Processed: Fwd: Bug#684065: plasma-widgets-workspace: Plasma clock is badly rendered on vertical taskbar

2012-08-07 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org:

> forwarded 684065 https://bugs.kde.org/show_bug.cgi?id=304711
Bug #684065 [plasma-widgets-workspace] plasma-widgets-workspace: Plasma clock 
is badly rendered on vertical taskbar
Set Bug forwarded-to-address to 'https://bugs.kde.org/show_bug.cgi?id=304711'.
> thanks
Stopping processing here.

Please contact me if you need assistance.
-- 
684065: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=684065
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems


--
To UNSUBSCRIBE, email to debian-qt-kde-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org
Archive: 
http://lists.debian.org/handler.s.c.134432722023960.transcr...@bugs.debian.org



Bug#676833: Same problem when building kdevplatform

2012-08-07 Thread Benjamin Eikel
Hello,

when building kdevplatform, I get the same error message:

"dh_sameversiondep: package libc6 was not found in the dpkg status. Internal 
error"

$ dpkg --print-architecture
amd64

$ dpkg --print-foreign-architectures
i386

When using dpkg-query, I get the same error message as Jan. Is there a 
workaround for this problem without installing pbuilder or deinstalling the 
i386 packages?

Kind regards
Benjamin


-- 
To UNSUBSCRIBE, email to debian-qt-kde-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org
Archive: http://lists.debian.org/201208071142.28179.deb...@eikel.org



Processed: limit source to qtcreator, tagging 683933

2012-08-07 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org:

> #qtcreator (2.5.0-2) unstable; urgency=medium
> #
> #  * Build tm_posix.cpp on kFreeBSD and Hurd to fix a crash because of an
> #undefined symbol. (Closes: #683933)
> #- Add posix_rt_nonlinux.diff
> #
> limit source qtcreator
Limiting to bugs with field 'source' containing at least one of 'qtcreator'
Limit currently set to 'source':'qtcreator'

> tags 683933 + pending
Bug #683933 [qtcreator] [qtcreator] undefined symbol: _ZTVN5Botan11POSIX_TimerE
Added tag(s) pending.
> thanks
Stopping processing here.

Please contact me if you need assistance.
-- 
683933: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=683933
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems


--
To UNSUBSCRIBE, email to debian-qt-kde-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org
Archive: 
http://lists.debian.org/handler.s.c.134434272514714.transcr...@bugs.debian.org



Bug#684177: okular cannot search anymore

2012-08-07 Thread Remi Denis-Courmont
Package: okular
Version: 4:4.8.4-2
Severity: important

Dear Maintainer,

With recent Wheezy packages (not sure exactly which), the search
function in Okular consistently fails. The waiting spinning cursor
shows and the search never completes, nor finding any match nor
reporting search failure. However, it prints this on stderr:

QMetaObject::invokeMethod: No such method 
Okular::Document::doContinueNextMatchSearch(void *,void 
*,int,int,QString,int,bool,QColor,bool)

So it seems the meta-object compilation (moc) in the Debian i386 build
of okular went badly wrong.

Apparently, the same bug was reported on Ubuntu as well:
http://bugs.launchpad.net/ubuntu/+source/okular/+bug/1027657

-- System Information:
Debian Release: wheezy/sid
  APT prefers unstable
  APT policy: (100, 'unstable')
Architecture: i386 (i686)

Kernel: Linux 3.5.0-basile-4-g2895365 (SMP w/2 CPU cores)
Locale: LANG=fr_FR.UTF-8, LC_CTYPE=fr_FR.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash

Versions of packages okular depends on:
ii  kde-runtime   4:4.8.4-1
ii  libc6 2.13-35
ii  libfreetype6  2.4.9-1
ii  libgcc1   1:4.7.1-6
ii  libjpeg8  8d-1
ii  libkdecore5   4:4.8.4-3
ii  libkdeui5 4:4.8.4-3
ii  libkio5   4:4.8.4-3
ii  libkparts44:4.8.4-3
ii  libkprintutils4   4:4.8.4-3
ii  libkpty4  4:4.8.4-3
ii  libokularcore14:4.8.4-2
ii  libphonon44:4.6.0.0-2
ii  libpoppler-qt4-3  0.18.4-3
ii  libqca2   2.0.3-4
ii  libqimageblitz4   1:0.0.6-4
ii  libqt4-dbus   4:4.8.2-2
ii  libqt4-svg4:4.8.2-2
ii  libqt4-xml4:4.8.2-2
ii  libqtcore44:4.8.2-2
ii  libqtgui4 4:4.8.2-2
ii  libsolid4 4:4.8.4-3
ii  libspectre1   0.2.6-2
ii  libstdc++64.7.1-6
ii  phonon4:4.6.0.0-2
ii  zlib1g1:1.2.7.dfsg-13

okular recommends no packages.

Versions of packages okular suggests:
ii  ghostscript9.05~dfsg-6
pn  jovie  
pn  okular-extra-backends  
pn  poppler-data   
ii  texlive-binaries   2012.20120628-2
ii  unrar  1:4.1.4-1

-- no debconf information


-- 
To UNSUBSCRIBE, email to debian-qt-kde-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org
Archive: 
http://lists.debian.org/20120807143608.31491.61173.report...@basile.remlab.net



Bug#684177: Same here

2012-08-07 Thread Adrian Knoth
Hi!

Same problem over here, Ubuntu bug report talks about qt4-x11,
indicating that a downgrade would help.

I can confirm that

  Remove the following packages: 
1)  libqt4-sql-mysql 

  Install the following packages:
2)  libqt4-sql-odbc [4:4.8.2-1 (testing)]

  Downgrade the following packages:  
3)  libqt4-dbus [4:4.8.2-2 (now, unstable) -> 4:4.8.2-1 (testing)]   
4)  libqt4-declarative [4:4.8.2-2 (now, unstable) -> 4:4.8.2-1 (testing)]
5)  libqt4-designer [4:4.8.2-2 (now, unstable) -> 4:4.8.2-1 (testing)]   
6)  libqt4-dev [4:4.8.2-2 (now, unstable) -> 4:4.8.2-1 (testing)]
7)  libqt4-dev-bin [4:4.8.2-2 (now, unstable) -> 4:4.8.2-1 (testing)]
8)  libqt4-help [4:4.8.2-2 (now, unstable) -> 4:4.8.2-1 (testing)]   
9)  libqt4-network [4:4.8.2-2 (now, unstable) -> 4:4.8.2-1 (testing)]
10) libqt4-opengl [4:4.8.2-2 (now, unstable) -> 4:4.8.2-1 (testing)] 
11) libqt4-opengl-dev [4:4.8.2-2 (now, unstable) -> 4:4.8.2-1 (testing)] 
12) libqt4-qt3support [4:4.8.2-2 (now, unstable) -> 4:4.8.2-1 (testing)] 
13) libqt4-script [4:4.8.2-2 (now, unstable) -> 4:4.8.2-1 (testing)] 
14) libqt4-scripttools [4:4.8.2-2 (now, unstable) -> 4:4.8.2-1 (testing)]
15) libqt4-sql [4:4.8.2-2 (now, unstable) -> 4:4.8.2-1 (testing)]
16) libqt4-svg [4:4.8.2-2 (now, unstable) -> 4:4.8.2-1 (testing)]
17) libqt4-test [4:4.8.2-2 (now, unstable) -> 4:4.8.2-1 (testing)]   
18) libqt4-xml [4:4.8.2-2 (now, unstable) -> 4:4.8.2-1 (testing)]
19) libqt4-xmlpatterns [4:4.8.2-2 (now, unstable) -> 4:4.8.2-1 (testing)]
20) libqtcore4 [4:4.8.2-2 (now, unstable) -> 4:4.8.2-1 (testing)]
21) libqtgui4 [4:4.8.2-2 (now, unstable) -> 4:4.8.2-1 (testing)] 
22) qdbus [4:4.8.2-2 (now, unstable) -> 4:4.8.2-1 (testing)] 
23) qt4-linguist-tools [4:4.8.2-2 (now, unstable) -> 4:4.8.2-1 (testing)]
24) qt4-qmake [4:4.8.2-2 (now, unstable) -> 4:4.8.2-1 (testing)]

indeed fixes the problem without recompiling okular.


HTH

-- 
mail: a...@thur.de  http://adi.thur.de  PGP/GPG: key via keyserver


-- 
To UNSUBSCRIBE, email to debian-qt-kde-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org
Archive: http://lists.debian.org/20120807173146.gj25...@ltw.loris.tv



Bug#684251: webkit code embedded in qt4-11 and possibly may be out of date and vulnerable

2012-08-07 Thread Silvio Cesare
Package: qt4-x11
Severity: important
Tags: security

I have been working on a tool called Clonewise to automatically identify
embedded code copies in Debian packages and determine if they are out of
date and vulnerable. Ideally, embedding code and libraries should be
avoided and a system wide library should be used instead.

I recently ran the tool on Debian 6 stable. The results are here at
http://www.foocodechu.com/downloads/Clonewise-report.txt*

*The qt4-x11 package reported potential issues appended to this message.

The analysis tries to justify why it believes a library or code is embedded
in the package and if the relationship is not already being tracked by
Debian in the embedded-code-copies database it shows the files that are
shared between the two pieces of software.

Apologies if these are false positives. Your help in advising me on whether
these issues are real will help me improve the analysis for the future.

--
Silvio Cesare
Deakin University

### Summary:
###

webkit CLONED_IN_SOURCE qt4-x11  CVE-2010-1386
webkit CLONED_IN_SOURCE qt4-x11  CVE-2010-1760
webkit CLONED_IN_SOURCE qt4-x11  CVE-2010-1766

### Reports by package:
###


# Package qt4-x11 may be vulnerable to the following issues:
#
CVE-2010-1386
CVE-2010-1760
CVE-2010-1766


# SUMMARY: page/Geolocation.cpp in WebCore in WebKit before r56188 and
before 1.2.5 does not properly restrict access to the lastPosition
function, which has unspecified impact and remote attack vectors, aka
rdar problem 7746357.
#

# CVE-2010-1386 relates to a vulnerability in package webkit.
# The following source filenames are likely responsible:
#   geolocation.c
#

# The following package clones are tracked in the embedded-code-copies
# database. They have not been fixed.
#

webkit CLONED_IN_SOURCE qt4-x11  CVE-2010-1386


# SUMMARY: loader/DocumentThreadableLoader.cpp in the XMLHttpRequest
implementation in WebCore in WebKit before r58409 does not properly
handle credentials during a cross-origin synchronous request, which
has unspecified impact and remote attack vectors, aka rdar problem
7905150.
#

# CVE-2010-1760 relates to a vulnerability in package webkit.
# The following source filenames are likely responsible:
#   documentthreadableloader.c
#

# The following package clones are tracked in the embedded-code-copies
# database. They have not been fixed.
#

webkit CLONED_IN_SOURCE qt4-x11  CVE-2010-1760


# SUMMARY: Off-by-one error in the
WebSocketHandshake::readServerHandshake function in
websockets/WebSocketHandshake.cpp in WebCore in WebKit before r56380,
as used in Qt and other products, allows remote websockets servers to
cause a denial of service (memory corruption) or possibly have
unspecified other impact via an upgrade header that is long and
invalid.
#

# CVE-2010-1766 relates to a vulnerability in package webkit.
# The following source filenames are likely responsible:
#   websockethandshake.c
#

# The following package clones are tracked in the embedded-code-copies
# database. They have not been fixed.
#

webkit CLONED_IN_SOURCE qt4-x11  CVE-2010-1766