Bug#303927: gzip TOCTOU file-permissions vulnerability

2005-04-13 Thread Theodor Milkov
Joey Hess wrote: Martin Pitt wrote: Maybe I understood you wrong, could you please give a small test case which describes the vulnerability exactly? I'm a wimp, so I will use gdb instead of writing some real exploit to win the race. It is quite easy to win the race when the file that's being deco

Bug#304582: mozilla-firefox: Sometimes all Google links point to the same page

2005-04-13 Thread Stian Haklev
Package: mozilla-firefox Version: 1.0.2-3 Severity: normal Sometimes when using Firefox to search for pages on Google, clicking on all the different hits (links to found pages) will take me to the same page (generally a page I've already opened in a new tab). Hoovering over a page title, the statu

Bug#304434: Does this also deal with the "old" crash?

2005-04-13 Thread Kaare Hviid
On Wed, 2005-04-13 at 15:36 -0700, Corey Hickey wrote: > Helge Kreutzmann wrote: > > Hello, > > as you might have noticed, a very similar bug was opened 6 years ago > > (bug number one order of magnitude lower than current). Unfortunately > > I don't have access to an testing/unstable alpha right n

Bug#304559: postfix: upgrade doesn't work cleanly

2005-04-13 Thread Romain Francoise
Adrian Bunk <[EMAIL PROTECTED]> writes: > postalias: warning: inet_protocols: IPv6 support is disabled: Address > family not supported by protocol > postalias: warning: inet_protocols: configuring for IPv4 support only Your kernel doesn't have support for IPv6. You need to add inet_protocols

Bug#294404: The commited fix is WRONG

2005-04-13 Thread Michael Tokarev
The last mdadm change -- 1.9.0-2.1 -- did NOT fix the bug, but made the situation worse. rcS.d/S04mdadm-raid is now the FIRST thing the system is doing when booting. At that stage, /proc is not mounted (it is mounted later), and in mdadm-raid bootscript, there's the following code: if [ "x

Bug#304579: gpgme[-dev]

2005-04-13 Thread Werner Koch
On Thu, 14 Apr 2005 07:53:37 +0200, folkert said: > The gpgme in the Debian distribution is very much behind. The current > version of gpgme is 1.0.2. Quiet a bit has changed since the Debian- 0.3 is the old API used by some old software (e.g. sylpheed). You should use the libgpgme11 package whi

Bug#242407: [Pkg-shadow-devel] Bug#242407: vipw race condition

2005-04-13 Thread Christian Perrier
tags 242407 fixed-upstream retitle 242407 [POST-SARGE] [ALEXANDER] vipw race condition thanks > I think the fix is trivial, the patch against your CVS > version is attached (I have already compiled/checked > it on my system). If I didn't miss something obvious, > evrything is fine with the propose

Bug#163635: [Pkg-shadow-devel] Bug#163635: Advice about this bug report

2005-04-13 Thread Christian Perrier
> Fix me if I'm wrong. > Correct solution will be remove CLOSE_SESSION conditions and use this code > uncondionaly if shadow was configured with PAM enabled (?) Hmm, well, I'm not sure anyone suggested such a drastic change. This could be likely to inadvertently change some behaviour here or ther

Bug#208514: [Pkg-shadow-devel] Bug#208514: add-shell should not depend on passwd : what's *really* intended here?

2005-04-13 Thread Christian Perrier
tags 208514 - wontfix tags 208514 confirmed retitle 208514 [DEBIAN DECISION] add-shell should not depend on passwd thanks > The reason shells need to depend on passwd is because if you > install shells without passwd being on the system, and then install > the passwd package, those shells will not

Bug#265565: [Pkg-shadow-devel] Bug#271565: passwd: /usr/sbin/remove-shell.sh fails when shell is not in /etc/shells

2005-04-13 Thread Christian Perrier
retitle 271565 [POST-SARGE] remove-shell fails when /etc/shells is missing, empty or is to be emptied thanks Well, [POST-SARGE] is more and more a way to mark bugs as "OK, we've dealt with that thing" as we obviously will deal with everything post sarge, but well, it is a convenient way for me to

Bug#304447: [Pkg-shadow-devel] Bug#304447: passwd: Minor manpage fixes

2005-04-13 Thread Christian Perrier
Quoting Simon Brandmair ([EMAIL PROTECTED]): > Package: passwd > Version: 1:4.0.3-31sarge1 > Severity: minor > Tags: patch > > Some minor fixes for the english manpage... As Tomasz has commited the fixes in his CVS, I will now add a 314 patch in Alioth CVS.as soon as I get net access again an

Bug#304579: gpgme[-dev]

2005-04-13 Thread folkert
Package: gpgme Version: 0.3.16-2 The gpgme in the Debian distribution is very much behind. The current version of gpgme is 1.0.2. Quiet a bit has changed since the Debian- version. Folkert van Heusden Auto te koop, zie: http://www.vanheusden.com/daihatsu.php Op zoek naar een IT of Finance baan?

Bug#297824: Confirm: #297824: btcompletedir manpage dangling symlink

2005-04-13 Thread A Costa
Package: bittorrent Version: 3.4.2-3 Followup-For: Bug #297824 I get the same error: /etc/cron.daily/man-db: mandb: warning: /usr/share/man/man1/btcompletedirgui.1.gz is a dangling symlink What it links to: % ls -l /usr/share/man/man1/btcompletedirgui.1.gz lrwxrwxrwx 1 root root 39 M

Bug#304578: update-mime ignores mailcap.order

2005-04-13 Thread Drew Parsons
Package: mime-support Version: 3.31-1 Severity: normal In /etc/mailcap, gpdf is ahead of xpdf, making gpdf the default for pdf documents. I prefer to use xpdf, so I follow the instructions in /etc/mailcap.order by adding the line xpdf:application/pdf in it, and then running /usr/sbin/update-mim

Bug#302714: mdadm fails to start a degraded raid6 array

2005-04-13 Thread Matthias Urlichs
Hi, Michael Tokarev: > > $ mdadm -A /dev/md7 /dev/hd[bceij]1 > > This worked. > > Matthias, please provide your /etc/mdadm/mdadm.conf > entries for the array in question (/dev/md7). From > the description of your problem it seems it is due > to incorrect content of the array entry in there -- >

Bug#304143: Bug#304217: pdl: 'whatis PDL::Reduce' garbage: "a *(C`reduce*(C' function for PDL"

2005-04-13 Thread A. Costa
On Wed, 13 Apr 2005 15:33:20 +0200 Rafael Laboissiere <[EMAIL PROTECTED]> wrote: > ...We should > consider the NAME section of a manpage as a kind of machine-readable > description. For instance, it would make no sense to have markups like > bold and italics in it. > > However, *(C` and *(C' rep

Bug#304570: ITP: codeblocks -- Code::Blocks is a free C/C++ IDE built

2005-04-13 Thread Michael Koch
On Thu, Apr 14, 2005 at 12:12:02AM -0400, Francois-Denis Gonthier wrote: > Package: wnpp > Severity: wishlist > Owner: "Francois-Denis Gonthier" <[EMAIL PROTECTED]> > > > * Package name: codeblocks > Version : x.y.z No version? > Upstream Author : Name <[EMAIL PROTECTED]> No up

Bug#304577: Allow tabs in kuake

2005-04-13 Thread Jeff Bonham
Package: kuake Version: 0.3-2 Severity: wishlist Wishlist: to have tabs in kuake, like in konsole. I use kuake for virtually all my terminal needs now, but occasionally I find that I have to open up a konsole anyway because the shell in kuake is busy. Tabs would solve this. -- System Informatio

Bug#304568: kernel-package: does not build kernel_headers

2005-04-13 Thread Ingo Saitz
tags 304568 +patch thanks Aargh, make is stupid. /usr/share/kernel-package contains an amount of whitespace at the end of the line which should be removed. After that it works correctly again. Patch attached. Ingo -- $ sh -c 'kill -ALRM $$' Der Wecker klingelt $ sh -c "kill -ALRM $$" remo

Bug#303930: xprint postscript crashes

2005-04-13 Thread Drew Parsons
On Thu, 2005-04-14 at 00:07 -0400, Ivan Nestlerode wrote: > > > > My suspicion is that there is a font problem (font file not found). > > > I had gsfonts on hold for a very long time (over a year), and I'm not > > > sure if > > > that is involved. > > > > > > > Sounds plausible. > > It looks ve

Bug#304575: epiphany-browser: download notification area icon does not have right-click menu

2005-04-13 Thread Matt Kraai
Package: epiphany-browser Version: 1.4.8-2 Severity: minor According to the Using the Status Notification Area of the GNOME HIG 2.0: Right-click or Shift-F10 should present a menu for the icon containing at least the icon's default action. Epiphany's notification area icon does nothing when it

Bug#304574: blam: notification area icon opens window after single click

2005-04-13 Thread Matt Kraai
Package: blam Version: 1.6.1-1 Severity: minor According to the Using the Status Notification Area section of the GNOME HIG 2.0: Double-click or Space key should perform the icon's default action. Normally this should open a window with relevant data ... Blam's notification area icon opens the

Bug#304576: pciutils: lspci -mn shows the wrong identifier for subvendor

2005-04-13 Thread Benjamin Rodgers
Package: pciutils Version: 1:2.1.11-15 Severity: normal The subvendor ID provided by "lspci -mn" is erroneous. Apparently lspci is duplicating the device ID instead of printing the subvendor ID. Example follows: __ BEGIN EXAMPLE __ > lspci -mn 00:00.0 0600 10de 01e0 c1 00 01e0 80ac [...] 02:0

Bug#302714: mdadm fails to start a degraded raid6 array

2005-04-13 Thread Michael Tokarev
Matthias Urlichs wrote: > I have a 7-disk raid6 array. Two of the disks have shut down due to a > flaky power supply. I rebooted the system. The degraded RAID didn't come > up. > > $ mdadm -A /dev/md7 /dev/hd[bceijkl]1 > mdadm: failed to add /dev/hdk1 to /dev/md7: Invalid argument > mdadm: failed t

Bug#304573: racoon-tool: useless sequence of operations on 'start'

2005-04-13 Thread Andrew Suffield
Package: racoon Severity: important Version: 1:0.5-5 'racoon start' starts racoon before it generates the racoon config file. That's pretty useless. It will only ever work by coincidence. -- .''`. ** Debian GNU/Linux ** | Andrew Suffield : :' : http://www.debian.org/ | `. `'

Bug#304572: debconf.py:runFrontEnd() bug in execv of frontend

2005-04-13 Thread Bob Tanner
Package: debconf Version: 1.4.48 Severity: important /usr/lib/python2.3/site-packages/debconf.py def runFrontEnd(): if not os.environ.has_key('DEBIAN_HAS_FRONTEND'): os.environ['PERL_DL_NONLAZY']='1' os.execv(_frontEndProgram, [_frontEndProgram, sys.executable]+sys.argv) If

Bug#303341: cannot reproduce

2005-04-13 Thread Gustavo Noronha Silva
Hello, I'm not able to reproduce this bug... could be caused by an earlier version of GTK+ than I have installed, maybe... would you mind trying to upgrade your system and trying to reproduce this again? We will go for a backtrace if you can... Thanks! -- [EMAIL PROTECTED]: Gustavo Noronha

Bug#304571: certtool: DN input braindamage

2005-04-13 Thread Andrew Suffield
Package: gnutls-bin Tags: patch The DN input mechanism used by certtool when creating certificates is braindamaged. Instead of asking for a fully-formed DN, it asks for a handful of attributes, and enforces a particlar order on them. This is useless when you wanted a certificate that has a given a

Bug#304570: ITP: codeblocks -- Code::Blocks is a free C/C++ IDE built

2005-04-13 Thread Francois-Denis Gonthier
Package: wnpp Severity: wishlist Owner: "Francois-Denis Gonthier" <[EMAIL PROTECTED]> * Package name: codeblocks Version : x.y.z Upstream Author : Name <[EMAIL PROTECTED]> * URL : http://www.example.org/ * License : (GPL, LGPL, BSD, MIT/X, etc.) Description

Bug#304502: unified way to get changes file name

2005-04-13 Thread Julian Gilbey
On Thu, Apr 14, 2005 at 12:25:40AM +0200, martin f krafft wrote: > also sprach Julian Gilbey <[EMAIL PROTECTED]> [2005.04.13.2332 +0200]: > > Nice idea. Couple of fixes needed, but it's basically OK. > > You want me to take care of those? > > Note that the first is already fixed in a second mess

Bug#304437: evolution: hang on startup after upgrade

2005-04-13 Thread Takuo KITAME
severity 304437 important tag 304437 unreproducible stop 2005-04-12 (火) の 23:14 -0600 に dann frazier さんは書きました: > Package: evolution > Version: 2.2.1.1-1 > Severity: grave > Justification: renders package unusable > > After upgradin

Bug#304190: Print crashes evolution

2005-04-13 Thread Takuo KITAME
could you please try again with 2.2.2-1? -- Takuo KITAME -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Bug#290242: (no subject)

2005-04-13 Thread Justin Pryzby
Cloned bug #300889 on elinks is now fixed by using the wget code. -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Bug#301165: forwarded this bug upstream

2005-04-13 Thread sean finney
forwarded 301165 http://bugs.cacti.net/view.php?id=437 thanks when snmpv3 is reimplemented, i'll be notified by upstream and will close this bug. sean -- signature.asc Description: Digital signature

Bug#304346: evolution: After upgrade from 2.0.4 to 2.2.1.1 authentication against groupwise server fails

2005-04-13 Thread Takuo KITAME
2005-04-12 (火) の 16:48 +0200 に Frode Jemtland さんは書きました: > Package: evolution > Version: 2.2.1.1-1 > Severity: normal > > Did run a apt-get install evolution this morning. I had evolution 2.0.4 > installed, and it worked. Have recived mail today

Bug#304569: kernel-package: does not build kernel_headers

2005-04-13 Thread Ingo Saitz
Package: kernel-package Version: 8.131 Severity: normal -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Trying to build linux 2.6.11-ac7 using make-kpkg --rootcmd fakeroot kernel_headers does not work on my system (see attached log output). I also do not have any kernel-patches installed. However

Bug#304324: EPlugins not being packaged

2005-04-13 Thread Takuo KITAME
2005-04-13 (水) の 18:25 -0400 に Adam D. Bradley さんは書きました: > The evolution package still needs to include the EPlugins themselves > (the /usr/lib/evolution/2.2/plugins tree), or they need to be packaged > separately and "recommended" by the evolution packa

Bug#304567: package does not include blenderplayer

2005-04-13 Thread Paul Sandulescu
Package: blender Version: 2.34-1 Severity: normal Tags: patch The Blender deb package does not include the blenderplayer executable, because the debian/rules file ommits it. blenderplayer enables the "File->Save Runtime" option (can also be used as a standalone console application). I'm including

Bug#304536: Package: installation-reports

2005-04-13 Thread Joey Hess
Bruno Friedmann wrote: > Initial boot worked:[O] > Configure network HW: [O] > Config network: [O] > Detect CD: [E] with the linux26 boot > Load installer modules: [O] > Detect hard drives: [O] > Partition hard drives: [O] > Create file systems:[O] > Mount part

Bug#304556: file permissions race in mkdir, mknod, mkfifo (CAN-2005-1039)

2005-04-13 Thread Joey Hess
Michael Stone wrote: > Generally it means that someone just learned something that people > already knew about. I've never heard of this class of vulnerabilities, but I perhaps that just makes me a clueless security noob. Anyway, it was pointed out in a reply to the gzip bug that this kind of hol

Bug#304566: phpmyadmin: [INTL:pt_BR] Please consider adding the attached debconf template translation

2005-04-13 Thread Rodrigo Tadeu Claro
Package: phpmyadmin Version: 3:2.6.2-rc1-1 Severity: wishlist Tags: patch l10n Please consider using the attached phpmyadmin Brazilian Portuguese (pt_BR) debconf template translation. It was properly checked against errors using the msgfmt utility from gettext package as can be see bellow : [EMA

Bug#304547: rpdump TOCTOU file-permissions vulnerability (CAN-2005-1066)

2005-04-13 Thread Joey Hess
Santiago Vila wrote: > Only two executables produced by the pine source package are actually > included in binary packages, namely /usr/bin/pine in package pine and > /usr/bin/pilot in package pilot. > > I do not consider my duty as pine maintainer to maintain dead code > (which is not shipped in

Bug#304462: Bug: merge --dry-run with wrong target

2005-04-13 Thread David Kimdon
> So the "fix" for this problem might simply be for the Debian package > to upgrade to Subversion 1.2.0 when available. That sounds like what we will do. I ran the script out on a pristine 1.1.4 build (no Debian patches) and the problem was present here. I also tried the 1.2.x branch off svn.co

Bug#304564: 855resolution: silently fails to do anything on some hardware

2005-04-13 Thread Aaron M. Ucko
Package: 855resolution Version: 0.3-4 Severity: wishlist I have an Intel 915G chipset, and wanted to see how 855resolution would deal with it. It has no trouble querying the card's mode database when run with -l (output included at the end of this report if you're curious), but attempts to adjust

Bug#304565: (no subject)

2005-04-13 Thread Daniel Nilsson
Package: installation-reports INSTALL REPORT Debian-installer-version: http://cdimage.debian.org/pub/cdimage-testing/sarge_d-i/alpha/rc3/sarge-alpha-businesscard.iso uname -a: Linux alpha 2.4.27-2-generic #1 Sat Apr 9 19:43:25 UTC 2005 alpha GNU/Linux Date: Wed Apr 13 21:44:20 EDT 2005 Meth

Bug#199079: Bug still reproducible?

2005-04-13 Thread Ron Murray
Christian Perrier wrote: > tags 199079 unreproducible moreinfo > retitle 199079 [TO CLOSE] passwd: groupadd/groupdel abort on signal 13 > thanks > > Despite my efforts (including installation of nagios and mysql stuff > which I don't need), I haven't been able to reproduce this bug, which > is ver

Bug#292783: totem: Unfixed in 1.1.1?

2005-04-13 Thread Sam Morris
Package: totem Version: 0.100-5 Followup-For: Bug #292783 I get this bug with 1.1.1. Using the xine backend with ALSA. Sam -- System Information: Debian Release: 3.1 APT prefers testing APT policy: (700, 'testing'), (600, 'unstable') Architecture: i386 (i686) Kernel: Linux 2.6.8-2-k7 Locale:

Bug#70793: Bug #70793 - pvm breaks with fresh potato installs

2005-04-13 Thread browaeys . alban
This is a followup for: pvm breaks with fresh potato installs http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=70793 "127.0.0.1 pvmslave localhost" issue may be reassign and cloned to debian-installer and boot-floppies. The issue has already been talked about debian-installer: incorrect /etc/ho

Bug#304563: dillo: babbles heavily when started from command line

2005-04-13 Thread Nikolaus Schulz
Package: dillo Version: 0.8.3-1 Severity: normal Hi. See subject. "When a program has nothing surprising to say, it should say nothing." :-) I considered this being wishlist, but think it's a (annoying) bug. Regards, Nikolaus -- System Information: Debian Release: 3.1 APT prefers testing

Bug#303927: gzip TOCTOU file-permissions vulnerability

2005-04-13 Thread psz
Joey Hess <[EMAIL PROTECTED]> wrote: > I'm a wimp, so ... instead of writing some real exploit to win the race. What race? A simple perl -e 'while (1) { unlink("xyz") and link("/etc/passwd","xyz") and exit }' should work. Paul Szabo [EMAIL PROTECTED] http://www.maths.usyd.edu.au/u/psz/ S

Bug#304437: evolution: Upgrade worked for me

2005-04-13 Thread Douglas F. Calvert
Package: evolution Version: 2.2.2-1 Followup-For: Bug #304437 The evolution upgrade to 2.2.1 worked for me. Evolution started up without any problems. Evolution prints a lot of messages about charset converters but I do not remember if this was there before 2.2.1. The following lines are a samp

Bug#304559: postfix: upgrade doesn't work cleanly

2005-04-13 Thread Adrian Bunk
On Wed, Apr 13, 2005 at 06:24:35PM -0600, LaMont Jones wrote: > On Thu, Apr 14, 2005 at 01:58:32AM +0200, Adrian Bunk wrote: > > Installing new version of config file /etc/postfix/postfix-files ... > > postconf: error while loading shared libraries: libpostfix-global.so.1: > > cannot open shared o

Bug#304547: rpdump TOCTOU file-permissions vulnerability (CAN-2005-1066)

2005-04-13 Thread Santiago Vila
On Wed, 13 Apr 2005, Joey Hess wrote: > Package: pine > Severity: normal > Tags: security > > I've verified that the rpdump.c included in the pine source package is > vulnerable to the symlink attack described here: > http://msgs.securepoint.com/cgi-bin/get/bugtraq0504/126.html > > I don't see r

Bug#304510: ITP: ed2k-hash -- A command line tool for creating eDonkey2000 hash links.

2005-04-13 Thread Luke Reeves
I'm attempting to do that, but I'm not the owner of the original RFP... Luke Peter Samuelson wrote: > [Luke Reeves] > >>I have the initial attempt at a packge at >>http://www.neuro-tech.net/debian/. See also bug #259863, an RFP for >>this software. > > > You should have retitled that

Bug#304498: RPy doc package should be better usable (without having to run Makefile)

2005-04-13 Thread Dirk Eddelbuettel
Chris, Thanks for the bug report! On 13 April 2005 at 12:18, Christian Hudon wrote: | Package: python-rpy-doc | Version: 0.4.1-2 | | The way the python-rpy-doc package is done now, it's not much more | useful than the rpy source package. There's just the raw texinfo source | together with a M

Bug#299007: gzip TOCTOU file-permissions vulnerability

2005-04-13 Thread psz
Joey Hess <[EMAIL PROTECTED]> wrote: >> ... really dumb idea to have a group/world-writeable directory >> without the sticky bit. > > It may be really dumb, but it's pretty common practice too. ... > Just a few examples within the Debian project ... Kindly add the Debian example: [EMAIL PROTECT

Bug#304559: postfix: upgrade doesn't work cleanly

2005-04-13 Thread LaMont Jones
On Thu, Apr 14, 2005 at 01:58:32AM +0200, Adrian Bunk wrote: > Installing new version of config file /etc/postfix/postfix-files ... > postconf: error while loading shared libraries: libpostfix-global.so.1: > cannot open shared object file: No such file or directory Are there any diversions of pos

Bug#304562: "FATAL: Error inserting fuse"

2005-04-13 Thread Nick Willson
Package: fuse-source Version: 2.2.1-4 Severity: important I built the module using "m-a a-i fuse". The module does not install: blackbird:/usr/src/linux# modprobe fuse FATAL: Error inserting fuse (/lib/modules/2.6.11/kernel/fs/fuse/fuse.ko): Unknown symbol in module, or unknown parameter (see

Bug#304561: chkrootkit: false positive if mldonkey (mlnet) is running

2005-04-13 Thread Marc Lehmann
Package: chkrootkit Version: 0.44-2 Severity: normal When mlnet (the mldonkey server) is running, chkrootkit wrongly detects it: Checking `bindshell'... INFECTED (PORTS: 4000) (indeed mlnet is listening on port 4000 and stopping it gets rid of the spurious detetcion). -- System Information

Bug#303927: gzip TOCTOU file-permissions vulnerability

2005-04-13 Thread Joey Hess
Martin Pitt wrote: > Of course the file can be removed by other users after gunzip has > finished, but that is not a gzip bug, but the result of the really > dumb idea to have a group/world-writeable directory without the sticky > bit. It may be really dumb, but it's pretty common practice too. Gr

Bug#303551: inkscape: Segfaults on startup (PowerPC)

2005-04-13 Thread Lee Braiden
On Wednesday 13 April 2005 23:22, Wolfram Quester wrote: > On Wed, Apr 13, 2005 at 08:08:53PM +0200, Guido Guenther wrote: > > Hi Lee, > > Could any of inkscape's extensions be buggy? Do you guys both have _all_ > > the extensions installed? Could you attach > > .inkscape/extension-errors.log? Hmm

Bug#303927: gzip TOCTOU file-permissions vulnerability

2005-04-13 Thread Joey Hess
Martin Pitt wrote: > Of course the file can be removed by other users after gunzip has > finished, but that is not a gzip bug, but the result of the really > dumb idea to have a group/world-writeable directory without the sticky > bit. It may be really dumb, but it's pretty common practice too. Gr

Bug#304556: file permissions race in mkdir, mknod, mkfifo (CAN-2005-1039)

2005-04-13 Thread Michael Stone
On Wed, Apr 13, 2005 at 07:52:34PM -0400, Joey Hess wrote: It's not really clear to me either why people consider this a security hole now after not worrying about this class of problems for years. Generally it means that someone just learned something that people already knew about. reason for it

Bug#304556: file permissions race in mkdir, mknod, mkfifo (CAN-2005-1039)

2005-04-13 Thread Joey Hess
Michael Stone wrote: > severity 304556 normal > thanks > > At most this is normal, probably minor. The -m flag is basically > replacing a call to chmod, which has exactly the same problem. Any time > you fiddle with permissions or ownership in the filesystem you're > opening yourself up to this ex

Bug#304559: postfix: upgrade doesn't work cleanly

2005-04-13 Thread Adrian Bunk
Package: postfix Version: 2.2.2-1 Severity: grave The severity is based on the fact that although postfix seems to work, it should be investigated if these issues could cause any harm. <-- snip --> # apt-get --purge install postfix Reading Package Lists... Done Building Dependency Tree... Do

Bug#304558: famd 100% cpu usage

2005-04-13 Thread spiorf
Package: fam Version: 2.7.0-6 With default config after a random time (but only if i'm using the pc) cpu usage of famd raise to 100%. -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Bug#301684: [debiandoc-sgml-pkgs] Bug#301684: userv: FTBFS: debiandoc2ps: unknown option `1'

2005-04-13 Thread Frank Lichtenheld
On Thu, Apr 14, 2005 at 01:03:16AM +0200, Osamu Aoki wrote: > On Wed, Apr 13, 2005 at 05:18:20PM +0200, Frank Lichtenheld wrote: > > tags 301684 patch > > thanks > > This patch looks generally OK to fix problem but I am not sure about > one thing. > > > Proposed patch for this: > ... > > +@@@sta

Bug#303927: gzip TOCTOU file-permissions vulnerability

2005-04-13 Thread Joey Hess
Martin Pitt wrote: > Of course the file can be removed by other users after gunzip has > finished, but that is not a gzip bug, but the result of the really > dumb idea to have a group/world-writeable directory without the sticky > bit. It may be really dumb, but it's pretty common practice too. Gr

Bug#301684: [debiandoc-sgml-pkgs] Bug#301684: userv: FTBFS: debiandoc2ps: unknown option `1'

2005-04-13 Thread Osamu Aoki
On Wed, Apr 13, 2005 at 05:18:20PM +0200, Frank Lichtenheld wrote: > tags 301684 patch > thanks This patch looks generally OK to fix problem but I am not sure about one thing. > Proposed patch for this: ... > +@@@start-info-docbookxml-latexps-active@@@ > + -1 1 page per pag

Bug#292473: [Pkg-nagios-devel] Bug#292473: acknowledged by developer (Bug#292473: fixed in nagios 2:1.3-cvs.20050402-1)

2005-04-13 Thread sean finney
On Wed, Apr 13, 2005 at 05:58:48PM +0300, Cyril Bouthors wrote: > I've reopened that bug because I'm still facing the exact same issue > with 1.3-cvs.20050402-1, I don't think it has something to do with the > load because it's still continues to do the same for hours and days if > the load goes ba

Bug#304461: rootstrap: hangs at network module if invoked without root privileges

2005-04-13 Thread Matt Zimmerman
On Thu, Apr 14, 2005 at 01:06:29AM +0200, Marc Haber wrote: > On Wed, Apr 13, 2005 at 12:58:53PM -0700, Matt Zimmerman wrote: > > The currently packaged version of UML (on which rootstrap relies) is > > unreliable in various ways, especially under 2.6 host kernels. > > Which way do you recommend

Bug#304556: file permissions race in mkdir, mknod, mkfifo (CAN-2005-1039)

2005-04-13 Thread Michael Stone
severity 304556 normal thanks At most this is normal, probably minor. The -m flag is basically replacing a call to chmod, which has exactly the same problem. Any time you fiddle with permissions or ownership in the filesystem you're opening yourself up to this exact problem--and there's essentially

Bug#271565: passwd: /usr/sbin/remove-shell.sh fails when shell is not in /etc/shells

2005-04-13 Thread Alexander Gattin
tags 271565 confirmed pending retitle 271565 remove-shell fails when /etc/shells is missing, empty or is to be emptied thanks Hi! First of all, remove-shell fails in other conditions than stated in original report. Nevertheless, the patch fixes the problem. The bug results in inability to delet

Bug#304510: ITP: ed2k-hash -- A command line tool for creating eDonkey2000 hash links.

2005-04-13 Thread Peter Samuelson
[Luke Reeves] > I have the initial attempt at a packge at > http://www.neuro-tech.net/debian/. See also bug #259863, an RFP for > this software. You should have retitled that bug, then, instead of opening this one. Please retitle / merge appropriately. signature.asc Description: Digital signat

Bug#304461: rootstrap: hangs at network module if invoked without root privileges

2005-04-13 Thread Marc Haber
On Wed, Apr 13, 2005 at 12:58:53PM -0700, Matt Zimmerman wrote: > The currently packaged version of UML (on which rootstrap relies) is > unreliable in various ways, especially under 2.6 host kernels. Which way do you recommend for having UML on Debian host systems? > It's also possible that it wa

Bug#304557: gen_mounts still does not recognize some local filesystems

2005-04-13 Thread Elmar Hoffmann
Package: tiger Version: 1:3.2.1-22 Severity: normal This basically is 302646, just with different filesystem types like fat, vfat, ntfs, hfs, hfsplus and ufs. mount(8), fstab(5) and Documentation/filesystems in the kernel source provide some more complete lists. elmar -- System Information: Deb

Bug#304543: SableVM

2005-04-13 Thread Barry Hawkins
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 [EMAIL PROTECTED] wrote: [...] > Well, I browsed around http://localhost:8180/index.jsp & ran some of the > demo sevlets & JSPs - so far so good. > > I'm setting up libapache-mod-jk2 as I speak... > > It's a stock installation of - > sablevm & ji

Bug#304554: ITP: weathermap4rdd -- script that generates picture network links utilization

2005-04-13 Thread Julien Danjou
Package: wnpp Severity: wishlist Owner: Julien Danjou <[EMAIL PROTECTED]> * Package name: weathermap4rdd Version : 1.1.1g Upstream Author : Alexandre Fontelle <[EMAIL PROTECTED]> * URL : http://weathermap4rrd.tropicalex.net/ * License : GPL Description :

Bug#304438: fails on all architectures

2005-04-13 Thread Blars Blarson
severity 304438 serious thanks The build fails on all buildds, duplicated on sparc pbuilder. -- Blars Blarson [EMAIL PROTECTED] http://www.blars.org/blars.html With Microsoft, failure is not an option. It is a standard feature. -- To UNSUBSC

Bug#304555: gen_mounts does not correctly parse multiple filesystem types

2005-04-13 Thread Elmar Hoffmann
Package: tiger Version: 1:3.2.1-22 Severity: normal gen_mounts does not correctly parse multiple filesystem types separated by comma in the mount output. For example using "ext3,ext2" as type for the root partition in /etc/fstab (to allow for fallback to ext2 when booting from a kernel without ex

Bug#304477: Attempt to use ENCODING when OUTPUT is scalar ref => die

2005-04-13 Thread Kenneth Pronovici
> > Package: libxml-writer-perl > > Version: 0.531-1 > > Severity: normal > > File: /usr/share/perl5/XML/Writer.pm > > > > -BEGIN PGP SIGNED MESSAGE- > > Hash: SHA1 > > > > $ perl -MXML::Writer -e 'new XML::Writer(OUTPUT => \$a, ENCODING => > > "utf-8");' > > Not a GLOB reference at /usr

Bug#304556: file permissions race in mkdir, mknod, mkfifo (CAN-2005-1039)

2005-04-13 Thread Joey Hess
Package: coreutils Version: 5.2.1-2 Severity: important Tags: security Our coreutils seems to be vulnerable to the problem described in CAN-2005-1039. http://www.securityfocus.com/archive/1/395489 A quick strace of "mkdir -m 400 foo" shows the problem: mkdir("foo", 0400) =

Bug#304134: setting generated in ~/.xsession.d/30im-scim has a wrong order

2005-04-13 Thread Osamu Aoki
On Mon, Apr 11, 2005 at 10:44:02AM +0800, Emfox Zhou wrote: > Package: m17n-env > Version: 0.0.3-5 > > I use m17n-env package the help setting SCIM imput method. > > After execute 'set-m17n-env' both under root and emfox, with all the items > selected, a file call '30im-scim' was generated in /h

Bug#292448: failure without tomcat4-webapps

2005-04-13 Thread Barry Hawkins
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 [EMAIL PROTECTED] wrote: [...] >> The Suggests for tomcat-webapps will most likely change to a Recommends, >> but there are admins who like to run fairly locked-down Tomcat installs >> without the admin and manager apps on them. The failures you have >

Bug#304552: buffer overflows (CAN-2005-1035)

2005-04-13 Thread Joey Hess
Package: pavuk Severity: serious Tags: security pavuk has some buffer overflows that are fixed in new upstream version 0.9.32. -- System Information: Debian Release: 3.1 APT prefers unstable APT policy: (500, 'unstable') Architecture: i386 (i686) Kernel: Linux 2.4.27 Locale: LANG=en_US.UTF-8,

Bug#304551: please allow options to reference environment variables

2005-04-13 Thread martin f krafft
Package: arch-buildpackage Version: 0.1-2 Severity: wishlist I am trying to get dpkg-buildpackage = pdebuild --buildresult .. --auto-debsign --debbuildopts -i"'\+\+(pristine-trees|saved|log).*|,,.*' $ENV{'DEBUILDOPTS'}" to work, which fails because of `use strict;`: Use of uninitialized

Bug#304553: evolution: ASMPT over SSL doesn't work after upgrade from 2.0.4 to 2.2.2 (see #304083)

2005-04-13 Thread Ferdinand O. Tempel
Package: evolution Version: 2.2.2-1 Severity: normal Just as described in #304083, it's impossible for me to send email using authenticated SMTP (plain authentication) over an SSL connection. Do note however that IMAPS works fine so SSL isn't broken. IMAPS also worked for me when I reported #304

Bug#242407: vipw race condition

2005-04-13 Thread Alexander Gattin
tags confirmed patch thanks Hi! Please, Tomasz, look into this bugreport: http://bugs.debian.org/242407 I checked it -- the race is really there. I think the fix is trivial, the patch against your CVS version is attached (I have already compiled/checked it on my system). If I didn't miss somet

Bug#32160: Does this also deal with the "old" crash?

2005-04-13 Thread Corey Hickey
Helge Kreutzmann wrote: > Hello, > as you might have noticed, a very similar bug was opened 6 years ago > (bug number one order of magnitude lower than current). Unfortunately > I don't have access to an testing/unstable alpha right now. > I was wondering if this might fix that, but I don't know

Bug#304540: python2.4-moinmoin: README.Debian is missing

2005-04-13 Thread Jonas Smedegaard
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 13-04-2005 23:40, Randy Gobbel wrote: > Package: python2.4-moinmoin > Version: 1.3.4-3 > Severity: important > > README.Debian is not there at all in /usr/share/doc/python2.4-moinmoin. I agree that should be fixed, but why do you consider it impor

Bug#304517: ITP: cacao -- Java virtual machine

2005-04-13 Thread Michael Koch
On Wed, Apr 13, 2005 at 06:08:24PM -0400, [EMAIL PROTECTED] wrote: > On Wed, Apr 13, 2005 at 08:35:19PM +0200, Michael Koch wrote: > > > Please make sure it uses the classpath packages in Debian and not again > > its own copy of classpath. > > I'll try. If you need help just mail me. I maintain

Bug#304502: unified way to get changes file name

2005-04-13 Thread martin f krafft
also sprach Julian Gilbey <[EMAIL PROTECTED]> [2005.04.13.2332 +0200]: > Nice idea. Couple of fixes needed, but it's basically OK. You want me to take care of those? Note that the first is already fixed in a second message to the BTS. -- .''`. martin f. krafft <[EMAIL PROTECTED]> : :' :

Bug#281618: tomcat4 & /usr/lib/fjsdk

2005-04-13 Thread ms419
I still experience this problem with - free-java-sdk 1.0-1 tomcat4 4.1.31-2 http://thread.gmane.org/gmane.linux.debian.devel.java/4329 I can run tomcat4 with JAVA_HOME=/usr/lib/sablevm, but not JAVA_HOME=/usr/lib/fjsdk & sablevm alternatives. Unfortunately, I can't say which symlink

Bug#304550: kmail: Signatures made by Apple Mail shown as bad when Mutt and Thunderbird show them as good

2005-04-13 Thread Neil Williams
Package: kmail Version: 4:3.3.2-3 Severity: normal When viewing the same message in multiple email clients using IMAP, only KMail shows a bad signature for messages signed using Apple Mail (signed as PGP/MIME). Headers from affected emails: X-Pgp-Agent: GPGMail 1.0.2 X-Mailer: Apple Mail (2.619

Bug#304549: slapd: The newest Version 2.2.23 instantly dies when a process tries to access it.

2005-04-13 Thread Silvio Schmidt
Package: slapd Version: 2.2.23 Severity: grave Justification: renders package unusable -- System Information: Debian Release: 3.1 APT prefers testing APT policy: (500, 'testing') Architecture: alpha Kernel: Linux 2.6.11 Locale: LANG=C, LC_CTYPE=C (charmap=ANSI_X3.4-1968) Versions of package

Bug#304547: rpdump TOCTOU file-permissions vulnerability (CAN-2005-1066)

2005-04-13 Thread Joey Hess
Package: pine Severity: normal Tags: security I've verified that the rpdump.c included in the pine source package is vulnerable to the symlink attack described here: http://msgs.securepoint.com/cgi-bin/get/bugtraq0504/126.html I don't see rpdump being put in any on the binary packages, but I did

Bug#304548: CAN-2005-1041: DoS vulnerability in fib_seq_start()

2005-04-13 Thread Moritz Muehlenhoff
Package: kernel-source-2.6.8 Version: 2.6.8-15 Severity: important Tags: security CAN-2005-1041 describes a DoS vulnerability inside the fib_seq_start function of fib_hash.c that permits local users to crash the kernel via /proc/net/route. Patch is available at: http://marc.theaimsgroup.com/?l=bk

Bug#303551: inkscape: Segfaults on startup (PowerPC)

2005-04-13 Thread Wolfram Quester
Hi, On Wed, Apr 13, 2005 at 08:08:53PM +0200, Guido Guenther wrote: > Hi Lee, > On Wed, Apr 13, 2005 at 04:13:10PM +0200, Wolfram Quester wrote: > > > Maybe it's not much help either way, but doesn't this narrow the segfault > > > down > > > to somewhere before those safeguards are set up? > > Y

Bug#304324: EPlugins not being packaged

2005-04-13 Thread Adam D. Bradley
The evolution package still needs to include the EPlugins themselves (the /usr/lib/evolution/2.2/plugins tree), or they need to be packaged separately and "recommended" by the evolution package. -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EM

Bug#304478: Possibility to change slapd/dump_database_destdir without dpkg-reconfigure

2005-04-13 Thread 7nrmi1s02
Torsten Landschoff torsten-at-debian.org |bugs-debian| wrote: >>--- slapd.templates 2005-04-01 18:59:49.0 +0200 >>+++ /tmp/slapd.templates 2005-04-13 17:58:55.928198366 +0200 >>@@ -10,18 +10,24 @@ >> Choices: always, when needed, never >> Default: when needed >> Description: Dump dat

  1   2   3   4   >