Upload of mysql-dfsg-5.0 to t-p-u for CVE-2008-4098

2008-11-26 Thread Devin Carraway
I'd like to upload a security fix for mysql-dfsg-5.0 to t-p-u. The fix is for CVE-2008-4098, which enables privilege esclation of authenticated mysql users via symlink traversal. In the worst case, it allows an attacker to write to tables in other databases. This was fixed in Etch with

Re: updating openoffice.org-sdbc-postgresql to 0.7.6 (was: ooo-build r14606 - in trunk: . patches/postgresql])

2008-11-26 Thread Rene Engelhard
Hi again, Rene Engelhard wrote: I would like to have pre-approval for applying the following change to a -13 upload of openoffice.org (amonst others, which might not ^^^ be that controversial...) Because of that reason I decided to upload -13 now. It updates the PostgreSQL SDBC

jabber-irc and python-xmpp blocked by freeze

2008-11-26 Thread Cosimo Alfarano
Hi DR Team, I'm writing to ask to let the two packages in subject go into testing. They're currently blocked in unstable, recently the maintainer (in CC) fixed some important bugs on jabber-irc package, and now I belive it's ready to be in unstable, according to:

Re: Remove cdfs-src from testing [SOLVED]

2008-11-26 Thread mariodebian
El mié, 26-11-2008 a las 01:16 +0100, mariodebian escribió: El mar, 25-11-2008 a las 18:28 +0100, Adeodato Simó escribió: * Ben Hutchings [Tue, 25 Nov 2008 02:21:21 +]: Based on Eduard Bloch's comments to #482075 it does not appear that cdfs-src can be fixed for lenny. Thanks

Re: handling util-vserver regression

2008-11-26 Thread Micah Anderson
Hi release team, I have not received a response to my original email on this subject, I suspect because it may not have been sent out properly. I do not see my original message in the lists.debian.org debian-release archive, although I do see it archived in services such as gmane[0]... Anyways,

Re: Unblock request: crystalspace

2008-11-26 Thread Julien Cristau
On Tue, Nov 25, 2008 at 13:37:21 -0500, Barry deFreese wrote: * Adjust build-depends. + Change xlibmesa-gl-dev | libgl-dev to libgl1-mesa-dev. eh? why remove the libgl-dev alternative? Cheers, Julien -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble?

Your advice on a t-p-u patch please

2008-11-26 Thread Jonathan Wiltshire
Hello managers I'm after your advice regarding a patch for gxemul (testing version 0.4.6.3-1). A bug has arisen that causes it to segfault if given invalid or arbitrary parameters. [0] Since the unstable version is not in sync with testing, I propose a patch to go into testing-proposed-updates.

request the freeze exception for ttf-mathematica4.1

2008-11-26 Thread Atsuhito Kohda
Dear Debian Release Team, I uploaded the new ttf-mathematica4.1_6 to unstable and I believe it is a good candidate of freeze exception because it fixed a grave Bug#505847 This bug is very grave because not only one can't install the package but also one can't remove the package. The relevant

Re: Unblock request: crystalspace

2008-11-26 Thread Barry deFreese
Julien Cristau wrote: On Tue, Nov 25, 2008 at 13:37:21 -0500, Barry deFreese wrote: * Adjust build-depends. + Change xlibmesa-gl-dev | libgl-dev to libgl1-mesa-dev. eh? why remove the libgl-dev alternative? Cheers, Julien Gah, that was a mistake. I'll fix that on the next

Re: network-manager for laptop users who install desktop task as well.

2008-11-26 Thread Yves-Alexis Perez
On mar, 2008-11-25 at 17:25 +0800, Andrew Lee wrote: I just tested Frans' Lenny D-I test build for LXDE+Xfce CD image with LXDE installation. After installation, I found wicd is not available in lenny, so I installed network-manager manually, and it didn't bring too much additional package

Bug #506977 FPC: copyright infringement in pre 2.2.2 sources

2008-11-26 Thread Torsten Werner
Hi, my suggestion is to remove fpc from oldstable and stable but unblock the unstable version 2.2.2-4 for lenny and trigger binNMUs for lazarus. What do you think? What is the correct way to remove packages from (old)stable? Should I file a bug report against ftp.debian.org or is it done by the

please unblock qmtest 2.4-5

2008-11-26 Thread Matthias Klose
qmtest 2.4-5 gets rid of the dependency on python-extclass, which wasn't ported to python2.5 until recently. qmtest works fine without python-extclass, so we do not rely on the fix for python-extclass uploaded in 1.2.0zope-2.5.1-6.1. Matthias qmtest (2.4-5) unstable; urgency=low * Remove

Unblock request for radioclk/1.0.ds1-7 (l10n updates)

2008-11-26 Thread Christian Perrier
Dear release managers, radioclk was uploaded a while ago by its maintainer, mostly for l10n updates but no unblock request was sent. Having it in lenny would bring the statistics of Portuguese translations to 100% for testing (and thus, combined with lilo, have 3 languages reaching 100%) The