[Bug 719833] [NEW] ssh upstart job fails to actually bring up ssh

2011-02-15 Thread Kees Cook
Public bug reported: When I reboot my router, ssh does not start. Feb 15 22:51:32 router init: ssh main process (897) terminated with status 255 Feb 15 22:51:32 router init: ssh main process ended, respawning Feb 15 22:51:32 router init: ssh main process (915) terminated with status 255 Feb 15

[Bug 719833] Re: ssh upstart job fails to actually bring up ssh

2011-02-15 Thread Kees Cook
-- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/719833 Title: ssh upstart job fails to actually bring up ssh -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com

[Bug 718469] Re: partition always incorrectly reported as being checked on next boot

2011-02-14 Thread Kees Cook
The update-notifier source package produces the update-notifier- common binary package. This package contains: /etc/update-motd.d/98-fsck-at-reboot /usr/lib/update-notifier/update-motd-fsck-at-reboot PAM uses /etc/update-motd.d/ to build the /etc/motd file. 98-fsck-at- reboot calls

[Bug 717358] Re: nautilus puts a menu bar at the top of the desktop

2011-02-14 Thread Kees Cook
The indicator-appmenu thing is not active in classic desktop afaict. ** Changed in: nautilus (Ubuntu) Status: New = Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/717358 Title:

[Bug 712075] Re: [drm:drm_edid_block_valid] *ERROR* EDID checksum is invalid

2011-02-14 Thread Kees Cook
So far, so good. I'm still seeing the warnings in dmesg, but there has not been any screen flickers, so the patch seems to be working. ** Changed in: linux (Ubuntu Natty) Status: Incomplete = In Progress -- You received this bug notification because you are a member of Ubuntu Bugs, which

[Bug 702026] Re: [MIR] dcmtk

2011-02-14 Thread Kees Cook
I'm not a fan of adding this library to main because it seems to reimplement a large set of interfaces that already have so many other libraries implementing them, and additionally has embedded code copies, like a number of image processing bits (libjpeg), etc. I would at least want this built

[Bug 714864] Re: SSL keys for iTalc in Edubuntu only gets generated at build time

2011-02-14 Thread Kees Cook
** Changed in: italc (Ubuntu Natty) Status: Confirmed = Triaged -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/714864 Title: SSL keys for iTalc in Edubuntu only gets generated at build time

[Bug 599892] Re: [Security] cacti - CVE-2009-4032, CVE-2010-1431, and CVE-2010-2092

2011-02-14 Thread Kees Cook
** Changed in: cacti (Ubuntu Lucid) Status: In Progress = Fix Committed -- You received this bug notification because you are a member of Ubuntu Bugs, which is a direct subscriber. https://bugs.launchpad.net/bugs/599892 Title: [Security] cacti - CVE-2009-4032, CVE-2010-1431, and

[Bug 702026] Re: [MIR] dcmtk

2011-02-14 Thread Kees Cook
** Changed in: dcmtk (Ubuntu) Assignee: Kees Cook (kees) = (unassigned) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/702026 Title: [MIR] dcmtk -- ubuntu-bugs mailing list ubuntu-bugs

[Bug 716703] Re: chromium-browser crashed with SIGSEGV in __static_initialization_and_destruction_0()

2011-02-14 Thread Kees Cook
Browsers are the #1 target for attackers, so it's urgent that we make sure that chromium on ARM is as hardened as on the other architectures. The primary difference between default build and the hardening-wrapper is the use of PIE. ** Also affects: chromium-browser (Ubuntu Natty) Importance:

[Bug 663294] Re: Firefox built with gcc-4.5 is a non-starter on i386 with -pie

2011-02-14 Thread Kees Cook
** Also affects: gcc-4.5 (Ubuntu Natty) Importance: High Status: Triaged ** Changed in: gcc-4.5 (Ubuntu Natty) Milestone: None = natty-alpha-3 ** Changed in: gcc-4.5 (Ubuntu Natty) Assignee: (unassigned) = Canonical Desktop Team (canonical-desktop-team) ** Changed in: gcc-4.5

[Bug 718363] Re: Sync mtdev 1.1.0-1 (main) from Debian unstable (main)

2011-02-14 Thread Kees Cook
Unfortunately, running debian/rules control is not part of the standard buildd system. This package cannot be syncd as is. Artur did you try building it and comparing it against the Ubuntu version? It clearly drops the udeb. Why not just include the udeb on the Debian side too? ** Changed in:

[Bug 718312] Re: Merge nvclock 0.8b4+cvs20100914-1 (main) from Debian svn

2011-02-14 Thread Kees Cook
Merging against an un-uploaded version from Debian is really only recommended if there are important fixes that we cannot wait for. I would much rather work from an actually released version of a Debian package. Speaking to the merge work itself, I would like to see each change (even those that

[Bug 718295] Re: Merge nbd 1:2.9.20-2 (main) from Debian unstable (main)

2011-02-14 Thread Kees Cook
Since the modprobe config file was first removed in jaunty, and an LTS has since carried the patch, the preinst file is not longer needed. The modprobe file, btw, might be not an Ubuntu-specific issue. I would recommend opening an upstream bug report about it. Either it should go upstream, or the

[Bug 718205] Re: Merge openssl 0.9.8o-5 (main) from Debian unstable (main)

2011-02-14 Thread Kees Cook
This update looks fine, but I'd like to take the opportunity to clean up the changelog information. There are a lot of Ubuntu deltas in this package, so I'd like to see the list of affected files for each logical change. This greatly helps people reviewing merges in the future. For example,

[Bug 599892] Re: [Security] cacti - CVE-2009-4032, CVE-2010-1431, and CVE-2010-2092

2011-02-14 Thread Kees Cook
Pocket copied cacti to proposed. Please test and give feedback here. See https://wiki.ubuntu.com/Testing/EnableProposed for documentation on how to enable and use -proposed. Thank you in advance! ** Tags added: verification-needed ** Tags removed: security-verification -- You received this bug

[Bug 599892] Re: [Security] cacti - CVE-2009-4032, CVE-2010-1431, and CVE-2010-2092

2011-02-14 Thread Kees Cook
To ubuntu-sru: if this passes the verification process, please also pocket copy to security. Thanks! -- You received this bug notification because you are a member of Ubuntu Bugs, which is a direct subscriber. https://bugs.launchpad.net/bugs/599892 Title: [Security] cacti - CVE-2009-4032,

[Bug 718469] [NEW] partition always incorrectly reported as being checked on next boot

2011-02-13 Thread Kees Cook
Public bug reported: Binary package hint: update-notifier A partition of mine is set to never be checked on max mounts. My motd always reports it as being checked on the next mount. ProblemType: Bug DistroRelease: Ubuntu 11.04 Package: update-notifier 0.110.3ubuntu1 ProcVersionSignature: Ubuntu

[Bug 718469] Re: partition always incorrectly reported as being checked on next boot

2011-02-13 Thread Kees Cook
-- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/718469 Title: partition always incorrectly reported as being checked on next boot -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com

[Bug 705828] Re: update-motd hook should check whether update-motd-cpu-checker exists

2011-02-13 Thread Kees Cook
Hi! This was fixed in 0.110.2ubuntu1 for all the scripts, though cpu- checker was removed in 0.110.1ubuntu1 ** Changed in: update-notifier (Ubuntu) Status: New = Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 702026] Re: [MIR] dcmtk

2011-02-12 Thread Kees Cook
** Changed in: dcmtk (Ubuntu) Assignee: Rohan Garg (rohangarg) = Kees Cook (kees) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/702026 Title: [MIR] dcmtk -- ubuntu-bugs mailing list ubuntu

[Bug 697197] Re: Empty password allows access to VNC in libvirt

2011-02-11 Thread Kees Cook
** Changed in: libvirt (Ubuntu Natty) Importance: High = Undecided ** Changed in: libvirt (Ubuntu Natty) Assignee: Serge Hallyn (serge-hallyn) = (unassigned) ** Changed in: qemu-kvm (Ubuntu Maverick) Milestone: maverick-updates = None ** Changed in: libvirt (Ubuntu Lucid)

[Bug 697197] Re: Empty password allows access to VNC in libvirt

2011-02-11 Thread Kees Cook
Thanks for preparing the debdiffs! It looks like karmic is vulnerable too, so we'll need that as well. I'll update the debdiffs to use proper DEP-3 and fix up the formatting of the changelogs a bit (CVE- vs CVE: ), and get these building. ** Also affects: libvirt (Ubuntu Karmic) Importance:

[Bug 697197] Re: Empty password allows access to VNC in libvirt

2011-02-11 Thread Kees Cook
** Changed in: qemu-kvm (Ubuntu Maverick) Assignee: Ubuntu Security Team (ubuntu-security) = Kees Cook (kees) ** Changed in: qemu-kvm (Ubuntu Lucid) Assignee: Ubuntu Security Team (ubuntu-security) = Kees Cook (kees) ** Changed in: qemu-kvm (Ubuntu Karmic) Importance: Undecided

[Bug 717358] [NEW] nautilus puts a menu bar at the top of the desktop

2011-02-11 Thread Kees Cook
Public bug reported: Binary package hint: nautilus I run the Ubuntu Classic Desktop without a top panel. After upgrading yesterday, nautilus puts a menu bar across the top of my desktop. This should not be here. ProblemType: Bug DistroRelease: Ubuntu 11.04 Package: nautilus 1:2.32.2.1-0ubuntu5

[Bug 717358] Re: nautilus puts a menu bar at the top of the desktop

2011-02-11 Thread Kees Cook
-- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/717358 Title: nautilus puts a menu bar at the top of the desktop -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com

[Bug 717358] Re: nautilus puts a menu bar at the top of the desktop

2011-02-11 Thread Kees Cook
** Attachment added: top-menu.jpg https://bugs.launchpad.net/ubuntu/+source/nautilus/+bug/717358/+attachment/1843795/+files/top-menu.jpg ** Tags added: regression-release -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 693630] Re: upstart uses wrong Debian revision

2011-02-11 Thread Kees Cook
** Changed in: upstart (Ubuntu Natty) Assignee: (unassigned) = Canonical Foundations Team (canonical-foundations) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/693630 Title: upstart uses

[Bug 714958] Re: desktop should disable automounting when screen is locked

2011-02-11 Thread Kees Cook
Alternatively, _delaying_ automount until unlocked might be better, in the case of sitting back down at your system, plugging in a device, and then unlocking your screen. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 717412] [NEW] NX-emulation ASLR is predictable

2011-02-11 Thread Kees Cook
*** This bug is a security vulnerability *** Public security bug reported: On 32bit non-PAE systems, the NX-emulation patch causes shared library and executable ASLR to become predictable due to moving the ranges up into the ASCII Armor area prefixed with a high byte of 0. This has been observed

[Bug 697197] Re: Empty password allows access to VNC in libvirt

2011-02-11 Thread Kees Cook
** Changed in: libvirt (Ubuntu Natty) Importance: High = Undecided ** Changed in: libvirt (Ubuntu Natty) Assignee: Serge Hallyn (serge-hallyn) = (unassigned) ** Changed in: qemu-kvm (Ubuntu Maverick) Milestone: maverick-updates = None ** Changed in: libvirt (Ubuntu Lucid)

[Bug 697197] Re: Empty password allows access to VNC in libvirt

2011-02-11 Thread Kees Cook
Thanks for preparing the debdiffs! It looks like karmic is vulnerable too, so we'll need that as well. I'll update the debdiffs to use proper DEP-3 and fix up the formatting of the changelogs a bit (CVE- vs CVE: ), and get these building. ** Also affects: libvirt (Ubuntu Karmic) Importance:

[Bug 716875] Re: NULL pointer dereference in generic_getxattr

2011-02-11 Thread Kees Cook
Thanks for reporting this issue and helping to make Ubuntu better! Based on the analysis in your log, it would seem to just be a NULL deref Oops and not an exploitable security vulnerability. I'm marking this bug public so that other developers can try to help and get this fixed. Thanks! **

[Bug 717485] [NEW] aufs au_new_inode:412:cc1[11919]: Warning: Un-notified UDBA or repeatedly renamed dir

2011-02-11 Thread Kees Cook
Public bug reported: I've started seeing AUFS errors on my system during sbuilds. Sometimes it will trigger a build failure. I do not seem to be able to reproduce the issue at will, unfortunately. This was seen while trying to build qemu-kvm: [69828.939172] aufs au_new_inode:412:cc1[11919]:

[Bug 717485] Re: aufs au_new_inode:412:cc1[11919]: Warning: Un-notified UDBA or repeatedly renamed dir

2011-02-11 Thread Kees Cook
-- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/717485 Title: aufs au_new_inode:412:cc1[11919]: Warning: Un-notified UDBA or repeatedly renamed dir -- ubuntu-bugs mailing list

[Bug 697197] Re: Empty password allows access to VNC in libvirt

2011-02-11 Thread Kees Cook
** Changed in: qemu-kvm (Ubuntu Maverick) Assignee: Ubuntu Security Team (ubuntu-security) = Kees Cook (kees) ** Changed in: qemu-kvm (Ubuntu Lucid) Assignee: Ubuntu Security Team (ubuntu-security) = Kees Cook (kees) ** Changed in: qemu-kvm (Ubuntu Karmic) Importance: Undecided

[Bug 714864] Re: SSL keys for iTalc in Edubuntu only gets generated at build time

2011-02-10 Thread Kees Cook
** Visibility changed to: Public ** Changed in: italc (Ubuntu Natty) Importance: Critical = High -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/714864 Title: SSL keys for iTalc in Edubuntu only

[Bug 713855] Re: Merge exim4 4.74-1 (main) from Debian experimental (main)

2011-02-09 Thread Kees Cook
This looks pretty good. Can you change 71_exiq_grep_error_on_messages_without_size.patch to use the upstream fix (from that report), drop the From (this should have been Author: with Daniel van Eeden) and add an Origin: line, and finally mention the debian bug # in the changelog? Thanks! **

[Bug 576949] Re: [lucid] LOAD DATA INFILE fails in replication, simple patch available in 5.1.43

2011-02-09 Thread Kees Cook
This looks good; I'll upload it to -proposed now. Thanks! -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to mysql-dfsg-5.1 in ubuntu. https://bugs.launchpad.net/bugs/576949 Title: [lucid] LOAD DATA INFILE fails in replication, simple

[Bug 576949] Re: [lucid] LOAD DATA INFILE fails in replication, simple patch available in 5.1.43

2011-02-09 Thread Kees Cook
This has been uploaded to -proposed. Once it has built, please test and give feedback here. See https://wiki.ubuntu.com/Testing/EnableProposed for documentation on how to enable and use -proposed. Thank you in advance! ** Changed in: mysql-dfsg-5.1 (Ubuntu Lucid) Status: Confirmed = Fix

[Bug 713855] Re: Merge exim4 4.74-1 (main) from Debian experimental (main)

2011-02-09 Thread Kees Cook
Thanks! I've uploaded this merge now. ** Changed in: exim4 (Ubuntu) Status: Incomplete = Fix Committed -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to exim4 in ubuntu. https://bugs.launchpad.net/bugs/713855 Title: Merge

[Bug 699967] Re: Empty list of plugins/services with hostname containing uppercase letters

2011-02-09 Thread Kees Cook
This has been uploaded to -proposed. Once it has built, please test and give feedback here. See https://wiki.ubuntu.com/Testing/EnableProposed for documentation on how to enable and use -proposed. Thank you in advance! ** Also affects: munin (Ubuntu Maverick) Importance: Undecided

[Bug 599892] Re: [Security] cacti - CVE-2009-4032, CVE-2010-1431, and CVE-2010-2092

2011-02-09 Thread Kees Cook
ACK for lucid, though I updated the version to be -2ubuntu0.1 instead of -2.1, following the versioning guide at https://wiki.ubuntu.com/SecurityTeam/UpdatePreparation I'll upload this to security-proposed shortly. Thanks! ** Tags added: security-verification ** Changed in: cacti (Ubuntu Lucid)

[Bug 690644] Re: [SRU] typo in completion for openssl x509

2011-02-09 Thread Kees Cook
Thanks for the maverick patch! This looks good; I'll get it uploaded for testing in -proposed. ** Tags added: verification-needed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/690644 Title: [SRU]

[Bug 652104] Re: TAB completion on p4 gives _get_comp_words_by_ref(): `preprev': unknown argument

2011-02-09 Thread Kees Cook
This has been uploaded to -proposed. Once it has built, please test and give feedback here. See https://wiki.ubuntu.com/Testing/EnableProposed for documentation on how to enable and use -proposed. Thank you in advance! -- You received this bug notification because you are a member of Ubuntu

[Bug 690644] Re: [SRU] typo in completion for openssl x509

2011-02-09 Thread Kees Cook
This has been uploaded to -proposed. Once it has built, please test and give feedback here. See https://wiki.ubuntu.com/Testing/EnableProposed for documentation on how to enable and use -proposed. Thank you in advance! ** Changed in: bash-completion (Ubuntu Maverick) Status: Confirmed =

[Bug 652104] Re: TAB completion on p4 gives _get_comp_words_by_ref(): `preprev': unknown argument

2011-02-09 Thread Kees Cook
Thanks for the maverick patch (from bug 690644) ! This looks good; I'll get it uploaded for testing in -proposed. ** Also affects: bash-completion (Ubuntu Maverick) Importance: Undecided Status: New ** Changed in: bash-completion (Ubuntu Maverick) Status: New = Fix Committed **

[Bug 576949] Re: [lucid] LOAD DATA INFILE fails in replication, simple patch available in 5.1.43

2011-02-09 Thread Kees Cook
This has been uploaded to -proposed. Once it has built, please test and give feedback here. See https://wiki.ubuntu.com/Testing/EnableProposed for documentation on how to enable and use -proposed. Thank you in advance! ** Changed in: mysql-dfsg-5.1 (Ubuntu Lucid) Status: Confirmed = Fix

[Bug 713855] Re: Merge exim4 4.74-1 (main) from Debian experimental (main)

2011-02-09 Thread Kees Cook
Thanks! I've uploaded this merge now. ** Changed in: exim4 (Ubuntu) Status: Incomplete = Fix Committed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/713855 Title: Merge exim4 4.74-1 (main)

[Bug 699967] Re: Empty list of plugins/services with hostname containing uppercase letters

2011-02-09 Thread Kees Cook
This has been uploaded to -proposed. Once it has built, please test and give feedback here. See https://wiki.ubuntu.com/Testing/EnableProposed for documentation on how to enable and use -proposed. Thank you in advance! ** Also affects: munin (Ubuntu Maverick) Importance: Undecided

[Bug 693630] Re: upstart uses wrong Debian revision

2011-02-09 Thread Kees Cook
** Changed in: upstart (Ubuntu) Status: New = Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/693630 Title: upstart uses wrong Debian revision -- ubuntu-bugs mailing list

[Bug 693630] Re: upstart uses wrong Debian revision

2011-02-09 Thread Kees Cook
** Also affects: upstart (Ubuntu Natty) Importance: Medium Status: Confirmed ** Changed in: upstart (Ubuntu Natty) Milestone: None = natty-alpha-3 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 714838] Re: Sync gnutls26 2.10.4-2 (main) from Debian unstable (main)

2011-02-09 Thread Kees Cook
I don't think the risk is worth it; this is in unstable because Debian just re-opened for development. I think we should wait to sync this until Natty+1 unless there is a more pressing reason. ** Changed in: gnutls26 (Ubuntu) Status: New = Won't Fix -- You received this bug notification

[Bug 486154] Re: System beep broken in Karmic despite heroic efforts to fix it

2011-02-09 Thread Kees Cook
I think until this is fixed in a sensible way upstream, there isn't a safe way to backport fixes to earlier releases. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/486154 Title: System beep broken

[Bug 713855] Re: Merge exim4 4.74-1 (main) from Debian experimental (main)

2011-02-09 Thread Kees Cook
This looks pretty good. Can you change 71_exiq_grep_error_on_messages_without_size.patch to use the upstream fix (from that report), drop the From (this should have been Author: with Daniel van Eeden) and add an Origin: line, and finally mention the debian bug # in the changelog? Thanks! **

[Bug 576949] Re: [lucid] LOAD DATA INFILE fails in replication, simple patch available in 5.1.43

2011-02-09 Thread Kees Cook
This looks good; I'll upload it to -proposed now. Thanks! -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/576949 Title: [lucid] LOAD DATA INFILE fails in replication, simple patch available in

[Bug 572110] Re: scary message on live cd installing

2011-02-09 Thread Kees Cook
Unsubscribing ubuntu-sponsors since Colin is evaluating this patch. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/572110 Title: scary message on live cd installing -- ubuntu-bugs mailing list

[Bug 702637] Re: Upload utouch-grail 1.0.18 to Ubuntu

2011-02-09 Thread Kees Cook
** Changed in: utouch-grail (Ubuntu) Status: In Progress = Incomplete -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/702637 Title: Upload utouch-grail 1.0.18 to Ubuntu -- ubuntu-bugs

[Bug 539056] Re: backport security fixes from 6.19 and 5.23

2011-02-09 Thread Kees Cook
Pocket copied drupal5 and drupal6 to -proposed. Please test and give feedback here. See https://wiki.ubuntu.com/Testing/EnableProposed for documentation on how to enable and use -proposed. Thank you in advance! ** Tags added: verification-needed ** Changed in: drupal5 (Ubuntu Hardy)

[Bug 539056] Re: backport security fixes from 6.19 and 5.23

2011-02-09 Thread Kees Cook
To ubuntu-sru: if this passes the verification process, please also pocket copy to security. Thanks! -- You received this bug notification because you are a member of Ubuntu Bugs, which is a direct subscriber. https://bugs.launchpad.net/bugs/539056 Title: backport security fixes from 6.19 and

[Bug 709401] Re: [security] twiki allows remote attackers to execute arbitrary Perl code (CVE-2008-5305)

2011-02-09 Thread Kees Cook
Pocket copied twiki to proposed. Please test and give feedback here. See https://wiki.ubuntu.com/Testing/EnableProposed for documentation on how to enable and use -proposed. Thank you in advance! To ubuntu-sru: if this passes the verification process, please also pocket copy to security. Thanks!

[Bug 715360] [NEW] update-maintainer needless reads entire control file and can explode

2011-02-08 Thread Kees Cook
Public bug reported: Binary package hint: ubuntu-dev-tools update-maintainer does not work on some control files. For example, Karmic's exim4 package: $ update-maintainer The old maintainer was: Ubuntu Core Developers ubuntu-devel-disc...@lists.ubuntu.com Resetting as: Ubuntu Developers

[Bug 715360] Re: update-maintainer needless reads entire control file and can explode

2011-02-08 Thread Kees Cook
-- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/715360 Title: update-maintainer needless reads entire control file and can explode -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com

[Bug 714908] Re: gnome-keyring reads unsafe SSH keys

2011-02-08 Thread Kees Cook
** Changed in: gnome-keyring (Ubuntu Natty) Importance: Undecided = Medium -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/714908 Title: gnome-keyring reads unsafe SSH keys -- ubuntu-bugs

[Bug 715360] Re: update-maintainer needlessly reads entire control file and can explode

2011-02-08 Thread Kees Cook
*** This bug is a duplicate of bug 713827 *** https://bugs.launchpad.net/bugs/713827 ** Summary changed: - update-maintainer needless reads entire control file and can explode + update-maintainer needlessly reads entire control file and can explode -- You received this bug notification

[Bug 712662] Re: network redirection has been enabled

2011-02-07 Thread Kees Cook
** Changed in: bash (Ubuntu Natty) Assignee: (unassigned) = Matthias Klose (doko) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/712662 Title: network redirection has been enabled --

[Bug 714908] [NEW] gnome-keyring reads unsafe SSH keys

2011-02-07 Thread Kees Cook
Public bug reported: Binary package hint: gnome-keyring OpenSSH enforces that one's keys must be mode 0700 so that unsafe permissions do not go unnoticed. gnome-keyring should perform this check as well. It looks like pkcs11/ssh-store/gkm-ssh-private-key.c gkm_ssh_private_key_parse() is the

[Bug 714908] Re: gnome-keyring reads unsafe SSH keys

2011-02-07 Thread Kees Cook
** Also affects: gnome-keyring (Ubuntu Natty) Importance: Undecided Status: New ** Changed in: gnome-keyring (Ubuntu Natty) Milestone: None = natty-alpha-3 ** Changed in: gnome-keyring (Ubuntu Natty) Assignee: (unassigned) = Canonical Desktop Team (canonical-desktop-team) **

[Bug 714958] [NEW] desktop should revoke at-console privs when screen is locked

2011-02-07 Thread Kees Cook
Public bug reported: Binary package hint: gnome-screensaver To avoid auto-run attacks on the system from USB auto-mounting, the desktop should revoke the at-console policy kit privileges while the screen is locked, or not auto-mount inserted devices, similar to how gnome-keyring flushes all keys

[Bug 714958] Re: desktop should revoke at-console privs when screen is locked

2011-02-07 Thread Kees Cook
** Also affects: gnome-screensaver (Ubuntu Natty) Importance: Undecided Status: New ** Changed in: gnome-screensaver (Ubuntu Natty) Importance: Undecided = Medium ** Changed in: gnome-screensaver (Ubuntu Natty) Status: New = Confirmed ** Changed in: gnome-screensaver

[Bug 706917] Re: ClamAV misses SafeBrowsing option in freshclam.conf

2011-02-04 Thread Kees Cook
** Visibility changed to: Public ** This bug is no longer flagged as a security vulnerability -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to clamav in ubuntu. https://bugs.launchpad.net/bugs/706917 Title: ClamAV misses

[Bug 713002] Re: Impossible to disable IPv4

2011-02-04 Thread Kees Cook
** Visibility changed to: Public ** This bug is no longer flagged as a security vulnerability -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to openssh in ubuntu. https://bugs.launchpad.net/bugs/713002 Title: Impossible to disable

[Bug 657473] Re: It looks like you could make SQL injection with $_POST['host'] or some other variables.

2011-02-04 Thread Kees Cook
Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest posting a debdiff for this issue. When a debdiff is available, members of the security

[Bug 599892] Re: [Security] cacti - CVE-2009-4032, CVE-2010-1431, and CVE-2010-2092

2011-02-04 Thread Kees Cook
** Changed in: cacti (Ubuntu) Status: New = Invalid -- You received this bug notification because you are a member of Ubuntu Bugs, which is a direct subscriber. https://bugs.launchpad.net/bugs/599892 Title: [Security] cacti - CVE-2009-4032, CVE-2010-1431, and CVE-2010-2092 --

[Bug 672895] Re: mythfilldatabase shows first 6 letters of password with wget command

2011-02-04 Thread Kees Cook
Thanks for the report! Have you communicated with the upstream MythTV author about this yet? ** Changed in: mythtv (Ubuntu) Status: New = Confirmed ** Changed in: mythtv (Ubuntu) Importance: Undecided = Low ** Visibility changed to: Public -- You received this bug notification

[Bug 695240] Re: $AllowedSender directive is ignored

2011-02-04 Thread Kees Cook
** Changed in: rsyslog (Ubuntu) Status: New = Confirmed ** Changed in: rsyslog (Ubuntu) Importance: Undecided = Medium -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/695240 Title:

[Bug 700198] Re: CVE-2009-0793

2011-02-04 Thread Kees Cook
Gimp is linked against the system lcms ** Changed in: gimp (Ubuntu Natty) Status: New = Invalid ** Changed in: gimp (Ubuntu Hardy) Status: New = Invalid ** Changed in: gimp (Ubuntu Karmic) Status: New = Invalid ** Changed in: gimp (Ubuntu Lucid) Status: New =

[Bug 702204] Re: USB key encrypted password setting not sticky

2011-02-04 Thread Kees Cook
** Package changed: udisks (Ubuntu) = gnome-keyring (Ubuntu) ** Changed in: gnome-keyring (Ubuntu) Importance: Undecided = Medium ** Changed in: gnome-keyring (Ubuntu) Status: New = Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is a

[Bug 706549] Re: UBUNTU10.10 NOFINCIONA centro de software

2011-02-04 Thread Kees Cook
Thank you for using Ubuntu and taking the time to report a bug. Your report should contain, at a minimum, the following information so we can better find the source of the bug and work to resolve it. Submitting the bug about the proper source package is essential. For help see

[Bug 706447] Re: Evolution crashes on email delete or expunge

2011-02-04 Thread Kees Cook
** Visibility changed to: Public ** This bug is no longer flagged as a security vulnerability -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/706447 Title: Evolution crashes on email delete or

[Bug 706397] Re: package blcr-dkms 0.8.2-10 failed to install/upgrade: blcr kernel module failed to build

2011-02-04 Thread Kees Cook
** Visibility changed to: Public ** This bug is no longer flagged as a security vulnerability -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/706397 Title: package blcr-dkms 0.8.2-10 failed to

[Bug 706388] Re: package libgsm1 1.0.13-3 failed to install/upgrade: subprocess installed post-installation script returned error exit status 2

2011-02-04 Thread Kees Cook
** Visibility changed to: Public ** This bug is no longer flagged as a security vulnerability -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/706388 Title: package libgsm1 1.0.13-3 failed to

[Bug 706137] Re: package phpmyadmin 4:3.3.2-1 failed to install/upgrade: подпроцесс установлен сценарий pre-removal возвратил код ошибки 1

2011-02-04 Thread Kees Cook
** Visibility changed to: Public ** This bug is no longer flagged as a security vulnerability -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/706137 Title: package phpmyadmin 4:3.3.2-1 failed to

[Bug 704846] Re: Evolution SIGSEGV when accepting VCS/ICS calendar attachment

2011-02-04 Thread Kees Cook
Thanks for getting the Apport details. This looks like just a regular crash, so I'm going to make the bug public and unmark it as security so hopefully some evolution developers can get a chance to look at it. ** Visibility changed to: Public ** This bug is no longer flagged as a security

[Bug 683705] Re: Evolution SIGSEGV when accepting VCS/ICS calendar attachment

2011-02-04 Thread Kees Cook
*** This bug is a duplicate of bug 704846 *** https://bugs.launchpad.net/bugs/704846 ** This bug has been marked a duplicate of private bug 704846 ** Visibility changed to: Public ** This bug is no longer flagged as a security vulnerability -- You received this bug notification because

[Bug 708497] Re: nautilus crashed with SIGSEGV in g_cclosure_marshal_VOID__PARAM()

2011-02-04 Thread Kees Cook
** Visibility changed to: Public ** This bug is no longer flagged as a security vulnerability -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/708497 Title: nautilus crashed with SIGSEGV in

[Bug 707793] Re: package virtualbox-ose-dkms 3.2.8-dfsg-2ubuntu1 failed to install/upgrade: virtualbox-ose kernel module failed to build

2011-02-04 Thread Kees Cook
** Visibility changed to: Public ** This bug is no longer flagged as a security vulnerability -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/707793 Title: package virtualbox-ose-dkms

[Bug 707034] Re: package glpi 0.72.3-1 failed to install/upgrade: le sous-processus script post-installation installé a retourné une erreur de sortie d'état 1

2011-02-04 Thread Kees Cook
** Visibility changed to: Public ** This bug is no longer flagged as a security vulnerability -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/707034 Title: package glpi 0.72.3-1 failed to

[Bug 706917] Re: ClamAV misses SafeBrowsing option in freshclam.conf

2011-02-04 Thread Kees Cook
** Visibility changed to: Public ** This bug is no longer flagged as a security vulnerability -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/706917 Title: ClamAV misses SafeBrowsing option in

[Bug 706608] Re: Não reproduz DVD, mesmo com os codecs

2011-02-04 Thread Kees Cook
Thanks for your comments. This does not appear to be a bug report and we are closing it. We appreciate the difficulties you are facing, but it would make more sense to raise your question in the support tracker. Please visit https://answers.launchpad.net/ubuntu/+addquestion ** Visibility changed

[Bug 706676] Re: package coreutils 7.4-2ubuntu3 failed to install/upgrade: no se puede acceder al archivo: No existe el archivo o directorio

2011-02-04 Thread Kees Cook
** Visibility changed to: Public ** This bug is no longer flagged as a security vulnerability -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/706676 Title: package coreutils 7.4-2ubuntu3 failed to

[Bug 706575] Re: PROBLEMAS AO VISUALIZAR VIDEOS AO VIVO

2011-02-04 Thread Kees Cook
Thank you for using Ubuntu and taking the time to report a bug. Your report should contain, at a minimum, the following information so we can better find the source of the bug and work to resolve it. Submitting the bug about the proper source package is essential. For help see

[Bug 709618] Re: movie player not play mp4 formate videos and system very slow

2011-02-04 Thread Kees Cook
Thank you for using Ubuntu and taking the time to report a bug. Your report should contain, at a minimum, the following information so we can better find the source of the bug and work to resolve it. Submitting the bug about the proper source package is essential. For help see

[Bug 709524] Re: wehen I was trying to watch the oline chanel this mess appears ''We're sorry, but only the following operating systems are supported at this time: Microsoft Windows XP/Vista (i386) Ap

2011-02-04 Thread Kees Cook
Thanks for your comments. This does not appear to be a bug report and we are closing it. We appreciate the difficulties you are facing, but it would make more sense to raise your question in the support tracker. Please visit https://answers.launchpad.net/ubuntu/+addquestion ** Visibility changed

[Bug 708525] Re: after upgrade nautlius fails; desktop blank

2011-02-04 Thread Kees Cook
** Visibility changed to: Public ** This bug is no longer flagged as a security vulnerability -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/708525 Title: after upgrade nautlius fails; desktop

[Bug 687653] Re: infinite recursion trying to format NotBranchError

2011-02-04 Thread Kees Cook
** This bug is no longer flagged as a security vulnerability -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/687653 Title: infinite recursion trying to format NotBranchError -- ubuntu-bugs mailing

[Bug 710886] Re: Disk overwrite by zcat. false icons and locked loopback

2011-02-04 Thread Kees Cook
Thanks for your comments. This does not appear to be a bug report and we are closing it. We appreciate the difficulties you are facing, but it would make more sense to raise your question in the support tracker. Please visit https://answers.launchpad.net/ubuntu/+addquestion ** Visibility changed

[Bug 711390] Re: package preview-latex-style 11.85-1ubuntu1 failed to install/upgrade: subprocess installed post-installation script returned error exit status 2

2011-02-04 Thread Kees Cook
** Visibility changed to: Public ** This bug is no longer flagged as a security vulnerability -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/711390 Title: package preview-latex-style 11.85-1ubuntu1

[Bug 710552] Re: emails send to me are deleted and I get a delivery status report in stead

2011-02-04 Thread Kees Cook
Thanks for your comments. This does not appear to be a bug report and we are closing it. We appreciate the difficulties you are facing, but it would make more sense to raise your question in the support tracker. Please visit https://answers.launchpad.net/ubuntu/+addquestion ** Visibility changed

[Bug 712380] Re: package install-info 4.13a.dfsg.1-5ubuntu1 failed to install/upgrade: le sous-processus script post-installation installé a retourné une erreur de sortie d'état 2

2011-02-04 Thread Kees Cook
** Visibility changed to: Public ** This bug is no longer flagged as a security vulnerability -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/712380 Title: package install-info 4.13a.dfsg.1-5ubuntu1

<    5   6   7   8   9   10   11   12   13   14   >