Processed: retitle 889276 to wavpack: CVE-2018-6767: stack buffer overflow via crafted wav file, tagging 889276
Processing commands for cont...@bugs.debian.org: > retitle 889276 wavpack: CVE-2018-6767: stack buffer overflow via crafted wav > file Bug #889276 [wavpack] wavpack: stack buffer overflow while running wavpack Changed Bug title to 'wavpack: CVE-2018-6767: stack buffer overflow via crafted wav file' from 'wavpack: stack buffer overflow while running wavpack'. > tags 889276 + upstream Bug #889276 [wavpack] wavpack: CVE-2018-6767: stack buffer overflow via crafted wav file Added tag(s) upstream. > thanks Stopping processing here. Please contact me if you need assistance. -- 889276: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=889276 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems ___ pkg-multimedia-maintainers mailing list pkg-multimedia-maintainers@lists.alioth.debian.org http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-multimedia-maintainers
streamtuner2 2.2.0+dfsg-1 MIGRATED to testing
FYI: The status of the streamtuner2 source package in Debian's testing distribution has changed. Previous version: (not in testing) Current version: 2.2.0+dfsg-1 -- This email is automatically generated once a day. As the installation of new packages into testing happens multiple times a day you will receive later changes on the next day. See https://release.debian.org/testing-watch/ for more information. ___ pkg-multimedia-maintainers mailing list pkg-multimedia-maintainers@lists.alioth.debian.org http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-multimedia-maintainers
libebur128 1.2.4-1 MIGRATED to testing
FYI: The status of the libebur128 source package in Debian's testing distribution has changed. Previous version: 1.2.3-1 Current version: 1.2.4-1 -- This email is automatically generated once a day. As the installation of new packages into testing happens multiple times a day you will receive later changes on the next day. See https://release.debian.org/testing-watch/ for more information. ___ pkg-multimedia-maintainers mailing list pkg-multimedia-maintainers@lists.alioth.debian.org http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-multimedia-maintainers
libplacebo 0.3.0-2 MIGRATED to testing
FYI: The status of the libplacebo source package in Debian's testing distribution has changed. Previous version: 0.2.0-2 Current version: 0.3.0-2 -- This email is automatically generated once a day. As the installation of new packages into testing happens multiple times a day you will receive later changes on the next day. See https://release.debian.org/testing-watch/ for more information. ___ pkg-multimedia-maintainers mailing list pkg-multimedia-maintainers@lists.alioth.debian.org http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-multimedia-maintainers
vlc 3.0.0~rc8-1 MIGRATED to testing
FYI: The status of the vlc source package in Debian's testing distribution has changed. Previous version: 3.0.0~rc7-2 Current version: 3.0.0~rc8-1 -- This email is automatically generated once a day. As the installation of new packages into testing happens multiple times a day you will receive later changes on the next day. See https://release.debian.org/testing-watch/ for more information. ___ pkg-multimedia-maintainers mailing list pkg-multimedia-maintainers@lists.alioth.debian.org http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-multimedia-maintainers
liblivemedia 2018.01.29-1 MIGRATED to testing
FYI: The status of the liblivemedia source package in Debian's testing distribution has changed. Previous version: 2017.10.28-2 Current version: 2018.01.29-1 -- This email is automatically generated once a day. As the installation of new packages into testing happens multiple times a day you will receive later changes on the next day. See https://release.debian.org/testing-watch/ for more information. ___ pkg-multimedia-maintainers mailing list pkg-multimedia-maintainers@lists.alioth.debian.org http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-multimedia-maintainers
bitstream 1.3-1 MIGRATED to testing
FYI: The status of the bitstream source package in Debian's testing distribution has changed. Previous version: 1.2-2 Current version: 1.3-1 -- This email is automatically generated once a day. As the installation of new packages into testing happens multiple times a day you will receive later changes on the next day. See https://release.debian.org/testing-watch/ for more information. ___ pkg-multimedia-maintainers mailing list pkg-multimedia-maintainers@lists.alioth.debian.org http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-multimedia-maintainers
multicat 2.2-3 MIGRATED to testing
FYI: The status of the multicat source package in Debian's testing distribution has changed. Previous version: 2.2-2 Current version: 2.2-3 -- This email is automatically generated once a day. As the installation of new packages into testing happens multiple times a day you will receive later changes on the next day. See https://release.debian.org/testing-watch/ for more information. ___ pkg-multimedia-maintainers mailing list pkg-multimedia-maintainers@lists.alioth.debian.org http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-multimedia-maintainers
mpv_0.23.0-2+deb9u1_source.changes ACCEPTED into proposed-updates->stable-new
Mapping stable-security to proposed-updates. Accepted: -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Format: 1.8 Date: Sat, 03 Feb 2018 15:05:34 +0100 Source: mpv Binary: mpv libmpv1 libmpv-dev mplayer2 Architecture: source Version: 0.23.0-2+deb9u1 Distribution: stretch-security Urgency: high Maintainer: Debian Multimedia MaintainersChanged-By: James Cowgill Description: libmpv-dev - video player based on MPlayer/mplayer2 (client library dev files) libmpv1- video player based on MPlayer/mplayer2 (client library) mplayer2 - transitional dummy package for mpv mpv- video player based on MPlayer/mplayer2 Closes: 888654 Changes: mpv (0.23.0-2+deb9u1) stretch-security; urgency=high . * debian/patches/08_ytdl-hook-whitelist-protocols.patch: - Add patch which whitelists protocols received from youtube-dl. Fixes CVE-2018-6360. (Closes: #888654) Checksums-Sha1: 3a465e5946dddf0a088c08d82fbe0d12dc49b1f9 2964 mpv_0.23.0-2+deb9u1.dsc 99df32c3fdeece2e01ff6bc112586b13f10cffb9 2812103 mpv_0.23.0.orig.tar.gz 2515141ca0efaf4fa377b20b0e3d0a1d427c81a9 101888 mpv_0.23.0-2+deb9u1.debian.tar.xz 7ad4f761213960d10cd5ef7c5c5d1b79dfd56d92 12306 mpv_0.23.0-2+deb9u1_source.buildinfo Checksums-Sha256: be7c21a267e339e22c0e388b2101e78e66af88d0d7cffa3d7432520620d5ab8d 2964 mpv_0.23.0-2+deb9u1.dsc 8aeefe5970587dfc454d2b89726b603f156bd7a9ae427654eef0d60c68d94998 2812103 mpv_0.23.0.orig.tar.gz 170c93ad37524b512afbb3839c1d28ebf70784ce37d3849ec7b2ccbaf83ab168 101888 mpv_0.23.0-2+deb9u1.debian.tar.xz 2ad9b537b5411b98d4b8f80fb31badfc9e19409d7066c1502ece9b8b3c31f42f 12306 mpv_0.23.0-2+deb9u1_source.buildinfo Files: 408d378b863a09c2940bd6d9b0819344 2964 video optional mpv_0.23.0-2+deb9u1.dsc 9bce377e101612d611daf2a5c99aa95f 2812103 video optional mpv_0.23.0.orig.tar.gz 5e50934c8a3ba252529f2c4ed7d73a04 101888 video optional mpv_0.23.0-2+deb9u1.debian.tar.xz 02e5cbea2de70342d8ce440f8d56273e 12306 video optional mpv_0.23.0-2+deb9u1_source.buildinfo -BEGIN PGP SIGNATURE- iQJIBAEBCgAyFiEE+Ixt5DaZ6POztUwQx/FnbeotAe8FAlp6Qp8UHGpjb3dnaWxs QGRlYmlhbi5vcmcACgkQx/FnbeotAe+l5w//Ry8zeFIyEdUREOSNHpBrgi1eXr7/ lJ7NGFUMQmuMu5Uz7v+mZ8ef6ZowqxyXdm60jitb98MPHxa48B6hKv7Jr4WeXgOV csmu4gDipK1c9fL8FDclSi6KICaEaw6nztAjwvjmkR6HBo7wHSiWzstZfjFqg31W Jmu9eloWyjA7uzJ4S6uOgik2P8Zr23KJhcAavoJq9cqoDPwIXN5QgYJc8Zj3ZUa/ 3L6ShpZzoGgddZoFm21DKM5o9Zjns8p5lcn/maL0TMlU/pg8rjKl4aIjC+7XU2fh NSIbuWst8zrdXv2vITSBASZpLnbbg10BJ+mwgEbBz5YMorp4k+TjONKYkTjumeIL pC/vt5VgzJMBLjYPvgaHKAiMHylG4NPmacmAszEUCvlRE5s7g4TtPSgzagZCPntJ 3FxUIRk8Z5f7b3Q39Mr5oUsrSqDS2D7XgGFbitm+QNf8E9LrAOHWkjTGtJ2pCWRk nG0GgRQPcfZ7QR5PFfFYU8e+IQ+x9u2GoimSAD8ktKaP3KUEMbpcuzwWgaWvqbcm EI5NWZWfHLTk8R6QOo+7E4Sypxy9AxDHpepl0YUZyRBOTPQxdotU1UYXVualwSDo FR39YccnhfgqV4MPC1CbkzsY1iK5HNSg/eSg9DT26oETEn5CDb4rqbUdDh0U0izQ jYcL1XnGt23NXB4= =7h0a -END PGP SIGNATURE- Thank you for your contribution to Debian. ___ pkg-multimedia-maintainers mailing list pkg-multimedia-maintainers@lists.alioth.debian.org http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-multimedia-maintainers
Processed: Bug #889767 in chromaprint marked as pending
Processing control commands: > tag -1 pending Bug #889767 [src:chromaprint] Updating the chromaprint Uploaders list Added tag(s) pending. -- 889767: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=889767 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems ___ pkg-multimedia-maintainers mailing list pkg-multimedia-maintainers@lists.alioth.debian.org http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-multimedia-maintainers
Re: Bug#888288: RFS: libheif/0.0.1+20180124133753+git68fb4fe-1 [ITP: #888278]
On 02/06/2018 10:21 AM, Joachim Bauch wrote: > Hi Sebastian, > > thanks for your feedback, I uploaded a new version to mentors: > https://mentors.debian.net/debian/pool/main/libh/libheif/libheif_0.0.1+20180206084258+git9d8f256-1.dsc > > Additional comments see below. > > On 03.02.2018 14:47, Sebastian Ramacher wrote: >> That fails to build: [...] > > Interesting, on Ubuntu the "string.h" seems to get pulled in by some > other header and it compiles fine. well, in general "you" should explicitely include headers for the functions you need, rather than relying on "some other" header to do that for you - that other header might have required internally but a newer version might have a different private implementation that allowed them to drop the include... > >> Some other issues: >> >> * The library package should be named based on the SONAME, so that would be >> libheif1. > > Changed to "libheif-1", or should the name be without the dash? the name should be "libheif1", without the dash. (the dash is usually used if you want multiple major versions of a library to be coinstallable, e.g. libheif1.0-2 and libheif3-1; urgh) > >> * Current Standards-Version is 4.1.3. > > Changed, however the lintian on mentors now complains that the version > is too new: "newer-standards-version 4.1.3 (current is 3.9.8)" seems like you have an old lintian on your system. (e.g. because you are building on a Debian/stretch machine in a sid-chroot; and/or because your machine hasn't been updated in a while) gfmdsr IOhannes signature.asc Description: OpenPGP digital signature ___ pkg-multimedia-maintainers mailing list pkg-multimedia-maintainers@lists.alioth.debian.org http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-multimedia-maintainers
Bug#889767: Updating the chromaprint Uploaders list
Source: chromaprint Version: 1.2-1 1.4.2-1 Severity: minor User: m...@qa.debian.org Usertags: mia-teammaint Simon Chopinwishes no longer to be uploader of chromaprint. We are tracking their status in the MIA team and would like to ask you to remove them from the Uploaders list of the package so we can close that part of the file. (If the person is listed as Maintainer, what we are asking is to please step in as a new maintainer.) Thanks. ___ pkg-multimedia-maintainers mailing list pkg-multimedia-maintainers@lists.alioth.debian.org http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-multimedia-maintainers
Processing of libffado_2.3.0-5.1_source.changes
libffado_2.3.0-5.1_source.changes uploaded successfully to localhost along with the files: libffado_2.3.0-5.1.dsc libffado_2.3.0-5.1.debian.tar.xz Greetings, Your Debian queue daemon (running on host usper.debian.org) ___ pkg-multimedia-maintainers mailing list pkg-multimedia-maintainers@lists.alioth.debian.org http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-multimedia-maintainers
Bug#887781: libffado: diff for NMU version 2.3.0-5.1
Control: tags 887781 + pending Dear maintainer, I've prepared an NMU for libffado (versioned as 2.3.0-5.1) and uploaded it to DELAYED/15. Please feel free to tell me if I should cancel it. cu Adrian -- "Is there not promise of rain?" Ling Tan asked suddenly out of the darkness. There had been need of rain for many days. "Only a promise," Lao Er said. Pearl S. Buck - Dragon Seed diff -Nru libffado-2.3.0/debian/changelog libffado-2.3.0/debian/changelog --- libffado-2.3.0/debian/changelog 2017-11-12 12:55:33.0 +0200 +++ libffado-2.3.0/debian/changelog 2018-02-06 21:14:14.0 +0200 @@ -1,3 +1,11 @@ +libffado (2.3.0-5.1) unstable; urgency=medium + + * Non-maintainer upload. + * Add upstream fix for FTBFS with glibc 2.26, +thanks to Juhani Numminen. (Closes: #887781) + + -- Adrian BunkTue, 06 Feb 2018 21:14:14 +0200 + libffado (2.3.0-5) unstable; urgency=medium * Team upload. diff -Nru libffado-2.3.0/debian/patches/glibc-2.26.patch libffado-2.3.0/debian/patches/glibc-2.26.patch --- libffado-2.3.0/debian/patches/glibc-2.26.patch 1970-01-01 02:00:00.0 +0200 +++ libffado-2.3.0/debian/patches/glibc-2.26.patch 2018-02-06 21:14:09.0 +0200 @@ -0,0 +1,14 @@ +Description: Backport upstream fix for FTBFS with glibc 2.26 +Bug-Debian: https://bugs.debian.org/887781 +Forwarded: http://subversion.ffado.org/changeset/2710 + +--- libffado-2.3.0.orig/src/libutil/PosixMessageQueue.h libffado-2.3.0/src/libutil/PosixMessageQueue.h +@@ -35,6 +35,7 @@ + #include + #include + #include ++#include + + namespace Util + { diff -Nru libffado-2.3.0/debian/patches/series libffado-2.3.0/debian/patches/series --- libffado-2.3.0/debian/patches/series 2017-11-11 16:20:31.0 +0200 +++ libffado-2.3.0/debian/patches/series 2018-02-06 21:13:11.0 +0200 @@ -4,3 +4,4 @@ powerpcspe.patch gcc7.patch dbus_with_gcc7.patch +glibc-2.26.patch ___ pkg-multimedia-maintainers mailing list pkg-multimedia-maintainers@lists.alioth.debian.org http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-multimedia-maintainers
Processed: libffado: diff for NMU version 2.3.0-5.1
Processing control commands: > tags 887781 + pending Bug #887781 [src:libffado] libffado FTBFS with glibc 2.26 Added tag(s) pending. -- 887781: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=887781 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems ___ pkg-multimedia-maintainers mailing list pkg-multimedia-maintainers@lists.alioth.debian.org http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-multimedia-maintainers
谢海强
117.84.100.10012=14; nudjrx.xls Description: application/msexcel ___ pkg-multimedia-maintainers mailing list pkg-multimedia-maintainers@lists.alioth.debian.org http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-multimedia-maintainers
libvpx_1.7.0-2_amd64.changes is NEW
binary:libvpx5 is NEW. binary:libvpx5 is NEW. Your package has been put into the NEW queue, which requires manual action from the ftpteam to process. The upload was otherwise valid (it had a good OpenPGP signature and file hashes are valid), so please be patient. Packages are routinely processed through to the archive, and do feel free to browse the NEW queue[1]. If there is an issue with the upload, you will receive an email from a member of the ftpteam. If you have any questions, you may reply to this email. [1]: https://ftp-master.debian.org/new.html or https://ftp-master.debian.org/backports-new.html for *-backports ___ pkg-multimedia-maintainers mailing list pkg-multimedia-maintainers@lists.alioth.debian.org http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-multimedia-maintainers
Processing of libvpx_1.7.0-2_amd64.changes
libvpx_1.7.0-2_amd64.changes uploaded successfully to localhost along with the files: libvpx_1.7.0-2.dsc libvpx_1.7.0.orig.tar.gz libvpx_1.7.0-2.debian.tar.xz libvpx-dev_1.7.0-2_amd64.deb libvpx-doc_1.7.0-2_all.deb libvpx5-dbgsym_1.7.0-2_amd64.deb libvpx5_1.7.0-2_amd64.deb libvpx_1.7.0-2_amd64.buildinfo vpx-tools-dbgsym_1.7.0-2_amd64.deb vpx-tools_1.7.0-2_amd64.deb Greetings, Your Debian queue daemon (running on host usper.debian.org) ___ pkg-multimedia-maintainers mailing list pkg-multimedia-maintainers@lists.alioth.debian.org http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-multimedia-maintainers
Processing of libvpx_1.7.0-1_amd64.changes
libvpx_1.7.0-1_amd64.buildinfo has incorrect size; deleting it Greetings, Your Debian queue daemon (running on host usper.debian.org) ___ pkg-multimedia-maintainers mailing list pkg-multimedia-maintainers@lists.alioth.debian.org http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-multimedia-maintainers
Processing of libvpx_1.7.0-1_amd64.changes
libvpx5-dbgsym_1.7.0-1_amd64.deb has incorrect size; deleting it libvpx5_1.7.0-1_amd64.deb has incorrect md5 checksum; deleting it Greetings, Your Debian queue daemon (running on host usper.debian.org) ___ pkg-multimedia-maintainers mailing list pkg-multimedia-maintainers@lists.alioth.debian.org http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-multimedia-maintainers
Re: Bug#888288: RFS: libheif/0.0.1+20180124133753+git68fb4fe-1 [ITP: #888278]
Hi Sebastian, thanks for your feedback, I uploaded a new version to mentors: https://mentors.debian.net/debian/pool/main/libh/libheif/libheif_0.0.1+20180206084258+git9d8f256-1.dsc Additional comments see below. On 03.02.2018 14:47, Sebastian Ramacher wrote: > That fails to build: > > | g++ -DHAVE_CONFIG_H -I. -I.. -Wdate-time -D_FORTIFY_SOURCE=2 -I../src -g > -O2 > -fdebug-prefix-map=/<>/libheif-0.0.1+20180124133753+git68fb4fe=. > -fstack-protector-strong -Wformat -Werror=format-security -Wall -Werror > -Wsign-compare -Wconversion -Wno-sign-conversion -Wno-error=conversion -c -o > heif_info-heif_info.o `test -f 'heif_info.cc' || echo './'`heif_info.cc > | encoder_png.cc: In member function 'virtual bool PngEncoder::Encode(const > heif_image_handle*, const heif_image*, const string&)': > | encoder_png.cc:56:62: error: 'strerror' was not declared in this scope > | fprintf(stderr, "Can't open %s: %s\n", filename.c_str(), > strerror(errno)); > | ^~~~ > | encoder_png.cc:56:62: note: suggested alternative: 'perror' > | fprintf(stderr, "Can't open %s: %s\n", filename.c_str(), > strerror(errno)); > | ^~~~ > | perror > | Makefile:553: recipe for target 'heif_convert-encoder_png.o' failed Interesting, on Ubuntu the "string.h" seems to get pulled in by some other header and it compiles fine. Anyway, this is fixed upstream and I verified by building the package on sid. > Some other issues: > > * The library package should be named based on the SONAME, so that would be > libheif1. Changed to "libheif-1", or should the name be without the dash? > * Current Standards-Version is 4.1.3. Changed, however the lintian on mentors now complains that the version is too new: "newer-standards-version 4.1.3 (current is 3.9.8)" > * If you bump debhelper compatibility to 10 or 11, you can drop the explicit > --with autreconf and --parallel in d/rules. You could also drop > dh-autoreconf > from Build-Depends. Nice, I bumped the compatibility to 10 in the updated package. If everything looks good from a packaging side now, we will release 1.0.0 shortly and I will update the package with the release. Thanks again and best regards, Joachim signature.asc Description: OpenPGP digital signature ___ pkg-multimedia-maintainers mailing list pkg-multimedia-maintainers@lists.alioth.debian.org http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-multimedia-maintainers
Processing of libvpx_1.7.0-1_amd64.changes
libvpx_1.7.0-1.dsc has incorrect md5 checksum; deleting it libvpx5-dbgsym_1.7.0-1_amd64.deb has incorrect md5 checksum; deleting it libvpx5_1.7.0-1_amd64.deb has incorrect size; deleting it Greetings, Your Debian queue daemon (running on host usper.debian.org) ___ pkg-multimedia-maintainers mailing list pkg-multimedia-maintainers@lists.alioth.debian.org http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-multimedia-maintainers