Bug#735261: mutiple upstream bugs

2015-01-13 Thread Michael Gilbert
control: severity -1 important

> It may sound cynical, but my advice would be that if you're hit with this, 
> change mail clients :/
>
> In the context of freeze/release, I'd suggest to tag this jessie-ignore, or 
> even forever-ignore.

This is a usability problem, so it doesn't really qualify as release critical.

Best wishes,
Mike


-- 
To UNSUBSCRIBE, email to debian-qt-kde-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org
Archive: 
https://lists.debian.org/CANTw=mmqmypx5tsxikd_fvevlcyfk_wr1wrztw3io16xjd2...@mail.gmail.com



Bug#735261: mutiple upstream bugs

2015-01-15 Thread Michael Gilbert
> However, the problem reported here is not a usability problem. If a mail
> client losing record of which mails have been read and which haven't isn't
> "non-serious data loss", I can't tell what is.

Actual data loss.

Best wishes,
Mike


-- 
To UNSUBSCRIBE, email to debian-qt-kde-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org
Archive: 
https://lists.debian.org/CANTw=mmyn1b1jayajqae+pu2evl9umfaugf+cwdzotv7fho...@mail.gmail.com



Bug#735261: mutiple upstream bugs

2015-01-18 Thread Michael Gilbert
On Fri, Jan 16, 2015 at 8:07 AM, Shai Berger wrote:
> On Friday 16 January 2015 01:45:53 Michael Gilbert wrote:
>> > However, the problem reported here is not a usability problem. If a mail
>> > client losing record of which mails have been read and which haven't
>> > isn't "non-serious data loss", I can't tell what is.
>>
>> Actual data loss.
>>
>
> So, the bits marking messages as "read" or "unread" are not data? What, pray
> tell, are they?

Easily recreatable bit flags.

Best wishes,
Mike


-- 
To UNSUBSCRIBE, email to debian-qt-kde-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org
Archive: 
https://lists.debian.org/CANTw=mnc4fw3nh-k6ng8l7wx6spq6lr66cug2xog0fgywf1...@mail.gmail.com



Bug#735261: mutiple upstream bugs

2015-01-18 Thread Michael Gilbert
On Sun, Jan 18, 2015 at 4:14 PM, Shai Berger  wrote:
>> > So, the bits marking messages as "read" or "unread" are not data? What,
>> > pray tell, are they?
>>
>> Easily recreatable bit flags.
>>
>
> So data isn't lost if it is "easily recreatable"? Really?

No.

> By that argument, there really shouldn't be any data loss bugs, because all
> data should be easily restorable from backup.

Also no.

> Those "easily recreatable" bits represent a significant part of my mail
> workflow. Almost any data can be recreated by repeating the work that created
> it. Your claims essentially come down to "workflows based on 'read status' are
> invalid or unimportant". Well, they're damned important to me.

Then you're either choosing the wrong mail client or not doing enough
to help upstream scratch that itch.

> I suspect that this discussion is going nowhere, but I still would like you to
> answer one more question: Can you describe the difference between "serious" 
> and
> "non-serious" data loss?

The difference is "actual" vs. "perceived" data loss.

Best wishes,
Mike


-- 
To UNSUBSCRIBE, email to debian-qt-kde-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org
Archive: 
https://lists.debian.org/CANTw=MM-H=ias1eppmfkqrb22_wm+bfsbaj99ebwgsp7sak...@mail.gmail.com



Bug#735261: mutiple upstream bugs

2015-01-18 Thread Michael Gilbert
On Sun, Jan 18, 2015 at 5:44 PM, Shai Berger wrote:
> I am asking about "serious" vs. "non-serious" because those are the terms used
> by reportbug ("non-serious data loss" is a reason to mark a bug "grave").

Both grave and critical refer to actual data loss.  Using the term
serious isn't particularly useful since that falls outside those two
categories anyway.

> Calling data-loss which you find unimportant "perceived, not  actual" isn't
> helpful at all. You're playing with terms rather than making points.

If it were unimportant, then the bts would have the bug at less than
important severity.

The description of the "important" may help correct the ongoing misperception:
https://www.debian.org/Bugs/Developer#severities

Best wishes,
Mike


-- 
To UNSUBSCRIBE, email to debian-qt-kde-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org
Archive: 
https://lists.debian.org/CANTw=mnwekasernntowe2vd3tzrtrn2r9rndeyoydhchrfp...@mail.gmail.com



Bug#735261: mutiple upstream bugs

2015-01-18 Thread Michael Gilbert
On Sun, Jan 18, 2015 at 6:18 PM, Shai Berger wrote:
>> Both grave and critical refer to actual data loss.  Using the term
>> serious isn't particularly useful since that falls outside those two
>> categories anyway.
>>
>
> Again, you're being tautological, repeating your terms rather than defining
> them.

Without some form of tautology, everyone's favorite itch would get the
highest severity.  Nothing would get done that way, so the project
created roughly defined bug severities.  Unfortunately language is not
black and white, so often enough people come along with perceptions
that differ from the project at large, and these kinds of discussion
ensue without productively accomplishing anything.

>> The description of the "important" may help correct the ongoing
>> misperception: https://www.debian.org/Bugs/Developer#severities
>>
>
> In my book, "a major effect on the usability of a package" means I can't do
> what I want (easily enough). The case here -- "I told the program something
> and it forgot it" -- is data loss.

The program can't do read/unread flags correctly.  That falls under
the first category.  Never did it forget the actual content of the
mail, which would be actual data loss.

Unfortunately, this itch isn't severe enough to block the upcoming
release.  If it somehow gets fixed in the meantime, you can always
plea your case to the release team to consider accepting it.

Can we please move on?

Best wishes,
Mike


-- 
To UNSUBSCRIBE, email to debian-qt-kde-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org
Archive: 
https://lists.debian.org/CANTw=mnigziumdj+hljpbki3efeosbogz9udjlmk9vhajy8...@mail.gmail.com



Bug#706105: system-config-printer-kde: Missing CUPS dependency

2013-04-24 Thread Michael Gilbert
control: tag -1 patch, pending

Hi,

I've uploaded an nmu fixing this issue to delayed/5.  Please see attached patch.

Best wishes,
Mike


kdeadmin.patch
Description: Binary data


Bug#460753: kdebase-runtime: should the depends on libxine1 be a recommends?

2008-01-14 Thread Michael Gilbert
Package: kdebase-runtime
Version: 4:4.0.0-1
Severity: normal

if one tries to remove libxine1, most of kde 4.0 will also be removed
(because kdebase-runtime has a dependency on libxine1).  this is a very
undesirable effect.

it seems like the dependency should be more of a recommendation because 
there is nothing in the kdebase that requires libxine1 (that i am aware 
of).

thanks for the hard work.

-- System Information:
Debian Release: lenny/sid
  APT prefers unstable
  APT policy: (500, 'unstable'), (1, 'experimental')
Architecture: i386 (i686)

Kernel: Linux 2.6.23-1-686 (SMP w/1 CPU core)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/bash

Versions of packages kdebase-runtime depends on:
ii  kde-icons-oxygen4:4.0.0-1Oxygen icon theme for KDE 4
ii  kdebase-runtime-bin-kde 4:4.0.0-1KDE 4 core binaries for the KDE ba
ii  kdebase-runtime-data4:4.0.0-1shared data files for the KDE base
ii  kdelibs54:4.0.0-1core libraries for all KDE 4 appli
ii  libc6   2.7-6GNU C Library: Shared libraries
ii  libclucene0ldbl 0.9.20-1 library for full-featured text sea
ii  libgcc1 1:4.3-20080112-1 GCC support library
ii  libopenexr2ldbl 1.2.2-4.4runtime files for the OpenEXR imag
ii  libphonon4  4:4.0.0-1cross-platform multimedia framewor
ii  libqt4-core 4.3.3-2  Qt 4 core non-GUI functionality ru
ii  libqt4-gui  4.3.3-2  Qt 4 core GUI functionality runtim
ii  libqt4-qt3support   4.3.3-2  Qt 3 compatibility library for Qt 
ii  libsmbclient3.0.28-2 shared library that allows applica
ii  libsoprano4 2.0.0-2  Qt4 interface to RDF storage
ii  libstdc++6  4.3-20080112-1   The GNU Standard C++ Library v3
ii  libstreamanalyzer0  0.5.7-1  streamanalyzer library for Strigi 
ii  libstrigiqtdbusclient0  0.5.7-1  library for writing D-Bus clients 
ii  libx11-62:1.0.3-7X11 client-side library
ii  libxcb1 1.1-1X C Binding
ii  libxcursor1 1:1.1.9-1X cursor management library
ii  libxine11.1.9-1  the xine video/media player librar

kdebase-runtime recommends no packages.

-- no debconf information



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]



Bug#460753: kdebase-runtime: should the depends on libxine1 be a recommends?

2008-01-15 Thread Michael Gilbert
reopen 460753
thank you

> Not really. /usr/lib/kde4/phonon_xine.so, the xine backend of phonon
> links against it. This dependency can't be removed and was added
> automatically added by dpjg-shlibs (and is completely correct).

i understand that this is how things currently work, but it isn't
necessarily optimal.  for example, if i decide to use the gstreamer
phonon backend instead of xine (not sure if this exists yet or how to
enable it, but when it is available, i will switch to it), i will no
longer need xine and will prefer to remove the packages because they
are unneeded.

and maybe this is a non-issue.  when the phonon gstreamer backend
becomes available, the kdebase-runtime dependency can just be changed
to "libxine1 | libgstreamer"... although it would be nice to be able
to use no audio and hence be able to remove all of the unneeded
sound/multimedia packages without losing all of kde.



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]



Bug#461641: libqt4-dev: should the dependency on libqt4-sql be a recommends?

2008-01-19 Thread Michael Gilbert
Package: libqt4-dev
Version: 4.3.3-2
Severity: normal

since there are currently security issues with a couple of the mysql 
packages in sid, i would like to remove them.  however, doing so would 
remove libqt4-dev as well since there is a dependency on libqt4-sql
(which depends on the mysql packages).

if the dependency on libqt4-sql were changed to a recommends, this
wouldn't be a problem.  i am not familiar with the libqt4-dev package,
so i don't know what kind of effect that has.  but it seems like the mysql
and qt4 development stuff are or should be separate/separable things.

thanks for all the hard work.

-- System Information:
Debian Release: lenny/sid
  APT prefers unstable
  APT policy: (500, 'unstable'), (1, 'experimental')
Architecture: i386 (i686)

Kernel: Linux 2.6.23-1-686 (SMP w/1 CPU core)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/bash

Versions of packages libqt4-dev depends on:
ii  libaudio-dev   1.9.1-1   Network Audio System - development
ii  libfreetype6-dev   2.3.5-1+b1FreeType 2 font engine, developmen
ii  libgl1-mesa-dev [libgl 7.0.2-4   A free implementation of the OpenG
ii  libglib2.0-dev 2.14.5-2  Development files for the GLib lib
ii  libglu1-mesa-dev [libg 7.0.2-4   The OpenGL utility library -- deve
ii  libice-dev 2:1.0.4-1 X11 Inter-Client Exchange library 
ii  libjpeg62-dev  6b-14 Development files for the IJG JPEG
ii  libmng-dev 1.0.9-1   M-N-G library (Development headers
ii  libpng12-dev [libpng12 1.2.15~beta5-3PNG library - development
ii  libpq-dev  8.2.6-1   header files for libpq5 (PostgreSQ
ii  libqt4-core4.3.3-2   Qt 4 core non-GUI functionality ru
ii  libqt4-gui 4.3.3-2   Qt 4 core GUI functionality runtim
ii  libqt4-qt3support  4.3.3-2   Qt 3 compatibility library for Qt 
ii  libqt4-sql 4.3.3-2   Qt 4 SQL database module
ii  libsm-dev  2:1.0.3-1+b1  X11 Inter-Client Exchange library 
ii  libsqlite0-dev 2.8.17-4  SQLite development files
ii  libx11-dev 2:1.0.3-7 X11 client-side library (developme
ii  libxcursor-dev 1:1.1.9-1 X cursor management library (devel
ii  libxext-dev1:1.0.3-2 X11 miscellaneous extensions libra
ii  libxft-dev 2.1.12-2  FreeType-based font drawing librar
ii  libxi-dev  2:1.1.3-1 X11 Input extension library (devel
ii  libxinerama-dev1:1.0.2-1 X11 Xinerama extension library (de
ii  libxmu-dev 2:1.0.4-1 X11 miscellaneous utility library 
ii  libxrandr-dev  2:1.2.2-1 X11 RandR extension library (devel
ii  libxrender-dev 1:0.9.4-1 X Rendering Extension client libra
ii  libxt-dev  1:1.0.5-3 X11 toolkit intrinsics library (de
ii  x11proto-core-dev  7.0.11-1  X11 core wire protocol and auxilia
ii  zlib1g-dev 1:1.2.3.3.dfsg-10 compression library - development

libqt4-dev recommends no packages.

-- no debconf information



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]



Bug#461652: konqueror: home button does not take user to home page

2008-01-19 Thread Michael Gilbert
Package: konqueror
Version: 4:3.5.8.dfsg.1-6
Severity: normal

the konqueror home button takes the user to their home directory, rather
than their home page (even when it is in the "Web Browsing" profile
mode).  this is just very unintuitive, especially when the user has been
conditioned to expect the home button to go to the home page in *all* of
their other browsers.

-- System Information:
Debian Release: lenny/sid
  APT prefers unstable
  APT policy: (500, 'unstable'), (1, 'experimental')
Architecture: i386 (i686)

Kernel: Linux 2.6.23-1-686 (SMP w/1 CPU core)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/bash

Versions of packages konqueror depends on:
ii  kcontrol   4:3.5.8.dfsg.1-6  control center for KDE
ii  kdebase-kio-plugins4:3.5.8.dfsg.1-6  core I/O slaves for KDE
ii  kdelibs4c2a4:3.5.8.dfsg.1-6  core libraries and binaries for al
ii  kdesktop   4:3.5.8.dfsg.1-6  miscellaneous binaries and files f
ii  kfind  4:3.5.8.dfsg.1-6  file-find utility for KDE
ii  libacl12.2.45-1  Access control list shared library
ii  libart-2.0-2   2.3.19-3  Library of functions for 2D graphi
ii  libattr1   1:2.4.39-1Extended attribute shared library
ii  libaudio2  1.9.1-1   Network Audio System - shared libr
ii  libc6  2.7-6 GNU C Library: Shared libraries
ii  libfontconfig1 2.5.0-2   generic font configuration library
ii  libfreetype6   2.3.5-1+b1FreeType 2 font engine, shared lib
ii  libgamin0 [libfam0]0.1.9-2   Client library for the gamin file 
ii  libgcc11:4.3-20080116-1  GCC support library
ii  libice62:1.0.4-1 X11 Inter-Client Exchange library
ii  libidn11   1.1-1 GNU libidn library, implementation
ii  libjpeg62  6b-14 The Independent JPEG Group's JPEG 
ii  libkonq4   4:3.5.8.dfsg.1-6  core libraries for Konqueror
ii  libpng12-0 1.2.15~beta5-3PNG library - runtime
ii  libqt3-mt  3:3.3.7-9 Qt GUI Library (Threaded runtime v
ii  libsm6 2:1.0.3-1+b1  X11 Session Management library
ii  libstdc++6 4.3-20080116-1The GNU Standard C++ Library v3
ii  libx11-6   2:1.0.3-7 X11 client-side library
ii  libxcursor11:1.1.9-1 X cursor management library
ii  libxext6   1:1.0.3-2 X11 miscellaneous extension librar
ii  libxft22.1.12-2  FreeType-based font drawing librar
ii  libxi6 2:1.1.3-1 X11 Input extension library
ii  libxinerama1   1:1.0.2-1 X11 Xinerama extension library
ii  libxrandr2 2:1.2.2-1 X11 RandR extension library
ii  libxrender11:0.9.4-1 X Rendering Extension client libra
ii  libxt6 1:1.0.5-3 X11 toolkit intrinsics library
ii  zlib1g 1:1.2.3.3.dfsg-10 compression library - runtime

konqueror recommends no packages.

-- no debconf information



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]



Bug#461656: konqueror: quick search bar

2008-01-19 Thread Michael Gilbert
Package: konqueror
Version: 4:3.5.8.dfsg.1-6
Severity: wishlist

it would be very nice if konqueror had a quick search toolbar (like the
one in firefox).  this could even be a way for kde to make some money
(via google).

thank you for your consideration.

-- System Information:
Debian Release: lenny/sid
  APT prefers unstable
  APT policy: (500, 'unstable'), (1, 'experimental')
Architecture: i386 (i686)

Kernel: Linux 2.6.23-1-686 (SMP w/1 CPU core)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/bash

Versions of packages konqueror depends on:
ii  kcontrol   4:3.5.8.dfsg.1-6  control center for KDE
ii  kdebase-kio-plugins4:3.5.8.dfsg.1-6  core I/O slaves for KDE
ii  kdelibs4c2a4:3.5.8.dfsg.1-6  core libraries and binaries for al
ii  kdesktop   4:3.5.8.dfsg.1-6  miscellaneous binaries and files f
ii  kfind  4:3.5.8.dfsg.1-6  file-find utility for KDE
ii  libacl12.2.45-1  Access control list shared library
ii  libart-2.0-2   2.3.19-3  Library of functions for 2D graphi
ii  libattr1   1:2.4.39-1Extended attribute shared library
ii  libaudio2  1.9.1-1   Network Audio System - shared libr
ii  libc6  2.7-6 GNU C Library: Shared libraries
ii  libfontconfig1 2.5.0-2   generic font configuration library
ii  libfreetype6   2.3.5-1+b1FreeType 2 font engine, shared lib
ii  libgamin0 [libfam0]0.1.9-2   Client library for the gamin file 
ii  libgcc11:4.3-20080116-1  GCC support library
ii  libice62:1.0.4-1 X11 Inter-Client Exchange library
ii  libidn11   1.1-1 GNU libidn library, implementation
ii  libjpeg62  6b-14 The Independent JPEG Group's JPEG 
ii  libkonq4   4:3.5.8.dfsg.1-6  core libraries for Konqueror
ii  libpng12-0 1.2.15~beta5-3PNG library - runtime
ii  libqt3-mt  3:3.3.7-9 Qt GUI Library (Threaded runtime v
ii  libsm6 2:1.0.3-1+b1  X11 Session Management library
ii  libstdc++6 4.3-20080116-1The GNU Standard C++ Library v3
ii  libx11-6   2:1.0.3-7 X11 client-side library
ii  libxcursor11:1.1.9-1 X cursor management library
ii  libxext6   1:1.0.3-2 X11 miscellaneous extension librar
ii  libxft22.1.12-2  FreeType-based font drawing librar
ii  libxi6 2:1.1.3-1 X11 Input extension library
ii  libxinerama1   1:1.0.2-1 X11 Xinerama extension library
ii  libxrandr2 2:1.2.2-1 X11 RandR extension library
ii  libxrender11:0.9.4-1 X Rendering Extension client libra
ii  libxt6 1:1.0.5-3 X11 toolkit intrinsics library
ii  zlib1g 1:1.2.3.3.dfsg-10 compression library - runtime

konqueror recommends no packages.

-- no debconf information



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]



Bug#479644: libqt4-webkit:CVE-2008-1025 Cross-site scripting (XSS) vulnerability in Apple WebKit

2008-05-06 Thread Michael Gilbert
i believe that this is actually an issue with webkit itself, not the
libqt4-webkit package (which uses webkit as a library).  CVE-2008-1025
seems to indicate that the issue is wholely within webkit (there is no
mention of qt).

submitter, do you have further details that would confirm that the
problem also resides in libqt4-webkit?  otherwise, this bug should be
reassigned to webkit.



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]



Bug#479644: libqt4-webkit:CVE-2008-1025 Cross-site scripting (XSS) vulnerability in Apple WebKit

2008-05-06 Thread Michael Gilbert
On 5/6/08, Michael Gilbert wrote:
> i believe that this is actually an issue with webkit itself, not the
> libqt4-webkit package (which uses webkit as a library).  CVE-2008-1025
> seems to indicate that the issue is wholely within webkit (there is no
> mention of qt).

i am mistaken, it looks like qt4-x11 duplicates the webkit source
code, rather than relying on it as a library, which in my opinion is
certainly not a very good approach.  please ignore the previous
message.



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]



Bug#479851: qt4-x11: should use external webkit library

2008-05-06 Thread Michael Gilbert
Package: qt4-x11
Version: 4.4.0~rc1-5
Severity: important

qt4-xll should use the already-packaged libwebkit-1.0 library, rather than
repackaging webkit separately.

this has a couple major advantages.  it reduces duplicated data (on the
debian archives, on the user's system, and in memory).  also, it reduces
duplicated maintenance overhead (only one maintainer needed to support
the single code base).  and finally, only one package needs to be
updated to fix security issues (see CVE-2008-1025 [1] where the webkit
library already has the fix, but qt4-x11 remains vulnerable).

[1] http://security-tracker.debian.net/tracker/CVE-2008-1025

-- System Information:
Debian Release: lenny/sid
  APT prefers unstable
  APT policy: (500, 'unstable'), (500, 'stable'), (1, 'experimental')
Architecture: i386 (i686)

Kernel: Linux 2.6.18-6-686 (SMP w/1 CPU core)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/bash



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]



Bug#366342: About oyu bug #366342 "kmid: cannot open /dev/sequencer" to DBTS

2008-07-03 Thread Michael Gilbert
found 366342 4:3.5.9-1
thank you

> We are sorry if nobody responded when you filed the bug, KDE has
> gotten more bugs in the past years than the maintainers could handle.
> The team is trying to fix this now, but we need your help. So please
> respond to this mail and tell us if:
>
> - you are still experiencing this bug (adding in what version)
> - the bug was already fixed (if known, in which version),
> - or if you have extra information on how reproduce this bug.

yes, this bug still exists.  download any of the songs from
www.mididb.org, and try to play with kmid.  you will get the errors as
described in previous messages.

thanks for doing this triage.



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]



Bug#366342: About oyu bug #366342 "kmid: cannot open /dev/sequencer" to DBTS

2008-07-05 Thread Michael Gilbert
> Do you have timidity installed?  If so, check that /etc/default/timidity
> has TIM_ALSASEQ=true uncommented.

no, timidity had not previously been installed on my system.  if you
look at kmid's dependencies, you will find that timidity is not one of
them.  should that be fixed?

i installed timidity and uncommented the "TIM_ALSASEQ=true" line.
when i ran the rc script, i got

$ sudo invoke-rc.d timidity start
Starting TiMidity++ ALSA midi emulation...ALSA lib
seq_hw.c:457:(snd_seq_hw_open) open /dev/snd/seq failed: No such file
or directory
error in snd_seq_open

so it looks like timidity doesn't work either.  note that there still
is no /dev/snd/seq file on my system

$ ls -l /dev/snd/seq
ls: cannot access /dev/snd/seq: No such file or directory

i tried running kmid, but ran into the same errors as before.



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]



Bug#366342: About oyu bug #366342 "kmid: cannot open /dev/sequencer" to DBTS

2008-07-05 Thread Michael Gilbert
> Then your problem is not with kmid. Seems to be with your audio setup. I'm
> closing this bug.

wouldn't it make more sense to reassign the bug to the appropriate
package?  it hasn't been fixed yet.  which package would this apply
to?



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]



Bug#366342: marked as done (kmid: cannot open /dev/sequencer)

2008-07-05 Thread Michael Gilbert
reopen 366342
thank you



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]



Bug#366342: no /dev/snd/seq for AC97 alsa driver

2008-07-07 Thread Michael Gilbert
reopen 366342
retitle 366342 libasound2: no /dev/snd/seq for AC97 alsa driver
reassign 366342 libasound2
thank you

this was a bug thought to apply only to kmid, but it appears that it
is specific to the AC97 alsa driver.  it appears that ths driver does
not provide a /dev/snd/seq device, which leads to various sound
problems, such as the inability to play midi files.

the AC97 driver should provide a /dev/snd/seq device.

thanks for the hard work.



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]



Bug#659155: Status of kdeadmin 4:4.8.4-2 (bug 659155)?

2012-11-21 Thread Michael Gilbert
> Pending an upload, whenever some of us has the time to do it.
>
> On the other hand, I'm still not quite sure that this can be viewed as a fix.
> I'm removing the patch tag, because the approiate tag would be pending, but as
> I said before, I'm still not sure of this.

The best way to see whether an issue is fixed is to make it available
to the people experiencing the problem.  If you're afraid of causing
problems in unstable, you can use experimental first.

Best wishes,
Mike


-- 
To UNSUBSCRIBE, email to debian-qt-kde-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org
Archive: 
http://lists.debian.org/CANTw=mm0krokee6sc1o3xxp3pnl4hdmpf0fceubvghj+_y-...@mail.gmail.com



Bug#659155: Status of kdeadmin 4:4.8.4-2 (bug 659155)?

2012-11-23 Thread Michael Gilbert
>> The best way to see whether an issue is fixed is to make it available
>> to the people experiencing the problem.  If you're afraid of causing
>> problems in unstable, you can use experimental first.
>
> Not the case here Michael :-)
>
> My worry is that this seems more like a hack than a proper fix.

Well, it's release-critical, so an imperfect fix now is better than a
perfect one that doesn't yet exist.

Best wishes,
Mike


-- 
To UNSUBSCRIBE, email to debian-qt-kde-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org
Archive: 
http://lists.debian.org/CANTw=MPM_SrwwggaVA3Wj2shmRtwJ=kjc6y4zg_sxzh7vrx...@mail.gmail.com



Bug#551290: kdegraphics: multiple vulnerabilities

2009-10-16 Thread Michael Gilbert
package: kdegraphics
version: 4:3.5.5-3
severity: serious
tags: security

hi,

it has been disclosed that xpdf is vulnerable to multiple new
vulnerabilities [0].  kdegraphics embeds xpdf in both stable and
oldstable, so please coordinate with the security team to release
patched versions. kdegraphics in unstable is also affected, but no
action is needed. it is dynamically linked to poppler, which is also
affected and tracked in another bug. thanks.

mike

[0] http://seclists.org/fulldisclosure/2009/Oct/227



-- 
To UNSUBSCRIBE, email to debian-qt-kde-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org



Bug#559798: CVE-2009-3736 local privilege escalation

2009-12-06 Thread Michael Gilbert
Package: arts
Severity: grave
Tags: security

Hi,

The following CVE (Common Vulnerabilities & Exposures) id was
published for libtool.  I have determined that this package embeds a
vulnerable copy of the libtool source code.  However, since this is a
mass bug filing (due to so many packages embedding libtool), I have not
had time to determine whether the vulnerable code is actually present
in any of the binary packages. Please determine whether this is the
case. If the package is not affected, please feel free to close the bug
with a message containing the details of what you did to check.

CVE-2009-3736[0]:
| ltdl.c in libltdl in GNU Libtool 1.5.x, and 2.2.6 before 2.2.6b,
| attempts to open a .la file in the current working directory, which
| allows local users to gain privileges via a Trojan horse file.

Note that this problem also affects etch and lenny, so if your package
is affected, please coordinate with the security team to release the
DSA for the affected packages.

If you fix the vulnerability please also make sure to include the
CVE id in your changelog entry.

For further information see:

[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3736
http://security-tracker.debian.org/tracker/CVE-2009-3736



-- 
To UNSUBSCRIBE, email to debian-qt-kde-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org



Bug#559817: CVE-2009-3736 local privilege escalation

2009-12-06 Thread Michael Gilbert
Package: kdelibs
Severity: grave
Tags: security

Hi,

The following CVE (Common Vulnerabilities & Exposures) id was
published for libtool.  I have determined that this package embeds a
vulnerable copy of the libtool source code.  However, since this is a
mass bug filing (due to so many packages embedding libtool), I have not
had time to determine whether the vulnerable code is actually present
in any of the binary packages. Please determine whether this is the
case. If the binary packages are not affected, please feel free to close
the bug with a message containing the details of what you did to check.

CVE-2009-3736[0]:
| ltdl.c in libltdl in GNU Libtool 1.5.x, and 2.2.6 before 2.2.6b,
| attempts to open a .la file in the current working directory, which
| allows local users to gain privileges via a Trojan horse file.

Note that this problem also affects etch and lenny, so if your package
is affected, please coordinate with the security team to release the
DSA for the affected packages.

If you fix the vulnerability please also make sure to include the
CVE id in your changelog entry.

For further information see:

[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3736
http://security-tracker.debian.org/tracker/CVE-2009-3736



-- 
To UNSUBSCRIBE, email to debian-qt-kde-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org



Bug#561752: kdelibs: remote info disclosure via css

2009-12-19 Thread Michael Gilbert
package: kdelibs
version: 4:3.5.10.dfsg.1-2.1
severity: important
tags: security

hi,

it has been disclosed that it is possible for any website to query the
user's site viewing history via css.  please see [0].  i have not
personally checked whether this package is vulnerable, but it seems to
be a general css design issue, so all css-supporting browsers are
likely affected. please check, and feel free to close the bug if the
package is not affected.   thanks.

mike



-- 
To UNSUBSCRIBE, email to debian-qt-kde-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org



Bug#561754: qt4-x11: remote info disclosure via css

2009-12-19 Thread Michael Gilbert
package: qt4-x11
version: 4:4.5.3-4 
severity: important
tags: security

hi,

it has been disclosed that it is possible for any website to query the
user's site viewing history via css.  please see [0].  i have not
personally checked whether this package is vulnerable, but it seems to
be a general css design issue, so all css-supporting browsers are
likely affected. please check, and feel free to close the bug if the
package is not affected.   thanks.

mike

[0]
http://thecoffeedesk.com/news/index.php/2009/08/02/view-remote-browser-history/
Hi,

Your package embeds source code from xulrunner, which makes
security updates very cumbersome, difficult, and potentially
error-prone.  Please update your package to make use of the
shared library.  Thank you for your attention on this matter.

Best wishes,
Mike



-- 
To UNSUBSCRIBE, email to debian-qt-kde-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org



Bug#561753: kde4libs: remote info disclosure via css

2009-12-19 Thread Michael Gilbert
package: kde4libs
version: 4:4.3.4-1
severity: important
tags: security

hi,

it has been disclosed that it is possible for any website to query the
user's site viewing history via css.  please see [0].  i have not
personally checked whether this package is vulnerable, but it seems to
be a general css design issue, so all css-supporting browsers are
likely affected. please check, and feel free to close the bug if the
package is not affected.   thanks.

mike



-- 
To UNSUBSCRIBE, email to debian-qt-kde-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org



Bug#561759: qt4-x11: predictable random number generator used

2009-12-19 Thread Michael Gilbert
package: qt4-x11
version: 4:4.5.3-4
severity: important
tags: security

hello,

it has been discovered that all of the major web browsers use a
predictable pseudo-random number generator (PRNG), which has at a
minimum the consequences described in [0]. please check whether this
package is affected.

[0] http://www.trusteer.com/temporary-user-tracking-in-major-browsers



-- 
To UNSUBSCRIBE, email to debian-qt-kde-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org



Bug#561757: kdelibs: predictable random number generator used

2009-12-19 Thread Michael Gilbert
package: kdelibs
version: 4:3.5.10.dfsg.1-2.1
severity: important
tags: security

hello,

it has been discovered that all of the major web browsers use a
predictable pseudo-random number generator (PRNG), which has at a
minimum the consequences described in [0]. please check whether this
package is affected.

[0] http://www.trusteer.com/temporary-user-tracking-in-major-browsers



-- 
To UNSUBSCRIBE, email to debian-qt-kde-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org



Bug#561758: kde4libs: predictable random number generator used

2009-12-19 Thread Michael Gilbert
package: kde4libs
version: 4:4.3.4-1
severity: important
tags: security

hello,

it has been discovered that all of the major web browsers use a
predictable pseudo-random number generator (PRNG), which has at a
minimum the consequences described in [0]. please check whether this
package is affected.

[0] http://www.trusteer.com/temporary-user-tracking-in-major-browsers



-- 
To UNSUBSCRIBE, email to debian-qt-kde-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org



Bug#561760: qt4-x11: many webkit vulnerabilities

2009-12-19 Thread Michael Gilbert
Package: qt4-x11
Version: 4:4.5.3-4
Severity: grave
Tags: security

Hi,

The following CVE (Common Vulnerabilities & Exposures) ids were
published for webkit.  qt4-x11 embeds webkit, so most of these issues
are likely applicable to this package.  Since there are so many
problems, I have not had time to check whether the vulnerable code is
present or has an impact. Please check this.  Note that situations like
this could be handled much easier if qt4-x11 and webkit were to share a
common library: http://bugs.debian.org/479851.

CVE-2006-2783[0]:
| Mozilla Firefox and Thunderbird before 1.5.0.4 strip the Unicode
| Byte-order-Mark (BOM) from a UTF-8 page before the page is passed to
| the parser, which allows remote attackers to conduct cross-site
| scripting (XSS) attacks via a BOM sequence in the middle of a
| dangerous tag such as SCRIPT.

CVE-2008-0298[1]:
| KHTML WebKit as used in Apple Safari 2.x allows remote attackers to
| cause a denial of service (browser crash) via a crafted web page,
| possibly involving a STYLE attribute of a DIV element.

CVE-2008-1588[2]:
| Safari on Apple iPhone before 2.0 and iPod touch before 2.0 allows
| remote attackers to spoof the address bar via Unicode ideographic
| spaces in the URL.

CVE-2008-2307[3]:
| Unspecified vulnerability in WebKit in Apple Safari before 3.1.2, as
| distributed in Mac OS X before 10.5.4, and standalone for Windows and
| Mac OS X 10.4, allows remote attackers to cause a denial of service
| (application crash) or execute arbitrary code via vectors involving
| JavaScript arrays that trigger memory corruption.

CVE-2008-2320[4]:
| Stack-based buffer overflow in CarbonCore in Apple Mac OS X 10.4.11
| and 10.5.4, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch
| 1.1 through 2.2.1 allows context-dependent attackers to execute
| arbitrary code or cause a denial of service (application crash) via a
| long filename to the file management API.

CVE-2008-3632[5]:
| Use-after-free vulnerability in WebKit in Apple iPod touch 1.1 through
| 2.0.2, and iPhone 1.0 through 2.0.2, allows remote attackers to
| execute arbitrary code or cause a denial of service (application
| crash) via a web page with crafted Cascading Style Sheets (CSS) import
| statements.

CVE-2008-4231[6]:
| Safari in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch
| 1.1 through 2.1 does not properly handle HTML TABLE elements, which
| allows remote attackers to execute arbitrary code or cause a denial of
| service (memory corruption and application crash) via a crafted HTML
| document.

CVE-2008-4724[7]:
| Multiple cross-site scripting (XSS) vulnerabilities in Google Chrome
| 0.2.149.30 allow remote attackers to inject arbitrary web script or
| HTML via an ftp:// URL for an HTML document within a (1) JPG, (2) PDF,
| or (3) TXT file.  NOTE: the provenance of this information is unknown;
| the details are obtained solely from third party information.

CVE-2009-1681[8]:
| WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and
| iPhone OS for iPod touch 1.1 through 2.2.1 does not prevent web sites
| from loading third-party content into a subframe, which allows remote
| attackers to bypass the Same Origin Policy and conduct "clickjacking"
| attacks via a crafted HTML document.

CVE-2009-1684[9]:
| Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari
| before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch
| 1.1 through 2.2.1 allows remote attackers to inject arbitrary web
| script or HTML via an event handler that triggers script execution in
| the context of the next loaded document.

CVE-2009-1685[10]:
| Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari
| before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch
| 1.1 through 2.2.1 allows remote attackers to inject arbitrary web
| script or HTML by overwriting the document.implementation property of
| (1) an embedded document or (2) a parent document.

CVE-2009-1686[11]:
| WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and
| iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle
| constant (aka const) declarations in a type-conversion operation
| during JavaScript exception handling, which allows remote attackers to
| execute arbitrary code or cause a denial of service (memory corruption
| and application crash) via a crafted HTML document.

CVE-2009-1688[12]:
| Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari
| before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch
| 1.1 through 2.2.1 allows remote attackers to inject arbitrary web
| script or HTML via vectors related to determining a security context
| through an approach that is not the "HTML 5 standard method."

CVE-2009-1689[13]:
| Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari
| before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch
| 1.1 through 2.2.1 allows remote attackers to inject arbitrary web

Bug#561765: kdelibs: many webkit vulnerabilities

2009-12-19 Thread Michael Gilbert
Package: kdelibs
Version: 4:3.5.10.dfsg.1-2.1
Severity: serious
Tags: security

Hi,

The following CVE (Common Vulnerabilities & Exposures) ids were
published for webkit.  webkit was forked from khtml, so these
issues very like apply to this package as well.  Since there are so
many problems, I have not had time to check whether the vulnerable code
is present or has an impact. Please check this and keep either myself
or the security team informed of the affected/not-affected issues.
Thank you very much for looking into this.

CVE-2006-2783[0]:
| Mozilla Firefox and Thunderbird before 1.5.0.4 strip the Unicode
| Byte-order-Mark (BOM) from a UTF-8 page before the page is passed to
| the parser, which allows remote attackers to conduct cross-site
| scripting (XSS) attacks via a BOM sequence in the middle of a
| dangerous tag such as SCRIPT.

CVE-2008-0298[1]:
| KHTML WebKit as used in Apple Safari 2.x allows remote attackers to
| cause a denial of service (browser crash) via a crafted web page,
| possibly involving a STYLE attribute of a DIV element.

CVE-2008-1588[2]:
| Safari on Apple iPhone before 2.0 and iPod touch before 2.0 allows
| remote attackers to spoof the address bar via Unicode ideographic
| spaces in the URL.

CVE-2008-2307[3]:
| Unspecified vulnerability in WebKit in Apple Safari before 3.1.2, as
| distributed in Mac OS X before 10.5.4, and standalone for Windows and
| Mac OS X 10.4, allows remote attackers to cause a denial of service
| (application crash) or execute arbitrary code via vectors involving
| JavaScript arrays that trigger memory corruption.

CVE-2008-2320[4]:
| Stack-based buffer overflow in CarbonCore in Apple Mac OS X 10.4.11
| and 10.5.4, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch
| 1.1 through 2.2.1 allows context-dependent attackers to execute
| arbitrary code or cause a denial of service (application crash) via a
| long filename to the file management API.

CVE-2008-3632[5]:
| Use-after-free vulnerability in WebKit in Apple iPod touch 1.1 through
| 2.0.2, and iPhone 1.0 through 2.0.2, allows remote attackers to
| execute arbitrary code or cause a denial of service (application
| crash) via a web page with crafted Cascading Style Sheets (CSS) import
| statements.

CVE-2008-4231[6]:
| Safari in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch
| 1.1 through 2.1 does not properly handle HTML TABLE elements, which
| allows remote attackers to execute arbitrary code or cause a denial of
| service (memory corruption and application crash) via a crafted HTML
| document.

CVE-2008-4724[7]:
| Multiple cross-site scripting (XSS) vulnerabilities in Google Chrome
| 0.2.149.30 allow remote attackers to inject arbitrary web script or
| HTML via an ftp:// URL for an HTML document within a (1) JPG, (2) PDF,
| or (3) TXT file.  NOTE: the provenance of this information is unknown;
| the details are obtained solely from third party information.

CVE-2009-0945[8]:
| Array index error in the insertItemBefore method in WebKit, as used in
| Apple Safari before 3.2.3 and 4 Public Beta, iPhone OS 1.0 through
| 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Google Chrome
| Stable before 1.0.154.65, and possibly other products allows remote
| attackers to execute arbitrary code via a document with a SVGPathList
| data structure containing a negative index in the (1)
| SVGTransformList, (2) SVGStringList, (3) SVGNumberList, (4)
| SVGPathSegList, (5) SVGPointList, or (6) SVGLengthList SVGList object,
| which triggers memory corruption.

CVE-2009-1681[9]:
| WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and
| iPhone OS for iPod touch 1.1 through 2.2.1 does not prevent web sites
| from loading third-party content into a subframe, which allows remote
| attackers to bypass the Same Origin Policy and conduct "clickjacking"
| attacks via a crafted HTML document.

CVE-2009-1684[10]:
| Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari
| before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch
| 1.1 through 2.2.1 allows remote attackers to inject arbitrary web
| script or HTML via an event handler that triggers script execution in
| the context of the next loaded document.

CVE-2009-1685[11]:
| Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari
| before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch
| 1.1 through 2.2.1 allows remote attackers to inject arbitrary web
| script or HTML by overwriting the document.implementation property of
| (1) an embedded document or (2) a parent document.

CVE-2009-1686[12]:
| WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and
| iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle
| constant (aka const) declarations in a type-conversion operation
| during JavaScript exception handling, which allows remote attackers to
| execute arbitrary code or cause a denial of service (memory corruption
| and application crash) via a crafted HTML docum

Bug#561762: kde4libs: many webkit vulnerabilities

2009-12-19 Thread Michael Gilbert
Package: kde4libs
Version: 4:4.3.4-1
Severity: serious
Tags: security

Hi,

The following CVE (Common Vulnerabilities & Exposures) ids were
published for webkit.  webkit was forked from khtml, so these
issues very like apply to this package as well.  Since there are so
many problems, I have not had time to check whether the vulnerable code
is present or has an impact. Please check this and keep either myself
or the security team informed of the affected/not-affected issues.
Thank you very much for looking into this.

CVE-2006-2783[0]:
| Mozilla Firefox and Thunderbird before 1.5.0.4 strip the Unicode
| Byte-order-Mark (BOM) from a UTF-8 page before the page is passed to
| the parser, which allows remote attackers to conduct cross-site
| scripting (XSS) attacks via a BOM sequence in the middle of a
| dangerous tag such as SCRIPT.

CVE-2008-0298[1]:
| KHTML WebKit as used in Apple Safari 2.x allows remote attackers to
| cause a denial of service (browser crash) via a crafted web page,
| possibly involving a STYLE attribute of a DIV element.

CVE-2008-1588[2]:
| Safari on Apple iPhone before 2.0 and iPod touch before 2.0 allows
| remote attackers to spoof the address bar via Unicode ideographic
| spaces in the URL.

CVE-2008-2307[3]:
| Unspecified vulnerability in WebKit in Apple Safari before 3.1.2, as
| distributed in Mac OS X before 10.5.4, and standalone for Windows and
| Mac OS X 10.4, allows remote attackers to cause a denial of service
| (application crash) or execute arbitrary code via vectors involving
| JavaScript arrays that trigger memory corruption.

CVE-2008-2320[4]:
| Stack-based buffer overflow in CarbonCore in Apple Mac OS X 10.4.11
| and 10.5.4, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch
| 1.1 through 2.2.1 allows context-dependent attackers to execute
| arbitrary code or cause a denial of service (application crash) via a
| long filename to the file management API.

CVE-2008-3632[5]:
| Use-after-free vulnerability in WebKit in Apple iPod touch 1.1 through
| 2.0.2, and iPhone 1.0 through 2.0.2, allows remote attackers to
| execute arbitrary code or cause a denial of service (application
| crash) via a web page with crafted Cascading Style Sheets (CSS) import
| statements.

CVE-2008-4231[6]:
| Safari in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch
| 1.1 through 2.1 does not properly handle HTML TABLE elements, which
| allows remote attackers to execute arbitrary code or cause a denial of
| service (memory corruption and application crash) via a crafted HTML
| document.

CVE-2008-4724[7]:
| Multiple cross-site scripting (XSS) vulnerabilities in Google Chrome
| 0.2.149.30 allow remote attackers to inject arbitrary web script or
| HTML via an ftp:// URL for an HTML document within a (1) JPG, (2) PDF,
| or (3) TXT file.  NOTE: the provenance of this information is unknown;
| the details are obtained solely from third party information.

CVE-2009-1681[8]:
| WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and
| iPhone OS for iPod touch 1.1 through 2.2.1 does not prevent web sites
| from loading third-party content into a subframe, which allows remote
| attackers to bypass the Same Origin Policy and conduct "clickjacking"
| attacks via a crafted HTML document.

CVE-2009-1684[9]:
| Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari
| before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch
| 1.1 through 2.2.1 allows remote attackers to inject arbitrary web
| script or HTML via an event handler that triggers script execution in
| the context of the next loaded document.

CVE-2009-1685[10]:
| Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari
| before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch
| 1.1 through 2.2.1 allows remote attackers to inject arbitrary web
| script or HTML by overwriting the document.implementation property of
| (1) an embedded document or (2) a parent document.

CVE-2009-1686[11]:
| WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and
| iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle
| constant (aka const) declarations in a type-conversion operation
| during JavaScript exception handling, which allows remote attackers to
| execute arbitrary code or cause a denial of service (memory corruption
| and application crash) via a crafted HTML document.

CVE-2009-1688[12]:
| Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari
| before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch
| 1.1 through 2.2.1 allows remote attackers to inject arbitrary web
| script or HTML via vectors related to determining a security context
| through an approach that is not the "HTML 5 standard method."

CVE-2009-1689[13]:
| Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari
| before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch
| 1.1 through 2.2.1 allows remote attackers to inject arbitrary web
| script 

Bug#561762: many webkit vulnerabilities

2010-08-07 Thread Michael Gilbert
severity 561762 important
thanks

even though kde4libs really needs to be checked against these webkit
issues, it isn't a reason to hold up the release.

mike



-- 
To UNSUBSCRIBE, email to debian-qt-kde-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org
Archive: 
http://lists.debian.org/20100807212746.c37af5f7.michael.s.gilb...@gmail.com



Bug#597469: qt4-x11: ftbfs buildd ran out of disk space

2010-09-19 Thread Michael Gilbert
package: qt4-x11
version: 4:4.6.3-2
severity: grave

https://buildd.debian.org/fetch.cgi?&pkg=qt4-x11&ver=4:4.6.3-2&arch=s390&stamp=1283800739&file=log



-- 
To UNSUBSCRIBE, email to debian-qt-kde-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org
Archive: 
http://lists.debian.org/20100919201626.b6e8f95f.michael.s.gilb...@gmail.com



Bug#597469: closed by Ana Guerrero (Re: Bug#597469: qt4-x11: ftbfs buildd ran out of disk space)

2010-09-20 Thread Michael Gilbert
> Thanks for caring about Qt4. Sadly, buildds running out of space is
> something that happens often and filing bugs about this issue is not
> useful given there is nothing that can be done from the maintainers.

this build failure is holding up migration of a security fix to
testing.  the maintainers can/should request a rebuild on the build
daemon.

mike



-- 
To UNSUBSCRIBE, email to debian-qt-kde-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org
Archive: 
http://lists.debian.org/20100920115044.7c08adc6.michael.s.gilb...@gmail.com