping for? Thanks, C

Bug#929283: zookeeper: CVE-2019-0201: information disclosure vulnerability

2019-06-05 Thread Chris Lamb
[adding 929...@bugs.debian.org to CC] Hi Moritz, > > Sure. Here's my updated patch: Uploaded zookeeper_3.4.9-3+deb9u2_amd64.changes to security-master. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org πŸ₯ chris-lamb.co.uk `-

Bug#929283: zookeeper: CVE-2019-0201: information disclosure vulnerability

2019-06-04 Thread Chris Lamb
sclosure vulnerability where users +who were not authorised to read data were able to view the access control +list. (Closes: #929283) + + -- Chris Lamb Fri, 24 May 2019 08:57:53 +0100 + zookeeper (3.4.9-3+deb9u1) stretch-security; urgency=high * Team upload. diff -Nru zookeeper-3

Bug#929929: zfs smid

2019-06-03 Thread Chris Zubrzycki
Is there any chance to keep the removed exported symbol? Could you guys convince the kernel team? There’s no copyright issue since it’s released code, it’s just keeping a symbol that has been in exported in the kernel for the past 7 years. On top of that, Greg is violating the kernel release rul

Bug#907135: [Box Backup] Debian now requires 2048bit RSA keys

2019-05-31 Thread Chris Wilson
f not making Debian 10. I could create a special branch with a cut-down version of the solution, e.g. forcing the SecurityLevel to -1 (compatibility and warn) for the time being, in order to get the fix out in time for Debian 10, and then put the full version into backports? Thanks, Chris. On Fri, 3

Bug#929297: minissdpd: CVE-2019-12106

2019-05-27 Thread Chris Lamb
Hi Moritz, > > > Chris, thanks for your proposal to update Stretch, I very much > > > appreciate it. […] > This doesn't warrant a DSA, feel free to fix it via a point release instead. Sure thing. Proposed in #929613. Regards, -- ,''`. : :&#x

Bug#929269: coturn: overwrites database file /var/lib/turn/turndb on upgrade or reinstall

2019-05-26 Thread Chris Lamb
, avoiding overwriting it on upgrade/reinstall. (Closes: #929269) The full debdiff is attached. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- diffstat for coturn-4.5.1.1 coturn-4.5.1.1 changelog

Bug#929017: mutt: undefined behavior on huge integer in a RFC 2231 header

2019-05-25 Thread Chris Lamb
atoi() function was being called on a number which can potentially overflow and thus can have security implications depending on the atoi() implementation. (Closes: #929017) The full debdiff is attached. Regards, -- ,''`. : :' : Chris Lamb

Bug#929297: minissdpd: CVE-2019-12106

2019-05-25 Thread Chris Lamb
Hey, > > The following vulnerability was published for minissdpd. > > > > CVE-2019-12106[0]: > > | The updateDevice function in minissdpd.c in MiniUPnP MiniSSDPd 1.4 and > > | 1.5 allows a remote attacker to crash the process due to a Use After > > | Free vu

Bug#928883: libzorpll-dev: add Breaks

2019-05-24 Thread Chris Lamb
bssl1.0-dev for smoother upgrades from stretch. This resulted from the switch from libssl1.0-dev to libssl-dev. (Closes: #928883) The full debdiff is attached. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk

Bug#929283: zookeeper: CVE-2019-0201: information disclosure vulnerability

2019-05-24 Thread Chris Lamb
okeeper (3.4.9-3+deb9u2) stretch-security; urgency=high + + * CVE-2019-0201: Prevent an information disclosure vulnerability where users +who were not authorised to read data were able to view the access control +list. (Closes: #929283) + + -- Chris Lamb Fri, 24 May 2019 08:57:53 +0

Bug#929283: zookeeper: CVE-2019-0201: information disclosure vulnerability

2019-05-22 Thread Chris Lamb
[Adding t...@security.debian.org to CC] Hi, > zookeeper: CVE-2019-0201: information disclosure vulnerability Happy to prepare an update for stretch; I plan to do one for jessie LTS (which, helpfully, has the same version...) Regards, -- ,''`. : :'

Bug#929297: minissdpd: CVE-2019-12106

2019-05-22 Thread Chris Lamb
Hi, > > The following vulnerability was published for minissdpd. > > > > CVE-2019-12106[0]: > > | The updateDevice function in minissdpd.c in MiniUPnP MiniSSDPd 1.4 and > > | 1.5 allows a remote attacker to crash the process due to a Use After > > | Free vu

Bug#929297: minissdpd: CVE-2019-12106

2019-05-20 Thread Chris Lamb
Hi, > minissdpd: CVE-2019-12106 Security team, would you like me to prepare an upload for stretch here? Best wishes, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Bug#929297: minissdpd: CVE-2019-12106

2019-05-20 Thread Chris Lamb
2019-12106 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12106 Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Bug#907135: [Box Backup] Debian now requires 2048bit RSA keys

2019-05-19 Thread Chris Wilson
to know more, the issue is quite complex, and there are no easy answers, which is why it took so long to fix. I've done my best to describe it at https://github.com/boxbackup/boxbackup/wiki/WeakSSLCertificates. Please feel free to correct any mistakes that I've made. Thanks, Chris. On S

Bug#927946: python-audit: SWIG-related type errors render module unusable

2019-04-25 Thread Chris Hofstaedtler
Dear Maintainer, the following patch fixes the problem for me, tested locally. Please consider applying it. Cheers, Chris --- audit-2.8.4.orig/bindings/swig/src/auditswig.i +++ audit-2.8.4/bindings/swig/src/auditswig.i @@ -41,6 +41,6 @@ typedef unsigned __u32; typedef unsigned uid_t; %include

Bug#927180: firefox-esr: does not launch (Power Mac G5)

2019-04-24 Thread Chris Hofstaedtler
k you for your report, but I'm downgrading the severity because ppc64 is not a release architecture at this time. Thank you for your understanding. Chris

Bug#926698: fixed in cpio 2.12+dfsg-8

2019-04-23 Thread Chris Lamb
gt; package... Yeah, I've been a bit hands-off in case the original maintainer wishes to take this package over again but there are limits. ) Best wishes, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org πŸ₯ chris-lamb.co.uk `-

Bug#926698: cpio: messes with /usr/sbin/rmt in --merged-usr environment

2019-04-23 Thread Chris Lamb
Hi Niels, > Could either of you please have a look at this bug in cpio (you are > listed as Uploaders)? Even if it is just in the form of "ENOTME, NMU > welcome". Looks like an easy-enough fix... pending upload. Regards, -- ,''`. : :' :

Bug#853750: hdfview not usable

2019-04-21 Thread Chris Billington
If anyone is interested in resolving this bug, they might be interested in the Arch Linux AUR package: https://aur.archlinux.org/cgit/aur.git/tree/PKGBUILD?h=hdfview as an example of how to build HDFview 3 from source. I'm using HDFview 3 on Arch via this package and all is well. -Chris O

Bug#909750: applications tries to write to /usr/* directories via libfontconfig1

2019-04-17 Thread Chris Hofstaedtler
This bug disappeared from my logs long time ago, at least haven't seen > > any application reproducing it so far. > > Interestingly, Chris (just Cc'ed) claims to have reproduced it about a > week ago with libfontconfig1:amd64 using strace and to my knowledge > libf

Bug#927148: python-deprecated: Incomplete debian/copyright?

2019-04-15 Thread Chris Lamb
exhaustive so please check over the entire package carefully and address these on your next upload. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Bug#923986: ruby-pygments.rb: FTBFS randomly (failing tests)

2019-04-11 Thread Chris Lamb
sted my brief status update earlier. Best wishes, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org πŸ₯ chris-lamb.co.uk `-

Bug#926646: libdmtx: Incomplete debian/copyright?

2019-04-08 Thread Chris Lamb
GPL-2. This is in no way exhaustive so please check over the entire package carefully and address these on your next upload. Best wishes, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Bug#923986: ruby-pygments.rb: FTBFS randomly (failing tests)

2019-04-07 Thread Chris Lamb
d just disabling that one or (better) explicitly marking it as XFAIL. Best wishes, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org πŸ₯ chris-lamb.co.uk `-

Bug#917203: FTBFS on at least two architectures: test failure in the enigma algorithm

2019-04-07 Thread Chris Lamb
inholt) for the patch. (Closes: #917203) * Update Vcs-{Git,Browser} to point to salsa.debian.org. The full debdiff is attached. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- diffstat for libm

Bug#923930: FTBFS: FAIL test_chain (exit status: 1)

2019-04-07 Thread Chris Lamb
0+dfsg-2.1 (in sid) and it failed with: https://gist.githubusercontent.com/lamby/41c5d8aa85972c7c2b289296637dfa7e/raw (Uninvestigated.) Best wishes, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org πŸ₯ chris-lamb.co.uk `-

Bug#926587: roundup: CVE-2019-10904

2019-04-07 Thread Chris Lamb
.cgi?name=CVE-2019-10904 Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Bug#926578: faudio: Incomplete debian/copyright?

2019-04-07 Thread Chris Lamb
check over the entire package carefully and address these on your next upload. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Bug#897489: python-whoosh: FTBFS: dh_auto_test: pybuild --test --test-pytest -i python{version} -p 3.6 returned exit code 13

2019-04-07 Thread Chris Lamb
archive"). Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org πŸ₯ chris-lamb.co.uk `-

Bug#924151: grub2-common: wrong grub.cfg for efi boot and fully encrypted disk

2019-04-06 Thread Chris Hofstaedtler
tried this as well, and found it to work. Now both bug reports hint at upgrading packages, but my reproduction try did not need any upgrades as it was a fresh install. So maybe the key lies there... Cheers, Chris

Bug#919486: osinfo-db: diff for NMU version 0.20181120-1.1

2019-04-06 Thread Chris Hofstaedtler
Hi Guido, * Guido [190406 19:37]: > On Fri, Apr 05, 2019 at 11:50:54PM +0200, Chris Hofstaedtler wrote: > > * Guido GΓΌnther [190405 22:04]: > > > If we had stable links for CD images (3813797) this would be different > > > but I did not get around to look into this

Bug#916145: closure-compiler: Not working with recent JS code

2019-04-06 Thread Chris Hofstaedtler
great situation, its also not threatening to the packages in Debian using it, so I'd suggest keeping it for now. Adrian: you raised the severity, care to lower it until buster is out (or say some words on why)? Cheers, Chris (from the Salzburg BSP)

Bug#924762: a bug in xfce4? / triage

2019-04-06 Thread Chris Hofstaedtler
sted command lines. Thanks, Chris

<    2   3   4   5   6   7   8   9   10   11   >