Bug#528352: NMU

2009-12-06 Thread Giuseppe Iuculano
Hi, Attached is a debdiff of the changes I made for 1.2.9-3.1 0-day NMU. Cheers, Giuseppe diff -u libstruts1.2-java-1.2.9/debian/changelog libstruts1.2-java-1.2.9/debian/changelog --- libstruts1.2-java-1.2.9/debian/changelog +++ libstruts1.2-java-1.2.9/debian/changelog @@ -1,3 +1,11 @@

Processing of libstruts1.2-java_1.2.9-3.1_i386.changes

2009-12-06 Thread Archive Administrator
libstruts1.2-java_1.2.9-3.1_i386.changes uploaded successfully to localhost along with the files: libstruts1.2-java_1.2.9-3.1.dsc libstruts1.2-java_1.2.9-3.1.diff.gz libstruts1.2-java_1.2.9-3.1_all.deb Greetings, Your Debian queue daemon (running on host ries.debian.org)

libstruts1.2-java_1.2.9-3.1_i386.changes ACCEPTED

2009-12-06 Thread Archive Administrator
Accepted: libstruts1.2-java_1.2.9-3.1.diff.gz to main/libs/libstruts1.2-java/libstruts1.2-java_1.2.9-3.1.diff.gz libstruts1.2-java_1.2.9-3.1.dsc to main/libs/libstruts1.2-java/libstruts1.2-java_1.2.9-3.1.dsc libstruts1.2-java_1.2.9-3.1_all.deb to

libstruts1.2-java override disparity

2009-12-06 Thread Archive Administrator
There are disparities between your recently accepted upload and the override file for the following file(s): libstruts1.2-java_1.2.9-3.1_all.deb: package says section is devel, override says java. Please note that a list of new sections were recently added to the archive: cli-mono, database,

Bug#528352: marked as done (CVE-2008-2025: Cross-site scripting (XSS) vulnerability)

2009-12-06 Thread Debian Bug Tracking System
Your message dated Sun, 06 Dec 2009 17:43:50 + with message-id e1nhl9c-0003ly...@ries.debian.org and subject line Bug#528352: fixed in libstruts1.2-java 1.2.9-3.1 has caused the Debian Bug report #528352, regarding CVE-2008-2025: Cross-site scripting (XSS) vulnerability to be marked as done.

[pkg-java] r11207 - trunk

2009-12-06 Thread Niels Thykier
Author: nthykier-guest Date: 2009-12-06 18:39:03 + (Sun, 06 Dec 2009) New Revision: 11207 Removed: trunk/jhove/ Log: Not sure it was okay to commit this in the first place. Removing to be Rather safe than sorry. ___ pkg-java-commits mailing

[pkg-java] r11208 - tags

2009-12-06 Thread Morten Sørensen
Author: starswifter-guest Date: 2009-12-06 22:15:55 + (Sun, 06 Dec 2009) New Revision: 11208 Added: tags/libtggraphlayout-java/ Log: [svn-inject] Creating libtggraphlayout-java/ directory. ___ pkg-java-commits mailing list

Bug#559767: java3d: FTBFS on armel: install: cannot stat `j3d-core/build/default/opt/native/libj3dcore-ogl.so': No such file or directory

2009-12-06 Thread Cyril Brulebois
Package: java3d Version: 1.5.2+dfsg-4 Severity: important Hi, that's another FTBFS on armel: | dh_installdirs -plibjava3d-jni | install -m 644 -D j3d-core/build/default/opt/native/libj3dcore-ogl.so \ | debian/libjava3d-jni/usr/lib/jni/libj3dcore-ogl.so | install: cannot stat

Bug#559766: java3d: FTBFS on non-Linux ports

2009-12-06 Thread Cyril Brulebois
Package: java3d Version: 1.5.2+dfsg-4 Severity: important User: debian-...@lists.debian.org Usertags: kfreebsd Hi, your package FTBFS on non-Linux ports as follows (example from kfreebsd-amd64, all logs are at [1]): | cd . /usr/lib/jvm/default-java/bin/java -classpath

Bug#559765: jetty: CVE-2007-6672 info disclosure

2009-12-06 Thread Michael Gilbert
Package: jetty Version: 6.1.21-1 Severity: serious Tags: security Hi, The following CVE (Common Vulnerabilities Exposures) id was published for jetty. CVE-2007-6672[0]: | Mortbay Jetty 6.1.5 and 6.1.6 allows remote attackers to bypass | protection mechanisms and read the source of files via

Bug#559768: java3d: FTBFS on hppa: java compilation issues

2009-12-06 Thread Cyril Brulebois
Package: java3d Version: 1.5.2+dfsg-4 Severity: important Hi, yet another FTBFS: | [javac] 2865. ERROR in /build/buildd/java3d-1.5.2+dfsg/j3d-core/src/classes/x11/javax/media/j3d/X11NativeConfigTemplate3D.java (at line 38) | [javac] import sun.awt.X11GraphicsDevice; | [javac]

Bug#559766: java3d: FTBFS on non-Linux ports

2009-12-06 Thread Cyril Brulebois
Cyril Brulebois k...@debian.org (07/12/2009): I might try and get back to it to work on a patch, but let's report bugs first. (And that's java anyway… :/) XML-based build systems, brr… Anyway, the attached patch helped a bit, I'm now getting java compilation errors, I've stripped the build log

Bug#559788: libgnucrypto-java: embeds classpath

2009-12-06 Thread Michael Gilbert
package: libgnucrypto-java version: 2.1.0-4 severity: important tags: security hi, libgnucrypto-java embeds classpath, which is very outdated. this also makes security updates very troublesome. please update the package to use the libraries provided by classpath. thanks. mike

Bug#559789: libgnucrypto-java: CVE-2008-5659 predictable random number generator

2009-12-06 Thread Michael Gilbert
Package: libgnucrypto-java Version: 2.1.0-2 Severity: grave Tags: security Hi, the following CVE (Common Vulnerabilities Exposures) id was published for classpath. libgnucrypto-java embeds classpath, so it is also affected. CVE-2008-5659[0]: | The gnu.java.security.util.PRNG class in GNU