Bug#778634: CVE-2008-7313 / CVE-2014-5008

2015-03-14 Thread Marcelo Jorge Vieira
Hi Moritz, On Sat, 2015-03-14 at 13:50 -0300, Marcelo Jorge Vieira wrote: Hi Moritz, On Thu, 2015-03-05 at 19:13 +0100, Moritz Mühlenhoff wrote: Did you test the reverse deps in wheezy and jessie to check whether they are compatible? wordpress (wheezy) libphp-magpierss

Processed: tagging 780447

2015-03-14 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: tags 780447 + pending Bug #780447 [libtcnative-1] tomcat-native: SSLv23_* calls shouldn't be disabled Added tag(s) pending. thanks Stopping processing here. Please contact me if you need assistance. -- 780447:

Processed: Rising severity

2015-03-14 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: severity 765490 grave Bug #765490 [xserver-xorg-video-vmware] xserver-xorg-video-vmware: resizing issues Severity set to 'grave' from 'important' thanks Stopping processing here. Please contact me if you need assistance. -- 765490:

Bug#780503: icu: incomplete fix for CVE-2014-7940

2015-03-14 Thread Michael Gilbert
package: src:icu version: 52.1-7.1 severity: serious tags: security Google added another check in a later patch for this issue, which wasn't included in the previous nmu: https://chromium.googlesource.com/chromium/deps/icu/+/a626a75aad2675254073366fcaa9465dacf17100/patches/col.patch Best wishes,

Processed: Re: Bug#780503: icu: incomplete fix for CVE-2014-7940

2015-03-14 Thread Debian Bug Tracking System
Processing control commands: tag -1 patch, pending Bug #780503 [src:icu] icu: incomplete fix for CVE-2014-7940 Added tag(s) pending and patch. -- 780503: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=780503 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems -- To

Bug#780503: icu: incomplete fix for CVE-2014-7940

2015-03-14 Thread Michael Gilbert
control: tag -1 patch, pending On Sat, Mar 14, 2015 at 9:48 PM, Michael Gilbert wrote: Google added another check in a later patch for this issue, which wasn't included in the previous nmu: Hi, I uploaded an nmu to delayed/3 fixing this problem. Please see attached. Best wishes, Mike diff

Processed: your mail

2015-03-14 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: severity 765514 serious Bug #765514 {Done: Michael Stone mst...@debian.org} [coreutils] coreutils: regression in chroot semantics Severity set to 'serious' from 'normal' End of message, stopping processing here. Please contact me if you need

Bug#763900: marked as done (iceweasel/ppc: jemallocCompile-time page size does not divide the runtime one.)

2015-03-14 Thread Debian Bug Tracking System
Your message dated Sat, 14 Mar 2015 22:34:09 + with message-id e1ywudf-0002sl...@franck.debian.org and subject line Bug#763900: fixed in iceweasel 31.5.0esr-1~deb7u1 has caused the Debian Bug report #763900, regarding iceweasel/ppc: jemallocCompile-time page size does not divide the runtime

Processed: xserver-xorg-video-vmware: diff for NMU version 1:13.0.2-3.1

2015-03-14 Thread Debian Bug Tracking System
Processing control commands: tags 765490 + pending Bug #765490 [xserver-xorg-video-vmware] xserver-xorg-video-vmware: resizing issues Added tag(s) pending. -- 765490: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=765490 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems

Bug#765490: xserver-xorg-video-vmware: diff for NMU version 1:13.0.2-3.1

2015-03-14 Thread Bernd Zeimetz
Control: tags 765490 + pending Dear maintainer, I've prepared an NMU for xserver-xorg-video-vmware (versioned as 1:13.0.2-3.1) and uploaded it to unstable. I'll ask for an unblock. Regards. Bernd diff -u xserver-xorg-video-vmware-13.0.2/debian/changelog

Bug#780473: marked as done (Architecture attribute must be a single line, not multiple lines)

2015-03-14 Thread Debian Bug Tracking System
Your message dated Sat, 14 Mar 2015 21:48:38 + with message-id e1ywtvc-0004xb...@franck.debian.org and subject line Bug#780473: fixed in kissplice 2.2.1-3 has caused the Debian Bug report #780473, regarding Architecture attribute must be a single line, not multiple lines to be marked as done.

Bug#765490: marked as done (xserver-xorg-video-vmware: resizing issues)

2015-03-14 Thread Debian Bug Tracking System
Your message dated Sat, 14 Mar 2015 22:36:57 + with message-id e1ywufx-00031x...@franck.debian.org and subject line Bug#765490: fixed in xserver-xorg-video-vmware 1:13.0.2-3.1 has caused the Debian Bug report #765490, regarding xserver-xorg-video-vmware: resizing issues to be marked as done.

Bug#778599: Vulnerabilities in nanohttp

2015-03-14 Thread Salvatore Bonaccorso
Hi, On Tue, Feb 17, 2015 at 10:07:06AM +, Patrick Coleman wrote: * Remote null pointer dereference A remote user can cause a null pointer dereference by sending a malformed Authorization: header. http://patrick.ld.net.au/libcsoap/nanohttp-nullp-1.patch For this issue CVE-2015-2297 was

Bug#780444: Update my email address

2015-03-14 Thread Paul Menzel
Control: submitter -1 ! Dear Debian folks, Unfortunately I submitted that report from the wrong email address. So update it. Thanks, Paul signature.asc Description: This is a digitally signed message part

Processed: Re: Bug#780444: Update my email address

2015-03-14 Thread Debian Bug Tracking System
Processing control commands: submitter -1 ! Bug #780444 [libwebkitgtk-3.0-0] libwebkitgtk-3.0-0: use after free: GLib-GObject-CRITICAL **: g_closure_unref: assertion 'closure-ref_count 0' failed Changed Bug submitter to 'Paul Menzel pm.deb...@googlemail.com' from 'Paul Menzel

Bug#780452: libwebkitgtk-3.0-0: Segfault in `VectorBufferBase` at `../Source/WTF/wtf/Vector.h:330`

2015-03-14 Thread Paul Menzel
Package: libwebkitgtk-3.0-0 Version: 2.4.8-1 Severity: grave Tags: upstream Control: forwarded -1 https://bugs.webkit.org/show_bug.cgi?id=142692 Control: affects -1 evolution Dear Debian folks, Evolution sometimes crashes due to a segmentation fault in libwebkitgtk-3.0.so.0.22.14.

Processed: libwebkitgtk-3.0-0: Segfault in `VectorBufferBase` at `../Source/WTF/wtf/Vector.h:330`

2015-03-14 Thread Debian Bug Tracking System
Processing control commands: forwarded -1 https://bugs.webkit.org/show_bug.cgi?id=142692 Bug #780452 [libwebkitgtk-3.0-0] libwebkitgtk-3.0-0: Segfault in `VectorBufferBase` at `../Source/WTF/wtf/Vector.h:330` Set Bug forwarded-to-address to 'https://bugs.webkit.org/show_bug.cgi?id=142692'.

Bug#778895: Bug#780388: RM: trafficserver/5.0.1-1

2015-03-14 Thread Niels Thykier
On 2015-03-13 09:29, Arnaud Fontaine wrote: Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: rm Hello, Considering that trafficserver is currently affected by 3 security bugs (CVE-2014-3624, CVE-2014-10022 (#778895) and #749846) fixed

Bug#767040: Superblock time check causes problems for fsck in initramfs

2015-03-14 Thread Beck, Andre
Hi, isn't that a bug in e2fsck anyway? There is accept_time_fudge which defaults to true and should take care of this situation. Even when it wouldn't default to true, my e2fsck.conf already had its alias buggy_init_scripts set to 1. Nevertheless, I'm briefly seeing an fsck running now on every

Bug#777191: grub-efi-amd64 on Debian Jessie cannot boot zfs native root filesystem running the latest git code soon to be 0.6.4 tagged - official release

2015-03-14 Thread Ian Campbell
On Thu, 2015-02-05 at 20:04 -0800, Azeem Esmail wrote: Works with 0.6.3 (v0.6.3-766_gfde0d6d) Does not work with 0.6.3 latest code (dailies version). What are these the versions of? At first reboot, the screen freezes with the following message: mount: mounting /sys on /root/sys failed:

Bug#776094: dovecot-imapd: corrupts mailbox after trying to retrieve it (fwd)

2015-03-14 Thread Andrew Worsley
On Thu, 19 Feb 2015 22:34:07 +0100 (CET) Santiago Vila sanv...@unex.es wrote: One more follow up suggestion based on my debugging locally. (You may already be aware of these options - so forgive me if you already are). You can install strace and strace the dovecot process e.g. Run ps axf and

Bug#779797: gdisk: Returns exit code 1 after successful operations

2015-03-14 Thread intrigeri
Hi Guillaume, Guillaume Delacour wrote (12 Mar 2015 23:05:35 GMT) : Splitted in two patches. Thanks! Is it on purpose that the newly-introduced test_exit_condition.diff isn't listed in debian/patches/series? Reading debian/changelog, I guess not = I can trivially fix that in the Vcs-Git before

Bug#780452: libwebkitgtk-3.0-0: Segfault in `VectorBufferBase` at `../Source/WTF/wtf/Vector.h:330`

2015-03-14 Thread Paul Menzel
Dear Debian folks, Am Samstag, den 14.03.2015, 10:00 +0100 schrieb Paul Menzel: […] I reported this to the WebKitGTK+ bug tracker as ticket #127474 [1]. I meant ticket #142692 [2] as denoted in the meta data. Thanks, Paul [2] https://bugs.webkit.org/show_bug.cgi?id=142692 Segfault

Processed: user release.debian....@packages.debian.org, usertagging 778810, tagging 778810

2015-03-14 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: user release.debian@packages.debian.org Setting user to release.debian@packages.debian.org (was ni...@thykier.net). usertags 778810 jessie-can-defer There were no usertags set. Usertags are now: jessie-can-defer. tags 778810 +

Bug#776483: package is in NEW

2015-03-14 Thread Tobias Hansen
Control: tags -1 +pending A fix for this is currently in the NEW queue. -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Processed: package is in NEW

2015-03-14 Thread Debian Bug Tracking System
Processing control commands: tags -1 +pending Bug #776483 [python-imaging] python-imaging: no smooth upgrade path from wheezy due to python-imaging-tk becoming a virtual package Added tag(s) pending. -- 776483: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=776483 Debian Bug Tracking System

Processed: severity of 777191 is important

2015-03-14 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: severity 777191 important Bug #777191 [grub-efi-amd64] grub-efi-amd64 on Debian Jessie cannot boot zfs native root filesystem running the latest git code soon to be 0.6.4 tagged - official release Severity set to 'important' from 'critical'

Bug#747958: fixed in new upstream

2015-03-14 Thread Matthias Klose
Control: tags -1 + patch this is fixed upstream in 2.6.2, but this drops Korean. 2.8.2 builds Korean, and a few other languages. see https://launchpad.net/ubuntu/+source/gimp-help/2.8.2-0ubuntu1 -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe.

Processed: fixed in new upstream

2015-03-14 Thread Debian Bug Tracking System
Processing control commands: tags -1 + patch Bug #747958 [gimp-help] FTBFS: parser error : Start tag expected, '' not found Added tag(s) patch. -- 747958: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=747958 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems -- To

Bug#779634: marked as done (pymad: FTBFS - No 'Setup' file. Perhaps you need to run the configure script.)

2015-03-14 Thread Debian Bug Tracking System
Your message dated Sat, 14 Mar 2015 11:34:05 + with message-id e1ywkkt-00013q...@franck.debian.org and subject line Bug#779634: fixed in pymad 0.8-2 has caused the Debian Bug report #779634, regarding pymad: FTBFS - No 'Setup' file. Perhaps you need to run the configure script. to be marked

Bug#780424: Emedded ZendDb component affected by several security issues

2015-03-14 Thread David Prévot
Hi François-Régis, [ I Shouldn’t reply to mail too late: I misunderstood your proposal… ] Do you think, in between, it's worth to make a package which remove the upstream embedded ZendDB and embed a proper (let says 2.3.6) version of it. That would be fine: you may just copy a recent ZendDB

Bug#778810: grub-efi-amd64-bin: boot/bootx86.efi problems

2015-03-14 Thread Ian Campbell
Control: severity -1 important Control: tags -1 +unreproducible +moreinfo On Wed, 2015-02-25 at 12:19 +, Ian Campbell wrote: On Sat, 2015-02-21 at 23:27 +0900, Mark Brown wrote: On Sat, Feb 21, 2015 at 10:31:19AM +, Ian Campbell wrote: On Sat, 2015-02-21 at 11:39 +0900, Mark Brown

Processed: Re: Bug#778810: grub-efi-amd64-bin: boot/bootx86.efi problems

2015-03-14 Thread Debian Bug Tracking System
Processing control commands: severity -1 important Bug #778810 [grub-efi-amd64-bin] grub-efi-amd64-bin: boot/bootx86.efi problems Severity set to 'important' from 'critical' tags -1 +unreproducible +moreinfo Bug #778810 [grub-efi-amd64-bin] grub-efi-amd64-bin: boot/bootx86.efi problems Added

Bug#780240: [Pkg-phototools-devel] Bug#780240: libgphoto2-port10: Wrong transition package for ABI changing library

2015-03-14 Thread hpfn
On Fri, 13 Mar 2015 22:24:13 +0100 Andreas Beckmann a...@debian.org wrote: On 2015-03-13 22:00, Herbert Parentes Fortes Neto (hpfn) wrote: Thanks for checking the package. Looks good now! Do you need a sponsor to upload this? It would be nice if you do the upload. I belive it would be

Bug#779621: jakarta-taglibs-standard: CVE-2015-0254

2015-03-14 Thread Miguel Landaeta
On Sat, Mar 14, 2015 at 02:03:52PM -0300, Miguel Landaeta wrote: the release cycle. I mean, the full diff between 2.1.1 and 2.1.3 has almost Sorry, I got it wrong. The new upstream releases are 1.2.1 and 1.2.3. -- Miguel Landaeta, nomadium at debian.org secure email with PGP

Bug#779621: jakarta-taglibs-standard: CVE-2015-0254

2015-03-14 Thread Emmanuel Bourg
Thank you for taking care of this Miguel. Upstream told me that the commits r1642442 [1] and r1642613 [2] contained the relevant fixes for this issue. I haven't checked if they can be easily backported though. Emmanuel Bourg [1] http://svn.apache.org/r1642442 [2] http://svn.apache.org/r1642613

Bug#779621: jakarta-taglibs-standard: CVE-2015-0254

2015-03-14 Thread Miguel Landaeta
On Sat, Mar 14, 2015 at 06:21:37PM +0100, Emmanuel Bourg wrote: Thank you for taking care of this Miguel. Upstream told me that the commits r1642442 [1] and r1642613 [2] contained the relevant fixes for this issue. I haven't checked if they can be easily backported though. Emmanuel Bourg

Bug#779048: no point in migrating

2015-03-14 Thread Adam Borowski
Why won't you just rename the package back to libjpeg-progs? Without this nonsense migration, there won't be any issues. The reason for libjpeg-turbo-progs, those waaah hijack complaints don't hold any water anymore as libjpeg9 is gone, and I don't think the Release Team is going to ever allow it

Processed: Re: Bug#780401: Sounds like it might be related to bug 726530

2015-03-14 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: reassign 780401 fvwm Bug #780401 [gimp] gimp: crashes window manager (fvwm) on closing Bug reassigned from package 'gimp' to 'fvwm'. No longer marked as found in versions gimp/2.8.14-1. Ignoring request to alter fixed versions of bug #780401 to

Bug#628671: marked as done (passwd: Ordinary users can't change their passwords.)

2015-03-14 Thread Debian Bug Tracking System
Your message dated Sat, 14 Mar 2015 15:39:56 + with message-id e1ywoao-0001hn...@franck.debian.org and subject line Bug#767611: Removed package(s) from unstable has caused the Debian Bug report #368297, regarding passwd: Ordinary users can't change their passwords. to be marked as done. This

Bug#658739: marked as done (gnutls26: LDAP+SSL account cannot use setuid binaries until gnutls26 is rebuilt with nettle not libgcrypt11)

2015-03-14 Thread Debian Bug Tracking System
Your message dated Sat, 14 Mar 2015 15:39:56 + with message-id e1ywoao-0001hn...@franck.debian.org and subject line Bug#767611: Removed package(s) from unstable has caused the Debian Bug report #368297, regarding gnutls26: LDAP+SSL account cannot use setuid binaries until gnutls26 is rebuilt

Bug#601667: marked as done (libpam-smbpass migrate breaks su (squeeze))

2015-03-14 Thread Debian Bug Tracking System
Your message dated Sat, 14 Mar 2015 15:39:56 + with message-id e1ywoao-0001hn...@franck.debian.org and subject line Bug#767611: Removed package(s) from unstable has caused the Debian Bug report #368297, regarding libpam-smbpass migrate breaks su (squeeze) to be marked as done. This means that

Bug#566351: marked as done (libgcrypt11: should not change user id as a side effect)

2015-03-14 Thread Debian Bug Tracking System
Your message dated Sat, 14 Mar 2015 15:39:56 + with message-id e1ywoao-0001hn...@franck.debian.org and subject line Bug#767611: Removed package(s) from unstable has caused the Debian Bug report #368297, regarding libgcrypt11: should not change user id as a side effect to be marked as done.

Bug#368297: marked as done (sudo-ldap failes when you change uri to ldaps)

2015-03-14 Thread Debian Bug Tracking System
Your message dated Sat, 14 Mar 2015 15:39:56 + with message-id e1ywoao-0001hn...@franck.debian.org and subject line Bug#767611: Removed package(s) from unstable has caused the Debian Bug report #368297, regarding sudo-ldap failes when you change uri to ldaps to be marked as done. This means

Bug#545414: marked as done (sudo-ldap: sudo fails with sudo: setreuid(ROOT_UID, user_uid): Operation not permitted for ldap users)

2015-03-14 Thread Debian Bug Tracking System
Your message dated Sat, 14 Mar 2015 15:39:56 + with message-id e1ywoao-0001hn...@franck.debian.org and subject line Bug#767611: Removed package(s) from unstable has caused the Debian Bug report #368297, regarding sudo-ldap: sudo fails with sudo: setreuid(ROOT_UID, user_uid): Operation not

Bug#658896: marked as done (sudo: setresuid(ROOT_UID, ROOT_UID, ROOT_UID): Operation not permitted)

2015-03-14 Thread Debian Bug Tracking System
Your message dated Sat, 14 Mar 2015 15:39:56 + with message-id e1ywoao-0001hn...@franck.debian.org and subject line Bug#767611: Removed package(s) from unstable has caused the Debian Bug report #368297, regarding sudo: setresuid(ROOT_UID, ROOT_UID, ROOT_UID): Operation not permitted to be

Bug#579647: marked as done (nss-ldap changing uid due to using gcrypt somewhere...)

2015-03-14 Thread Debian Bug Tracking System
Your message dated Sat, 14 Mar 2015 15:39:56 + with message-id e1ywoao-0001hn...@franck.debian.org and subject line Bug#767611: Removed package(s) from unstable has caused the Debian Bug report #368297, regarding nss-ldap changing uid due to using gcrypt somewhere... to be marked as done.

Bug#779621: jakarta-taglibs-standard: CVE-2015-0254

2015-03-14 Thread Miguel Landaeta
owner 779621 ! thanks On Tue, Mar 03, 2015 at 07:57:36AM +0100, Moritz Muehlenhoff wrote: Package: jakarta-taglibs-standard Severity: important Tags: security Please see http://www.securityfocus.com/archive/1/534772 Cheers, Moritz Hi, I can try to backport the fix

Processed: Re: jakarta-taglibs-standard: CVE-2015-0254

2015-03-14 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: owner 779621 ! Bug #779621 [jakarta-taglibs-standard] jakarta-taglibs-standard: CVE-2015-0254 Owner recorded as Miguel Landaeta nomad...@debian.org. thanks Stopping processing here. Please contact me if you need assistance. -- 779621:

Bug#780143:

2015-03-14 Thread Chris Bainbridge
Axel's patch from upstream git fixes the issue (tested with fixedsc font in terminator).

Bug#780473: Architecture attribute must be a single line, not multiple lines

2015-03-14 Thread Matthias Klose
Package: src:kissplice Version: 2.2.1-2 Severity: serious Tags: sid wheezy this is not allowed by policy, and the builds break then, see https://buildd.debian.org/status/package.php?p=kissplice Package: kissplice Architecture: any-amd64 any-arm64 any-mips64 any-mips64el any-ia64

Bug#745454: marked as done ([libgcrypt11] Non free RFC)

2015-03-14 Thread Debian Bug Tracking System
Your message dated Sat, 14 Mar 2015 15:39:56 + with message-id e1ywoao-0001hn...@franck.debian.org and subject line Bug#767611: Removed package(s) from unstable has caused the Debian Bug report #745454, regarding [libgcrypt11] Non free RFC to be marked as done. This means that you claim that

Bug#778634: CVE-2008-7313 / CVE-2014-5008

2015-03-14 Thread Marcelo Jorge Vieira
Hi Moritz, On Thu, 2015-03-05 at 19:13 +0100, Moritz Mühlenhoff wrote: Did you test the reverse deps in wheezy and jessie to check whether they are compatible? wordpress (wheezy) libphp-magpierss (jessie/wheezy) ampache (jessie) No, I didn't. But I will do it today and I will upload the

Bug#778634: marked as done (libphp-snoopy: CVE-2008-7313 / CVE-2014-5008)

2015-03-14 Thread Debian Bug Tracking System
Your message dated Sat, 14 Mar 2015 17:48:46 + with message-id e1ywqb4-00085k...@franck.debian.org and subject line Bug#778634: fixed in libphp-snoopy 2.0.0-1 has caused the Debian Bug report #778634, regarding libphp-snoopy: CVE-2008-7313 / CVE-2014-5008 to be marked as done. This means that