Bug#1059163: cpio: Path traversal vulnerability

2023-12-21 Thread Aníbal Monsalve Salazar
On Wed, 2023-12-20 19:55:30 +0100, Ingo Brückl wrote: > Package: cpio > Version: 2.13+dfsg-7.1 > Severity: grave > > The patch "revert-CVE-2015-1197-handling" (to close bugs #946267 and #946469) > re-enables path traversal vulnerability with maliciously crafted cpio > archives. Hello Ingo, I

Bug#992098: version -6 seems to have introduced another bug

2021-08-13 Thread Aníbal Monsalve Salazar
021 10:51:09 CEST Aníbal Monsalve Salazar wrote: > > > I ran into this problem too at the exact same step of a kernel build. > > > Upstream author responded with > > > "Thanks. Fixed in dfc801c44a93bed7b3951905b188823d6a0432c8" > > > > > > I'

Bug#992098: Can confirm + upstream patch available

2021-08-13 Thread Aníbal Monsalve Salazar
On Thu, 2021-08-12 16:18:02 +0200, Diederik de Haas wrote: > Control: tag -1 fixed-upstream patch > > I ran into this problem too at the exact same step of a kernel build. > Upstream author responded with > "Thanks. Fixed in dfc801c44a93bed7b3951905b188823d6a0432c8" >

Bug#992098: cpio: Regression form CVE-2021-38185 fix: cpio hangs when target path passed with 128 characters

2021-08-13 Thread Aníbal Monsalve Salazar
On Wed, 2021-08-11 16:25:01 +0200, Salvatore Bonaccorso wrote: > Source: cpio > Version: 2.13+dfsg-5 > Severity: serious > Tags: upstream > Justification: regression, has influences to other programs, partially FTBFS > of packages, and other impact > X-Debbugs-Cc: car...@debian.org > > Hi > >

Bug#773029: groonga-server-common: purging deletes conffiles owned by other packages: /etc/groonga/{groonga.conf, synonyms.tsv}

2015-10-14 Thread Aníbal Monsalve Salazar
On Wed, 2014-12-31 19:54:11 +0900, HAYASHI Kentaro wrote: > Hi, > > Thank you for reporting & pointing out issues, Andreas! > > I've just uploaded fixed version of Groonga. > (There are some minor problems, so I've also fixed it) > > Here is the dsc file. >

Bug#796731: freecontact: FTBFS on mips (test suite failure)

2015-08-28 Thread Aníbal Monsalve Salazar
On Fri, 2015-08-28 18:08:33 +, Dejan Latinovic wrote: Hi, this is obviously a consequence of mips buildd's limitations. In past all three successfully builds had happened on ball. I also was able to built freecontact successfully for mips on machine with FPU, locally. On machine without

Bug#783374: last NMU patch breaks gparted completely (on my system)

2015-05-25 Thread Aníbal Monsalve Salazar
On Fri, 2015-05-01 05:05:10 +0200, Guillem Jover wrote: Control: tag -1 - patch Hi! On Sun, 2015-04-26 at 12:09:16 -0400, Michael Gilbert wrote: On Sun, Apr 26, 2015 at 9:46 AM, Felix Zielcke wrote: Just tried out the newest upload of gparted. Which fails completely The one before which is

Bug#778997: pciutils: lspci -nn freezes

2015-02-22 Thread Aníbal Monsalve Salazar
On Sun, 2015-02-22 22:10:09 +0100, Vincent Lefevre wrote: Package: pciutils Version: 1:3.2.1-3 Severity: grave Justification: renders package unusable lspci -nn freezes. It isn't even possible to kill it with kill -9: ypig% ps -fC lspci UIDPID PPID C STIME TTY TIME

Bug#773359: package tbb_4.2~20140122-4 FTBFS on mips and mipsel

2015-01-21 Thread Aníbal Monsalve Salazar
On Tue, 2015-01-20 14:02:08 +, Steven Capper wrote: On 20 January 2015 at 10:51, Aníbal Monsalve Salazar ani...@debian.org wrote: Hello Steven, Hi Aníbal, At IMGtech.com, we would like to support this patch for tbb. If you prefer, I could sponsor a new Debian version of tbb

Bug#773359: package tbb_4.2~20140122-4 FTBFS on mips and mipsel

2015-01-20 Thread Aníbal Monsalve Salazar
On Wed, 2014-12-17 13:11:32 +, Jurica Stanojkovic wrote: Package: tbb Version: 4.2~20140122-4 Severity: serious Tags: sid + patch Justification: FTBFS User: debian-m...@lists.debian.org Usertags: mips-patch Hello, Package tbb_4.2~20140122-4 FTBFS on mips and mipsel. Mips platform

Bug#774645: libevent: CVE-2014-6272: potential heap overflow in buffer/bufferevent APIs

2015-01-07 Thread Aníbal Monsalve Salazar
On Wed, 2015-01-07 13:10:51 +0100, Salvatore Bonaccorso wrote: Please find attached debdiff for unstable. I have *not* uploaded it to any delayed queue so far. Are you working on the update yourself? Hello Salvatore, I'm about to upload a package with the fix. Before the upload, I'll compare

Bug#772793: cpio: CVE-2014-9112

2014-12-12 Thread Aníbal Monsalve Salazar
On Fri, 2014-12-12 10:41:50 +0100, Salvatore Bonaccorso wrote: Hi, On Thu, Dec 11, 2014 at 07:15:17AM +0100, Moritz Muehlenhoff wrote: Package: cpio Severity: grave Tags: security Hi, please see http://seclists.org/fulldisclosure/2014/Nov/74 for the original report. Patches:

Bug#750857: NMU debdiff for mod-gnutls_0.6-1.2

2014-11-13 Thread Aníbal Monsalve Salazar
debdiff mod-gnutls_0.6-1.1.dsc mod-gnutls_0.6-1.2.dsc diff -Nru mod-gnutls-0.6/debian/changelog mod-gnutls-0.6/debian/changelog --- mod-gnutls-0.6/debian/changelog 2014-10-08 08:16:49.0 +0100 +++ mod-gnutls-0.6/debian/changelog 2014-11-13 10:41:23.0 + @@ -1,3 +1,15 @@

Bug#750857: NMU debdiff for mod-gnutls_0.6-1.1

2014-10-08 Thread Aníbal Monsalve Salazar
in the NMU debdiff, mod-gnutls builds successfully on mips, mipsel and amd64. Regards, Aníbal -- Aníbal Monsalve Salazar anibal.monsalvesala...@imgtec.com debdiff mod-gnutls_0.6-1.dsc mod-gnutls_0.6-1.1.dsc diff -Nru mod-gnutls-0.6/debian/changelog mod-gnutls-0.6/debian/changelog --- mod-gnutls-0.6

Bug#741557: libapache2-mod-gnutls: apache will not start if mod_authnz_ldap is loaded before mod_gnutls

2014-10-08 Thread Aníbal Monsalve Salazar
Control: severity -1 important On Thu, 2014-05-29 16:51:22 +0200, Andreas Metzler wrote: On 2014-04-02 Nikolai Lusan niko...@lusan.id.au wrote: [...] Short of me compiling a local package linked against an earlier version to libgnutls is there a solution? I note that the libcurl4-gnutls-dev

Bug#754623: NMU defdiff for percona-xtradb-cluster-galera-2.x_175-2.1 archs

2014-10-08 Thread Aníbal Monsalve Salazar
debdiff percona-xtradb-cluster-galera-2.x_175-2.dsc percona-xtradb-cluster-galera-2.x_175-2.1.dsc diff -Nru percona-xtradb-cluster-galera-2.x-175/debian/changelog percona-xtradb-cluster-galera-2.x-175/debian/changelog --- percona-xtradb-cluster-galera-2.x-175/debian/changelog 2014-06-18

Bug#721421: libdevel-bt-perl: FTBFS on armel, hurd-i386, kfreebsd-amd64

2014-09-25 Thread Aníbal Monsalve Salazar
On Tue, 2014-09-23 22:59:46 +0300, Niko Tyni wrote: I also had a look at the mips one, and there the problem doesn't seem to be with the backtrace, as running gdb separately works as expected. However, running perl with -d:bt doesn't seem to do anything. It looks like the host is just too

Bug#754757: timeout during g++

2014-09-25 Thread Aníbal Monsalve Salazar
On Tue, 2014-09-16 21:20:23 +0200, Bas Wijnen wrote: Hello Mips-porters, My package, openmsx, failed to build on mips due to a compiler timeout. (#754757) Looking at the earlier successful buildd logs, it has always taken quite long to build. In the bug it was reported that compilation does

Bug#754726: NMU debdiff for liblog4ada_1.2-4.1

2014-09-24 Thread Aníbal Monsalve Salazar
, liblog4ada builds successfully on mips, mipsel and amd64. Regards, Aníbal -- Aníbal Monsalve Salazar anibal.monsalvesala...@imgtec.com debdiff liblog4ada_1.2-4.dsc liblog4ada_1.2-4.1.dsc diff -Nru liblog4ada-1.2/debian/changelog liblog4ada-1.2/debian/changelog --- liblog4ada-1.2/debian/changelog

Bug#756788: NMU debdiff for libwebp_0.4.1-1.1

2014-09-04 Thread Aníbal Monsalve Salazar
, libwebp builds successfully on mips, mipsel and amd64. Regards, Aníbal -- Aníbal Monsalve Salazar anibal.monsalvesala...@imgtec.com debdiff libwebp_0.4.1-1.dsc libwebp_0.4.1-1.1.dsc diff -Nru libwebp-0.4.1/debian/changelog libwebp-0.4.1/debian/changelog --- libwebp-0.4.1/debian/changelog 2014

Bug#756788: NMU debdiff for libwebp_0.4.1-1.2

2014-09-04 Thread Aníbal Monsalve Salazar
, libwebp builds successfully on mips, mipsel and amd64. Regards, Aníbal -- Aníbal Monsalve Salazar anibal.monsalvesala...@imgtec.com debdiff libwebp_0.4.1-1.1.dsc libwebp_0.4.1-1.2.dsc diff -Nru libwebp-0.4.1/debian/changelog libwebp-0.4.1/debian/changelog --- libwebp-0.4.1/debian/changelog

Bug#755703: libtirpc1 0.2.4-1 causes rpc.gssd to crash on nfs4 sec=krb5 mount

2014-08-02 Thread Aníbal Monsalve Salazar
On Tue, 2014-07-22 16:48:31 +0200, John Hughes wrote: nfs4 sec=krb5 mounts stopped working, rpc.gssd segfaults in libgssapi_krb5 Jul 22 16:22:22 celtic kernel: [ 285.086078] rpc.gssd[1611]: segfault at 6c ip 7f24c8f9e72f sp 7fff60b1df10 error 4 in

Bug#756812: nfs-common: rpc.gssd crashes while mounting an encrypted nfs4 filesystem

2014-08-02 Thread Aníbal Monsalve Salazar
On Fri, 2014-08-01 23:41:12 +0200, eu...@debian.org wrote: rpc.gssd started crashing again when mounting an encrypted nfs4 filesystem. Hello, Could you please help me testing: · libtirpc1 0.2.4-2 · rpcbind 0.2.1-5 · nfs-common 1:1.2.8-7 · nfs-kernel-server 1:1.2.8-7 You will find them in

Bug#754754: NMU debdiff for jq_1.4-2.1

2014-07-21 Thread Aníbal Monsalve Salazar
builds successfully on mips, mipsel and amd64. Regards, Aníbal -- Aníbal Monsalve Salazar anibal.monsalvesala...@imgtec.com debdiff jq_1.4-2.dsc jq_1.4-2.1.dsc diff -Nru jq-1.4/debian/changelog jq-1.4/debian/changelog --- jq-1.4/debian/changelog 2014-07-06 01:18:20.0 +0100 +++ jq-1.4

Bug#748685: NMU debdiff for bibletime_2.9.2-1.1

2014-06-27 Thread Aníbal Monsalve Salazar
debdiff bibletime_2.9.2-1.dsc bibletime_2.9.2-1.1.dsc diff -Nru bibletime-2.9.2/debian/changelog bibletime-2.9.2/debian/changelog --- bibletime-2.9.2/debian/changelog2013-08-12 21:03:22.0 +0100 +++ bibletime-2.9.2/debian/changelog2014-06-27 11:59:22.0 +0100 @@ -1,3 +1,14 @@

Bug#746916: NMU debdiff for soprano_2.9.4+dfsg-1.1

2014-06-26 Thread Aníbal Monsalve Salazar
On Wed, 2014-06-25 14:12:17 -0300, Lisandro Damián Nicanor Pérez Meyer wrote: On Wednesday 25 June 2014 22:30:34 Aníbal Monsalve Salazar wrote: debdiff soprano_2.9.4+dfsg-1.dsc soprano_2.9.4+dfsg-1.1.dsc diff -Nru soprano-2.9.4+dfsg/debian/changelog soprano-2.9.4+dfsg/debian/changelog

Bug#746918: NMU debdiff for taglib_1.9.1-2.1

2014-06-26 Thread Aníbal Monsalve Salazar
debdiff taglib_1.9.1-2.dsc taglib_1.9.1-2.1.dsc diff -Nru taglib-1.9.1/debian/changelog taglib-1.9.1/debian/changelog --- taglib-1.9.1/debian/changelog 2013-11-04 14:20:34.0 + +++ taglib-1.9.1/debian/changelog 2014-06-26 13:16:09.0 +0100 @@ -1,3 +1,14 @@ +taglib

Bug#746916: NMU debdiff for soprano_2.9.4+dfsg-1.1

2014-06-25 Thread Aníbal Monsalve Salazar
debdiff soprano_2.9.4+dfsg-1.dsc soprano_2.9.4+dfsg-1.1.dsc diff -Nru soprano-2.9.4+dfsg/debian/changelog soprano-2.9.4+dfsg/debian/changelog --- soprano-2.9.4+dfsg/debian/changelog 2013-11-04 15:13:52.0 + +++ soprano-2.9.4+dfsg/debian/changelog 2014-06-24 10:47:30.0 +0100 @@

Bug#584162: ssmtp: Partial loss of message body, sending message to wrong recipicients

2014-06-20 Thread Aníbal Monsalve Salazar
On Thu, 2014-06-19 14:44:30 -0400, Daniel Richard G. wrote: Well, sSMTP is my dumb forwarder of choice, and as the original reporter appears to have moved on, and sSMTP has been dropped from testing due to this bug, and no one else seems to care, it looks like I'll have to step in. Attached

Bug#751478: NMU debdiff for flann_1.8.4-3.1

2014-06-17 Thread Aníbal Monsalve Salazar
on mips, mipsel and amd64. Regards, Aníbal -- Aníbal Monsalve Salazar anibal.monsalvesala...@imgtec.com debdiff flann_1.8.4-3.dsc flann_1.8.4-3.1.dsc diff -Nru flann-1.8.4/debian/changelog flann-1.8.4/debian/changelog --- flann-1.8.4/debian/changelog2013-12-08 07:15:32.0 +

Bug#751478: NMU debdiff for flann_1.8.4-3.1

2014-06-17 Thread Aníbal Monsalve Salazar
On Tue, 2014-06-17 10:55:29 +0200, Mathieu Malaterre wrote: control: tags -1 pending I am building flann right now. If you give me just one sec, I'll upload it. Sure. thanks for the patch Thank you! signature.asc Description: Digital signature

Bug#748685: bibletime update required

2014-06-16 Thread Aníbal Monsalve Salazar
On Wed, 2014-06-11 14:05:43 +0300, Plamen Aleksandrov wrote: There is a new version of bibletime (2.10) which is working with libsword 1.7. I strongly recommend to update bibletime - this should fix the problem. If you have some reason not to update it, I can create a patch for 2.9. Hello

Bug#747813: NMU debdiff for minidlna 1.1.2+dfsg-1.1

2014-06-16 Thread Aníbal Monsalve Salazar
debdiff minidlna_1.1.2+dfsg-1.dsc minidlna_1.1.2+dfsg-1.1.dsc diff -Nru minidlna-1.1.2+dfsg/debian/changelog minidlna-1.1.2+dfsg/debian/changelog --- minidlna-1.1.2+dfsg/debian/changelog2014-04-28 21:33:25.0 +0100 +++ minidlna-1.1.2+dfsg/debian/changelog2014-06-16

Bug#599972: NMU debdiff for argus_3.0.0-3.1

2014-05-28 Thread Aníbal Monsalve Salazar
in the NMU patch argus builds successfully on mips, mipsel and amd64. Regards, Aníbal -- Aníbal Monsalve Salazar anibal.monsalvesala...@imgtec.com debdiff argus_3.0.0-3.dsc argus_3.0.0-3.1.dsc diff -Nru argus-3.0.0/debian/changelog argus-3.0.0/debian/changelog --- argus-3.0.0/debian/changelog2014

Bug#735248: NMU debdiff for cmake_2.8.12.1-1.3

2014-05-23 Thread Aníbal Monsalve Salazar
Hello Modestas, Please find below the NMU debdiff for cmake_2.8.12.1-1.3. It fixes a regression that blocks #685112. https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=685112 Regards, Aníbal -- anibal.monsalvesala...@imgtec.com debdiff cmake_2.8.12.1-1.2.dsc cmake_2.8.12.1-1.3.dsc diff -Nru

Bug#747418: belle-sip: FTBFS on kfreebsd-i386 (internal error: belle_sdp.g : java.lang.NullPointerException)

2014-05-19 Thread Aníbal Monsalve Salazar
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Format: 1.8 Date: Fri, 16 May 2014 11:28:47 +0100 Source: belle-sip Binary: libbellesip0 libbellesip-dev libbellesip-dbg Architecture: source mipsel Version: 1.3.0-1.1 Distribution: unstable Urgency: medium Maintainer: Debian VoIP Team

Bug#748228: NMU patch for kbtin_1.0.14-1.1

2014-05-16 Thread Aníbal Monsalve Salazar
on mips, mipsel and amd64. Regards, Aníbal -- Aníbal Monsalve Salazar anibal.monsalvesala...@imgtec.com debdiff kbtin_1.0.14-1.dsc kbtin_1.0.14-1.1.dsc diff -Nru kbtin-1.0.14/debian/changelog kbtin-1.0.14/debian/changelog --- kbtin-1.0.14/debian/changelog 2012-12-23 17:13:35.0 +

Bug#748228: NMU patch for kbtin_1.0.14-1.1

2014-05-16 Thread Aníbal Monsalve Salazar
On Fri, 2014-05-16 21:36:35 +1000, Aníbal Monsalve Salazar wrote: With the changes in the NMU patch grib-api builds successfully on mips, mipsel and amd64. Typo. s/grib-api/kbtin/ -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe. Trouble

Bug#748228: NMU patch for kbtin_1.0.14-1.1

2014-05-16 Thread Aníbal Monsalve Salazar
On Fri, 2014-05-16 16:50:01 +0200, Adam Borowski wrote: On Fri, May 16, 2014 at 09:36:35PM +1000, Aníbal Monsalve Salazar wrote: My NMU patch for kbtin_1.0.14-1.1 is below, at the end of this message. Looks like there's some work duplication: yesterday I prepared an upload fixing

Bug#748228: NMU patch for kbtin_1.0.14-1.1

2014-05-16 Thread Aníbal Monsalve Salazar
On Sat, 2014-05-17 08:44:56 +1000, Aníbal Monsalve Salazar wrote: On Fri, 2014-05-16 16:50:01 +0200, Adam Borowski wrote: On Fri, May 16, 2014 at 09:36:35PM +1000, Aníbal Monsalve Salazar wrote: My NMU patch for kbtin_1.0.14-1.1 is below, at the end of this message. Looks like there's some

Bug#584162: ssmtp: Partial loss of message body, sending message to wrong recipicients

2014-05-14 Thread Aníbal Monsalve Salazar
On Tue, 2010-06-01 23:10:53 +0200, Christoph Biedl wrote: Usually I provide patches to ease fixing but the amount of changes that are required for header_parse leave me in the feeling this should be done upstream. Hello Christoph, Please send me the patch and I'll test and apply it upstream.

Bug#741743: NMU patch for kicad_0.20140224+bzr4027-3.1

2014-05-12 Thread Aníbal Monsalve Salazar
builds successfully on mips, mipsel and amd64. Regards, Aníbal -- Aníbal Monsalve Salazar anibal.monsalvesala...@imgtec.com debdiff kicad_0.20140224+bzr4027-3.dsc kicad_0.20140224+bzr4027-3.1.dsc diff -Nru kicad-0.20140224+bzr4027/debian/changelog kicad-0.20140224+bzr4027/debian/changelog --- kicad

Bug#734789: [CVE-2013-7284] Remote pre-authentication code execution in PlRPC

2014-04-22 Thread Aníbal Monsalve Salazar
On Sun, 2014-04-06 11:12:17 +0200, Moritz Mühlenhoff wrote: On Sat, Mar 29, 2014 at 09:07:11AM +1100, Aníbal Monsalve Salazar wrote: On Fri, 2014-03-28 16:22:14 +0100, Moritz Muehlenhoff wrote: On Thu, Jan 09, 2014 at 09:01:53PM +0100, Florian Weimer wrote: Package: libplrpc-perl Severity

Bug#742940: since: Does not work on mips (includes test suite failures and FTBFS)

2014-04-09 Thread Aníbal Monsalve Salazar
The NMU patch for since_1.1-4.1 is below. debdiff since_1.1-4.dsc since_1.1-4.1.dsc diff -Nru since-1.1/debian/changelog since-1.1/debian/changelog --- since-1.1/debian/changelog 2014-03-29 03:54:11.0 + +++ since-1.1/debian/changelog 2014-04-08 05:35:59.0 +0100 @@ -1,3 +1,13

Bug#742940: fixed in since 1.1-4.1

2014-04-09 Thread Aníbal Monsalve Salazar
On Wed, 2014-04-09 15:04:41 +0200, Axel Beckert wrote: Hi Aníbal, Aníbal Monsalve Salazar wrote: I apologize and am sorry for the inconvenience I caused you with this NMU. Apology accepted. Sorry for being too harsh and angry in the first place. As probably most of us I'm currently

Bug#742940: since: Does not work on mips (includes test suite failures and FTBFS)

2014-04-07 Thread Aníbal Monsalve Salazar
On Sat, 2014-03-29 07:17:33 +0100, Axel Beckert wrote: Package: since Version: 1.1-4 Severity: serious Tags: upstream Package version 1.1-4 added a build-time test-suite which revealed that since on mips does not work properly: $ echo foo foo $ since foo foo $ since foo since:

Bug#743584: NMU patch for trafficserver 4.1.2-1.2

2014-04-04 Thread Aníbal Monsalve Salazar
debdiff trafficserver_4.1.2-1.1.dsc trafficserver_4.1.2-1.2.dsc diff -Nru trafficserver-4.1.2/debian/changelog trafficserver-4.1.2/debian/changelog --- trafficserver-4.1.2/debian/changelog2014-04-03 04:22:04.0 +0100 +++ trafficserver-4.1.2/debian/changelog2014-04-04

Bug#743584: trafficserver 4.1.2-1.1 FTBFS on kfreebsd-*

2014-04-04 Thread Aníbal Monsalve Salazar
Hello Arno, On Fri, 2014-04-04 00:32:43 +0200, Arno Töll wrote: while I do not mind if you go ahead, Thank you. I did not look into these build issues as trafficserver 4.2 is to be released any day ahead and I wanted to work on the package with the new upstream base. That being said

Bug#743584: trafficserver 4.1.2-1.1 FTBFS on kfreebsd-*

2014-04-03 Thread Aníbal Monsalve Salazar
, Aníbal Monsalve Salazar wrote: On both kfreebsd-amd64 and kfreebsd-i386, trafficserver 4.1.2-1.1 FTBFS with the same error message. Build logs are available at: https://buildd.debian.org/status/fetch.php?pkg=trafficserverarch=kfreebsd-amd64ver=4.1.2-1.1stamp=1396503334 https

Bug#736565: NMU patch for staden-io-lib 1.13.5-1.1

2014-04-02 Thread Aníbal Monsalve Salazar
On Wed, 2014-04-02 09:10:00 +0200, Andreas Tille wrote: Hi Aníbal, thanks for the NMU which is welcome. The only thing I would like you to do is to commit the changes to VCS. Any DD has commit permision so all people who can upload can also commit the changes. This time I did fetched the

Bug#711787: falconpl: FTBFS on mipsen

2014-04-01 Thread Aníbal Monsalve Salazar
On Sun, 2014-03-09 16:08:35 +1100, Aníbal Monsalve Salazar wrote: On Sun, Jun 09, 2013 at 09:16:26PM +0200, Julien Cristau wrote: Source: falconpl Version: 0.9.6.9-git20120606-2 Severity: serious Justification: fails to build from source (but built successfully in the past) The falconpl

Bug#711787: NMU patch for falconpl 0.9.6.9-git20120606-2.1

2014-04-01 Thread Aníbal Monsalve Salazar
debdiff falconpl_0.9.6.9-git20120606-2.dsc falconpl_0.9.6.9-git20120606-2.1.dsc diff -Nru falconpl-0.9.6.9-git20120606/debian/changelog falconpl-0.9.6.9-git20120606/debian/changelog --- falconpl-0.9.6.9-git20120606/debian/changelog 2012-12-26 05:43:56.0 + +++

Bug#736565: NMU patch for staden-io-lib 1.13.5-1.1

2014-04-01 Thread Aníbal Monsalve Salazar
debdiff staden-io-lib_1.13.5-1.dsc staden-io-lib_1.13.5-1.1.dsc diff -Nru staden-io-lib-1.13.5/debian/changelog staden-io-lib-1.13.5/debian/changelog --- staden-io-lib-1.13.5/debian/changelog 2014-03-15 03:07:55.0 + +++ staden-io-lib-1.13.5/debian/changelog 2014-04-01

Bug#736565: [Debian-med-packaging] Bug#736565: FTBFS on non-PC architectures: FAIL: scram_mt.test

2014-03-31 Thread Aníbal Monsalve Salazar
On Mon, 2014-03-31 14:06:49 +0900, Charles Plessy wrote: staden-io-lib is going to be removed from Testing because of a RC bug that is solved in Sid but can not migrate as long as the package still fails to build o non-PC architectures. My original plan was to remove staden-io-lib from

Bug#736565: [Debian-med-packaging] Bug#736565: FTBFS on non-PC architectures: FAIL: scram_mt.test

2014-03-31 Thread Aníbal Monsalve Salazar
On Mon, 2014-03-31 18:03:12 +1100, Aníbal Monsalve Salazar wrote: On Mon, 2014-03-31 14:06:49 +0900, Charles Plessy wrote: staden-io-lib is going to be removed from Testing because of a RC bug that is solved in Sid but can not migrate as long as the package still fails to build o non-PC

Bug#742551: libdispatch: FTBFS on powerpc: test failures

2014-03-29 Thread Aníbal Monsalve Salazar
On Tue, 2014-03-25 00:08:42 +0100, Cyril Brulebois wrote: Source: libdispatch Version: 0~svn197-3.3 Severity: serious Justification: FTBFS [ Last two NMUers in X-D-Cc. ] Hi, your package FTBFS on powerpc, where it seems to have built by luck in 0~svn197-3.2 on porpora:

Bug#734789: [CVE-2013-7284] Remote pre-authentication code execution in PlRPC

2014-03-28 Thread Aníbal Monsalve Salazar
On Fri, 2014-03-28 16:22:14 +0100, Moritz Muehlenhoff wrote: On Thu, Jan 09, 2014 at 09:01:53PM +0100, Florian Weimer wrote: Package: libplrpc-perl Severity: grave Version: 0.2020-2 Tags: security upstream The PlRPC module uses Storable in an unsafe way, leading to a remote code execution

Bug#736481: nettoe: FTBFS due to test suite failures

2014-03-28 Thread Aníbal Monsalve Salazar
On Wed, 2014-03-26 23:26:26 +0100, Ansgar Burchardt wrote: Aníbal Monsalve Salazar ani...@debian.org writes: On Wed, 2014-03-26 14:51:08 +0100, Ansgar Burchardt wrote: Changing options passed to ./configure depending on the build environment looks fairly wrong to me. The objective

Bug#736481: nettoe: FTBFS due to test suite failures

2014-03-26 Thread Aníbal Monsalve Salazar
On Tue, 2014-03-25 13:53:26 +, Dejan Latinovic wrote: Could you consider applying this patch? NMU patch for nettoe 1.5-1.1 is below. debdiff nettoe_1.5-1.dsc nettoe_1.5-1.1.dsc diff -Nru nettoe-1.5/debian/changelog nettoe-1.5/debian/changelog --- nettoe-1.5/debian/changelog 2014-01-10

Bug#736481: nettoe: FTBFS due to test suite failures

2014-03-26 Thread Aníbal Monsalve Salazar
On Wed, 2014-03-26 14:51:08 +0100, Ansgar Burchardt wrote: Hi, On 03/26/2014 14:39, Aníbal Monsalve Salazar wrote: --- nettoe-1.5/debian/changelog 2014-01-10 11:39:53.0 + +++ nettoe-1.5/debian/changelog 2014-03-25 12:39:27.0 + @@ -1,3 +1,12 @@ +nettoe (1.5

Bug#736565: FTBFS on non-PC architectures: FAIL: scram_mt.test

2014-03-09 Thread Aníbal Monsalve Salazar
On Sat, Feb 15, 2014 at 03:26:19PM +1100, Aníbal Monsalve Salazar wrote: retitle 736565 FTBFS on non-PC architectures: FAIL: scram_mt.test reassign 736565 staden-io-lib 1.13.3-2 severity 736565 serious user debian-m...@lists.debian.org usertags 736565 + mips-port stop On Sat, Jan 25, 2014

Bug#736565: FTBFS on non-PC architectures: FAIL: scram_mt.test

2014-03-09 Thread Aníbal Monsalve Salazar
On Sun, Mar 09, 2014 at 10:10:28AM +, Aníbal Monsalve Salazar wrote: Hello Alexander and Charles, The regression test fails because xx#minimal.full.sam has one extra line at the end when it's compared to xx#minimal.full.bam.sam. The extra line is: A416 yy 4 1

Bug#736565: FTBFS on non-PC architectures: FAIL: scram_mt.test

2014-03-09 Thread Aníbal Monsalve Salazar
On Sun, Mar 09, 2014 at 07:58:25PM +0900, Charles Plessy wrote: Missing a line on MIPS definitely looks like a bug. This said, it works on amd64 (at least the test suite) and I doubt that there are users for the staden-io-lib on MIPS. Have you tried to contact the upstream author ? Not

Bug#738137: libpwiz: FTBFS on mips*: virtual memory exhausted

2014-03-08 Thread Aníbal Monsalve Salazar
On Sun, Mar 02, 2014 at 12:44:41PM +0100, Filippo Rusconi wrote: On Fri, Feb 28, 2014 at 01:23:16PM +, Dejan Latinovic wrote: I have attached a patch that solves this issue for me on mips/mipsel. OK, I'll put that in the git repository today and I'll have an upload pretty soon.

Bug#740985: FTBFS on amd64 mips mipsel: checking for KQUEUE... configure: error: Package requirements (libkqueue) were not met

2014-03-06 Thread Aníbal Monsalve Salazar
Package: libdispatch Version: 0~svn197-3.2 Severity: serious User: debian-m...@lists.debian.org Usertags: mips-patch bdispatch FTBFS on amd64 mips mipsel using pbuilder with a minimal and clean sid environment. Pbuilder logs are availabel at:

Bug#740309: [Debichem-devel] Bug#740309: libpwiz FTBFS: configure: error: cannot compile a test that uses Boost thread

2014-03-03 Thread Aníbal Monsalve Salazar
On Sun, Mar 02, 2014 at 02:21:58PM +0100, Filippo Rusconi wrote: Thanks for the report. Same problem here, I'm investigating this one. The problem is in libboost1.54-dev, see: https://bugs.debian.org/739807 Dejan found the patch to fix libboost1.54 at:

Bug#738137: libpwiz: FTBFS on mips*: virtual memory exhausted

2014-02-28 Thread Aníbal Monsalve Salazar
On Thu, Feb 20, 2014 at 01:17:33AM +0100, Andreas Beckmann wrote: unfortunately disabling parallel builds didn't help, perhaps you should request removal from sid on mips and mipsel, s.t. the package may migrate to testing on the other architectures. libpwiz is currently a blocker for the

Bug#740309: libpwiz FTBFS: configure: error: cannot compile a test that uses Boost thread

2014-02-27 Thread Aníbal Monsalve Salazar
Package: libpwiz Version: 3.0.4624-8 Severity: serious libpwiz 3.0.4624-8 FTBFS on amd64 within a clean and updated sid pbuilder chroot. The complete pbuilder log is at: http://people.debian.org/~anibal/libpwiz/libpwiz_3.0.4624-8_amd64.log.bz2 Log extract is below. checking for

Bug#731967: debdiff of NMU of libqb 0.16.0.real-1.1

2014-02-19 Thread Aníbal Monsalve Salazar
debdiff libqb_0.16.0.real-1.dsc libqb_0.16.0.real-1.1.dsc diff -Nru libqb-0.16.0.real/debian/changelog libqb-0.16.0.real/debian/changelog --- libqb-0.16.0.real/debian/changelog 2013-08-02 06:39:15.0 +0100 +++ libqb-0.16.0.real/debian/changelog 2014-02-20 07:32:10.0 + @@ -1,3

Bug#599972: argus_3.0.0-3.1_mipsel.changes REJECTED

2014-02-14 Thread Aníbal Monsalve Salazar
On Sat, Feb 15, 2014 at 12:03:22AM +, Debian FTP Masters wrote: argus-server: lintian output: 'embedded-library usr/sbin/argus: libpcap', automatically rejected package. argus-server: If you have a good reason, you may override this lintian tag. === Please feel free to respond to

Bug#733742: rpcbind: cannot get uid of '': Transport endpoint is not connected

2013-12-31 Thread Aníbal Monsalve Salazar
Thank you for your bugreport. Please try version 0.2.1-2. signature.asc Description: Digital signature

Bug#733742: rpcbind: cannot get uid of '': Transport endpoint is not connected

2013-12-31 Thread Aníbal Monsalve Salazar
Thank you for your message. Please try version 0.2.1-2. signature.asc Description: Digital signature

Bug#720164: FTBFS: cpuid.c:29:25: fatal error: linux/major.h: No such file or directory

2013-08-19 Thread Aníbal Monsalve Salazar
Package: cpuid Version: 20130610-1 Severity: serious Tags: patch https://buildd.debian.org/status/fetch.php?pkg=cpuidarch=kfreebsd-amd64ver=20130610-1stamp=1376897399 make[1]: Entering directory `/«PKGBUILDDIR»' cc -D_FORTIFY_SOURCE=2 -g -O2 -fstack-protector \ --param=ssp-buffer-size=4

Bug#720164: FTBFS: cpuid.c:29:25: fatal error: linux/major.h: No such file or directory

2013-08-19 Thread Aníbal Monsalve Salazar
tags 720164 - patch stop On Mon, Aug 19, 2013 at 04:51:34PM +0600, Andrey Rahmatullin wrote: On Mon, Aug 19, 2013 at 10:39:53AM +, Aníbal Monsalve Salazar wrote: cpuid.c:29:25: fatal error: linux/major.h: No such file or directory The patch below fixes the FTBFS on GNU/kFreeBSD. The patch

Bug#718931: mnemonicode: encoded data decodes to different data (asymmetric)

2013-08-07 Thread Aníbal Monsalve Salazar
On Wed, Aug 07, 2013 at 12:29:40AM +0200, Paul Wise wrote: Package: mnemonicode Version: 0.73-1 Severity: normal After converting my OpenPGP fingerprint to a binary file, I note that I can't get the same data back when encoding and then decoding it. The first four bytes and the last four

Bug#711321: sensible-utils: bashism in select-editor

2013-06-06 Thread Aníbal Monsalve Salazar
On Thu, Jun 06, 2013 at 12:10:26PM +0200, Thorsten Glaser wrote: Package: sensible-utils Version: 0.0.8 Severity: serious Justification: Policy 10.4 tglase@tglase:~ $ select-editor Select an editor. To change later, run 'select-editor'. 1. /bin/ed 2. /usr/bin/jupp 3.

Bug#711321: sensible-utils: bashism in select-editor

2013-06-06 Thread Aníbal Monsalve Salazar
On Thu, Jun 06, 2013 at 12:10:26PM +0200, Thorsten Glaser wrote: tglase@tglase:~ $ select-editor Select an editor. To change later, run 'select-editor'. 1. /bin/ed 2. /usr/bin/jupp 3. /usr/bin/mcedit /usr/bin/select-editor[47]: read: -p: no coprocess The last line repeats

Bug#695361: less: buggy backslash handling in prompt string: \ needs to be doubled

2013-03-11 Thread Aníbal Monsalve Salazar
On Sat, Dec 08, 2012 at 02:30:36PM +0100, Vincent Lefevre wrote: 2. break other packages that depend on the old behavior, at least man-db 2.6.3-2 and previous versions. Hello Vincent, I just wanted to check with you before uploading less 456-2. Do you know about other packages that less

Bug#698632: rstatd: Patch 03-627217-netio.patch breaks RPC protocol compatibility for rstatd

2013-02-07 Thread Aníbal Monsalve Salazar
On Tue, Feb 05, 2013 at 03:43:56PM +0100, Salvatore Bonaccorso wrote: At this stage of the freeze this option (droping the patch for 627217) looks the best to me, what do you think Anibal? Hello Salvatore, I'll prepare a new package without it. Cheers, Aníbal -- To UNSUBSCRIBE, email to

Bug#698632: rstatd: Patch 03-627217-netio.patch breaks RPC protocol compatibility for rstatd

2013-02-07 Thread Aníbal Monsalve Salazar
627217 found rstatd/4.0.1-8 stop On Mon, Jan 21, 2013 at 02:50:43PM +0100, Salvatore Bonaccorso wrote: Source: rstatd Version: 4.0.1-7 Severity: serious Justification: Regression, mixed environments Squeeze and Wheezy -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Hi Anibal At our

Bug#695268: liblockfile1: harmful remove action in M-A:same package

2012-12-11 Thread Aníbal Monsalve Salazar
On Sun, Dec 09, 2012 at 05:55:20PM -0600, Rob Browning wrote: I suspect this may be a reasonable fix: Thank you. Please see http://bugs.debian.org/695655 -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact

Bug#638068: Re : initramfs-tools generates unbootable initrd.img on IA-64

2012-06-15 Thread Aníbal Monsalve Salazar
On Fri, Jun 15, 2012 at 10:54:35AM +, maximilian attems wrote: Sorry for the time it took. According to your bug report klibc dash on ia64 has a working echo, so it's basic functionality should be good. It is not clear to me why the initramfs won't boot without busybox? It does here very

Bug#676807: libnfsidmap2: rpc.idmapd fails to load: requested translation method, 'nsswitch', is not available

2012-06-09 Thread Aníbal Monsalve Salazar
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Format: 1.8 Date: Sat, 09 Jun 2012 17:26:28 +1000 Source: libnfsidmap Binary: libnfsidmap-dev libnfsidmap2 Architecture: source mipsel Version: 0.25-4 Distribution: unstable Urgency: low Maintainer: Anibal Monsalve Salazar ani...@debian.org

Bug#676584: libx86 1.1+ds1-8 FTFS on amd64

2012-06-07 Thread Aníbal Monsalve Salazar
Package: libx86 Severity: Serious Version: 1.1+ds1-8 https://buildd.debian.org/status/fetch.php?pkg=libx86arch=amd64ver=1.1%2Bds1-8stamp=1338893113 cc -g -O2 -fPIE -fstack-protector --param=ssp-buffer-size=4 -Wformat -Werror=format-security -O2 -Wall -DDEBUG -g -fPIC -fPIE -pie -Wl,-z,relro

Bug#673542: libpng12-0 Bug#673542 Bug#673645

2012-05-20 Thread Aníbal Monsalve Salazar
package libpng12-0 severity 673542 important forcemerge 673542 673645 stop http://bugs.debian.org/650601 The libpng transition hasn't started yet. Please refer to the webpage above. It will involve hundreds of binary packages. -- To UNSUBSCRIBE, email to

Bug#632786: CVE-2011-2501 libpng: regression of CVE-2004-0421 in 1.2.23+

2011-07-05 Thread Aníbal Monsalve Salazar
Package: libpng Tags: security patch Severity: critical https://bugzilla.redhat.com/show_bug.cgi?id=717084 Vincent Danen 2011-06-27 18:34:45 EDT It was reported [1] that the fix for CVE-2004-0421 in libpng was inadvertently reverted during the 1.2.23 development cycle. The original flaw

Bug#629553: libgssglue: incompatible with krb5 1.9

2011-06-08 Thread Aníbal Monsalve Salazar
On Tue, Jun 07, 2011 at 12:55:02PM -0400, Sam Hartman wrote: package: libgssglue-dev severity: serious justification: package breaks nfs-utils build version: 0.2-2 Hi, Kevin and Debian maintainers: In an upcoming release, MIT has started adopting the new GSS-API type names at the top of page 12

Bug#570676: Processed: severity of 570676 is serious

2011-05-29 Thread Aníbal Monsalve Salazar
On Wed, Apr 06, 2011 at 11:00:42PM +, Debian Bug Tracking System wrote: Processing commands for cont...@bugs.debian.org: severity 570676 serious Bug #570676 [src:libx86] libx86: FTBFS: thunk.c:44: error: impossible constraint in 'asm' Severity set to 'serious' from 'important' thanks

Bug#619052: rpc.gssd: double free or corruption (was: libgssglue-0.2)

2011-03-22 Thread Aníbal Monsalve Salazar
On Wed, Mar 16, 2011 at 09:28:04PM -0400, Kevin Coffman wrote: A new version of library libgssglue is now available from: http://www.citi.umich.edu/projects/nfsv4/linux/libgssglue/libgssglue-0.2.tar.gz Changes since libgssglue-0.1: * Modify the gss_acquire_cred() code to accept, and

Bug#615558: Bug#614345: pu: package libpng/1.2.44-2

2011-02-27 Thread Aníbal Monsalve Salazar
On Sun, Feb 27, 2011 at 11:22:46AM -0800, Steve Langasek wrote: The right line is of course /lib/libpng12.so.0 /usr/lib/libpng.so.3 I'll prepare another debdiff including the change above and a fix for the recent RC bug #615558. signature.asc Description: Digital signature

Bug#610034: CVE-2011-0002: libuser creates LDAP users with a default

2011-02-08 Thread Aníbal Monsalve Salazar
The attached file is an updated debdiff between the current version in sid and my NMU. diff -u libuser-0.56.9.dfsg.1/debian/rules libuser-0.56.9.dfsg.1/debian/rules --- libuser-0.56.9.dfsg.1/debian/rules +++ libuser-0.56.9.dfsg.1/debian/rules @@ -59,6 +59,22 @@ # install for pythonX.Y

Bug#610034: CVE-2011-0002: libuser creates LDAP users with a default

2011-02-07 Thread Aníbal Monsalve Salazar
package libuser tag 610034 + patch stop The attached file is the debdiff between the current version in sid and my NMU. diff -u libuser-0.56.9.dfsg.1/debian/changelog libuser-0.56.9.dfsg.1/debian/changelog --- libuser-0.56.9.dfsg.1/debian/changelog +++ libuser-0.56.9.dfsg.1/debian/changelog @@

Bug#601817: gparted crashes applying move to right of more than one logical partition

2010-10-29 Thread Aníbal Monsalve Salazar
Package: gparted Version: 0.6.2-1 Severity: serious Tags: fixed-upstream At https://bugzilla.gnome.org/show_bug.cgi?id=628863 Frieder Ferlemann reported: On an IBM T42 notebook gparted reproducibly (tried 3 times with varying layouts) crashes when rearranging partitions leaving the system

Bug#601818: gparted crashes at start: glibmm-ERROR **

2010-10-29 Thread Aníbal Monsalve Salazar
Package: gparted Version: 0.6.2-1

Bug#598303: tau: CVE-2010-3382: insecure library loading

2010-10-06 Thread Aníbal Monsalve Salazar
package tau tags 598303 + patch

Bug#598303: tau: CVE-2010-3382: insecure library loading

2010-10-06 Thread Aníbal Monsalve Salazar
Yay overengineering. What's wrong with a simple export LD_LIBRARY_PATH=$TAUROOT/$TAUARCH/lib/$thebinding${LD_LIBRARY_PATH:+:$LD_LIBRARY_PATH} ? In the general case where you have a $foo before ${LD_LIBRARY_PATH:+:$LD_LIBRARY_PATH} the result is not good if $foo is empty. See for example:

Bug#598303: tau: CVE-2010-3382: insecure library loading

2010-10-06 Thread Aníbal Monsalve Salazar
On Wed, Oct 06, 2010 at 01:40:51PM +0200, Julien Cristau wrote: This makes absolutely no sense. $TAUROOT/$TAUARCH/lib/$thebinding is not empty. I know that. I was talking about a general case where you have just one variable. See the end of

Bug#598303: tau: CVE-2010-3382: insecure library loading

2010-10-06 Thread Aníbal Monsalve Salazar
A new patchset is below. debdiff tau_2.16.4-1.3.dsc tau_2.16.4-1.4.dsc | diffstat debian/patches/06-598303-CVE-2010-3382-insecure-library-loading.diff | 35 ++ tau-2.16.4/debian/changelog |9 ++ tau-2.16.4/debian/patches/series

Bug#523260: gnuplot-nox: depend on a newer version of libedit2

2010-09-20 Thread Aníbal Monsalve Salazar
tags 523260 + pending stop On Thu, Sep 16, 2010 at 12:48:42PM +0200, Agustin Martin wrote: On Wed, Sep 15, 2010 at 01:46:43PM +0200, Agustin Martin wrote: If the only problem are new symbols added, may be just changing libedit2.shlibs: libedit 2 libedit2 (= 2.5.cvs.20010821-1) dependency to (=

Bug#597585: [SECURITY] [DSA-2112-1] CVE-2010-0405 integer overflow

2010-09-20 Thread Aníbal Monsalve Salazar
Package: bzip2 Version: 1.0.5-5 Severity: serious Tags: security patch pending On Mon, Sep 20, 2010 at 11:05:59AM +, Stefan Fritsch wrote: Mikolaj Izdebski has discovered an integer overflow flaw in the BZ2_decompress function in bzip2/libbz2. An attacker could use a crafted bz2 file to

  1   2   3   >