tycho_0.25.0-1_amd64.changes is NEW

2016-11-29 Thread Debian FTP Masters
binary:libtycho-java is NEW. binary:libtycho-java is NEW. source:tycho is NEW. Your package has been put into the NEW queue, which requires manual action from the ftpteam to process. The upload was otherwise valid (it had a good OpenPGP signature and file hashes are valid), so please be patient.

Processing of tycho_0.25.0-1_amd64.changes

2016-11-29 Thread Debian FTP Masters
tycho_0.25.0-1_amd64.changes uploaded successfully to localhost along with the files: tycho_0.25.0-1.dsc tycho_0.25.0.orig.tar.xz tycho_0.25.0-1.debian.tar.xz libtycho-java_0.25.0-1_all.deb tycho_0.25.0-1_amd64.buildinfo Greetings, Your Debian queue daemon (running on host usper

Bug#845385: Privilege escalation via removal

2016-11-29 Thread Emmanuel Bourg
Le 29/11/2016 à 23:45, Markus Koschany a écrit : > I don't understand why this is a security issue when > /etc/tomcat8/Catalina/attack is owned by root:root after the purge and > the tomcat8 user doesn't even exist anymore. My understanding is that the file is left with execution permissions for

Bug#845385: Privilege escalation via removal

2016-11-29 Thread Markus Koschany
I think the solution is quite simple. Let's replace chown -Rhf root:root /etc/tomcat8/ || true with rm -rf /etc/tomcat8 I mean purge means purge. Remove all files, don't leave anything behind. As another improvement suggestion for Tomcat 9, we could stop deleting the tomcat user on purge and

Bug#845385: Privilege escalation via removal

2016-11-29 Thread Markus Koschany
> I don't understand why this is a security issue when > /etc/tomcat8/Catalina/attack is owned by root:root after the purge and > the tomcat8 user doesn't even exist anymore. Nevermind. I missed the "world". However dpkg warns about that /etc/tomcat8/Catalina is not empty on purge, so the admin wi

Bug#845385: Privilege escalation via removal

2016-11-29 Thread Markus Koschany
On Wed, 23 Nov 2016 09:35:34 +1100 Paul Szabo wrote: > Package: tomcat8 > Version: 8.0.14-1+deb8u4 > Severity: critical > Tags: security > > Having installed tomcat8, the directory /etc/tomcat8/Catalina is set > writable by group tomcat8, as per the postinst script. Then the tomcat8 > user, in th

Bug#846298: tomcat7: Security update causes java.lang.ClassNotFoundException: org.apache.jasper.runtime.JspRuntimeLibrary$PrivilegedIntrospectHelper

2016-11-29 Thread Anthony DeRobertis
Package: tomcat7 Version: 7.0.56-3+deb8u5 Severity: important I applied the latest security update and it broke tomcat completely. The logs show: SEVERE: SecurityClassLoad java.lang.ClassNotFoundException: org.apache.jasper.runtime.JspRuntimeLibrary$PrivilegedIntrospectHelper at java.ne

xz-java_1.6-1_amd64.changes ACCEPTED into unstable

2016-11-29 Thread Debian FTP Masters
Accepted: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Format: 1.8 Date: Tue, 29 Nov 2016 23:12:16 +0100 Source: xz-java Binary: libxz-java libxz-java-doc Architecture: source all Version: 1.6-1 Distribution: unstable Urgency: medium Maintainer: Debian Java Maintainers Changed-By: Emmanuel

Processing of xz-java_1.6-1_amd64.changes

2016-11-29 Thread Debian FTP Masters
xz-java_1.6-1_amd64.changes uploaded successfully to localhost along with the files: xz-java_1.6-1.dsc xz-java_1.6.orig.tar.xz xz-java_1.6-1.debian.tar.xz libxz-java-doc_1.6-1_all.deb libxz-java_1.6-1_all.deb xz-java_1.6-1_amd64.buildinfo Greetings, Your Debian queue daemon (r

Bug#845795: scala-parser-combinators: no symlink for scala-parser-combinators.jar?

2016-11-29 Thread Emmanuel Bourg
Le 29/11/2016 à 20:13, Patrice Duroux a écrit : > I do not use any wrapper script, I just everything provided by the native > Debian > package (latexdraw) and I juste run it after installation using terminal and > saw > the warning message (its a chance!). By wrapper script I meant this: https

Bug#845795: scala-parser-combinators: no symlink for scala-parser-combinators.jar?

2016-11-29 Thread Patrice Duroux
Hi Emmanuel, I do not use any wrapper script, I just everything provided by the native Debian package (latexdraw) and I juste run it after installation using terminal and saw the warning message (its a chance!). Also why it is not the case for the scala-library package on which it depends? I mean

bouncycastle 1.55-2 MIGRATED to testing

2016-11-29 Thread Debian testing watch
FYI: The status of the bouncycastle source package in Debian's testing distribution has changed. Previous version: 1.55-1 Current version: 1.55-2 -- This email is automatically generated once a day. As the installation of new packages into testing happens multiple times a day you will rece

jabref 2.10+ds-7 MIGRATED to testing

2016-11-29 Thread Debian testing watch
FYI: The status of the jabref source package in Debian's testing distribution has changed. Previous version: 2.10+ds-6 Current version: 2.10+ds-7 -- This email is automatically generated once a day. As the installation of new packages into testing happens multiple times a day you will rece

Bug#811053: *.poms Should Not Be Required to Ensure Trailing Newline

2016-11-29 Thread 殷啟聰
Actually, not all programs think `debian/libandroid-dex-java.poms` has a trailing new line. Inside the text, it is like: `line1\n` While the version without trailing new line would be: `line1` So some program considers this file has one line regardless the trailing new line. And the bug is, ma