Bug#838812: pg_upgradecluster skips databases owned by a role who is not a user

2016-10-31 Thread Tilman Koschnick
Package: postgresql-common Version: 177.pgdg80+1 Followup-For: Bug #838812 Dear Maintainer, I can confirm the problem; the attached patch fixes it. A brief explanation: In the query to select databases which need upgrading, pg_database is joined onto pg_user, which is a view of pg_shadow,

Bug#596205: python-django: new minor release fixes CSRF bug

2010-09-09 Thread Tilman Koschnick
Package: python-django Version: 1.2.1-1 Severity: grave Tags: security Justification: user security hole Hi, the Django project released version 1.2.2, fixing a security problem in the CSRF protection system. Details are on the Django Blog:

Bug#567175: gmetad: creates world read/writable rrd data files

2010-01-27 Thread Tilman Koschnick
Package: gmetad Version: 3.1.2-2.1 Severity: grave Tags: security Justification: causes non-serious data loss Hi, gmetad creates its RRD data files with permissions 666, in world-accessible directories (755), e.g.: $ ls -ld /var/lib/ganglia/rrds/__SummaryInfo__ drwxr-xr-x 2 nobody root 4096

Bug#295375: This is a serious issue

2007-03-04 Thread Tilman Koschnick
On Sun, 2006-12-31 at 10:29 +0100, Andreas Barth wrote: * Tilman Koschnick ([EMAIL PROTECTED]) [061231 09:16]: I have discussed this issue with my sponsor in the past, and we have agreed that the proper split is not worth the hassle at the moment. There are no packages apart from gpsd

Bug#389361: XSS vulnerability in elog

2006-09-25 Thread Tilman Koschnick
Package: elog Version: 2.6.1+r1642-1 Severity: grave Tags: security Justification: user security hole Hi, when editing a log entry in HTML mode, elog accepts arbitrary JavaScript code. This code will be executed in the browser of other users viewing the entry (provided they have JavaScript

Bug#340852: gpsd: FTBFS: undefined reference to `floor'

2005-12-11 Thread Tilman Koschnick
merge 340081 340852 thanks On Sat, 2005-11-26 at 13:17 +0100, Kurt Roeckx wrote: Package: gpsd Version: 2.30-1 Severity: serious Hi, Your package is failing to build with the following error: gpxlogger.o: In function `signal_handler':/build/buildd/gpsd-2.30/gpxlogger.c:6 7: undefined

Bug#340852: gpsd: FTBFS: undefined reference to `floor'

2005-12-11 Thread Tilman Koschnick
On Sun, 2005-12-11 at 13:32 +0800, Zak B. Elep wrote: package gpsd tags 340852 patch thanks control ;) I've fixed this in my merge of gpsd for Ubuntu. Attached is the (rather trivial) fix, though I suspect that a better solution would be to notify upstream of this problem and modify

Bug#340081: gpsd: ftbfs [sparc] undefined reference to `floor'

2005-11-21 Thread Tilman Koschnick
tags 340081 pending thanks On Sun, 2005-11-20 at 11:15 -0800, Blars Blarson wrote: Package: gpsd Version: 2.30-1 Severity: serious Justification: fails to build from source gpsd failed to build on a sparc buildd, duplicated on my sparc pbuilder. Thanks for your report. This will be

Bug#294626: apt-proxy: dependency to python2.3-profiler missing

2005-02-22 Thread Tilman Koschnick
On Tue, February 22, 2005 11:56, Herbert Thielen said: Package: apt-proxy Version: 1.9.25 Followup-For: Bug #294626 As python-twisted is only suggesting python-profiler, the package apt-proxy has to depend on python-profiler, as apt-proxy refuses to work otherwise. From the twisted

Bug#292370: CAN-2004-1388

2005-02-01 Thread Tilman Koschnick
On Tue, 2005-02-01 at 08:25 +0100, Martin Schulze wrote: This problem has been assigned Candidate: CAN-2004-1388 URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-1388 Reference: BUGTRAQ:20050126 DMA[2005-0125a] - 'berlios gpsd format string vulnerability' Reference:

Bug#292347: gpsd: remote security problem with format strings

2005-01-27 Thread Tilman Koschnick
tags 292347 pending thanks On Wed, 2005-01-26 at 15:06 +0100, Ulf Härnhammar wrote: Subject: gpsd: remote security problem with format strings Package: gpsd Severity: grave Justification: user security hole Tags: security Hello, a remote security problem with format strings has been