Bug#938351: marked as pending in renpy

2020-10-27 Thread Markus Koschany
Am 27.10.20 um 20:10 schrieb Gregor Riepl: >> https://salsa.debian.org/games-team/renpy/commit/fc29ebfe106238b590a7896450a5d1ad1f94f84e >> >> >> Switch to python3. >> >> Closes: #938351 >>

Bug#972993: eclipse-wtp: FTBFS cannot find symbol

2020-10-26 Thread Markus Koschany
Source: eclipse-wtp Version: 3.18-4 Severity: serious Tags: ftbfs X-Debbugs-Cc: eclipse-wtp: FTBFS cannot find symbol Hi, while I was rebuilding reverse-dependencies of jflex, I discovered that eclipse-wtp fails to build from source. The error is unrelated to the new version of jflex.

Bug#912485: childsplay: Please migrate to python3-pygame

2020-10-20 Thread Markus Koschany
I have started to port childsplay to python3. There are no estimates when it's done but I hope I can finish the work before we freeze. Markus signature.asc Description: OpenPGP digital signature

Bug#972394: likely cause: Python.h not found because of version mismatch 3.8 vs 3.9

2020-10-19 Thread Markus Koschany
Am 19.10.20 um 23:33 schrieb Joachim Wuttke: > Markus: > > Further investigation shows that the problem is not with NumPy. > CMake not even finds Python.h. > > The problem is most likely a mixture of Python 3.8 and 3.9 files on your > system. > > Try to uninstall libpython3-dev, which still

Bug#972394: got same error in other project

2020-10-19 Thread Markus Koschany
Hi Joachim, Am 19.10.20 um 23:15 schrieb Joachim Wuttke: > Hi Markus, > > I confirm that this is a serious issue. > > I got the same error message > >    Could NOT find Python3 (missing: Python3_INCLUDE_DIRS Python3_LIBRARIES >    Development NumPy Development.Module Development.Embed) (found

Bug#972394: siconos: FTBFS could not find Python 3

2020-10-17 Thread Markus Koschany
Package: libsiconos-io-dev Version: 4.3.0+dfsg-1 Severity: serious Hi, while I was rebuilding all reverse-dependencies of bullet, I discovered that siconos fails to build from source. The issue is related to Python 3, maybe a missing build-dependency. Full build log is attached. The error

Bug#964195: guacamole-client: CVE-2020-9497 and CVE-2020-9498

2020-10-10 Thread Markus Koschany
I somehow missed the guacamole-server package in Debian. Currently I believe it is possible to backport the patch from 1.2.0 to 0.9.9. However there is still the problem with freerdp2 (#888321), most likely a new upstream version for unstable/testing is required anyway. Markkus signature.asc

Bug#964195: guacamole-client: CVE-2020-9497 and CVE-2020-9498

2020-10-10 Thread Markus Koschany
Hi, I am currently investigating the security vulnerabilities in guacamole-client. I believe the reported CVE-2020-9497 and CVE-2020-9498 issues only affect the server part of guacamole but this one has not been packaged yet. The security researchers who reported the vulnerabilities have

Bug#957271: gfpoken: ftbfs with GCC-10

2020-10-04 Thread Markus Koschany
On Sat, 5 Sep 2020 17:03:15 +0200 Reiner Herrmann wrote: > Hi, > > the GCC 10 build error is easily fixed with the attached patch. > > But the build also fails while generating artwork via a Gimp script > (art/mktiles): > > > Starting extension: 'extension-script-fu' > > No batch interpreter

Bug#966190: marked as pending in alien-arena

2020-10-04 Thread Markus Koschany
Control: tag -1 pending Hello, Bug #966190 in alien-arena reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at:

Bug#942814: libhibernate-validator-java: update to 5.3.6 breaks reverse-dependencies

2020-09-26 Thread Markus Koschany
Am 26.09.20 um 10:27 schrieb Emmanuel Bourg: > On 25/09/2020 13:50, Markus Koschany wrote: > >> Why did you upgrade hibernate-validator to version 5.x when >> no other package in Debian requires it? Wouldn't it have been >> simpler to revert the upgrade instea

Bug#942814: libhibernate-validator-java: update to 5.3.6 breaks reverse-dependencies

2020-09-25 Thread Markus Koschany
Am 25.09.20 um 08:17 schrieb Emmanuel Bourg: [...] > Hi Paul, > > The version 4.x has been packaged separately as > libhibernate-validator4-java. libspring-java has been updated to use it > but not the other reverse dependencies. > > Emmanuel Bourg Hi, pdfsam is the only other

Bug#967125: desmume: Unversioned Python removal in sid/bullseye

2020-09-20 Thread Markus Koschany
On Sun, 20 Sep 2020 23:51:22 +0200 Markus Koschany wrote: > > I believe this issue was fixed in libglade2-dev (#967157) and > monster-masher ^ should be desmume of course :-) signature.asc Description: OpenPGP digital signature

Bug#957671: marked as pending in pcsxr

2020-09-20 Thread Markus Koschany
Control: tag -1 pending Hello, Bug #957671 in pcsxr reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at:

Bug#969123: webext-ublock-origin: FF80 broke ublock again

2020-08-31 Thread Markus Koschany
On Sat, 29 Aug 2020 01:37:27 +0200 Christoph Anton Mitterer wrote: [...] > Interestingly it seems other (all) add-ons are broken too, at least for > me... but not when I create fresh profiles. I stand corrected. Apparently this is a similar problem like https://bugs.debian.org/931640

Bug#967213: marked as pending in teeworlds

2020-08-30 Thread Markus Koschany
- CVE-2019-10879.patch - immintrin_FTBFS.patch - no-sse2-required.patch - recursiv_dir.patch . [ Markus Koschany ] * New upstream version 0.7.5. - Fix CVE-2020-12066: Remote denial-of-service. * Build-depend on python3 instead of python. Fix python3 incompatibilities

Bug#966892: marked as pending in megaglest

2020-08-28 Thread Markus Koschany
Control: tag -1 pending Hello, Bug #966892 in megaglest reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at:

Bug#969123: webext-ublock-origin: FF80 broke ublock again

2020-08-28 Thread Markus Koschany
Hello ftp team, ublock origin is in the NEW queue again. [1] The binary packages have not changed since the last review. I had uploaded a newer version to unstable and when you finally approved the version I had uploaded to experimental it got automatically removed from Debian because the version

Bug#969123: webext-ublock-origin: FF80 broke ublock again

2020-08-28 Thread Markus Koschany
Control: tags -1 pending On Thu, 27 Aug 2020 23:13:45 +0200 Christoph Anton Mitterer wrote: [...] > It seems stupid *zilla broke ublock origina again with the new Firefox. Thanks for reporting. I believe this is fixed in 1.29.0+dfsg. Unfortunately the package has to go through NEW again which

Bug#966885: marked as pending in spring

2020-08-05 Thread Markus Koschany
Control: tag -1 pending Hello, Bug #966885 in spring reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at:

Bug#966406: pygame-sdl2: diff for NMU version 7.3.3-1.1

2020-07-28 Thread Markus Koschany
Hello Adrian, Am 28.07.20 um 07:42 schrieb Adrian Bunk: > Package: pygame-sdl2 > Version: 7.3.3-1 > Severity: normal > Tags: patch pending > > Dear maintainer, > > I've prepared an NMU for pygame-sdl2 (versioned as 7.3.3-1.1) and > uploaded it to DELAYED/14. Please feel free to tell me if I

Bug#957604: marked as pending in neverball

2020-07-22 Thread Markus Koschany
Control: tag -1 pending Hello, Bug #957604 in neverball reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at:

Bug#957497: marked as pending in lmemory

2020-07-22 Thread Markus Koschany
Control: tag -1 pending Hello, Bug #957497 in lmemory reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at:

Bug#957021: marked as pending in atomix

2020-07-22 Thread Markus Koschany
Control: tag -1 pending Hello, Bug #957021 in atomix reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at:

Bug#964242: bsdmainutils: depends on non-existing version of bsdextrautils

2020-07-06 Thread Markus Koschany
affects 964242 javahelper thanks This also affects javahelper which depends on bsdmainutils and breaks a lot of Java packages in Debian currently. Regards, Markus signature.asc Description: OpenPGP digital signature

Bug#963367: marked as pending in simutrans-pak128.britain

2020-06-27 Thread Markus Koschany
Control: tag -1 pending Hello, Bug #963367 in simutrans-pak128.britain reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at:

Bug#963460: marked as pending in simutrans-pak64

2020-06-27 Thread Markus Koschany
Control: tag -1 pending Hello, Bug #963460 in simutrans-pak64 reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at:

Bug#962512: nethack: Security issues in Buster's nethack 3.6.1

2020-06-09 Thread Markus Koschany
Control: fixed -1 3.6.6-1 Control: severity -1 important Am 09.06.20 um 03:25 schrieb Jason L. Quinn: [...] > Seems like the vunerabilities are important enough to warrant an upgrade in > Buster. I'm not against an update of nethack in Buster. However currently such an update would break

Bug#961932: nethack-lisp: broken and unmaintained

2020-05-31 Thread Markus Koschany
Package: nethack-lisp Version: 3.6.6-1 Severity: serious I have just updated nethack to the latest upstream version to fix several security vulnerabilities and a compilation error with GCC 10. Unfortunately the Debian specific lisp patches don't work anymore with the current release. I could fix

Bug#928813: libapache2-mod-jk: Jk can not find any configured worker

2020-05-27 Thread Markus Koschany
Am 27.05.20 um 21:54 schrieb Thorsten Glaser: [...] > Thank you. Please also take care of buster. I will take care of Buster eventually. Markus signature.asc Description: OpenPGP digital signature

Bug#928813: marked as pending in libapache-mod-jk

2020-05-27 Thread Markus Koschany
Control: tag -1 pending Hello, Bug #928813 in libapache-mod-jk reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at:

Bug#928813: libapache2-mod-jk: Jk can not find any configured worker

2020-05-27 Thread Markus Koschany
Am 27.05.20 um 17:28 schrieb Thorsten Glaser: [...] > In stretch, an “a2enmod jk” will enable mods-available/jk.conf > and make things work. > > From reading the changelog, you wanted to “Install new httpd-jk.conf > file which follows Apache 2.4 syntax”, but the directory is wrong; > these files

Bug#936557: freeorion: Python2 removal in sid/bullseye

2020-05-17 Thread Markus Koschany
Am 17.05.20 um 15:36 schrieb Fedja Beader via Pkg-games-devel: > Why does this bug still exist? > > I was able to build headless Freeorion on Devuan with Python 3 just by > changing the control file (see >

Bug#959937: tomcat9: update to tomcat9:amd64 9.0.31-1~deb10u1 breaks application

2020-05-07 Thread Markus Koschany
Control: severity -1 normal Am 07.05.20 um 17:58 schrieb Michael Meier: [...] > The application doesn't use ajp. > > The sense of using unattended-upgrades and debian stable (no breaking > changes on updates) is not to read each security announcement in before. > > I'm not working in an area,

Bug#959937: tomcat9: update to tomcat9:amd64 9.0.31-1~deb10u1 breaks application

2020-05-07 Thread Markus Koschany
ut note that we ship the latest upstream version basically unmodified, so this would be most likely an upstream bug. Regards, Markus Koschany signature.asc Description: OpenPGP digital signature

Bug#959747: tomcat8: Tomcat8 fix for CVE-2020-1938 breaks compatibility with Apache2 mod_proxy_ajp

2020-05-04 Thread Markus Koschany
Control: severity -1 normal Hello, Am 04.05.20 um 21:58 schrieb Gianluca Bonetti: > Package: tomcat8 > Version: 8.5.54-0+deb9u1 > Severity: grave > > Dear Maintainer, > > Last tomcat8 upgrade, fixing CVE-2020-1938, is breaking the > functionalities of Tomcat AJP connector > in standard setup.

Bug#953487: fixed in runescape 0.7-1

2020-04-10 Thread Markus Koschany
I suggest we wait a little for a response from non-f...@buildd.debian.org before we make another upload. However if there is no response in two weeks, we can just proceed by making a binary upload of runescape. Bug #956275 can be resolved by replacing the runescape.png icon. The license is most

Bug#953487: fixed in runescape 0.7-1

2020-04-10 Thread Markus Koschany
Hello Carlos, I had uploaded the new version of runescape to fix bug 953487 because you stated in https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=953487#25 that the package has been whitelisted. Apparently this is not the case hence I am writing to non-f...@buildd.debian.org again and I

Bug#956276: runescape: downloads unverified binary and runs it

2020-04-09 Thread Markus Koschany
Am 09.04.20 um 15:18 schrieb Stephen Kitt: > Le 09/04/2020 14:47, Markus Koschany a écrit : >> Am 09.04.20 um 13:58 schrieb Stephen Kitt: >>> Le 09/04/2020 13:44, Markus Koschany a écrit : >>>> Am 09.04.20 um 13:24 schrieb Stephen Kitt: >>>>> On Th

Bug#956276: runescape: downloads unverified binary and runs it

2020-04-09 Thread Markus Koschany
Am 09.04.20 um 13:58 schrieb Stephen Kitt: > Le 09/04/2020 13:44, Markus Koschany a écrit : >> Am 09.04.20 um 13:24 schrieb Stephen Kitt: >>> On Thu, 9 Apr 2020 12:37:03 +0200, Markus Koschany >>> wrote: >>>> Am 09.04.20 um 11:36 schrieb Ivo De Decker: >

Bug#956276: runescape: downloads unverified binary and runs it

2020-04-09 Thread Markus Koschany
Am 09.04.20 um 13:24 schrieb Stephen Kitt: > On Thu, 9 Apr 2020 12:37:03 +0200, Markus Koschany wrote: >> Am 09.04.20 um 11:36 schrieb Ivo De Decker: >>> It seems runescape downloads a binary and runs it, without verifying its >>> integrity. At least the d

Bug#956268: Problems identified in debian/copyright

2020-04-09 Thread Markus Koschany
> This is not a problem with my understanding of the format, this is a problem > with an incomplete debian/copyright file. The whole package is distributed under the GPL-3+ and MIT licensed code explicitly allows that. This is a minor documentation bug and will be fixed with one of the

Bug#956276: runescape: downloads unverified binary and runs it

2020-04-09 Thread Markus Koschany
fication is done. Could you quote the relevant part of Debian Policy, that requires verification (and what kind of verification) of downloaded files. Is downloading of verified orig tarballs now a requirement or is it still just sufficient to download the tarball and verify its integrity b

Bug#956268: Problems identified in debian/copyright

2020-04-09 Thread Markus Koschany
he sources. The changelog copies in debian/upstream were the last time we could extract the information without any issues. Markus Koschany signature.asc Description: OpenPGP digital signature

Bug#955755: marked as pending in commons-configuration2

2020-04-05 Thread Markus Koschany
Control: tag -1 pending Hello, Bug #955755 in commons-configuration2 reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at:

Bug#952062: marked as pending in openjfx

2020-04-04 Thread Markus Koschany
Control: tag -1 pending Hello, Bug #952062 in openjfx reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at:

Bug#948740: marked as pending in clanlib

2020-02-28 Thread Markus Koschany
Control: tag -1 pending Hello, Bug #948740 in clanlib reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at:

Bug#951959: marked as pending in megaglest

2020-02-28 Thread Markus Koschany
Control: tag -1 pending Hello, Bug #951959 in megaglest reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at:

Bug#951974: marked as pending in spring

2020-02-27 Thread Markus Koschany
Control: tag -1 pending Hello, Bug #951974 in spring reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at:

Bug#952049: pekka-kana-2: FTBFS: SDL_image.h:100:24: error: missing binary operator before token "("

2020-02-27 Thread Markus Koschany
Hi Carlos, I have uploaded pekka-kana-2 to unstable. The pristine-tar commit for version 1.2.6 was missing. Please don't forget to include it next time. Regards, Markus signature.asc Description: OpenPGP digital signature

Bug#951943: blockattack: FTBFS: SagoDataHolder.hpp:26:10: fatal error: SDL_mixer.h: No such file or directory

2020-02-27 Thread Markus Koschany
Hi Simon, thanks for the patch, very helpful. I have forwarded it upstream to https://github.com/blockattack/blockattack-game/issues/23 Regards, Markus signature.asc Description: OpenPGP digital signature

Bug#951943: marked as pending in blockattack

2020-02-27 Thread Markus Koschany
Control: tag -1 pending Hello, Bug #951943 in blockattack reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at:

Bug#952295: marked as pending in freecol

2020-02-24 Thread Markus Koschany
Control: tag -1 pending Hello, Bug #952295 in freecol reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at:

Bug#949301: marked as pending in ufoai

2020-02-23 Thread Markus Koschany
Control: tag -1 pending Hello, Bug #949301 in ufoai reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at:

Bug#951281: FTBFS: /usr/bin/ld: cannot find -lpthreads

2020-02-21 Thread Markus Koschany
On Wed, 19 Feb 2020 22:24:05 +0200 Juhani Numminen wrote: > Markus Koschany kirjoitti 19.2.2020 klo 20.32: > > Hello Juani, > > > > Am 15.02.20 um 09:49 schrieb Juhani Numminen: > > [...] > >> Markus, you have made team uploads of widelands before. I won

Bug#951281: marked as pending in widelands

2020-02-21 Thread Markus Koschany
Control: tag -1 pending Hello, Bug #951281 in widelands reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at:

Bug#951281: FTBFS: /usr/bin/ld: cannot find -lpthreads

2020-02-19 Thread Markus Koschany
Hello Juani, Am 15.02.20 um 09:49 schrieb Juhani Numminen: [...] > Markus, you have made team uploads of widelands before. I wonder if you > could make an upload that adds the patch? Could you adjust the patch to use the same mechanism to find SDL2 as in openjk?

Bug#874870: Version 2.x is qt5-based

2020-02-14 Thread Markus Koschany
Hi, Am 14.02.20 um 23:12 schrieb Boyuan Yang: [...] > Since the complete removal of Qt4 is just around the corner, I am proposing to > do the following work to keep doomsday in Debian's development repository: > > * A Team-upload onto experimental of v2.2.2 with Qt5 support, > * NO support for

Bug#937393: pyblosxom: Python2 removal in sid/bullseye

2020-02-01 Thread Markus Koschany
According to upstream's notice on http://pyblosxom.github.io/, Pyblosxom is no longer in active development. There was the attempt to port it to Python 3 but this one was never completed. Nowadays we have several good alternatives in Debian that achieve the same thing, e.g. hugo or jekyll. I

Bug#949089: libxmlrpc3-java: CVE-2019-17570: deserialization of server-side exception from faultCause in XMLRPC error response

2020-01-17 Thread Markus Koschany
Hi Salvatore, Am 17.01.20 um 06:31 schrieb Salvatore Bonaccorso: [...] > The patch proposed by Red Hat looks straightforward (with my limited > understanding though), but might have as well potential for regression > reports, as it is disabling deserialization by default, i.e. only uses > it if

Bug#949089: libxmlrpc3-java: CVE-2019-17570: deserialization of server-side exception from faultCause in XMLRPC error response

2020-01-16 Thread Markus Koschany
Hi, Am 16.01.20 um 21:27 schrieb Salvatore Bonaccorso: > Source: libxmlrpc3-java > Version: 3.1.3-9 > Severity: grave > Tags: security upstream > Justification: user security hole > > Hi, > > The following vulnerability was published for libxmlrpc3-java. > > CVE-2019-17570[0]: > |

Bug#949089: libxmlrpc3-java: CVE-2019-17570: deserialization of server-side exception from faultCause in XMLRPC error response

2020-01-16 Thread Markus Koschany
Control: owner -1 ! More information and proposed patch at https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-17570 signature.asc Description: OpenPGP digital signature

Bug#948224: pillow: CVE-2020-5310 CVE-2020-5311 CVE-2020-5312 CVE-2020-5313

2020-01-05 Thread Markus Koschany
Package: pillow X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerabilities were published for pillow. It appears they are fixed in version 6.2.2. CVE-2020-5310[0]: | libImaging/TiffDecode.c in Pillow before 6.2.2 has a TIFF decoding | integer

Bug#948180: found 948180 in 4.1.2+dfsg-5, closing 948180

2020-01-05 Thread Markus Koschany
Am 05.01.20 um 13:39 schrieb Salvatore Bonaccorso: > Hi Markus, > > On Sun, Jan 05, 2020 at 01:26:37PM +0100, Markus Koschany wrote: >> Am 05.01.20 um 06:44 schrieb Salvatore Bonaccorso: >>> found 948180 4.1.2+dfsg-5 >>> close 948180 4.2.0+dfsg-1 >>>

Bug#948180: found 948180 in 4.1.2+dfsg-5, closing 948180

2020-01-05 Thread Markus Koschany
Am 05.01.20 um 06:44 schrieb Salvatore Bonaccorso: > found 948180 4.1.2+dfsg-5 > close 948180 4.2.0+dfsg-1 > thanks You could have kept the bug report open until the issue is really fixed in unstable. I didn't see the new version in experimental until after I filed the bug report but sometimes

Bug#948180: opencv: CVE-2019-5063 and CVE-2019-5064

2020-01-04 Thread Markus Koschany
Package: opencv X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerabilities were published for opencv. CVE-2019-5064[0]: | An exploitable heap buffer overflow vulnerability exists in the data | structure persistence functionality of OpenCV, version

Bug#947212: Bug#947143: RFS: wordpress/5.3.2+dfsg1-0.1 [NMU] [RC] -- weblog manager

2019-12-23 Thread Markus Koschany
Hello Niels, Am 23.12.19 um 15:04 schrieb DebBug: > Anyone to chime in? Craig? Markus? There is a bit of confusion here, so I try to explain the situation and how we should proceed. Thank you for filing bug report #947212 to track the security issues in Wordpress. This will help to answer those

Bug#945115: armagetronad does not find itself (and fails to start)

2019-11-22 Thread Markus Koschany
Control: tags -1 pending Am 20.11.19 um 14:45 schrieb Bernhard Übelacker: > Control: tags -1 + upstream fixed-upstream patch > > > Dear Maintainer, > the issue seems to be with newer gcc versions string literals > get not put into memory mappings " r-xp ", > instead they are mapped " r--p ". >

Bug#925337: fixed in ublock-origin 1.22.2+dfsg-1~deb9u1

2019-11-22 Thread Markus Koschany
Hello, You have to enable the -proposed-updates archive in Stretch to download the latest version of ublock-origin. It will be merged to stable eventually. Regards, Markus signature.asc Description: OpenPGP digital signature

Bug#944431: marked as pending in berusky2

2019-11-13 Thread Markus Koschany
Control: tag -1 pending Hello, Bug #944431 in berusky2 reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at:

Bug#943870: marked as pending in auralquiz

2019-11-09 Thread Markus Koschany
Control: tag -1 pending Hello, Bug #943870 in auralquiz reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at:

Bug#942507: pdfsam: Not working due to multiple errors

2019-10-25 Thread Markus Koschany
Control: severity -1 important I'm downgrading this issue to important because pdfsam in testing is not affected. As long as hibernate-validator 5.x does not migrate to testing, before this bug is fixed in unstable, it should not be a problem signature.asc Description: OpenPGP digital

Bug#925337: webext-ublock-origin: deactivated with Firefox 66

2019-10-25 Thread Markus Koschany
Control: block 943470 by 942349 Hello, Am 25.10.19 um 01:49 schrieb Jens Rottmann: > Ping. > > As Jonas anticipated, regression in Stable: ublock no longer works after > Firefox ESR updated to 68. > > Thanks and best regards, > Jens The testing version of ublock-origin is pending approval by

Bug#943439: src:asc: Please update/remove libwxgtk3.0-dev build-dependency

2019-10-24 Thread Markus Koschany
Hi Olly, Am 24.10.19 um 21:31 schrieb Olly Betts: > Package: src:asc > Version: 2.6.1.0-5 > Severity: serious > Justification: blocks the almost-complete wxwidgets3.0-gtk3 transition [...] Thanks for reporting. I have uploaded a new revision of asc that uses libwxgtk3.0-gtk3-dev instead of

Bug#943439: marked as pending in asc

2019-10-24 Thread Markus Koschany
Control: tag -1 pending Hello, Bug #943439 in asc reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at:

Bug#942814: libhibernate-validator-java: update to 5.3.6 breaks reverse-dependencies

2019-10-21 Thread Markus Koschany
Package: libhibernate-validator-java Version: 5.3.6-1 Severity: serious The update of libhibernate-validator-java to version 5.3.6. broke at least pdfsam (#942507) and libspring-java. The new version is incompatible with libgeronimo-validation-1.0-spec-java and requires

Bug#942507: pdfsam: Not working due to multiple errors

2019-10-21 Thread Markus Koschany
Control: tags -1 confirmed On Thu, 17 Oct 2019 12:41:57 +0200 Domenico Cufalo wrote: > Package: pdfsam > Version: 4.0.4-1 > Severity: grave > Justification: renders package unusable > > Dear Maintainer, > > I'm sorry for the generic subject of this bug report, but... I don't know how > to

Bug#935669: assaultcube-data (1.2.0.2.1-3) in enabled autobuilding

2019-10-17 Thread Markus Koschany
Hi, Am 17.10.19 um 01:53 schrieb Carlos Donizete Froes: > Hi, > > The assaultcube-data (1.2.0.2.1-3) package includes "XS-Autobuild: yes" in the > header portion of "debian/control"[1] and the disclaimer compliance with the > licenses contained in "debian/copyright"[2] where It's okay to create

Bug#942315: tcpdump: Version in oldoldstable is higher than oldstable and stable

2019-10-16 Thread Markus Koschany
Hello, Am 16.10.19 um 20:30 schrieb Romain Francoise: > Hi Guillem, > > On Mon, Oct 14, 2019 at 3:45 PM Guillem Jover wrote: >> With the latest upload to oldoldstable-security, the versions in >> oldstable and stable are now lower. This means that upgrades will >> not take effect for this

Bug#941687: lablie: FTBFS with jackson-databind 2.10.0

2019-10-07 Thread Markus Koschany
Hello Miroslav, Am 07.10.19 um 09:36 schrieb Miroslav Kravec: > Hello Markus, > > thank you for informing about this issue. Is this blocking you? Are > you releasing a new version of jackson databind to Debian? > > Kind regards, > Miro Not at all. I had to package a new release of

Bug#941530: jackson-databind: CVE-2019-16942 CVE-2019-16943

2019-10-03 Thread Markus Koschany
Control: clone 941530 -1 Control: retitle -1 jackson-databind: consider using a whitelist Control: severity -1 wishlist Hi, Am 02.10.19 um 09:43 schrieb Salvatore Bonaccorso: [...] > Whilst I'm not yet sure if we should really release a futher DSA for > jackson-databind (we will come back to you

Bug#941530: jackson-databind: CVE-2019-16942 CVE-2019-16943

2019-10-01 Thread Markus Koschany
Hi Salvatore, Am 01.10.19 um 22:34 schrieb Salvatore Bonaccorso: > Source: jackson-databind > Version: 2.10.0-1 > Severity: grave > Tags: security upstream > Justification: user security hole > Forwarded: https://github.com/FasterXML/jackson-databind/issues/2478 > Control: found -1 2.9.8-3 >

Bug#874870: Version 2.x is qt5-based

2019-10-01 Thread Markus Koschany
Hello, Am 29.09.19 um 22:38 schrieb Moritz Mühlenhoff: > On Sun, Mar 18, 2018 at 09:11:24PM -0300, Lisandro Damián Nicanor Pérez Meyer > wrote: >> Hi! Version 2.x is qt5-based. Please check if you can update this game. Feel >> free to ask for help with Qt5 if needed. > > It's been 1.5 years

Bug#940498: jackson-databind: CVE-2019-14540 CVE-2019-16335

2019-09-29 Thread Markus Koschany
Control: tags -1 pending On Mon, 16 Sep 2019 15:14:37 +0200 Salvatore Bonaccorso wrote: > Source: jackson-databind > Version: 2.9.9.3-1 > Severity: grave > Tags: security upstream > Justification: user security hole [...] > p.s.: wondering where that will going to end ;-) Hi, I also think it

Bug#874809: [alsoft-conf] Future Qt4 removal from Buster

2019-09-02 Thread Markus Koschany
Hi, Am 02.09.19 um 20:56 schrieb Moritz Mühlenhoff: [...] > alsoft-conf is dead upstream, does anyone in the Debian Games Team intend to > port it themselves? Otherwise I'll file a removal bug. I'm fine with removing alsoft-conf from Debian. There was only one initial upload by the actual

Bug#933854: marked as pending in lucene-solr

2019-09-02 Thread Markus Koschany
Control: tag -1 pending Hello, Bug #933854 in lucene-solr reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at:

Bug#933854: solr-jetty: Jetty lacks necessary write permissions to /var/lib/solr/data/index/

2019-09-02 Thread Markus Koschany
Control: tags 933857 pending Control: tags 933854 pending On Sun, 1 Sep 2019 19:47:48 -0700 "J.P. Larocque" wrote: > stephan, thanks for tracking this down. I almost figured it out, and > then I found that you already reported this bug. Your other bug > report was also super helpful for me to

Bug#923330: jajuk: Fails to start with Java Runtime Environment 1.7 minimum required. You use a JVM ext.JVM@23fc625e

2019-08-27 Thread Markus Koschany
I pushed more changes to Git. We could fix the NullPointerException in insubstantial but now I get two different errors. Failed to register bus name / null and NoClassDefFoundError: org/slf4j/LoggerFactory I don't know why this class is suddenly missing from the classpath. signature.asc

Bug#911078: triplea: Fails to start with NullPointerException

2019-08-26 Thread Markus Koschany
Hello, On Wed, 7 Aug 2019 08:36:38 -0700 Dan Van Atta wrote: > Apologies for the long delay, updates to Debian are a deeper issue than I > initially realized. TripleA has had a history of maintenance overhead > problems, seeing the Debian fork has me realize that it is a fork with its > own

Bug#933715: jh_linkjars: dpkg -L "debhelper-compat" returned exit code 1

2019-08-02 Thread Markus Koschany
Package: javahelper Version: 0.72.9 Severity: serious jh_linkjars apparently chokes on the new debhelper-compat package. Since it is not a real package dpkg -L does not work. I presume the workaround is to either add debhelper-compat to a blacklist or to find a more general way to not use dpkg

Bug#931097: unattended-upgrades: InvalidURL(f"URL can't contain control characters. {url!r} "

2019-06-26 Thread Markus Koschany
Hello, Am 26.06.19 um 09:59 schrieb duncanwebb: > Package: unattended-upgrades > Version: 0.83.3.2+deb8u1 > Severity: serious > Justification: normal > > Dear Maintainer, > > Jessie uses python 3.4 and python 3.4 does not support f"" strings > > So now unattended upgrades no longer performs

Bug#930676: goplay: Should this package be removed?

2019-06-22 Thread Markus Koschany
Hello, On Tue, 18 Jun 2019 12:46:30 +0200 Julian Andres Klode wrote: > Package: goplay > Severity: serious > > Hi folks, > > goplay has not received any updates since 2015, it uses libept, > which we'd like to get rid of eventually I think, as it's also > unmaintained, so I think it would be

Bug#929483: marked as pending in robocode

2019-05-24 Thread Markus Koschany
Control: tag -1 pending Hello, Bug #929483 in robocode reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at:

Bug#925509: netbeans: Netbeans not usable with java in Buster

2019-05-03 Thread Markus Koschany
Hi Jochen, Am 03.05.19 um 13:47 schrieb Jochen Sprickerhof: [...] > This is due to libnb-javaparser-java which is still on the jdk-9 > version. [...] > So one way would be to get this packaged (maybe rename nb-javac-9-*.jar > to nb-javac-11-*.jar) and convince the release team to include

Bug#925509: netbeans: Netbeans not usable with java in Buster

2019-05-02 Thread Markus Koschany
Hi, Am 02.05.19 um 20:56 schrieb Jochen Sprickerhof: [...] > I had a look into this was able to create new projects when I remove the > nb-javac.patch. @Markus do we really need it? The nb-javac patch is necessary, otherwise the nb-javac module is not properly detected at runtime. You should see

Bug#928240: etw: Segmentation fault at start

2019-05-01 Thread Markus Koschany
Thank you very much. I have uploaded a new revision with your patch a few minutes ago. The game itself appears to work, the settings menu for the controls is a bit hidden. ETW was originally developed for the AMIGA, so that may explain some of the oddities. Regards, Markus signature.asc

Bug#928240: Bug #928240 in etw marked as pending

2019-05-01 Thread Markus Koschany
Control: tag -1 pending Hello, Bug #928240 in etw reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at:

Bug#928240: etw: Segmentation fault at start

2019-04-30 Thread Markus Koschany
Hi, Am 01.05.19 um 00:31 schrieb Steinar H. Gunderson: > On Tue, Apr 30, 2019 at 11:23:52PM +0100, Simon McVittie wrote: >>> On a quick analysis: It appears that etw tries to find its own path by >>> opening /proc/self/maps (code is in etw/prefix.c), looking for an executable >>> mapping (r-xp)

Bug#927152: teeworlds: CVE-2019-10877 CVE-2019-10878 CVE-2019-10879

2019-04-15 Thread Markus Koschany
Package: teeworlds X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerabilities were published for teeworlds. CVE-2019-10877[0]: | In Teeworlds 0.7.2, there is an integer overflow in CMap::Load() in | engine/shared/map.cpp that can lead to a buffer

Bug#888547: CVE-2017-1000190

2019-04-14 Thread Markus Koschany
Hi, Am 13.04.19 um 11:31 schrieb Ivo De Decker: [...] > It is possible to remove the test-dependency (probably by disabling the > tests)? That way simple-xml could be removed from buster. Even if we don't do > this for buster, it might be good to do this for bullseye anyway, if the > package

<    1   2   3   4   5   6   7   8   9   10   >