Doing a "view source" on the messages also fails.
A couple of sample messages that failed to display until I restarted icedove are attached.
Notable are the large size of the headers of the messages, although as many of the newsgroups I read with icedove are mailing lists carried on gmane.org, headers of this size would not be uncommon.
Arthur.
Path: news.gmane.org!not-for-mail Message-ID: <20100410133816.6256.49215.reportbug__46071.3245011449$1270908012$gmane$...@belanna.comodo.priv.at> From: gregor herrmann <gre...@debian.org> Newsgroups: gmane.linux.debian.devel.release Subject: Bug#577209: nmu: Please schedule binNMUs against libdbi-perl Date: Sat, 10 Apr 2010 15:38:16 +0200 Lines: 55 Approved: n...@gmane.org Reply-To: gregor herrmann <gre...@debian.org>, 577...@bugs.debian.org NNTP-Posting-Host: lo.gmane.org Mime-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit X-Trace: dough.gmane.org 1270908012 5772 80.91.229.12 (10 Apr 2010 14:00:12 GMT) X-Complaints-To: use...@dough.gmane.org NNTP-Posting-Date: Sat, 10 Apr 2010 14:00:12 +0000 (UTC) To: Debian Bug Tracking System <sub...@bugs.debian.org> Original-X-From: bounce-debian-release=debian-release=m.gmane....@lists.debian.org Sat Apr 10 16:00:11 2010 Return-path: <bounce-debian-release=debian-release=m.gmane....@lists.debian.org> Envelope-to: debian-rele...@m.gmane.org Original-Received: from liszt.debian.org ([82.195.75.100]) by lo.gmane.org with esmtp (Exim 4.69) (envelope-from <bounce-debian-release=debian-release=m.gmane....@lists.debian.org>) id 1O0bEI-0004Zs-Sn for debian-rele...@m.gmane.org; Sat, 10 Apr 2010 16:00:10 +0200 Original-Received: from localhost (localhost [127.0.0.1]) by liszt.debian.org (Postfix) with QMQP id 592552D1EE5; Sat, 10 Apr 2010 14:00:10 +0000 (UTC) Old-Return-Path: <debb...@busoni.debian.org> X-Spam-Checker-Version: SpamAssassin 3.2.5 (2008-06-10) on liszt.debian.org X-Spam-Level: X-Spam-Status: No, score=-6.1 required=4.0 tests=FOURLA,FVGT_m_MULTI_ODD, IMPRONONCABLE_1,IMPRONONCABLE_2,LDO_WHITELIST,MONEY,MURPHY_WRONG_WORD1, MURPHY_WRONG_WORD2,PGPSIGNATURE,STOCKLIKE autolearn=failed version=3.2.5 X-Original-To: lists-debian-rele...@liszt.debian.org Delivered-To: lists-debian-rele...@liszt.debian.org Original-Received: from localhost (localhost [127.0.0.1]) by liszt.debian.org (Postfix) with ESMTP id 8A52313A6612 for <lists-debian-rele...@liszt.debian.org>; Sat, 10 Apr 2010 13:42:20 +0000 (UTC) X-Virus-Scanned: at lists.debian.org with policy bank en-ht X-Amavis-Spam-Status: No, score=-8.08 tagged_above=-10000 required=5.3 tests=[BAYES_00=-2, FOURLA=0.1, FVGT_m_MULTI_ODD=0.02, IMPRONONCABLE_1=1, IMPRONONCABLE_2=1, LDO_WHITELIST=-5, MONEY=0.5, MURPHY_WRONG_WORD1=0.1, MURPHY_WRONG_WORD2=0.2, PGPSIGNATURE=-5, STOCKLIKE=1] autolearn=ham Original-Received: from liszt.debian.org ([127.0.0.1]) by localhost (lists.debian.org [127.0.0.1]) (amavisd-new, port 2525) with ESMTP id d5MHMGYON6cW for <lists-debian-rele...@liszt.debian.org>; Sat, 10 Apr 2010 13:42:11 +0000 (UTC) Original-Received: from busoni.debian.org (busoni.debian.org [140.211.15.34]) (using TLSv1 with cipher AES256-SHA (256/256 bits)) (Client did not present a certificate) by liszt.debian.org (Postfix) with ESMTPS id 692D413A6208; Sat, 10 Apr 2010 13:42:11 +0000 (UTC) Original-Received: from debbugs by busoni.debian.org with local (Exim 4.69) (envelope-from <debb...@busoni.debian.org>) id 1O0awq-0001wk-1V; Sat, 10 Apr 2010 13:42:08 +0000 X-Loop: ow...@bugs.debian.org Resent-From: gregor herrmann <gre...@debian.org> Resent-To: debian-bugs-dist@lists.debian.org Resent-CC: debian-p...@lists.debian.org, Debian Release Team <debian-rele...@lists.debian.org> X-Loop: ow...@bugs.debian.org Resent-Date: Sat, 10 Apr 2010 13:42:04 +0000 Resent-Message-ID: <handler.577209.b.12709067074...@bugs.debian.org> X-Debian-PR-Message: report 577209 X-Debian-PR-Package: release.debian.org X-Debian-PR-Keywords: Original-Received: via spool by sub...@bugs.debian.org id=B.12709067074294 (code B ref -1); Sat, 10 Apr 2010 13:42:04 +0000 Original-Received: (at submit) by bugs.debian.org; 10 Apr 2010 13:38:27 +0000 Original-Received: from colleen.colgarra.priv.at ([82.150.197.85]) by busoni.debian.org with esmtps (TLS1.0:RSA_AES_256_CBC_SHA1:32) (Exim 4.69) (envelope-from <gre...@debian.org>) id 1O0atG-00015x-Vy for sub...@bugs.debian.org; Sat, 10 Apr 2010 13:38:27 +0000 Original-Received: from chello212186032184.406.14.vie.surfer.at ([212.186.32.184] helo=belanna.comodo.priv.at) by colleen.colgarra.priv.at with esmtpsa (TLS1.0:RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from <gre...@debian.org>) id 1O0at7-0006mM-0T for sub...@bugs.debian.org; Sat, 10 Apr 2010 15:38:17 +0200 Original-Received: from gregoa by belanna.comodo.priv.at with local (Exim 4.71) (envelope-from <gre...@debian.org>) id 1O0at6-0003ck-6m for sub...@bugs.debian.org; Sat, 10 Apr 2010 15:38:16 +0200 X-Mailer: reportbug 4.11 Delivered-To: sub...@bugs.debian.org Resent-Date: Sat, 10 Apr 2010 13:42:08 +0000 X-Rc-Spam: 2008-11-04_01 X-Rc-Virus: 2007-09-13_01 X-Rc-Spam: 2008-11-04_01 X-Mailing-List: <debian-rele...@lists.debian.org> archive/latest/35323 X-Loop: debian-rele...@lists.debian.org List-Id: <debian-release.lists.debian.org> List-Post: <mailto:debian-rele...@lists.debian.org> List-Help: <mailto:debian-release-requ...@lists.debian.org?subject=help> List-Subscribe: <mailto:debian-release-requ...@lists.debian.org?subject=subscribe> List-Unsubscribe: <mailto:debian-release-requ...@lists.debian.org?subject=unsubscribe> Precedence: list Resent-Sender: debian-release-requ...@lists.debian.org Archived-At: <http://permalink.gmane.org/gmane.linux.debian.devel.release/34147> Xref: ppp121-45-136-118.lns11.adl6.internode.on.net gmane.linux.debian.devel.release:853 Package: release.debian.org Severity: normal User: release.debian....@packages.debian.org Usertags: binnmu User: release.debian....@packages.debian.org Usertags: binnmu -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 It looks like the arch:any packages build-depending on libdbi-perl need binNMUs against the new libdbi-perl 1.610.90-1. Please note that libdbd-mysql-perl already saw a sourceful upload; I've now locally verified that libdbd-sqlite3-perl errors out and works after a rebuild. If my grep-dctrl foo worked this should be: nmu libdbd-odbc-perl_1.23-1 . ALL . -m "Rebuilt against new libdbi-perl." nmu libdbd-pg-perl_2.17.1-1 . ALL . -m "Rebuilt against new libdbi-perl." nmu libdbd-sqlite2-perl_2:0.33-8 . ALL . -m "Rebuilt against new libdbi-perl." nmu libdbd-sqlite3-perl_1.29-1 . ALL . -m "Rebuilt against new libdbi-perl." nmu libdbd-sybase-perl_1.00-3 . ALL . -m "Rebuilt against new libdbi-perl." nmu libdbix-oo-perl_0.0.9-2 . ALL . -m "Rebuilt against new libdbi-perl." nmu libpoe-component-dbiagent-perl_0.26-1 . ALL . -m "Rebuilt against new libdbi-perl." nmu libtfbs-perl_0.5.svn.20091128-1 . ALL . -m "Rebuilt against new libdbi-perl." nmu olive_1.3-3 . ALL . -m "Rebuilt against new libdbi-perl." nmu sympa_5.4.7-1 . ALL . -m "Rebuilt against new libdbi-perl." Cheers, gregor, who hopes he got his first binNMU request right -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQIcBAEBCAAGBQJLwH9EAAoJELs6aAGGSaoGY1oQAItBdW+SUNNWwPnIdPfEu95N 0x/C+USGh2d6Q4BfGiRGPgaIl3WYVyrrITwYPdSp5LI5z2ouZ0nhWK2Xb3DW1rc7 zi5D86XSIKER83bPVD2qd5AfDf9x1FXhrq73OGIIbmD8A4S+Wt09L8pM5foEEEJp AtwT575FoSmlVclJt63ByBzbm8t2NrxZiwQu+aeNQQ+BcBF6BUmmbge5k9xKbP26 FT/lsvaQKHRtkEnWcVxxzpGUcPXB1PyutVW4XAPghD3h/+7iEA4EJ+1EGa5jR6L2 AoqoWDPQUaGYnBkxz4fkdNVq5Vpjm88t06SVB4ofqgFKBN1mdPlL2IPgcJOxfBD8 O7zMTyTxq3pdfYjmRVhZfunp4AcBU9YfdmAB4hVefyEBte+hnymTWn+DexokDaVi 6PO+ipHg4qVkqcnfok1AmY2QBhvs/n4w2D/npUM5ghz3/O8exDC9EBf/3YbmgiKN jwFPGDX/Yd1vuFDQ/aCPS9gI9GlxlFHYocjYLWtNHPng7CMAy9ssrBILvzA3bI+A f9qwmFJa2BlJxfeJi+LEWQ/PPdl1C59xeL3hGH3+Ro5kJQAVFuyGC4eK4BNPmG/3 1f0O1eC4+8joRDzmcaKuMfnhHMRvrvhnpImRD2iro5jX4y9E5lv0BUWk7JBks7eU dG8KBKCe6ZB4w28MDnBb =R2TB -----END PGP SIGNATURE-----
Path: news.gmane.org!not-for-mail Message-ID: <20100413161221.ga26...@perso.beuc.net> From: Sylvain Beucler <b...@beuc.net> Newsgroups: gmane.linux.debian.devel.release Subject: tla update for Debian 5.0.5 Date: Tue, 13 Apr 2010 18:12:21 +0200 Lines: 174 Approved: n...@gmane.org NNTP-Posting-Host: lo.gmane.org Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="FL5UXtIhxfXey3p5" X-Trace: dough.gmane.org 1271175169 6359 80.91.229.12 (13 Apr 2010 16:12:49 GMT) X-Complaints-To: use...@dough.gmane.org NNTP-Posting-Date: Tue, 13 Apr 2010 16:12:49 +0000 (UTC) Cc: b...@decadent.ork.uk To: debian-rele...@lists.debian.org Original-X-From: bounce-debian-release=debian-release=m.gmane....@lists.debian.org Tue Apr 13 18:12:47 2010 Return-path: <bounce-debian-release=debian-release=m.gmane....@lists.debian.org> Envelope-to: debian-rele...@m.gmane.org Original-Received: from liszt.debian.org ([82.195.75.100]) by lo.gmane.org with esmtp (Exim 4.69) (envelope-from <bounce-debian-release=debian-release=m.gmane....@lists.debian.org>) id 1O1ijE-0005gf-If for debian-rele...@m.gmane.org; Tue, 13 Apr 2010 18:12:44 +0200 Original-Received: from localhost (localhost [127.0.0.1]) by liszt.debian.org (Postfix) with QMQP id 194BE13A581E; Tue, 13 Apr 2010 16:12:44 +0000 (UTC) Old-Return-Path: <b...@beuc.net> X-Spam-Checker-Version: SpamAssassin 3.2.5 (2008-06-10) on liszt.debian.org X-Spam-Level: X-Spam-Status: No, score=-10.0 required=4.0 tests=FVGT_m_MULTI_ODD, LDO_WHITELIST,MURPHY_DRUGS_REL8,PGPSIGNATURE autolearn=failed version=3.2.5 X-Original-To: lists-debian-rele...@liszt.debian.org Delivered-To: lists-debian-rele...@liszt.debian.org Original-Received: from localhost (localhost [127.0.0.1]) by liszt.debian.org (Postfix) with ESMTP id 7DDD013A57FD for <lists-debian-rele...@liszt.debian.org>; Tue, 13 Apr 2010 16:12:38 +0000 (UTC) X-Virus-Scanned: at lists.debian.org with policy bank en-ht X-Amavis-Spam-Status: No, score=-11.96 tagged_above=-10000 required=5.3 tests=[BAYES_00=-2, FVGT_m_MULTI_ODD=0.02, LDO_WHITELIST=-5, MURPHY_DRUGS_REL8=0.02, PGPSIGNATURE=-5] autolearn=ham Original-Received: from liszt.debian.org ([127.0.0.1]) by localhost (lists.debian.org [127.0.0.1]) (amavisd-new, port 2525) with ESMTP id GPX26pwzUuMf for <lists-debian-rele...@liszt.debian.org>; Tue, 13 Apr 2010 16:12:30 +0000 (UTC) X-policyd-weight: DYN_NJABL=SKIP(0) NOT_IN_SBL_XBL_SPAMHAUS=-1.5 NOT_IN_BL_NJABL=-1.5 DSBL_ORG=SKIP(0) CL_IP_EQ_HELO_IP=-2 (check from: .beuc. - helo: .smtp1-g21.free. - helo-domain: .free.) FROM/MX_MATCHES_NOT_HELO(DOMAIN)=0; rate: -5 Original-Received: from smtp1-g21.free.fr (smtp1-g21.free.fr [212.27.42.1]) by liszt.debian.org (Postfix) with ESMTP id 0FC8213A5578 for <debian-rele...@lists.debian.org>; Tue, 13 Apr 2010 16:12:29 +0000 (UTC) Original-Received: from smtp1-g21.free.fr (localhost [127.0.0.1]) by smtp1-g21.free.fr (Postfix) with ESMTP id 53DCB940159 for <debian-rele...@lists.debian.org>; Tue, 13 Apr 2010 18:12:24 +0200 (CEST) Original-Received: from localhost.localdomain (unknown [82.238.35.175]) by smtp1-g21.free.fr (Postfix) with ESMTP id 5B8389401ED for <debian-rele...@lists.debian.org>; Tue, 13 Apr 2010 18:12:22 +0200 (CEST) Original-Received: from me by localhost.localdomain with local (Exim 4.71) (envelope-from <b...@beuc.net>) id 1O1iir-0004in-Pr; Tue, 13 Apr 2010 18:12:21 +0200 Content-Disposition: inline X-Operating-System: GNU/Linux User-Agent: Mutt/1.5.20 (2009-06-14) X-Rc-Virus: 2007-09-13_01 X-Rc-Spam: 2008-11-04_01 Resent-Message-ID: <due6unumkef.a.1bb.8fj...@liszt> Resent-From: debian-rele...@lists.debian.org X-Mailing-List: <debian-rele...@lists.debian.org> archive/latest/35355 X-Loop: debian-rele...@lists.debian.org List-Id: <debian-release.lists.debian.org> List-Post: <mailto:debian-rele...@lists.debian.org> List-Help: <mailto:debian-release-requ...@lists.debian.org?subject=help> List-Subscribe: <mailto:debian-release-requ...@lists.debian.org?subject=subscribe> List-Unsubscribe: <mailto:debian-release-requ...@lists.debian.org?subject=unsubscribe> Precedence: list Resent-Sender: debian-release-requ...@lists.debian.org Resent-Date: Tue, 13 Apr 2010 16:12:44 +0000 (UTC) Archived-At: <http://permalink.gmane.org/gmane.linux.debian.devel.release/34179> Xref: ppp121-45-136-118.lns11.adl6.internode.on.net gmane.linux.debian.devel.release:885 --FL5UXtIhxfXey3p5 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable Hello stable release managers, I would like to upload a security update for Lenny, for package 'tla'. http://www.debian.org/security/2009/dsa-1953 As it's a minor issue, the security team asked me to upload it through a point-release update (cf. forwarded message below). A package can be found at: http://www.beuc.net/tmp/tla/lenny-stable/tla_1.3.5+dfsg-14+lenny1.dsc Is it OK with you? Here's the interdiff: diff -u tla-1.3.5+dfsg/debian/changelog tla-1.3.5+dfsg/debian/changelog --- tla-1.3.5+dfsg/debian/changelog +++ tla-1.3.5+dfsg/debian/changelog @@ -1,3 +1,11 @@ +tla (1.3.5+dfsg-14+lenny1) stable; urgency=3Dlow + + * QA upload. + * Fix CVE-2009-3560 and CVE-2009-3720 denial-of-services by patching + bundled libexpat (closes: #560940). + + -- Sylvain Beucler <b...@beuc.net> Tue, 13 Apr 2010 17:55:51 +0200 + tla (1.3.5+dfsg-14) unstable; urgency=3Dlow =20 * QA upload. diff -u tla-1.3.5+dfsg/debian/patches/00list tla-1.3.5+dfsg/debian/patches/= 00list --- tla-1.3.5+dfsg/debian/patches/00list +++ tla-1.3.5+dfsg/debian/patches/00list @@ -5,0 +6,2 @@ +CVE-2009-3560.dpatch +CVE-2009-3720.dpatch only in patch2: unchanged: --- tla-1.3.5+dfsg.orig/debian/patches/CVE-2009-3720.dpatch +++ tla-1.3.5+dfsg/debian/patches/CVE-2009-3720.dpatch @@ -0,0 +1,22 @@ +#! /bin/sh /usr/share/dpatch/dpatch-run +## CVE-2009-3720.dpatch by Sylvain Beucler <b...@beuc.net> +## +## All lines beginning with `## DP:' are a description of the patch. +## DP: Fix CVE-2009-3720 vulnerability +## DP: Check: +## DP: http://expat.cvs.sourceforge.net/viewvc/expat/expat/lib/xmltok_impl= =2Ec?r1=3D1.13&r2=3D1.15&diff_format=3Dl +## DP: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=3D560940 + +...@dpatch@ +diff -urNad tla-1.3.5+dfsg~/src/expat/lib/xmltok_impl.c tla-1.3.5+dfsg/src= /expat/lib/xmltok_impl.c +--- tla-1.3.5+dfsg~/src/expat/lib/xmltok_impl.c 2006-07-20 08:34:33.000000= 000 +0200 ++++ tla-1.3.5+dfsg/src/expat/lib/xmltok_impl.c 2010-01-23 19:35:20.0000000= 00 +0100 +@@ -1741,7 +1741,7 @@ + const char *end, + POSITION *pos) + { +- while (ptr !=3D end) { ++ while (ptr < end) { + switch (BYTE_TYPE(enc, ptr)) { + #define LEAD_CASE(n) \ + case BT_LEAD ## n: \ only in patch2: unchanged: --- tla-1.3.5+dfsg.orig/debian/patches/CVE-2009-3560.dpatch +++ tla-1.3.5+dfsg/debian/patches/CVE-2009-3560.dpatch @@ -0,0 +1,23 @@ +#! /bin/sh /usr/share/dpatch/dpatch-run +## CVE-2009-3560.dpatch by Sylvain Beucler <b...@beuc.net> +## +## All lines beginning with `## DP:' are a description of the patch. +## DP: Fix CVE-2009-3560 vulnerability +## DP: Check: +## DP: http://expat.cvs.sourceforge.net/viewvc/expat/expat/lib/xmlparse.c?= r1=3D1.164&r2=3D1.166&diff_format=3Dh +## DP: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=3D560940 + +...@dpatch@ +diff -urNad tla-1.3.5+dfsg~/src/expat/lib/xmlparse.c tla-1.3.5+dfsg/src/ex= pat/lib/xmlparse.c +--- tla-1.3.5+dfsg~/src/expat/lib/xmlparse.c 2006-07-20 08:34:33.000000000= +0200 ++++ tla-1.3.5+dfsg/src/expat/lib/xmlparse.c 2010-01-23 19:32:26.000000000 = +0100 +@@ -3615,6 +3615,9 @@ + return XML_ERROR_UNCLOSED_TOKEN; + case XML_TOK_PARTIAL_CHAR: + return XML_ERROR_PARTIAL_CHAR; ++ case -XML_TOK_PROLOG_S: ++ tok =3D -tok; ++ break; + case XML_TOK_NONE: + #ifdef XML_DTD + /* for internal PE NOT referenced between declarations */ Best regards, - Sylvain ----- Forwarded message from Moritz Muehlenhoff <j...@inutil.org> ----- Date: Mon, 22 Mar 2010 18:56:22 +0100 =46rom: Moritz Muehlenhoff <j...@inutil.org> To: Sylvain Beucler <b...@beuc.net> Cc: t...@security.debian.org, b...@decadent.org.uk Subject: Re: Versioning: security updates and binary uploads User-Agent: Mutt/1.5.20 (2009-06-14) On Mon, Mar 22, 2010 at 02:19:13PM +0100, Sylvain Beucler wrote: > Ciao! >=20 > On Mon, Mar 22, 2010 at 01:21:55PM +0100, Giuseppe Iuculano wrote: > > Il 21/03/2010 14:16, Sylvain Beucler ha scritto: > > > There's no conflict right now, because 'b' '<' 'etch', but there would > > > be a conflict if 'etch' had been called instead 'alfred' or anything > > > that is '<' 'b'. > > >=20 > > > So maybe I should use: > > > -> tla-1.3.5+dfsg-9+b1+etch1 > > > as a rule? > >=20 > > As you wrote, there is no conflict right now, so you should use > > tla-1.3.5+dfsg-9+etch1. >=20 > Ok, thanks. > =20 > > BTW, currently there isn't any security issues opened for tla, what are > > you preparing? >=20 > tla includes a copy of libexpat, so it's affected by: > http://www.debian.org/security/2009/dsa-1953 > A fix was uploaded to testing, but not to stable and old-stable. This specific issue doesn't warrant a DSA, please update it through a stable point update: http://www.debian.org/doc/developers-reference/pkgs.html#upload-stable =20 > Btw, do you still accept old-stable uploads? Support for Etch has ended some weeks ago. Cheers, Moritz ----- End forwarded message ----- --FL5UXtIhxfXey3p5 Content-Type: application/pgp-signature; name="signature.asc" Content-Description: Digital signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iEYEARECAAYFAkvEl+UACgkQcllesYFwS5OMhgCfRCJnP1LSVEQ7p2sj9vyKpvx1 W2UAoM1bmkbCrAbpMIrlsKxnjLaKSY5a =oi0+ -----END PGP SIGNATURE----- --FL5UXtIhxfXey3p5--