Processed: Fwd: Processed: your mail

2018-11-13 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org:

> notfound 913641 1:6.1.3-1
Bug #913641 [libreoffice-report-builder] libreoffice-report-builder: report 
builder reports fail to run
No longer marked as found in versions libreoffice/1:6.1.3-1.
> severity 913461 wishlist
Bug #913461 [src:libstrophe] libstrophe: please provide a package for 
stretch-backports
Severity set to 'wishlist' from 'grave'
> severity 913641 grave
Bug #913641 [libreoffice-report-builder] libreoffice-report-builder: report 
builder reports fail to run
Severity set to 'grave' from 'normal'
> tag 913461 - moreinfo
Bug #913461 [src:libstrophe] libstrophe: please provide a package for 
stretch-backports
Removed tag(s) moreinfo.
> tag 913641 + moreinfo
Bug #913641 [libreoffice-report-builder] libreoffice-report-builder: report 
builder reports fail to run
Added tag(s) moreinfo.
> thanks
Stopping processing here.

Please contact me if you need assistance.
-- 
913461: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=913461
913641: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=913641
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems



Bug#913641: libreoffice-report-builder: report builder reports fail to run

2018-11-13 Thread Lionel Elie Mamane
On Tue, Nov 13, 2018 at 12:58:02PM +0100, rene.engelh...@mailbox.org wrote:
> Am 13. November 2018 12:13:52 MEZ schrieb Lionel Elie Mamane 
> :
>> Package: libreoffice-report-builder
>> Version: 1:6.1.3-1
>> Severity: normal

> Huh, what? On a stable? Seriousl

Yes, I'm dogfooding more recent version of LibreOffice. Seriously,
that's how one gets early testers and bug reports before release.

>> Trying to run any report (a report builder one, not a legacy one)
>> fails with error message:

>> Can not activate the factory for
>> org.libreoffice.report.pentaho.SOReportJobFactory$_SOReportJobFactory

> I assume it's related to stables openjdk 8 update and the discussion
> in https://gerrit.libreoffice.org/63118.

Hmmm... Switching LibreOffice to use OpenJDK 7 solves that issue. I
guess this confirms your assumption?

> Need to file a bug on openjdk...

Not clear if you are saying I need to do it, or you need to do it. I
don't quite understand the issue, you do, so I assume you will, you
will be able to explain to the Java package maintainers the issue?
Please CC me, I'd like to be educated on that.

> >-- System Information:
> >Debian Release: 9.6
> >  APT prefers stable-updates
> >APT policy: (600, 'stable-updates'), (600, 'stable'), (400, 'testing'),
> >(300, 'unstable'), (1, 'experimental')
> >Architecture: amd64 (x86_64)
> >Foreign Architectures: i386
> > [...]
> >Versions of packages libreoffice-report-builder depends on:
> >ii  libbase-java   1.1.6-2
> >ii  libcommons-logging-java1.2-1
> >ii  libflute-java  1:1.1.6-3
> >ii  libfonts-java  1.1.6.dfsg-3
> >ii  libformula-java1.1.7.dfsg-2
> >ii  liblayout-java 0.2.10-2
> >ii  libloader-java 1.1.6.dfsg-4
> >ii  libpentaho-reporting-flow-engine-java  0.9.4-4
> >ii  libreoffice-common 1:6.1.3-1
> >ii  libreoffice-core   1:6.1.3-1
> >ii  libreoffice-java-common1:6.1.3-1
> >ii  libreoffice-report-builder-bin 1:6.1.3-1
> >ii  librepository-java 1.1.6-3
> >ii  libsac-java1.3+dfsg-2
> >ii  libserializer-java 1.1.6-4
> >ii  libxml-java1.1.6.dfsg-3

> This honestly is Soo broken. Ok, the backport will have the same problem 
> (that's why I needed +2 there) but..

That's honestly not broken at all. That's why our packages have
dependencies, so that they can have what they require.

>> ii  openjdk-8-jre [java6-runtime]  8u181-b13-2~deb9u1

> This is probably the cause What happens with the old openjdk 8 on
> stretch or openjdk 11.0.1+13?

Downgrading to 8u171-b11-2 makes this problem disappear.



Bug#913641: libreoffice-report-builder: report builder reports fail to run

2018-11-13 Thread Lionel Elie Mamane
Package: libreoffice-report-builder
Version: 1:6.1.3-1
Severity: normal

Trying to run any report (a report builder one, not a legacy one)
fails with error message:

Can not activate the factory for
org.libreoffice.report.pentaho.SOReportJobFactory$_SOReportJobFactory

Nothing particular on stderr.

-- System Information:
Debian Release: 9.6
  APT prefers stable-updates
  APT policy: (600, 'stable-updates'), (600, 'stable'), (400, 'testing'), (300, 
'unstable'), (1, 'experimental')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 4.9.0-7-amd64 (SMP w/8 CPU cores)
Locale: LANG=en_GB.utf8, LC_CTYPE=en_GB.utf8 (charmap=UTF-8), 
LANGUAGE=en_GB.utf8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages libreoffice-report-builder depends on:
ii  libbase-java   1.1.6-2
ii  libcommons-logging-java1.2-1
ii  libflute-java  1:1.1.6-3
ii  libfonts-java  1.1.6.dfsg-3
ii  libformula-java1.1.7.dfsg-2
ii  liblayout-java 0.2.10-2
ii  libloader-java 1.1.6.dfsg-4
ii  libpentaho-reporting-flow-engine-java  0.9.4-4
ii  libreoffice-common 1:6.1.3-1
ii  libreoffice-core   1:6.1.3-1
ii  libreoffice-java-common1:6.1.3-1
ii  libreoffice-report-builder-bin 1:6.1.3-1
ii  librepository-java 1.1.6-3
ii  libsac-java1.3+dfsg-2
ii  libserializer-java 1.1.6-4
ii  libxml-java1.1.6.dfsg-3

libreoffice-report-builder recommends no packages.

libreoffice-report-builder suggests no packages.

Versions of packages libreoffice-base depends on:
ii  libc6 2.27-8
ii  libgcc1   1:8.2.0-9
ii  libreoffice-base-core 1:6.1.3-1
ii  libreoffice-base-drivers  1:6.1.3-1
ii  libreoffice-core  1:6.1.3-1
ii  libstdc++68.2.0-9
ii  uno-libs3 6.1.3-1
ii  ure   6.1.3-1

Versions of packages libreoffice-base recommends:
ii  default-jre [java6-runtime]2:1.8-58
ii  libreoffice-java-common1:6.1.3-1
ii  libreoffice-writer 1:6.1.3-1
ii  openjdk-7-jre [java6-runtime]  7u151-2.6.11-3
ii  openjdk-8-jre [java6-runtime]  8u181-b13-2~deb9u1

Versions of packages libreoffice-base suggests:
ii  unixodbc  2.3.4-1

-- no debconf information



Bug#913641: libreoffice-report-builder: report builder reports fail to run

2018-11-13 Thread rene . engelhard
notfound 913641 1:6.1.3-1
found 1:5.2.7-1+deb9u4
severity 913641 grave
tag 913641 + moreinfo
thanks

Am 13. November 2018 12:13:52 MEZ schrieb Lionel Elie Mamane :
>Package: libreoffice-report-builder
>Version: 1:6.1.3-1
>Severity: normal

Huh, what? On a stable? Seriousl

>Trying to run any report (a report builder one, not a legacy one)
>fails with error message:
>
>Can not activate the factory for
>org.libreoffice.report.pentaho.SOReportJobFactory$_SOReportJobFactory
>
>Nothing particular on stderr.

I assume it's related to stables openjdk 8 update and the discussion in 
https://gerrit.libreoffice.org/63118.

Doesn't affect sid or buster with jdk 11 (which is default there.. )

Need to file a bug on openjdk...

>-- System Information:
>Debian Release: 9.6
>  APT prefers stable-updates
>APT policy: (600, 'stable-updates'), (600, 'stable'), (400, 'testing'),
>(300, 'unstable'), (1, 'experimental')
>Architecture: amd64 (x86_64)
>Foreign Architectures: i386
> [...]
>Versions of packages libreoffice-report-builder depends on:
>ii  libbase-java   1.1.6-2
>ii  libcommons-logging-java1.2-1
>ii  libflute-java  1:1.1.6-3
>ii  libfonts-java  1.1.6.dfsg-3
>ii  libformula-java1.1.7.dfsg-2
>ii  liblayout-java 0.2.10-2
>ii  libloader-java 1.1.6.dfsg-4
>ii  libpentaho-reporting-flow-engine-java  0.9.4-4
>ii  libreoffice-common 1:6.1.3-1
>ii  libreoffice-core   1:6.1.3-1
>ii  libreoffice-java-common1:6.1.3-1
>ii  libreoffice-report-builder-bin 1:6.1.3-1
>ii  librepository-java 1.1.6-3
>ii  libsac-java1.3+dfsg-2
>ii  libserializer-java 1.1.6-4
>ii  libxml-java1.1.6.dfsg-3

This honestly is Soo broken. Ok, the backport will have the same problem 
(that's why I needed +2 there) but..

>ii  openjdk-8-jre [java6-runtime]  8u181-b13-2~deb9u1

This is probably the cause What happens with the old openjdk 8 on stretch or 
openjdk 11.0.1+13?

Regards

Rene

-- 
Diese Nachricht wurde von meinem Android-Gerät mit K-9 Mail gesendet.



Processed: your mail

2018-11-13 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org:

> found 913641 1:5.2.7-1+deb9u4
Bug #913641 [libreoffice-report-builder] libreoffice-report-builder: report 
builder reports fail to run
Marked as found in versions libreoffice/1:5.2.7-1+deb9u4.
> thanks
Stopping processing here.

Please contact me if you need assistance.
-- 
913641: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=913641
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems



Bug#913641: libreoffice-report-builder: report builder reports fail to run

2018-11-13 Thread rene . engelhard
tag 913641 - moreinfo
retitle 913641 libreoffice-report-builder: report builder reports fail to run 
after S8195874 in OpenJDK
thanks

Am 13. November 2018 13:13:09 MEZ schrieb Lionel Elie Mamane :
>On Tue, Nov 13, 2018 at 12:58:02PM +0100, rene.engelh...@mailbox.org
>wrote:
>> Am 13. November 2018 12:13:52 MEZ schrieb Lionel Elie Mamane
>:
>>> Package: libreoffice-report-builder
>>> Version: 1:6.1.3-1
>>> Severity: normal
>
>> Huh, what? On a stable? Seriousl
>
>Yes, I'm dogfooding more recent version of LibreOffice. Seriously,
>that's how one gets early testers and bug reports before release.

Use testing or sid. Or use the backport. Installing sid packages per se on 
stable is broken.

>>> Trying to run any report (a report builder one, not a legacy one)
>>> fails with error message:
>
>>> Can not activate the factory for
>>>
>org.libreoffice.report.pentaho.SOReportJobFactory$_SOReportJobFactory
>
>> I assume it's related to stables openjdk 8 update and the discussion
>> in https://gerrit.libreoffice.org/63118.
>
>Hmmm... Switching LibreOffice to use OpenJDK 7 solves that issue. I
>guess this confirms your assumption?

Yes.

>> Need to file a bug on openjdk...
>
>Not clear if you are saying I need to do it, or you need to do it. I
>don't quite understand the issue, you do, so I assume you will, you
>will be able to explain to the Java package maintainers the issue?

I will do, yes.

>Please CC me, I'd like to be educated on that.

The Gerrit discussion explains it..openjdk doesn't honour some classpath 
specifications anymore so stuff is simply not found.

>>> ii  openjdk-8-jre [java6-runtime]  8u181-b13-2~deb9u1
>
>> This is probably the cause What happens with the old openjdk 8 on
>> stretch or openjdk 11.0.1+13?
>
>Downgrading to 8u171-b11-2 makes this problem disappear.

Ok, that also confirms it...

Regards,

René

-- 
Diese Nachricht wurde von meinem Android-Gerät mit K-9 Mail gesendet.



Bug#913641: libreoffice-report-builder: report builder reports fail to run

2018-11-13 Thread Anton Cohen
On Tue, 13 Nov 2018 13:13:09 +0100 Lionel Elie Mamane 
wrote:
> Downgrading to 8u171-b11-2 makes this problem disappear.

Except 8u171-b11-2 (and all 8u171 builds) was removed from the pool for
stretch today.

> That's honestly not broken at all. That's why our packages have
dependencies, so that they can have what they require.

It is very broken that stretch doesn't have any working Java package in apt
repos (except in openjdk-11 in stretch-backports).

I realize this isn't a libreoffice package issue, but it seems like #911925
is being ignored.

Thanks,
Anton

-- 
This email and any attachments may contain information that is subject to 
copyright, that constitutes trade secrets, or that is proprietary, 
privileged, confidential or otherwise legally exempt from disclosure. If 
you are not the intended recipient, you are not authorized to read, print, 
retain, copy or disseminate any part of this email or any attachments. We 
do not waive any legal protections due to misdirection. If you have 
received this email in error, please notify the sender immediately and 
delete all copies. Any views expressed are those of the author and may not 
reflect those of the company. Emails are not perfectly secure and we do not 
warrant ours to be free of errors, viruses or other defects. By 
communicating with us by email, you accept these risks.


Bug#913702: libwpd: CVE-2018-19208

2018-11-13 Thread Salvatore Bonaccorso
Source: libwpd
Version: 0.10.2-2
Severity: important
Tags: upstream security

Hi,

The following vulnerability was published for libwpd.

CVE-2018-19208[0]:
| In libwpd 0.10.2, there is a NULL pointer dereference in the function
| WP6ContentListener::defineTable in WP6ContentListener.cpp that will
| lead to a denial of service attack. This is related to WPXTable.h.

I do not know if it was reported to upstream or only in Red Hat bugzilla.

==25333== Memcheck, a memory error detector
==25333== Copyright (C) 2002-2017, and GNU GPL'd, by Julian Seward et al.
==25333== Using Valgrind-3.13.0 and LibVEX; rerun with -h for copyright info
==25333== Command: wpd2html ./poc0-1
==25333==
==25333== Invalid read of size 8
==25333==at 0x488C37A: operator[] (WPXTable.h:89)
==25333==by 0x488C37A: WP6ContentListener::defineTable(unsigned char, 
unsigned short) (WP6ContentListener.cpp:1314)
==25333==by 0x4893899: 
WP6Parser::parseDocument(librevenge::RVNGInputStream*, WPXEncryption*, 
WP6Listener*) (WP6Parser.cpp:149)
==25333==by 0x488D8DA: 
WP6ContentListener::_handleSubDocument(WPXSubDocument const*, 
WPXSubDocumentType, WPXTableList, unsigned int) (WP6ContentListener.cpp:1783)
==25333==by 0x489B90E: WPXContentListener::handleSubDocument(WPXSubDocument 
const*, WPXSubDocumentType, WPXTableList, unsigned int) 
(WPXContentListener.cpp:1226)
==25333==by 0x489C122: WPXContentListener::_openPageSpan() 
(WPXContentListener.cpp:415)
==25333==by 0x489C854: WPXContentListener::_openSection() 
(WPXContentListener.cpp:198)
==25333==by 0x488EF15: WP6ContentListener::_handleListChange(unsigned 
short) (WP6ContentListener.cpp:1888)
==25333==by 0x489CFC1: WPXContentListener::_openSpan() 
(WPXContentListener.cpp:797)
==25333==by 0x488B903: WP6ContentListener::insertCharacter(unsigned int) 
(WP6ContentListener.cpp:423)
==25333==by 0x48938BF: 
WP6Parser::parseDocument(librevenge::RVNGInputStream*, WPXEncryption*, 
WP6Listener*) (WP6Parser.cpp:138)
==25333==by 0x4893922: WP6Parser::parse(librevenge::RVNGInputStream*, 
WPXEncryption*, WP6Listener*) (WP6Parser.cpp:83)
==25333==by 0x4893D58: WP6Parser::parse(librevenge::RVNGTextInterface*) 
(WP6Parser.cpp:225)
==25333==  Address 0x0 is not stack'd, malloc'd or (recently) free'd
==25333==
==25333==
==25333== Process terminating with default action of signal 11 (SIGSEGV)
==25333==  Access not within mapped region at address 0x0
==25333==at 0x488C37A: operator[] (WPXTable.h:89)
==25333==by 0x488C37A: WP6ContentListener::defineTable(unsigned char, 
unsigned short) (WP6ContentListener.cpp:1314)
==25333==by 0x4893899: 
WP6Parser::parseDocument(librevenge::RVNGInputStream*, WPXEncryption*, 
WP6Listener*) (WP6Parser.cpp:149)
==25333==by 0x488D8DA: 
WP6ContentListener::_handleSubDocument(WPXSubDocument const*, 
WPXSubDocumentType, WPXTableList, unsigned int) (WP6ContentListener.cpp:1783)
==25333==by 0x489B90E: WPXContentListener::handleSubDocument(WPXSubDocument 
const*, WPXSubDocumentType, WPXTableList, unsigned int) 
(WPXContentListener.cpp:1226)
==25333==by 0x489C122: WPXContentListener::_openPageSpan() 
(WPXContentListener.cpp:415)
==25333==by 0x489C854: WPXContentListener::_openSection() 
(WPXContentListener.cpp:198)
==25333==by 0x488EF15: WP6ContentListener::_handleListChange(unsigned 
short) (WP6ContentListener.cpp:1888)
==25333==by 0x489CFC1: WPXContentListener::_openSpan() 
(WPXContentListener.cpp:797)
==25333==by 0x488B903: WP6ContentListener::insertCharacter(unsigned int) 
(WP6ContentListener.cpp:423)
==25333==by 0x48938BF: 
WP6Parser::parseDocument(librevenge::RVNGInputStream*, WPXEncryption*, 
WP6Listener*) (WP6Parser.cpp:138)
==25333==by 0x4893922: WP6Parser::parse(librevenge::RVNGInputStream*, 
WPXEncryption*, WP6Listener*) (WP6Parser.cpp:83)
==25333==by 0x4893D58: WP6Parser::parse(librevenge::RVNGTextInterface*) 
(WP6Parser.cpp:225)
==25333==  If you believe this happened as a result of a stack
==25333==  overflow in your program's main thread (unlikely but
==25333==  possible), you can try to increase the size of the
==25333==  main thread stack using the --main-stacksize= flag.
==25333==  The main thread stack size used in this run was 8388608.
==25333==
==25333== HEAP SUMMARY:
==25333== in use at exit: 39,843 bytes in 1,012 blocks
==25333==   total heap usage: 9,446 allocs, 8,434 frees, 879,851 bytes allocated
==25333==
==25333== LEAK SUMMARY:
==25333==definitely lost: 40 bytes in 1 blocks
==25333==indirectly lost: 16 bytes in 1 blocks
==25333==  possibly lost: 0 bytes in 0 blocks
==25333==still reachable: 39,787 bytes in 1,010 blocks
==25333== suppressed: 0 bytes in 0 blocks
==25333== Rerun with --leak-check=full to see details of leaked memory
==25333==
==25333== For counts of detected and suppressed errors, rerun with: -v
==25333== ERROR SUMMARY: 1 errors from 1 contexts (suppressed: 0 from 0)
Segmentation fault

If you fix the vulnerability please 

Let's take another look...!!

2018-11-13 Thread Marina Cook
Hello debian-openoffice@lists.debian.org,

I Hope you are doing well.

I am Marina Cook and I am contacting you to find out, if you have need for IT 
Website or mobile application development services. We are fast Growing Website 
Services Company and having an in-house software design and development team, 
which has expertise in the following areas:-


  *   Website Design (E-commerce, Personal, Corporate, Responsive)
  *   Mobile Application (iPhone Apps, Android, iOS, Web Services)
  *   Digital Marketing (SEO, SMO, SEM, PPC)
I have very competitive rates for the above services, and should you feel 
interested, I can send you more details regarding this in my next email. Please 
let me know if you are interested.

Thanks
Marina Cook
Business Development Executive