Bug#914291: jaxrs-api: copyright file wrong

2018-11-21 Thread Markus Koschany
Control: severity -1 normal Am 21.11.18 um 18:15 schrieb Thorsten Glaser: > Source: jaxrs-api > Version: 2.1.2-2 > Severity: serious > Justification: Policy 2.3, 12.5, possibly 2.1 > > In an internal Java™ project of $dayjob I was checking licences > of updated components and found that

Bug#914093: [mediathekview] Mediathelview hangs in startup

2018-11-19 Thread Markus Koschany
Am 19.11.18 um 12:55 schrieb Reinhard Karcher: > Am Montag, 19. November 2018, 12:51:03 CET schrieb Markus Koschany: >> Am 19.11.18 um 10:26 schrieb Reinhard Karcher: >>> Package: mediathekview >>> Version: 13.2.1-1 >>> Severity: grave >> >>>

Bug#914093: [mediathekview] Mediathelview hangs in startup

2018-11-19 Thread Markus Koschany
Am 19.11.18 um 10:26 schrieb Reinhard Karcher: > Package: mediathekview > Version: 13.2.1-1 > Severity: grave > > mediathekview hangs in startup: [...] Hi, thanks for the report. It appears libguava-java must be added as a runtime dependency too. This will be fixed shortly. Regards, Markus

Bug#913565: Bug #913565 in h2database marked as pending

2018-11-18 Thread Markus Koschany
Control: tag -1 pending Hello, Bug #913565 in h2database reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below, and you can check the diff of the fix at:

Bug#911858: Bug #911858 in controlsfx marked as pending

2018-11-18 Thread Markus Koschany
Control: tag -1 pending Hello, Bug #911858 in controlsfx reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below, and you can check the diff of the fix at:

Bug#913840: Bug #913840 in jackson-dataformat-xml marked as pending

2018-11-16 Thread Markus Koschany
Control: tag -1 pending Hello, Bug #913840 in jackson-dataformat-xml reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below, and you can check the diff of the fix at:

Bug#913764: mozilla-noscript: FTBFS because of dh_webext UnicodeDecodeError

2018-11-14 Thread Markus Koschany
Source: mozilla-noscript Version: 10.1.9.6-2 Severity: serious Hi, mozilla-noscript currently FTBFS because of https://buildd.debian.org/status/fetch.php?pkg=mozilla-noscript=all=10.1.9.6-2=1537976571=0 dh_webext: Ignored some command-line arguments: ['-i'] Traceback (most recent call last):

Bug#893345: Bug #893345 in javafxsvg marked as pending

2018-11-14 Thread Markus Koschany
Control: tag -1 pending Hello, Bug #893345 in javafxsvg reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below, and you can check the diff of the fix at:

Bug#912393: Bug #912393 in scala marked as pending

2018-11-10 Thread Markus Koschany
Control: tag -1 pending Hello, Bug #912393 in scala reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below, and you can check the diff of the fix at:

Bug#912916: mysql-connector-java: CVE-2018-3258: allows low privileged attacker to compromise it

2018-11-09 Thread Markus Koschany
Control: retitle -1 mysql-connector-java: removal from Debian Control: block -1 by 913323 913354 913360 913343 913362 So here we go. The removal of mysql-connector-java is currently blocked by five bugs. I have submitted patches for four of them and I will take care of netbeans myself. I'm

Bug#895765: IGV FTBFS with Java 11

2018-11-09 Thread Markus Koschany
the necessary changes to the Debian packaging without using a patch. Markus From 86feef76191c245ec314f1efc66f0f6dfba1a634 Mon Sep 17 00:00:00 2001 From: Markus Koschany Date: Fri, 9 Nov 2018 16:14:47 +0100 Subject: [PATCH 1/2] B-D on libjaxb-api-java and fix FTBFS with Java 11. --- debian/control

Bug#912916: mysql-connector-java: CVE-2018-3258: allows low privileged attacker to compromise it

2018-11-08 Thread Markus Koschany
Am 08.11.18 um 19:34 schrieb Moritz Mühlenhoff: [...] > So upon a closer look this seems to only affect the 8.x releases of the > connector (Oracle only lists those affected release series which are > affected and this only lists 8.x, while 5.1.x is still supported; there's > a 5.1.47 release). >

Bug#910748: Bug #910748 in lombok marked as pending

2018-11-08 Thread Markus Koschany
Control: tag -1 pending Hello, Bug #910748 in lombok reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below, and you can check the diff of the fix at:

Bug#912546: Bug #912546 in jackson-module-jaxb-annotations marked as pending

2018-11-07 Thread Markus Koschany
Control: tag -1 pending Hello, Bug #912546 in jackson-module-jaxb-annotations reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below, and you can check the diff of the fix at:

Bug#913011: eboard: add Conflicts: eboard-extras-pack1

2018-11-06 Thread Markus Koschany
Control: tags -1 pending Thanks for reporting. The extra packs are included in eboard now. I have updated the Breaks and Replaces fields in debian/control and I am going to request the removal of eboard-extras-pack1 from Debian. Regards, Markus signature.asc Description: OpenPGP digital

Bug#912997: glusterfs: Several security vulnerabilities

2018-11-05 Thread Markus Koschany
Package: glusterfs X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerabilities were published for glusterfs. CVE-2018-14651[0]: | It was found that the fix for CVE-2018-10927, CVE-2018-10928, | CVE-2018-10929, CVE-2018-10930, and CVE-2018-10926 was

Bug#912916: mysql-connector-java: CVE-2018-3258: allows low privileged attacker to compromise it

2018-11-05 Thread Markus Koschany
Am 05.11.18 um 14:13 schrieb Moritz Mühlenhoff: [...] > The Java connector follows the horrible Oracle policy of not disclosing > vulnerability information. Given that we now have mariadb-connector-java > in the archive (with a transparent upstream), can we migrate existing > reverse deps

Bug#912916: mysql-connector-java: CVE-2018-3258: allows low privileged attacker to compromise it

2018-11-04 Thread Markus Koschany
Package: mysql-connector-java X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerability was published for mysql-connector-java. CVE-2018-3258[0]: | Vulnerability in the MySQL Connectors component of Oracle MySQL | (subcomponent: Connector/J).

Bug#911194: libbtm-java: FTBFS with Java 11 due to javax.rmi removal

2018-11-03 Thread Markus Koschany
libbtm-java looks like a removal candidate for me. Last release was in 2012, project looks pretty much stalled. https://github.com/bitronix/btm The only r-dep is ehcache which uses libbtm-java for its tests. signature.asc Description: OpenPGP digital signature

Bug#912541: Bug #912541 in libjackson-json-java marked as pending

2018-11-03 Thread Markus Koschany
Control: tag -1 pending Hello, Bug #912541 in libjackson-json-java reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below, and you can check the diff of the fix at:

Bug#912642: Bug #912642 in activemq marked as pending

2018-11-02 Thread Markus Koschany
Control: tag -1 pending Hello, Bug #912642 in activemq reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below, and you can check the diff of the fix at:

Bug#912547: Bug #912547 in libpicocontainer-java marked as pending

2018-11-02 Thread Markus Koschany
Control: tag -1 pending Hello, Bug #912547 in libpicocontainer-java reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below, and you can check the diff of the fix at:

Bug#910764: Forward 910764 OpenJFX 11 segmentation fault

2018-10-31 Thread Markus Koschany
Control: severity -1 important On Tue, 30 Oct 2018 14:39:11 +0100 Markus Koschany wrote: > Control: forwarded -1 > https://bugs.java.com/bugdatabase/view_bug.do?bug_id=JDK-8213149 > thanks > > Look like upstream can't reproduce this issue with their custom JDK image. >

Bug#912295: Bug #912295 in jboss-jdeparser2 marked as pending

2018-10-30 Thread Markus Koschany
Control: tag -1 pending Hello, Bug #912295 in jboss-jdeparser2 reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below, and you can check the diff of the fix at:

Bug#906837: xul-ext-ublock-origin no longer works with firefox-esr 60

2018-10-30 Thread Markus Koschany
Am 30.10.18 um 18:25 schrieb Thierry: > Adrian Bunk wrote: > >> Package: xul-ext-ublock-origin >> Version: 1.10.4+dfsg-1 >> Severity: serious >> Control: fixed -1 1.16.6+dfsg-1 >> Control: close -1 >> >> XUL addons are no longer supported. >> >> This is already fixed in unstable. > > OK, but

Bug#910764: Forward 910764 OpenJFX 11 segmentation fault

2018-10-30 Thread Markus Koschany
Control: forwarded -1 https://bugs.java.com/bugdatabase/view_bug.do?bug_id=JDK-8213149 thanks Look like upstream can't reproduce this issue with their custom JDK image. signature.asc Description: OpenPGP digital signature

Bug#911187: axis: FTBFS with Java 11 due to javax.rmi and CORBA removal

2018-10-30 Thread Markus Koschany
I was investigating the Java 11 FTBFS of axis and uddi4j. I wonder if we rather should focus on removing these packages instead of patching them. Axis has seen its last release in 2006. AFAIK Apache CXF would be a better alternative because it is actively maintained. Unfortunately it is not

Bug#912221: jabref: incompatible with openjdk 11

2018-10-30 Thread Markus Koschany
Am 30.10.18 um 01:15 schrieb Emmanuel Bourg: > Le 30/10/2018 à 00:41, gregor herrmann a écrit : > >> I guess we need to make sure that we build with openjdk-8. >> (You know this better than me but I seem to remember that the plan >> was to keep openjdk-8 in buster for building packages?) > > No

Bug#912231: bnd FTBFS with OpenJDK 11

2018-10-29 Thread Markus Koschany
ava:372) /usr/bin/mh_installpom: line 148: debian/.mh/pom.properties: No such file or directory make: *** [debian/rules:9: binary] Error 1 From: Markus Koschany Date: Mon, 29 Oct 2018 20:36:31 +0100 Subject: java11 Fix biz.aQute.remote/src/aQute/remote/agent/RedirectOutput.java:41: error: nullOutputStrea

Bug#911980: Bug #911980 in objenesis marked as pending

2018-10-28 Thread Markus Koschany
Control: tag -1 pending Hello, Bug #911980 in objenesis reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below, and you can check the diff of the fix at:

Bug#892434: Bug #892434 in scorched3d marked as pending

2018-10-27 Thread Markus Koschany
Control: tag -1 pending Hello, Bug #892434 in scorched3d reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below, and you can check the diff of the fix at:

Bug#892351: Bug#911487: teeworlds: remote DOS by forging connection packets

2018-10-25 Thread Markus Koschany
Control: owner -1 ! I'm currently working on updating Teeworlds to version 0.7. Markus signature.asc Description: OpenPGP digital signature

Bug#911093: libjetbrains-annotations-java: missing Breaks+Replaces: libintellij-annotations-java (<< 16.0.2-4)

2018-10-25 Thread Markus Koschany
On Mon, 15 Oct 2018 17:48:38 +0200 Andreas Beckmann wrote: > Package: libjetbrains-annotations-java > Version: 16.0.2-4 > Severity: serious > User: debian...@lists.debian.org > Usertags: piuparts replaces-without-breaks > > Hi, > > during a test with piuparts and DOSE tools I noticed your

Bug#910764: openjfx: segmentation fault in GtkNativeMainLoopThread

2018-10-24 Thread Markus Koschany
I believe I have found a way to workaround this issue for the moment. If I pass -Djdk.gtk.version=2 to PDFsam version 3.3.7 it no longer crashes. However there is another issue with fontawesomefx, so there is still some work to do. I think I will forward this issue to the OpenJFX developers

Bug#886394: pdfsam still shows the same error although it does give the banner as gimp does while starting up.

2018-10-23 Thread Markus Koschany
Control: forwarded -1 https://github.com/torakiki/pdfsam/issues/310 thanks Apparently upstream managed to run PDFsam with OpenJFX 11. I'm currently investigating why it doesn't work for us. signature.asc Description: OpenPGP digital signature

Bug#856086: Bug#885037: Patch for monster-masher

2018-10-21 Thread Markus Koschany
Am 21.10.18 um 23:51 schrieb Yavor Doganov: > Markus Koschany wrote: >> I only noticed that the Close button in the "Info" submenu doesn't >> work as intended. > > There is no "Info" submenu; I guess you mean the Close button in the > About dialog?

Bug#856086: Patch for monster-masher

2018-10-21 Thread Markus Koschany
Hi! Thanks again for your patches to port monster-masher away from esound and gconfmm. I only noticed that the Close button in the "Info" submenu doesn't work as intended. Otherwise the game seems to work. Minor nitpick: Please consider to submit a debdiff for future patches because it is easier

Bug#887600: Bug #887600 in asc marked as pending

2018-10-21 Thread Markus Koschany
Control: tag -1 pending Hello, Bug #887600 in asc reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below, and you can check the diff of the fix at:

Bug#911487: teeworlds: remote DOS by forging connection packets

2018-10-20 Thread Markus Koschany
I have just requested a CVE id for this issue. Upstream clarified the fixing commits. They are https://github.com/teeworlds/teeworlds/commit/a263185571903ead01f6b351a91ea219ac9d215f https://github.com/teeworlds/teeworlds/commit/aababc63e1bc41672502ca6c7a1dd9f61d94

Bug#911487: teeworlds: remote DOS by forging connection packets

2018-10-20 Thread Markus Koschany
Hi, Am 20.10.18 um 21:01 schrieb Salvatore Bonaccorso: [...] > For 0.6.5 the following two commits might be the relevant ones (not > found any further possibly releated): > > https://github.com/teeworlds/teeworlds/commit/4c00063b2fd9c25998f3d308723e1ae65c20548d >

Bug#911487: teeworlds: remote DOS by forging connection packets

2018-10-20 Thread Markus Koschany
Package: teeworlds-server Version: 0.6.4+dfsg-1 Severity: grave Tags: security It was discovered that a Teeworlds server could be made inaccessible by forging connection packets. This made it look like the server was always full thus access to the server was effectively denied. My own private

Bug#910395: mediathekview with openjfx 11

2018-10-16 Thread Markus Koschany
I have decided to split the issue into smaller parts. I'm going to fix the JavaFX 11 "not found" issue by using the --add-modules option in mediathekview's wrapper script. I don't even have to patch the sources then. Another patch will ensure compatibility with the default-jdk version in Debian.

Bug#910395: mediathekview with openjfx 11

2018-10-15 Thread Markus Koschany
Hi, Am 15.10.18 um 19:45 schrieb Erich Schubert: > Hi, > > It seems the classpath is not set up correctly. > > With Java 11 as my main java, the following works: > > java -cp >

Bug#911079: [pdfsam] Window blank

2018-10-15 Thread Markus Koschany
Control: tags -1 unreproducible Control: severity -1 important Am 15.10.18 um 14:11 schrieb Marco Righi: > Package: pdfsam > Version: 1.1.4-4 > Severity: grave > > --- Please enter the report below this line. --- > Hi, > After pdfsam execution appears only a little box (see image_1). > After

Bug#911078: triplea: Fails to start with NullPointerException

2018-10-15 Thread Markus Koschany
Package: triplea Version: 1.9.0.0.7062-2 Severity: grave Justification: renders package unusable After the switch to OpenJFX 11, triplea fails to start with a NullPointerException. triplea.engine.version.bin:1.9 java.lang.NullPointerException at

Bug#910807: webext-ublock-origin: Does not work with firefox

2018-10-11 Thread Markus Koschany
Control: tags -1 confirmed pending Am 11.10.18 um 16:24 schrieb Eugen Dedu: > Package: webext-ublock-origin > Version: 1.17.0+dfsg-1 > Severity: grave > Justification: renders package unusable > > Dear Maintainer, > > After upgrading to 1.17.0+dfsg-1 version, the package does not work with >

Bug#910585: Bug #910585 in openjfx marked as pending

2018-10-09 Thread Markus Koschany
Control: tag -1 pending Hello, Bug #910585 in openjfx reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below, and you can check the diff of the fix at:

Bug#910585: openjfx: no glassgtk3 in java.library.path

2018-10-09 Thread Markus Koschany
Package: openjfx Version: 11+26-3 Followup-For: Bug #910585 Ok, that fixed the initial issue but now I get a core dump... Attached is the log file. # # A fatal error has been detected by the Java Runtime Environment: # # SIGSEGV (0xb) at pc=0x0001, pid=23180, tid=23230 # # JRE

Bug#910585: openjfx: no glassgtk3 in java.library.path

2018-10-09 Thread Markus Koschany
Control: tags -1 pending I believe the issue is caused by a missing build-dependency on libgtk-3-dev. signature.asc Description: OpenPGP digital signature

Bug#910395: Bug#910611: openjfx: draws mediathekview and pdfsam unusable

2018-10-08 Thread Markus Koschany
Control: forcemerge 910395 910611 Am 08.10.18 um 19:37 schrieb Philip Rinn: > Package: openjfx > Version: 11+26-3 > Severity: normal > > Hi, > > since some days (sadly I don't know it the 8 -> 11 update triggered this) > mediathekview and pdfsam don't start anymore: Hi, we are aware of the

Bug#893194: Bug #893194 in fontawesomefx marked as pending

2018-10-08 Thread Markus Koschany
Control: tag -1 pending Hello, Bug #893194 in fontawesomefx reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below, and you can check the diff of the fix at:

Bug#910585: openjfx: no glassgtk3 in java.library.path

2018-10-08 Thread Markus Koschany
Package: openjfx Version: 11+26-3 Severity: serious I have made significant progress with packaging a newer version of MediathekView. However when I try to run the application I get a RuntimeException which indicates that some package is missing. I suspect libopenjfx-jni is the culprit.

Bug#910495: openjfx FTBFS on !x86: offlineasm: No magic values found. Skipping assembly file generation.

2018-10-07 Thread Markus Koschany
Am 07.10.18 um 18:21 schrieb Markus Koschany: > The patch contained a mistake but I just tried it on plummer.debian.org > (ppc64el porterbox) and it unfortunately doesn't make any difference. I should have added that I still think it has something to do with the disabled JIT. The aforemen

Bug#910495: openjfx FTBFS on !x86: offlineasm: No magic values found. Skipping assembly file generation.

2018-10-07 Thread Markus Koschany
The patch contained a mistake but I just tried it on plummer.debian.org (ppc64el porterbox) and it unfortunately doesn't make any difference. signature.asc Description: OpenPGP digital signature

Bug#910495: openjfx FTBFS on !x86: offlineasm: No magic values found. Skipping assembly file generation.

2018-10-07 Thread Markus Koschany
Am 07.10.18 um 14:31 schrieb Emmanuel Bourg: > Control; severity -1 important > > Downgrading the severity, upstream doesn't support non x86 architectures > and the packages are only provided as a best effort. I believe this issue is related to the patches that disable JIT compilation. After

Bug#905215: CVE-2018-2941

2018-10-07 Thread Markus Koschany
Am 07.10.18 um 13:16 schrieb Moritz Muehlenhoff: [...] > No, unfortunately it's the same "we fix, but don't tell" bullshit policy > as with all other Oracle products. > > Given that mediathekview is our only reverse dependency in stretch we > can probably mark it as ignored for stretch anyway?

Bug#905215: CVE-2018-2941

2018-10-07 Thread Markus Koschany
Hi, On Wed, 01 Aug 2018 16:45:30 +0200 Moritz Muehlenhoff wrote: > Source: openjfx > Severity: grave > Tags: security > > http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html > fixed CVE-2018-2941 in JavaFX, which should affect our openjfx package. We have recently

Bug#910501: openjfx: Installs javafx.control jar for javafx.web jar

2018-10-07 Thread Markus Koschany
Package: openjfx Version: 11+26-1 Severity: serious OpenJFX installs the javafx.control jar for javafx.web.jar. Most likely a copy error in libopenjfx-java.poms. This means that web related classes are missing which makes e.g. mediathekview FTBFS. Markus

Bug#906383: lombok-patcher: FTBFS in buster/sid

2018-10-02 Thread Markus Koschany
Control: tags -1 pending Control: block -1 by 910112 Fix is ready to upload in Git but blocked by #910112. signature.asc Description: OpenPGP digital signature

Bug#910112: javahelper: jh_linkjars is broken because of fix for multiple dep fields and newlines

2018-10-02 Thread Markus Koschany
Package: javahelper Version: 0.68 Severity: serious The recent javahelper update broke jh_linkjars. This commit introduced the regression https://salsa.debian.org/java-team/javatools/commit/a87bc535da1dcba04e0e5fdca524e00c43de3efe The error manifests for example in lombok-ast and

Bug#909999: ghostscript (via pdf2ps) crashes on most inputs following upgrade to 9.06~dfsg-2+deb8u9

2018-10-01 Thread Markus Koschany
Am 01.10.18 um 06:13 schrieb Berkeley Roshan Churchill: > Package: ghostscript > Version: 9.06~dfsg-2+deb8u9 > Severity: grave > Justification: renders package unusable > > Dear Maintainer, > >* What led up to the situation? > > Ghostscript was upgraded to 9.06~dfsg-2+deb8u9 > >* What

Bug#909076: ghostscript: ps2ascii crashes: Error: /typecheck in --.bind--

2018-09-29 Thread Markus Koschany
I have tried some of those commits: http://git.ghostscript.com/?p=ghostpdl.git=search=HEAD=commit=txtwrite This one adds even more whitespace and moves the 1 character further to the right. http://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=d0d4e282f98487ca2979edbaf6834d9341bcee53 This

Bug#909076: ghostscript: ps2ascii crashes: Error: /typecheck in --.bind--

2018-09-28 Thread Markus Koschany
Hi, Am 28.09.18 um 20:54 schrieb Salvatore Bonaccorso: [...] > So this would imply changed behaviour in a stable release, and thus > need extra care to not break more (ps2ascii might not be widely used > still). Thanks for sharing this information. I agree that changed behavior in a stable

Bug#909076: ghostscript: ps2ascii crashes: Error: /typecheck in --.bind--

2018-09-28 Thread Markus Koschany
Hi, Am 28.09.18 um 00:16 schrieb Salvatore Bonaccorso: > Hi Markus, > > On Thu, Sep 27, 2018 at 10:33:06PM +0200, Markus Koschany wrote: [...] >> The text is correctly displayed now in Jessie but the Stretch version >> shows Chinese characters instead. Hence I would apprecia

Bug#909076: ghostscript: ps2ascii crashes: Error: /typecheck in --.bind--

2018-09-27 Thread Markus Koschany
Hi, I believe I have found the solution to this problem. Apparently they changed the underlying device for ps2ascii to txtwrite last year. http://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=2fa6beaa40144c592661a611bf35ff6f06d3354f If I apply this commit in Jessie, ps2ascii appears to work

Bug#909739: php-horde: CVE-2017-16907 XSS via Color field

2018-09-27 Thread Markus Koschany
Package: php-horde X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerability was published for php-horde. CVE-2017-16907[0]: | In Horde Groupware 5.2.19 and 5.2.21, there is XSS via the Color field | in a Create Task List action. If you fix the

Bug#909738: php-horde-kronolith: CVE-2017-16908 XSS via Name field

2018-09-27 Thread Markus Koschany
Package: php-horde-kronolith X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerability was published for php-horde-kronolith. CVE-2017-16908[0]: | In Horde Groupware 5.2.19, there is XSS via the Name field during | creation of a new Resource. This can

Bug#909737: php-horde-kronolith: CVE-2017-16906 XSS via URL field

2018-09-27 Thread Markus Koschany
Package: php-horde-kronolith X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerability was published for php-horde-kronolith. CVE-2017-16906[0]: | In Horde Groupware 5.2.19-5.2.22, there is XSS via the URL field in a | "Calendar - New Event" action.

Bug#909000: Enigmail 2.0 needed in Stretch after Thunderbird 60 upload

2018-09-20 Thread Markus Koschany
Hey, just wanted to chime in here. I successfully backported the Buster version of enigmail to Stretch by removing the versioned dependency on gnupg. So far I haven't experienced any difficulties. Of course this isn't a solution for the OpenPGP.js problem but at least to me it seems that the

Bug#909244: kobodeluxe not playable - immediately pauses and can't be resumed

2018-09-20 Thread Markus Koschany
Hi, Am 20.09.18 um 11:00 schrieb Damyan Ivanov: > Package: kobodeluxe > Version: 0.5.1-9 > Severity: grave > Justification: renders package unusable > > Trying to start a game in kobodeluxe results in a "PAUSED" game, with no > possibility to resume it. The only way out is to press Esc and exit

Bug#909215: glusterfs: Multiple security issues

2018-09-19 Thread Markus Koschany
Package: glusterfs X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerabilities were published for glusterfs. CVE-2018-10904[0]: | It was found that glusterfs server does not properly sanitize file | paths in the "trusted.io-stats-dump" extended

Bug#907688: Bug #907688 in activemq marked as pending

2018-09-18 Thread Markus Koschany
Control: tag -1 pending Hello, Bug #907688 in activemq reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below, and you can check the diff of the fix at:

Bug#908864: drascula: Incorrect version of the 'drascula.dat' engine data file found. Expected 5.0 but got 4.0.!

2018-09-15 Thread Markus Koschany
Control: tags -1 pending On Sat, 15 Sep 2018 12:45:59 +0200 Reiner Herrmann wrote: > In ScummVM 2.0.0 the version requirement of drascula has been bumped: > https://github.com/scummvm/scummvm/commit/327dcf9 > They also include an updated drascula.dat in this commit. > I tested it, and by

Bug#908835: dom4j: FTBFS because of javadoc error

2018-09-14 Thread Markus Koschany
Source: dom4j Version: 2.1.1-1 Severity: serious I just stumbled upon this bug. Apparently the last upload was never built on our buildd. There is some kind of javadoc error: javadoc: error - Error fetching URL: file:/usr/share/doc/default-jdk/api/ I may look into this later but filing a bug

Bug#868424: gnome-breakout: Port to GooCanvas / GTK+ 3

2018-09-11 Thread Markus Koschany
Control: tags -1 pending Again great work! Looks good to me. The only thing I noticed is, gnome-breakout can't be built twice in a row. ;) I get this error: debian/rules override_dh_auto_install make[1]: Entering directory '/build/gnome-breakout-0.5.3' dh_auto_install make -j1

Bug#908509: Missing build-dependency against python(3)

2018-09-10 Thread Markus Koschany
Control: tags -1 confirmed pending Am 10.09.2018 um 18:28 schrieb Laurent Bigonville: > Package: webext-ublock-origin > Version: 1.16.14+dfsg-1 > Severity: serious > > Hi, > > Looking at the build logs, it seems that the buildsystem is using both > python and python3 (*sigh*) but none of them

Bug#905989: python3-enet: missing python3 dependency

2018-09-07 Thread Markus Koschany
+ + * Non-maintainer upload. + * Add missing Python3 dependencies to python3-enet. +Thanks to Adrian Bunk for the report and patch. (Closes: #905989) + + -- Markus Koschany Fri, 07 Sep 2018 20:49:16 +0200 + python-enet (0.0~vcs.2017.05.26.git-2) unstable; urgency=medium * Upload to unstable

Bug#908135: unknown-horizons: does not start with fife 0.4.1+git20180904-1

2018-09-06 Thread Markus Koschany
Package: unknown-horizons Version: 2017.2-1 Severity: grave Unknown Horizons does not start with the latest fife version. I am currently packaging the Python 3 version and then I will update UH to the latest Git version. Markus

Bug#907863: libeclipse-osgi-java, libequinox-osgi-java: error when trying to install together

2018-09-03 Thread Markus Koschany
Am 03.09.2018 um 15:38 schrieb Emmanuel Bourg: > Hi Markus, > > Le 03/09/2018 à 14:48, Markus Koschany a écrit : > >> I think this could have been better communicated. I was the one who >> split libequinox-osgi-java off from Eclipse. Why can't we just use the >&g

Bug#907863: libeclipse-osgi-java, libequinox-osgi-java: error when trying to install together

2018-09-03 Thread Markus Koschany
Hi, Am 03.09.2018 um 14:04 schrieb Emmanuel Bourg: > Control: reassign -1 libeclipse-osgi-java > Control: affects -1 libequinox-osgi-java > > libeclipse-osgi-java will replace libequinox-osgi-java. I forgot to add > the proper Breaks/Replaces fields. I think this could have been better

Bug#885751: teg: Port to GooCanvas / GTK+ 3 / GSettings

2018-08-30 Thread Markus Koschany
Am 30.08.2018 um 01:53 schrieb Yavor Doganov: > tags 885751 + patch > thanks > > Attached are patches that should fix this bug completely (removing all > dependencies on old libraries that are scheduled for removal), plus > the following issues of non-RC severity: [...] Yavor, thank you very

Bug#907559: cgview: Does not start

2018-08-29 Thread Markus Koschany
Am 29.08.2018 um 19:31 schrieb Andreas Tille: [...] >> Maybe you should raise this issue with upstream (Batik and/or cgview) > > Well cgview is not actively maintained (but has quite a number of users) > and what exactly should I say to Batik upstream if they decided to move > it to a noew

Bug#906350: doxia: FTBFS in buster/sid (Cannot find parent dependency org.apache.maven:maven-parent:pom:27)

2018-08-29 Thread Markus Koschany
Control: tags -1 confirmed > [ERROR] The build could not read 1 project -> [Help 1] > [ERROR] > [ERROR] The project org.apache.maven.doxia:doxia:1.7 > (/<>/pom.xml) has 1 error > [ERROR] Invalid packaging for parent POM > org.apache.maven:maven-parent:27, must be "pom" but is "jar" @

Bug#906384: lucene-solr: FTBFS in buster/sid

2018-08-25 Thread Markus Koschany
Am 25.08.2018 um 23:27 schrieb Markus Koschany: > Control: tags -1 pending > > The FTBFS was caused by the latest upgrade of libwoodstox-java. The jar > files were renamed and could not be found anymore. > > I am quite sure this is related to #904063 somehow. Once #906447 is

Bug#906384: lucene-solr: FTBFS in buster/sid

2018-08-25 Thread Markus Koschany
Control: tags -1 pending The FTBFS was caused by the latest upgrade of libwoodstox-java. The jar files were renamed and could not be found anymore. I am quite sure this is related to #904063 somehow. Once #906447 is resolved I could try to verify this assumption. Markus signature.asc

Bug#902861: axis: FTBFS with Java 10 due to com.sun.net.ssl removal

2018-08-23 Thread Markus Koschany
Am 24.08.2018 um 01:00 schrieb Emmanuel Bourg: >> This issue was apparently fixed in version 1.10.4-2. Axis can be rebuilt >> from source again. > > Actually the issue was triggered by the automatic use of the --release > javac option in ant/1.10.3-2, the flag removed the internal com.sun.net >

Bug#901044: Bug #901044 in jnr-posix marked as pending

2018-08-23 Thread Markus Koschany
Control: tag -1 pending Hello, Bug #901044 in jnr-posix reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below, and you can check the diff of the fix at:

Bug#902570: asm: Package rebuilt from source gets lots of empty jars

2018-08-23 Thread Markus Koschany
Control: tags -1 confirmed On Wed, 27 Jun 2018 21:12:35 -0700 Daniel Schepler wrote: > Source: asm > Version: 6.0-1 > Severity: serious > > When I build src:asm using pbuilder, the build completes without > errors. However, then the generated deb file contains mostly empty > jars - the only

Bug#888547: CVE-2017-1000190

2018-08-23 Thread Markus Koschany
Am 23.08.2018 um 15:55 schrieb Emmanuel Bourg: > On 23/08/2018 13:14, Markus Koschany wrote: >> Apparently upstream doesn't consider this "to be their problem". Since >> simple-xml has no reverse-dependencies and the current uploader is MIA, >> I think we should

Bug#888547: CVE-2017-1000190

2018-08-23 Thread Markus Koschany
Apparently upstream doesn't consider this "to be their problem". Since simple-xml has no reverse-dependencies and the current uploader is MIA, I think we should consider requesting the removal of simple-xml. Markus signature.asc Description: OpenPGP digital signature

Bug#906396: Bug #906396 in plexus-archiver marked as pending

2018-08-23 Thread Markus Koschany
Control: tag -1 pending Hello, Bug #906396 in plexus-archiver reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below, and you can check the diff of the fix at:

Bug#893201: Bug #893201 in gnome-split marked as pending

2018-08-23 Thread Markus Koschany
Control: tag -1 pending Hello, Bug #893201 in gnome-split reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below, and you can check the diff of the fix at:

Bug#902789: Bug #902789 in spatial4j-0.4 marked as pending

2018-08-23 Thread Markus Koschany
Control: tag -1 pending Hello, Bug #902789 in spatial4j-0.4 reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below, and you can check the diff of the fix at:

Bug#885740: gnomekiss: Port to GTK+ 3

2018-08-21 Thread Markus Koschany
Am 21.08.2018 um 11:41 schrieb Yavor Doganov: > Yavor Doganov wrote: >> Please find attached a patch that ports the program to GTK+ 3. > > I wasn't careful enough; my patch introduces memory leaks. Please > find attached an updated version (compressed); please use it instead. > Thanks. Hey,

Bug#906746: Bug #906746 in freeorion marked as pending

2018-08-21 Thread Markus Koschany
Control: tag -1 pending Hello, Bug #906746 in freeorion reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below, and you can check the diff of the fix at:

Bug#906409: Bug #906409 in spring marked as pending

2018-08-21 Thread Markus Koschany
Control: tag -1 pending Hello, Bug #906409 in spring reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below, and you can check the diff of the fix at:

Bug#906308: CVE-2018-14348

2018-08-19 Thread Markus Koschany
to write to it. (Closes: #906308) + + -- Markus Koschany Sun, 19 Aug 2018 23:10:45 +0200 + libcgroup (0.41-8) unstable; urgency=medium * Drop package libcgroup-dbg in favor of automatic dbgsym packages. diff -Nru libcgroup-0.41/debian/patches/CVE-2018-14348.patch libcgroup-0.41/debian/patches

Bug#885735: Bug #885735 in gamazons marked as pending

2018-08-18 Thread Markus Koschany
Control: tag -1 pending Hello, Bug #885735 in gamazons reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below, and you can check the diff of the fix at:

Bug#885735: gamazons: Port to GooCanvas / GTK+ 3

2018-08-18 Thread Markus Koschany
Control: tags -1 pending Hi, thank you very much for your patch! The game looks playable to me again. I have applied your patch and uploaded a new revision. Good work! Cheers, Markus signature.asc Description: OpenPGP digital signature

Bug#902720: CVE-2018-1000544

2018-08-15 Thread Markus Koschany
be exploited to write arbitrary files to +the filesystem. (Closes: #902720) + * Drop CVE-2017-5946.patch because this one was already fixed in version +1.2.1. + + -- Markus Koschany Mon, 13 Aug 2018 13:57:54 +0200 + ruby-zip (1.2.1-1) unstable; urgency=medium * Team upload diff -Nru ruby-zip

<    1   2   3   4   5   6   7   8   9   10   >