Bug#868609: le FTBFS with latest ncurses

2017-08-23 Thread Raphael Geissert
On 23 August 2017 at 14:56, Alexander V. Lukyanov <l...@netis.ru> wrote: > On Fri, Aug 18, 2017 at 12:39:00PM +0200, Raphael Geissert wrote: >> Do you plan to make a new release with the fixes? or should I grab the >> patches from github? > > 1.16.5 has been released.

Bug#868609: le FTBFS with latest ncurses

2017-08-18 Thread Raphael Geissert
Alexander, Do you plan to make a new release with the fixes? or should I grab the patches from github? I'd like to fix this some time soon to get le back in testing. Thanks in advance. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net

Bug#849382: [apt] Every package on the system gets silently upgraded to backports. The result is severe system breakage, malfunctioning and data loss.

2017-01-26 Thread Raphael Geissert
Hi, As discussed via IRC, this could be a case of https://bugs.debian.org/838920 in unattended-upgrades. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net

Bug#802811: libqt5x11extras5: causes konsole to segfault in libX11 on startup

2015-10-27 Thread Raphael Geissert
e because qtx11extras migrated to > testing when it shouldn't have. This is the first time it happens for us. Doesn't that sound like there's a missing dependency, somewhere? It sounds like a person using a testing-unstable mix would also be affected. /me who also got hit by it -- Raphael Gei

Bug#796495: yubiserver: multiple vulnerabilities, affecting old/stable?

2015-08-22 Thread Raphael Geissert
/doc/manuals/developers-reference/pkgs.html#bug-security Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net

Bug#780624: libmpeg2-4: introduces new symbols

2015-03-16 Thread Raphael Geissert
directly, perhaps picked up?, do not have a proper versioned dependency on libmpeg2-4. One such package is gstreamer1.0-plugins-ugly, though there might be others. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-rc-requ

Bug#775673: texlive-bin: CVE-2015-0973: overflow in the embedded libpng

2015-01-18 Thread Raphael Geissert
-referencing. Thanks in advance. [1]http://article.gmane.org/gmane.comp.security.oss.general/15382 Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact

Bug#772221: byobu: bashism in /bin/sh script

2014-12-07 Thread Raphael Geissert
Control: severity -1 minor Hi, Please ignore the part of sourced script with arguments, as it is a false positive in this case. Apologies. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org

Bug#772233: bashism in /bin/sh script

2014-12-07 Thread Raphael Geissert
Control: tag -1 patch Attached patch should do it. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.netIndex: gnunet-0.10.1-2/src/gns/gnunet-gns-proxy-setup-ca === --- gnunet-0.10.1-2/src/gns/gnunet-gns

Bug#772217: cmtk: bashism in /bin/sh script

2014-12-06 Thread Raphael Geissert
it accordingly. If it's important or greater please hurry to get this fixed for jessie. Hints about how to fix bashisms can be found at: https://wiki.ubuntu.com/DashAsBinSh Thanks in advance, Raphael Geissert -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject

Bug#772219: cluster-glue: bashism in /bin/sh script

2014-12-06 Thread Raphael Geissert
/DashAsBinSh Thanks in advance, Raphael Geissert -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#772221: byobu: bashism in /bin/sh script

2014-12-06 Thread Raphael Geissert
is, and adjust it accordingly. If it's important or greater please hurry to get this fixed for jessie. Hints about how to fix bashisms can be found at: https://wiki.ubuntu.com/DashAsBinSh Thanks in advance, Raphael Geissert -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org

Bug#772225: couchdb: bashism in /bin/sh script

2014-12-06 Thread Raphael Geissert
://wiki.ubuntu.com/DashAsBinSh Thanks in advance, Raphael Geissert -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#772239: git-remote-gcrypt: bashism in /bin/sh script

2014-12-06 Thread Raphael Geissert
it accordingly. If it's important or greater please hurry to get this fixed for jessie. Hints about how to fix bashisms can be found at: https://wiki.ubuntu.com/DashAsBinSh Thanks in advance, Raphael Geissert -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject

Bug#772233: gnunet: bashism in /bin/sh script

2014-12-06 Thread Raphael Geissert
. If it's important or greater please hurry to get this fixed for jessie. Hints about how to fix bashisms can be found at: https://wiki.ubuntu.com/DashAsBinSh Thanks in advance, Raphael Geissert -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe

Bug#772250: fbb: bashism in /bin/sh script

2014-12-06 Thread Raphael Geissert
bashisms can be found at: https://wiki.ubuntu.com/DashAsBinSh Thanks in advance, Raphael Geissert -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#772256: ferret-vis: bashism in /bin/sh script

2014-12-06 Thread Raphael Geissert
bashisms can be found at: https://wiki.ubuntu.com/DashAsBinSh Thanks in advance, Raphael Geissert -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#772262: dnssec-trigger: bashism in /bin/sh script

2014-12-06 Thread Raphael Geissert
to get this fixed for jessie. Hints about how to fix bashisms can be found at: https://wiki.ubuntu.com/DashAsBinSh Thanks in advance, Raphael Geissert -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#772325: libmbim-utils: bashism in /bin/sh script

2014-12-06 Thread Raphael Geissert
or greater please hurry to get this fixed for jessie. Hints about how to fix bashisms can be found at: https://wiki.ubuntu.com/DashAsBinSh Thanks in advance, Raphael Geissert -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas

Bug#772347: xbmc: bashism in /bin/sh script

2014-12-06 Thread Raphael Geissert
. If it's important or greater please hurry to get this fixed for jessie. Hints about how to fix bashisms can be found at: https://wiki.ubuntu.com/DashAsBinSh Thanks in advance, Raphael Geissert -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe

Bug#772365: simpleburn: bashism in /bin/sh script

2014-12-06 Thread Raphael Geissert
at: https://wiki.ubuntu.com/DashAsBinSh Thanks in advance, Raphael Geissert -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#772376: tau: bashism in /bin/sh script

2014-12-06 Thread Raphael Geissert
what the proper severity of the bug is, and adjust it accordingly. If it's important or greater please hurry to get this fixed for jessie. Hints about how to fix bashisms can be found at: https://wiki.ubuntu.com/DashAsBinSh Thanks in advance, Raphael Geissert -- To UNSUBSCRIBE, email to debian

Bug#772410: scilab: bashism in /bin/sh script

2014-12-06 Thread Raphael Geissert
. If it's important or greater please hurry to get this fixed for jessie. Hints about how to fix bashisms can be found at: https://wiki.ubuntu.com/DashAsBinSh Thanks in advance, Raphael Geissert -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe

Bug#772188: avis: bashism in /bin/sh script

2014-12-05 Thread Raphael Geissert
/DashAsBinSh Thanks in advance, Raphael Geissert -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#772195: 389-ds-base: bashism in /bin/sh script

2014-12-05 Thread Raphael Geissert
bashisms can be found at: https://wiki.ubuntu.com/DashAsBinSh Thanks in advance, Raphael Geissert -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#772191: armagetronad-dedicated: bashism in /bin/sh script

2014-12-05 Thread Raphael Geissert
at: https://wiki.ubuntu.com/DashAsBinSh Thanks in advance, Raphael Geissert -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#763148: Re: Bug#763148: Prevent migration to jessie

2014-10-05 Thread Raphael Geissert
: given your apparent lack of understanding of the situation and way of communicating it only makes me wonder on the ability to work with you as the maintainer of such a security- sensitive package that ffmpeg is. I truly hope you understand the implications of such an impediment. Regards, -- Raphael

Bug#694143: php5-ffmpeg: FTBFS because of deprecated functions

2014-05-13 Thread Raphael Geissert
once and then to sponsor the package. Will be filing the removal request later today. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas

Bug#745836: wget: certificate revocation is not checked

2014-04-28 Thread Raphael Geissert
[...] It is not a bug, it is a missing feature. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#694143: php5-ffmpeg: FTBFS because of deprecated functions

2014-04-28 Thread Raphael Geissert
! The missing declaration of time_t was puzzling me. Thanks, I will take a look at the other bugs to get the package back in shape. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject

Bug#743883: Is it realy fixed?

2014-04-11 Thread Raphael Geissert
*) and restart applications as soon as possible. [emphasis is mine] We did mention it. -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas

Bug#734238: Patch for CVE-2013-6045

2014-04-07 Thread Raphael Geissert
and upload to security-master.d.o. Can you do that? Thanks. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#741561: No longer ship cacert certificates

2014-03-13 Thread Raphael Geissert
or that doesn't require a special parameter to connect to any server for which it can not verify the validity of the certificate should be fixed. Don't hesitate to file a bug report against those tools. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE

Bug#741299: freetype: CVE-2014-2240, CVE-2014-2241: stack OOB read/write, DoS

2014-03-10 Thread Raphael Geissert
, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#731860: libtar: CVE-2013-4420: directory traversal when extracting archives

2014-02-14 Thread Raphael Geissert
of .. will yield the desired result, but the even ..s will be missed. Ah, yes, indeed. Nice catch. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe. Trouble

Bug#731860: libtar: CVE-2013-4420: directory traversal when extracting archives

2014-02-11 Thread Raphael Geissert
contains an entry called ../../../empty-file tar tf should print a warning message and list the full path, while libtar should simply print it as 'empty-file'. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net triple-double-dot.tar Description: Unix tar archive

Bug#734238: Fix for CVE-2013-6045 breaks decoding of chroma-subsampled images

2014-01-06 Thread Raphael Geissert
to memory outside the allocated buffer. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#732963: ssh fails with OpenSSL version mismatch. Built against 1000105f, you have 10001060

2013-12-23 Thread Raphael Geissert
Known bug in openssh. Merging. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#732966: [openssl] Update to openssl 1.0.1e-5 renders X unusable

2013-12-23 Thread Raphael Geissert
mismatch. Built against 1000105f, you have 10001060 That's openssh. If there's anything else that's breaking your DM or something else then it might be another bug in a different package, but not in openssl. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net

Bug#732144: Bug#731357: opu: package librsvg/2.26.3-2

2013-12-20 Thread Raphael Geissert
Hi again, Found another case where it didn't work as expected. Updated, attached, patch should do it. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net Index: librsvg-2.26.3/rsvg-image.c === --- librsvg

Bug#732144: Bug#731357: opu: package librsvg/2.26.3-2

2013-12-19 Thread Raphael Geissert
Control: tag 732144 patch Attached patch should correctly handle URIs and non-URIs. I've tested it with a few applications using relative and absolute paths, and URIs. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net Index: librsvg-2.26.3/rsvg-image.c

Bug#731860: libtar: CVE-2013-4420: directory traversal when extracting archives

2013-12-10 Thread Raphael Geissert
) id in your changelog entry. For further information see: [0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4420 http://security-tracker.debian.org/tracker/CVE-2013-4420 Attached is a proposed patch that makes libtar work similarly to tar. Cheers, -- Raphael Geissert - Debian

Bug#731237: openjpeg: CVE-2013-1447 CVE-2013-6045 CVE-2013-6052 CVE-2013-6054

2013-12-03 Thread Raphael Geissert
Hi, There are also some other issues that are specific to 1.5.1 (or at least they do not affect 1.3): CVE-2013-6053: information leaks CVE-2013-6887: DoS All the patches will be available as soon as I forward to oss-sec the messages I sent to the distros list. Cheers, -- Raphael Geissert

Bug#730637: gtk+3.0: FTBFS when building with -j8

2013-11-27 Thread Raphael Geissert
/shared' make[1]: *** [all] Error 2 make[1]: Leaving directory `/tmp/buildd/gtk+3.0-3.4.2/debian/build/shared' make: *** [debian/stamp-makefile-build/shared] Error 2 dpkg-buildpackage: error: debian/rules build gave error exit status 2 I haven't tried with the version in sid. Cheers, -- Raphael

Bug#692606: Marking as done in recent versions

2013-10-28 Thread Raphael Geissert
correctly tracked as fixed in later versions. I'll coordinate with SRM for uploading a fix to stable. Are you available to test a tentatively fixed package before upload? The change is trivial, but sure. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net

Bug#726578: pwgen: Multiple vulnerabilities in passwords generation

2013-10-17 Thread Raphael Geissert
and is command-line and output-compatible with pwgen. Basically changing everything under the hood without letting others know. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject

Bug#723716: hplip: CVE-2013-4325

2013-10-14 Thread Raphael Geissert
Control: tag -1 patch Control: found -1 3.10.6-2 Hi, Could you also please prepare fixed packages targeting old/stable for a DSA? Once prepared please send the debdiff to team@security.d.o to coordinate their upload and release. Thanks in advance, -- Raphael Geissert - Debian Developer

Bug#722536: eglibc: CVE-2013-4332

2013-10-08 Thread Raphael Geissert
Control: tags -1 + patch Hi, Attached patch applies to eglibc 2.11 and 2.13 (squeeze and wheezy). It is the same as upstream, but with a fixed context. Tested on both releases. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net CVE-2013-4332.patch Description

Bug#723103: dieharder: non-free due to $beverage clause?

2013-09-16 Thread Raphael Geissert
and act if necessary. [1]http://ftp-master.metadata.debian.org/changelogs/main/d/dieharder/unstable_copyright Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe. Trouble

Bug#694143: [php-maint] Bug#694143: FTBFS against libav 9

2013-09-10 Thread Raphael Geissert
once we have released and the transition is planned with release team. In the mean time libav9 was uploaded, could you please look into a fix? I had completely forgotten about this bug *sigh* Will try to give it a shot this week unless somebody beats me to it. Cheers, -- Raphael Geissert

Bug#719462: should this package be removed?

2013-08-30 Thread Raphael Geissert
), targeting the $codename-security archives with a symbolic urgency of high and send the debdiffs to team@security.d.o prior to their upload to the security archive. Thanks in advance. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email

Bug#719462: should this package be removed?

2013-08-29 Thread Raphael Geissert
know what you think. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#719462: libmodplug: CVE-2013-4233 CVE-2013-4234

2013-08-28 Thread Raphael Geissert
Hi, On 14 August 2013 16:17, Raphael Geissert geiss...@debian.org wrote: Looking at your fix in c4d4e0478, I'd look into fixing it in a way that doesn't imply that integers overflow, as that's undefined behavior and can be optimised away by compilers. None of the instructions can actually

Bug#712745: Re: [Pkg-puppet-devel] Bug#712745: Bug#7712745: puppet: CVE-2013-3567

2013-08-20 Thread Raphael Geissert
check if that is the issue by modifying transaction/report.rb's initialize to @report_format = 3. Regards, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact

Bug#712745: [Pkg-puppet-devel] Bug#712745: Bug#712745: puppet: CVE-2013-3567

2013-08-20 Thread Raphael Geissert
this is in fact a regression. -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#719462: libmodplug: CVE-2013-4233 CVE-2013-4234

2013-08-14 Thread Raphael Geissert
. Wouldn't it be better to just set a limit to j that is checked while calculating the amount of memory that is needed, and that is lower enough than INT_MAX that performing one more iteration won't overflow it? Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net

Bug#712745: Re: [Pkg-puppet-devel] Bug#712745: Bug#7712745: puppet: CVE-2013-3567

2013-08-05 Thread Raphael Geissert
Hi Stig, Chris, Stig: Have you been able to check the report? I haven't taken a proper look at it, but I think there's at least one extra field that doesn't correspond to the format version. On 31 July 2013 17:43, Chris Boot c...@tiger-computing.co.uk wrote: On 25/06/13 17:36, Raphael Geissert

Bug#692606: network-manager-strongswan: charon dump on vpn start

2013-08-02 Thread Raphael Geissert
On 2 August 2013 12:29, Raphael Geissert geiss...@debian.org wrote: I strongly believe this to be the problem with the plugin initialisation, fixed with c140757221. Oh, and if that's the cause then, this is a bug in the strongswan package, so: reassign 692606 strongswan-nm affects 692606

Bug#714409: libgtk-3-0: triggers ci file contains unknown directive `interest-noawait' on install (needs newer dpkg)

2013-07-14 Thread Raphael Geissert
, reverting the severity. Sorry about that. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#714264: CVE-2013-2190: screen unlocked after resuming due to crash

2013-06-27 Thread Raphael Geissert
://bugzilla.redhat.com/show_bug.cgi?id=954054 Please adjust the affected versions in the BTS as needed. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities Exposures) id in your changelog entry. Cheers, -- Raphael Geissert - Debian Developer www.debian.org

Bug#712745: [Pkg-puppet-devel] Bug#712745: Bug#7712745: puppet: CVE-2013-3567

2013-06-25 Thread Raphael Geissert
On 21 June 2013 17:07, Raphael Geissert geiss...@debian.org wrote: As promised via IRC, attached patch is a version that actually works. And now a patch to be applied on top of it to restore the compatibility of the reports. Cheers, -- Raphael Geissert - Debian Developer www.debian.org

Bug#712745: Bug#7712745: puppet: CVE-2013-3567

2013-06-19 Thread Raphael Geissert
Hi, Upstream provided me with the following gist against 2.6.18 that fixes this vulnerability: https://gist.github.com/stahnma/d7598b49a4abc07845b9 Haven't checked how much backporting is needed. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net

Bug#711316: [Pkg-phototools-devel] Bug#711316: Bug#711316: darktable: CVE-2013-2126: double free

2013-06-10 Thread Raphael Geissert
provided when submitting the bug report. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#711317: libkdcraw: CVE-2013-2126: double free

2013-06-06 Thread Raphael Geissert
/bugreport.cgi?bug=710353#17 Could you please prepare fixed packages for oldstable and stable, to be included in point releases? Thanks. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject

Bug#711316: darktable: CVE-2013-2126: double free

2013-06-06 Thread Raphael Geissert
/bugreport.cgi?bug=710353#17 Could you please prepare fixed packages for stable, to be included in point releases? Thanks. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe

Bug#702775: [Pkg-monitoring-maintainers] Bug#702775: ganglia: limiting security support

2013-05-28 Thread Raphael Geissert
reviewing the code, implement standard web security measures and make sure the expected use and its requirements are considered also by upstream and continued during the following releases. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian

Bug#702775: [Pkg-monitoring-maintainers] Bug#702775: ganglia: limiting security support

2013-05-28 Thread Raphael Geissert
security team were involved in analyzing the code and a reference to this bug. Feel free to add a security notice upstream, but the README.Debian.security file is to state that the Debian security team is going to provide limited support. As such, it should be kept in Debian. Cheers, -- Raphael

Bug#702775: ganglia: limiting security support

2013-03-11 Thread Raphael Geissert
, however. As such, please add a README.Debian.security file briefly mentioning the limited security support, effective for the version in wheezy and newer. Thanks in advance. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-rc

Bug#702736: [pkg-firebird-general] Bug#693210: server crash on prearing an empty query with tracing enabled

2013-03-11 Thread Raphael Geissert
there's also another issue affecting firebird, this less severe issue could be fixed in the same DSA. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe. Trouble

Bug#687334: Please add security queues for armhf and s390x

2013-03-10 Thread Raphael Geissert
Hi, Am I missing something, or with the recent changes this bug can be closed now? (i.e. security build queues and buildds are all setup.) Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org

Bug#701897: CVE-2012-5667: buffer overflow with overly long input lines

2013-03-04 Thread Raphael Geissert
Hi, The issue can easily be reproduced on an x86_64 system running squeeze with the public reproducer. Valgrind also shows the issue (but beware of the time and memory it takes). Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian

Bug#701897: CVE-2012-5667: buffer overflow with overly long input lines

2013-02-28 Thread Raphael Geissert
/cgi-bin/cvename.cgi?name=CVE-2012-5667 http://security-tracker.debian.org/tracker/CVE-2012-5667 Please adjust the affected versions in the BTS as needed. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-rc-requ

Bug#701549: refdb-clients: bashism in /bin/sh script

2013-02-24 Thread Raphael Geissert
to fix bashisms at: https://wiki.ubuntu.com/DashAsBinSh Thank you, Raphael Geissert -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#701555: lcmaps-plugins-jobrep-admin: bashism in /bin/sh script

2013-02-24 Thread Raphael Geissert
/DashAsBinSh Thank you, Raphael Geissert -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#701558: fcitx-bin: bashism in /bin/sh script

2013-02-24 Thread Raphael Geissert
can find hints about how to fix bashisms at: https://wiki.ubuntu.com/DashAsBinSh Thank you, Raphael Geissert -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#687334: Please add security queues for armhf and s390x

2013-01-02 Thread Raphael Geissert
On Thursday 13 September 2012 04:17:03 Philipp Kern wrote: On Tue, Sep 11, 2012 at 03:24:32PM -0500, Raphael Geissert wrote: This is just to keep a record of things that need to be done before the release: * Add security queues for armhf * Add security queues for s390x Of course

Bug#660488: miredo: diff for NMU version 1.2.3-1.1

2012-10-18 Thread Raphael Geissert
tags 660488 + patch thanks Dear maintainer, I've prepared an NMU for miredo (versioned as 1.2.3-1.1) and uploaded it to DELAYED/2. Please feel free to tell me if I should delay it longer. Regards. Raphael Geissert diff -Nru miredo-1.2.3/debian/changelog miredo-1.2.3/debian/changelog --- miredo

Bug#690594: tasksel: execution aborted due to compilation errors

2012-10-15 Thread Raphael Geissert
. Seems like you should 'use 5.014' and/or have a versioned Depends on perl-base. Cheers, Raphael Geissert -- System Information: Debian Release: wheezy/sid APT prefers testing Architecture: i386 (i686) Shell: /bin/sh linked to /bin/dash Versions of packages tasksel depends on: ii apt

Bug#690632: solarpowerlog: bashism in /bin/sh script

2012-10-15 Thread Raphael Geissert
bashisms at: https://wiki.ubuntu.com/DashAsBinSh Thank you, Raphael Geissert -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#689763: jsxgraph: includes non-free jsmin code

2012-10-05 Thread Raphael Geissert
Package: jsxgraph Version: 0.83+svn1872~dfsg-3 Severity: serious Hi, tools/jsmin.py includes the following license clause that makes it non-free: The Software shall be used for Good, not Evil. Cheers, Raphael Geissert -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org

Bug#689764: icinga-web: includes non-free jsmin

2012-10-05 Thread Raphael Geissert
Source: icinga-web Version: 1.7.1-4 Severity: serious Hi, lib/phing/classes/phing/tasks/ext/jsmin/JsMin.php includes the following license clause that makes it non-free: The Software shall be used for Good, not Evil. Cheers, Raphael Geissert -- To UNSUBSCRIBE, email to debian-bugs-rc-requ

Bug#686174: Your isc-dhcp 4.2.2.dfsg.1-5+wheezy1 upload

2012-09-15 Thread Raphael Geissert
Hi again, On Friday 14 September 2012 18:46:48 Raphael Geissert wrote: * Uploads must be coordinated and ACKed by the security team. Unless I'm missing something, it didn't happen this way. I've been pointed out that you talked to Nico about it. Please accept my apologies. Kind regards

Bug#686174: Your isc-dhcp 4.2.2.dfsg.1-5+wheezy1 upload

2012-09-14 Thread Raphael Geissert
. * The testing-security queue is not functional. Any security update for wheezy, during its freeze, must go through testing-proposed-updates if it can't go through sid. Regards, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-rc-requ

Bug#687334: Please add security queues for armhf and s390x

2012-09-11 Thread Raphael Geissert
I'm going to file a similar bug against ftp-master.d.o for that. Cheers, Raphael Geissert -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#687335: Support armhf and s390x in the security archive

2012-09-11 Thread Raphael Geissert
archive * Work with the buildd people to give them access to sec's incoming Thanks. Cheers, Raphael Geissert -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#686961: CVE-2012-3549: kfreebsd SCTP DoS

2012-09-07 Thread Raphael Geissert
://security-tracker.debian.org/tracker/CVE-2012-3549 Please adjust the affected versions in the BTS as needed. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe. Trouble

Bug#686454: CVE-2011-5129: xchat buffer overflow

2012-09-01 Thread Raphael Geissert
Please adjust the affected versions in the BTS as needed. -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#685192: apt: redirection handling changes in 0.9.4 may break aptitude

2012-08-23 Thread Raphael Geissert
One day later than expected... On Tuesday 21 August 2012 10:56:06 Raphael Geissert wrote: If you do consider those cases, then Breaks should probably be used instead. Recommends is not enough even for the scenario where this bug was reproduced: grml - recommends are disabled by default. I

Bug#685192: apt: redirection handling changes in 0.9.4 may break aptitude

2012-08-21 Thread Raphael Geissert
to the initial topic: Adding a recommends, okay? ... because I don't think Recommends is appropriate. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact

Bug#685192: apt: redirection handling changes in 0.9.4 may break aptitude

2012-08-17 Thread Raphael Geissert
:-/ Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#674089: mime-support: removed application/x-httpd-* can lead to immense security problems

2012-05-31 Thread Raphael Geissert
be no application/x-httpd-* entry in mime.types. Perhaps .php and others should be added back as text/x-php and a NEWS entry added. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe

Bug#580540: softgun: FTBFS in non-linux architectures: config.mk:24: *** Unknown architecture. Stop.

2012-05-13 Thread Raphael Geissert
On Sunday 13 May 2012 11:26:19 Steve McIntyre wrote: On Thu, May 06, 2010 at 12:06:03PM -0500, Raphael Geissert wrote: Please remember that kfreebsd-i386 and kfreebsd-amd64 are now release architectures and failure to build on those is considered release critical. Not if they've never built

Bug#667226: kgb: diff for NMU version 1.0b4+ds-13.2

2012-05-11 Thread Raphael Geissert
Hi, Thanks for the patch and the NMU. As a minor nitpick you should probably consider giving the patch file a more descriptive name, like missing-unistdh.patch :) Anyway, it's not worth another upload just to change that. Cheers, -- Raphael Geissert - Debian Developer www.debian.org

Bug#663206: vpnc: does not install anymore - shebang missing from install scripts

2012-03-12 Thread Raphael Geissert
reopen 663206 thanks Hi, Upgrading dpkg does workaround the bug, but it is an unintentional side effect. Maintainer scripts must have a shebang as per section 6.1 of policy. (thanks to James McCoy for finding the proper reference :) Cheers, -- Raphael Geissert - Debian Developer

Bug#663382: cupt: missing depends on apt?

2012-03-10 Thread Raphael Geissert
package cache E: error performing command 'install' # cupt update E: unable to open file '//var/lib/apt/extended_states': No such file or directory E: error while parsing extended states E: error while creating package cache E: error performing command 'update' Cheers, -- Raphael Geissert - Debian

Bug#663382: cupt: missing depends on apt?

2012-03-10 Thread Raphael Geissert
and /var/lib/apt. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#661197: CVE-2012-0270: buffer overflows

2012-02-24 Thread Raphael Geissert
Package: csound Severity: grave Tags: security Hi, Two vulnerabilities have been found in csound. Please refer to the following page for more information: http://secunia.com/secunia_research/2012-3/ Regards, Raphael Geissert -- To UNSUBSCRIBE, email to debian-bugs-rc-requ

Bug#651705: le: FTBFS in unstable configure: error: cannot make curses work

2012-01-08 Thread Raphael Geissert
at all) the reasoning looks correct. For the next version I've already had to fiddle with auto* and run autoreconf, so I'll see how that plays with multiarch. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-rc-requ

Bug#647849: ca-certificates: removal of signet.pl's CAs

2011-11-06 Thread Raphael Geissert
lenny, squeeze, and sid. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#637057: [php-maint] Bug#637057: Installing php5-idn makes apache2 segfault (if using the php5 module)

2011-09-16 Thread Raphael Geissert
another story... Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

  1   2   3   4   5   >