Bug#560959: dpkg-source: -x has really annoying output

2009-12-12 Thread Ryan Niebur
Package: dpkg-dev Version: 1.15.5.4 Severity: minor bash jade test-apt-get-source $ apt-get source wxwidgets2.6 Reading package lists... Done Building dependency tree Reading state information... Done Need to get 15.3MB of source archives. Get:1 http://ftp.us.debian.org squeeze/main wxwidgets2.6 2

Bug#560744: O: xview -- XView UI toolkit library and client programs

2009-12-12 Thread Andreas Tille
On Fri, Dec 11, 2009 at 10:35:09PM +0100, Martin Buck wrote: > Reverse dependencies from other source packages are: > treetool Treetool is removed from Debian. > arb I'm unsure whether I will continue maintaining this package. Xview is not the only outdated prerequisite. Kind regards

Bug#522256: RFA: ctwm -- Claude's Tab window manager

2009-12-12 Thread Aaron Farias
Hey there i was wondering if this package has any bugs, on it I'm willing to adopt it. i need some help though with a sponsor so i was wondering if i can adopt you're package and you become my sponsor. for uploading thank you Very Much Aaron H Farias Martinez -- -BEGIN PGP PUBLIC KEY BLOCK--

Bug#560958: cstocs: Missing dependecy on libdbd-xbase-perl

2009-12-12 Thread Fabrice Coutadeur
Package: cstocs Version: 1:3.42-1.1 Severity: normal Tags: patch User: ubuntu-de...@lists.ubuntu.com Usertags: origin-ubuntu karmic ubuntu-patch Hi, When running dbfcstocs in a fresh install system, I'm getting the following error: Can't locate XBase.pm in @INC (@INC contains: /etc/perl /usr/lo

Bug#560332: pbuilder: Please exclude sys/ from the base tarball

2009-12-12 Thread Junichi Uekawa
Are you saying anything in addition to bug# 542837 ? Is this a dupe bug? At Thu, 10 Dec 2009 15:24:10 +0100, Cyril Brulebois wrote: > > Package: pbuilder > Version: 0.194 > Severity: wishlist > User: debian-...@lists.debian.org > Usertags: kfreebsd > > Hi, > > on GNU/kFreeBSD systems, freebsd-

Bug#560789: pbuilder: output uses CAPITAL FONTS

2009-12-12 Thread Junichi Uekawa
I was wondering about this too, if you figure it out that would be nice. At Sat, 12 Dec 2009 11:42:00 +0100, Loïc Minier wrote: > > On Sat, Dec 12, 2009, Jari Aalto wrote: > > For some reason the fonts change in the middle to capital letters. > > This is hard to read. Please use standard lowercas

Bug#560957: kmail deleted contents of inbox with dimap

2009-12-12 Thread Florian Aldehoff
Package: kmail Version: 4:3.5.9-5 Severity: grave Justification: causes non-serious data loss Identical to bug 158978 in Launchpad, see https://bugs.launchpad.net/kdepim/+bug/158978 for additional information and reports from other users. The bug was also reported to affect Kmail 1.12.1 in KDE

Bug#560949: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Ola Lundqvist
Hi Michael Thanks for the report. I will look at this. I hardly think that expat is included in any important functions at least. But I'll check. Best regards, // Ola On Sat, Dec 12, 2009 at 10:57:56PM -0500, Michael Gilbert wrote: > package: vnc4 > severity: serious > tags: security > > Hi, >

Bug#560956: ITP: ttf-kouzan-mouhitsu - Brush-style Japanese font

2009-12-12 Thread Hideki Yamane
Package: wnpp Severity: wishlist X-Debbugs-CC: pkg-fonts-de...@lists.alioth.debian.org Package name: ttf-kouzan-mouhitsu Version: 20090806-1 Upstream Author: 青柳 衡山 (Kouzan Aoyagi) URL: http://musashi.or.tv/kouzanmouhitufont.htm License: You can use it with no charg

Bug#560916: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Ron
On Sun, Dec 13, 2009 at 12:25:38AM -0500, Michael Gilbert wrote: > On Sun, 13 Dec 2009 15:46:53 +1030 Ron wrote: > > > > > Hi, > > > > 2.6 should be ok for this. wx does indeed bundle a bunch of embedded > > source, but the debian binary packages avoid using it where possible, > > and expat is

Bug#554167: RFC: mawk (not maintainer, updated package)

2009-12-12 Thread Jonathan Nieder
Ryan Niebur wrote: > On Sun, Dec 13, 2009 at 12:04:17AM -0600, Jonathan Nieder wrote: [...] >> I am wondering what to do next: should I pursue a 14-day delayed NMU? >> Do nothing and hope some of my changes are picked up? > > have you tried asking the maintainer if you could work with him? all I >

Bug#560915: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Ron
Hi, Unlike 2.6, wx2.4 does indeed seem to be affected by this. Its exposure seems to be limited to the libwx_gtk_xrc-2.4 lib in the libwxgtk2.4-1-contrib binary package. Since xrc is a "resource compiler", used to supply random junk that is provided with an app, for the app, without actually emb

Bug#554167: RFC: mawk (not maintainer, updated package)

2009-12-12 Thread Ryan Niebur
On Sun, Dec 13, 2009 at 12:04:17AM -0600, Jonathan Nieder wrote: > Dear mentors and Steve, > > I am looking for some advice concerning the new version > 1.3.3-20090920-0.1 of the package "mawk". > > It builds these binary packages: > mawk - a pattern scanning and text processing language >

Bug#560924: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Siddhesh Poyarekar
On Sun, Dec 13, 2009 at 11:11 AM, Michael Gilbert wrote: > The optimal solution is to make use of the system expat in case of > future issues. > Absolutely. But that is too much of a rewrite for now :) -- Siddhesh Poyarekar http://siddhesh.in -- To UNSUBSCRIBE, email to debian-bugs-dist-re

Bug#554167: RFC: mawk (not maintainer, updated package)

2009-12-12 Thread Jonathan Nieder
Dear mentors and Steve, I am looking for some advice concerning the new version 1.3.3-20090920-0.1 of the package "mawk". It builds these binary packages: mawk - a pattern scanning and text processing language The package appears to be lintian clean. The upload would fix these bugs: 3835

Bug#560924: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Siddhesh Poyarekar
On Sun, Dec 13, 2009 at 11:06 AM, Siddhesh Poyarekar wrote: > On Sun, Dec 13, 2009 at 9:20 AM, Michael Gilbert > wrote: >> CVE-2009-3560[0]: >> | The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, >> | as used in the XML-Twig module for Perl, allows context-dependent >> | attack

Bug#560924: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
On Sun, 13 Dec 2009 11:06:13 +0530 Siddhesh Poyarekar wrote: > On Sun, Dec 13, 2009 at 9:20 AM, Michael Gilbert > wrote: > > CVE-2009-3560[0]: > > | The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, > > | as used in the XML-Twig module for Perl, allows context-dependent > > | a

Bug#560924: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Siddhesh Poyarekar
On Sun, Dec 13, 2009 at 9:20 AM, Michael Gilbert wrote: > CVE-2009-3560[0]: > | The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, > | as used in the XML-Twig module for Perl, allows context-dependent > | attackers to cause a denial of service (application crash) via an XML > | d

Bug#560955: [who-uploads] Print help if run with no arguments

2009-12-12 Thread Kumar Appaiah
Package: devscripts Version: 2.10.59 Severity: wishlist User: devscri...@packages.debian.org Tags: patch, who-uploads Hi! It's really not intuitive if who-uploads is run without arguments and I get no output. Please consider displaying the help message, at least. Patch attached. Thanks! Kumar

Bug#560916: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
On Sun, 13 Dec 2009 15:46:53 +1030 Ron wrote: > > Hi, > > 2.6 should be ok for this. wx does indeed bundle a bunch of embedded > source, but the debian binary packages avoid using it where possible, > and expat is indeed being sourced from the system in 2.6. > > If you grep the buildd logs you

Bug#560762: OK, All three machines are now 'debian-multimedia' free

2009-12-12 Thread Dominique Brazziel
Totem plays .avi again and no orange balls anywhere. OK to close. :) -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#543272: audacious: incorrectly depends on dbus-x11

2009-12-12 Thread Jon DeVree
I read bug 503427 so I know you're between a rock and a hard place, but it seems that bug 503427 was noting that no dependencies on dbus-x11 existed of any type. A Recommends dependency on dbus-x11 would seem to satisfy the original bug and this bug. APT itself defaults to installing Recommends by

Bug#560954: generates incorrect paths in kernel.cfg when /boot not on root filesystem

2009-12-12 Thread Robert Edmonds
Package: extlinux Version: 2:3.83+dfsg-5 Severity: important i have /boot on a separate filesystem. update-extlinux generated a kernel.cfg file that referenced "kernel /boot/vmlinux-..." and "initrd=/boot/initrd.img-..." when it should have omitted the leading /boot path component. -- System Inf

Bug#560953: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: smart severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many package

Bug#560952: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: vtk severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many packages

Bug#539019: RM: libmd5-perl -- ROM; deprecated

2009-12-12 Thread Ansgar Burchardt
notfound 539019 2.03-2 reassign 539019 ftp.debian.org retitle 539019 RM: libmd5-perl -- ROM; deprecated thanks Hi, please remove the libmd5-perl package from unstable. The MD5 Perl module has been made obsolete by Digest::MD5 years ago. There are two rdeps remaining, no other packages in unstab

Bug#560928: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: coin3 severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many package

Bug#560947: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: apache2 severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many packa

Bug#560938: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: sitecopy severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many pack

Bug#560930: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: ghostscript severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many p

Bug#560942: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: xmlrpc-c severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many pack

Bug#560940: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: tla severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many packages

Bug#560949: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: vnc4 severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many packages

Bug#560929: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: gdcm severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many packages

Bug#560932: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: iceape severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many packag

Bug#560944: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: kompozer severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many pack

Bug#560934: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: libparagui1.1 severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many

Bug#560943: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: iceweasel severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many pac

Bug#560948: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: texlive-bin severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many p

Bug#560950: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: xotcl severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many package

Bug#560936: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: poco severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many packages

Bug#560933: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: insighttoolkit severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so man

Bug#560935: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: paraview severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many pack

Bug#560946: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: xulrunner severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many pac

Bug#560927: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: cmake severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many package

Bug#560945: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: vxl severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many packages

Bug#560951: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: python-xml severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many pa

Bug#560939: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: swish-e severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many packa

Bug#560937: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: simgear severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many packa

Bug#560941: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: wbxml severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many package

Bug#560931: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: grmonitor severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many pac

Bug#560926: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: cadaver severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many packa

Bug#560920: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: matanza severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many packa

Bug#560918: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: celementtree severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many

Bug#560922: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: udunits severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many packa

Bug#560919: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: audacity severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many pack

Bug#560923: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: apr-util severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many pack

Bug#560917: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: wxwidget2.8 severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many p

Bug#560924: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: ayttm severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many package

Bug#560925: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: cableswig severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many pac

Bug#560921: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: tdom severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many packages

Bug#560915: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: wxwindows2.4 severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many

Bug#560916: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: wxwidgets2.6 severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many

Bug#560914: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: python-4suite severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many

Bug#560912: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: python2.5 severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many pac

Bug#560913: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: python2.4 severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many pac

Bug#559556: zsh completion in draai does not work

2009-12-12 Thread Joost van Baal
tags 559556 + pending thanks Hi chrysn, Thanks for your bugreport. Op Sat 5 Dec 2009 om 12:16:19 +0100 schreef chrysn: > Package: draai > Version: 20090615-2 > Severity: minor > > draai installs its zsh completion method in > /usr/share/zsh/site-functions/_draai, where it is not read by zsh. a

Bug#560911: openoffice.org: Cannot set styles in Writer if using XMonad window manager

2009-12-12 Thread Michal Suchanek
Package: openoffice.org Version: 1:3.1.1-9 Severity: normal There is an issue with the style dialog in OOo and windowmanagers that are designed to focus new windows to allow keyboard input like XMonad. OOo on X11 (and X11 only) does not focus the dialog with other, more commonly used windowmanag

Bug#560910: iptables ignores mask on source ip address: 1.2.3.4/16 treated as 1.2.3.4/0

2009-12-12 Thread Hugh McDonald
Package: iptables Version: 1.4.4-2 Severity: critical Justification: breaks unrelated software iptables verson 1.4.5-1 for amd64 ignores the address mask on source address arguments. "-s 192.168.1.0/24" is treated as "-s 192.168.1.0/0" both as reported by "iptables -L -n -v" and as seen in firewa

Bug#560453: fim: FTBFS: DebugConsole.cpp:122: error: invalid conversion from 'const char*' to 'char*'

2009-12-12 Thread Michele Martone
Hi, There are updated fim files (1.2) on : ftp://ftp-master.debian.org:/pub/UploadQueue/fim_0.3-beta-prerelease-1.2.diff.gz ftp://ftp-master.debian.org:/pub/UploadQueue/fim_0.3-beta-prerelease-1.2.dsc ftp://ftp-master.debian.org:/pub/UploadQueue/fim_0.3-beta-prerelease-1.2_i386.deb I hope this was

Bug#474212: openoffice.org: Still broken in 3.1

2009-12-12 Thread Michal Suchanek
Package: openoffice.org Version: 1:3.1.1-9 Severity: normal I don't see any way to revert to parent properties in child style in 3.1 either. Typically an office suite that really supports style inheritance would provide visual clue which settings of the style are parent/default and which are add

Bug#560909: haskell-hdbc-odbc-doc: Wrong description; says "Sqlite v3"

2009-12-12 Thread Josh Triplett
Package: haskell-hdbc-odbc-doc Version: 2.2.0.0-3 Severity: minor Package: haskell-hdbc-odbc-doc [...] Description: Sqlite v3 HDBC (Haskell Database Connectivity) ODBC Documentation HDBC provides an abstraction layer between Haskell programs and SQL relational databases. This lets you write data

Bug#515534: (no subject)

2009-12-12 Thread J.M.Roth
After upgrading to lenny my saslauthd was broken too. I'm attaching the diff between my old defaults file and the one coming with the new version, which I'm using now. --- saslauthd 2009-12-13 03:22:14.0 +0100 +++ sasl.old2007-04-12 02:16:24.0 +0200 @@ -1,19 +1,10 @@ # # Se

Bug#560908: openjdk-6: deluge of vulnerabilities

2009-12-12 Thread Michael Gilbert
Package: openjdk-6 Version: 6b16-1.6.1-2 Severity: grave Tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for openjdk-6. I have not had the time to check any of this since there are just way too many issues. Please check whether openjdk is vulnerable

Bug#560907: pytrainer: Missing manpage for pytr

2009-12-12 Thread Alessio Treglia
Package: pytrainer Severity: wishlist Script called pytr comes installed under /usr/bin but there isn't any manpage for it. Please provide a manpage for that. -- System Information: Debian Release: squeeze/sid APT prefers karmic-updates APT policy: (500, 'karmic-updates'), (500, 'karmic-se

Bug#560906: pytrainer: Desktop file contains deprecated Encoding key

2009-12-12 Thread Alessio Treglia
Package: pytrainer Severity: minor Tags: patch pytrainer.desktop contains a deprecated Encoding key, it should be removed. The following patch fixes this. --- pytrainer.desktop.orig 2009-12-13 03:23:33.352669808 +0100 +++ pytrainer.desktop 2009-12-13 03:23:40.433918525 +0100 @@ -1,7 +1,6

Bug#560905: webkit: CVE-2009-3932 google gears plugin vulnerability

2009-12-12 Thread Michael Gilbert
Package: webkit Version: 1.1.17-2 Severity: important Tags: security Hi, the following CVE (Common Vulnerabilities & Exposures) id was published for chrome: CVE-2009-3932[0]: | The Gears plugin in Google Chrome before 3.0.195.32 allows | user-assisted remote attackers to cause a denial of service

Bug#187512: netatalk: getzones fails

2009-12-12 Thread didier
Hi, It's the behavior of getzones if no zones are defined. -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#559831: closed by (John V. Belmonte) (Bug#559831: fixed in xmlsec1 1.2.14-1)

2009-12-12 Thread Michael Gilbert
On Sat, 12 Dec 2009 21:06:30 -0500 John Belmonte wrote: > On closer investigation It turns out that Debian xmlsec1 is not > affected by CVE-2009-3736 since we don't enable dynamic crypto module > loading (--enable-crypto_dl). my mistake. i realize now that the upstream release completely removed

Bug#560904: fceu: FCEU choppy with opengl

2009-12-12 Thread Chance Platt
Package: fceu Version: 0.98.12-3 Severity: important Tags: patch FCEU is choppy when using OpenGL output with ATI cards. The code checks for GL_EXT_paletted_texture, and if it doesn't exist, falls back to a software palette adjustment method. It doesn't update the screen three frames out of f

Bug#560903: viewvc: CVE-2009-3618 and CVE-2009-3619 xss and character printing vulnerabilities

2009-12-12 Thread Michael Gilbert
Package: viewvc Version: 1.0.9-1 Severity: serious Tags: security Hi, the following CVE (Common Vulnerabilities & Exposures) ids were published for viewvc. CVE-2009-3618[0]: | Cross-site scripting (XSS) vulnerability in viewvc.py in ViewVC 1.0 | before 1.0.9 and 1.1 before 1.1.2 allows remote att

Bug#559831: closed by (John V. Belmonte) (Bug#559831: fixed in xmlsec1 1.2.14-1)

2009-12-12 Thread John Belmonte
close 559831 stop On Sat, Dec 12, 2009 at 6:52 PM, Michael Gilbert wrote: > i don't think that this has been resolved since there are no depends on > libtool in your control file. On closer investigation It turns out that Debian xmlsec1 is not affected by CVE-2009-3736 since we don't enable dyna

Bug#560902: ITP: qodem -- Friendly ncurses-based Unicode-aware communications package

2009-12-12 Thread Kevin L
Package: wnpp Owner: Kevin Lamonte Severity: wishlist * Package name: qodem Version : Upstream Author : * URL or Web page : * License : Description : Friendly ncurses-based Unicode-aware communications package Qodem is an open-source re-implementation of the Q

Bug#560863: ITP: lamson -- The Python SMTP Server

2009-12-12 Thread Sebastian Otaegui
I could not find it I most definitely would like to help on that Can you send me the link to the project ? On 12/12/09, David Watson wrote: > Sebastian Otaegui wrote: >> Package: wnpp >> Severity: wishlist >> Owner: Sebastian Otaegui >> >> >> * Package name: lamson >> Version :

Bug#560771: [Pkg-acpi-devel] Bug#560771: acpid: CVE-2009-4235: weak permissions on /var/log/acpid

2009-12-12 Thread Ted Felix
Looks like the problem is in this line from open_logs(): logfd = open(logfile, O_WRONLY|O_CREAT|O_APPEND); It should be this: logfd = open(logfile, O_WRONLY|O_CREAT|O_APPEND, 0640); And (theoretically, as I've not tested it) the problem is solved. As mentioned, this doesn't fix any existi

Bug#560869: FTBFS: failures in jh_manifest

2009-12-12 Thread Matthew Johnson
reassign 560869 javahelper tag 560869 pending thanks On Sat Dec 12 23:24, Cyril Brulebois wrote: > Package: libmatthew-java > Version: 0.7.2-2 > Severity: serious > Justification: FTBFS This is a bug in javahelper, I've just fixed it in git and I'll upload (yet another) new version. Should just n

Bug#560900: [debchange] Option to use maintainer details from debian/control for the changelog

2009-12-12 Thread Modestas Vainius
Package: devscripts Version: 2.10.59 Severity: wishlist File: /usr/bin/debchange Tags: patch Hello, it would be great if debchage optionally allowed to use maintainer details from debian/control rather than DEBFULLNAME/DEBEMAIL. I suggested a couple of use cases in the updated manual page (quoted

Bug#560901: expat: CVE-2009-3560

2009-12-12 Thread Michael Gilbert
package: expat version: 1.95.8-3.4 Severity: serious Tags: security Hi, the following CVE (Common Vulnerabilities & Exposures) id was published for xpat. CVE-2009-3560[0]: | The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, | as used in the XML-Twig module for Perl, allows cont

Bug#560832: [buildd-tools-devel] Bug#560832: [INTL:de] German translation update for de.po in schroot

2009-12-12 Thread Roger Leigh
tags 560832 + fixed-upstream pending thanks On Sat, Dec 12, 2009 at 06:00:24PM +0100, Helge Kreutzmann wrote: > Package: schroot > Version: 1.3.0-1 > Severity: wishlist > Tags: l10n patch > X-Debbugs-CC: Jens Seidel > > Please apply the attached patch to the version in GIT (i.e. your next > vers

Bug#560899: glabels: Print preview fails because evince not installed

2009-12-12 Thread greg schmidt
Package: glabels Version: 2.2.5-1 Severity: normal print preview pops up dialog Error launching preview Failed to execute child process "evince" (No such file or directory) -- System Information: Debian Release: squeeze/sid APT prefers testing APT policy: (990, 'testing'), (500, 'unstable'

Bug#560894: Openoffice.org hangs on "Insert -> Header/Footnote"

2009-12-12 Thread Daniel Moerner
On 12/12/2009 05:03 PM, Rene Engelhard wrote: > On Sat, Dec 12, 2009 at 04:34:14PM -0800, Daniel Moerner wrote: >> oowriter is just hanging when I "Insert -> Header/Footnote". There is no >> segfault or backtrace in gdb. I have no idea how to debug this. This issue > > And strace/ltrace? I'm havi

Bug#560890: devscripts: Shouldn't send an e-mail without a version number when using "bts found"

2009-12-12 Thread Adam D. Barratt
Hi, On Sat, 2009-12-12 at 22:08 -0200, Nelson A. de Oliveira wrote: > While using bts, I wrongly pressed the Enter key and saw this: > > === > $ bts found 559833 > bts: found has no version number, but sending to the BTS anyway > === > > > What is the purpose in accepting to send a message havi

Bug#559124: unnecessary files

2009-12-12 Thread Clint Adams
On Wed, Dec 02, 2009 at 07:23:53AM +0300, sergio wrote: > It's not so little for have them there. This files not needed for > ordinary users. Yes, sometimes it's very handy to see something there. > But usually this needed on developing. And if this is permanently it's > reasonable to keep th

Bug#560898: coreutils: insecure temp file usage

2009-12-12 Thread Michael Gilbert
package: coreutils version: 8.0-2 severity: serious tags: security hi, it has been disclosed that coreutils uses temp files in an insecure way [0]. note that etch and lenny are also affected. [0] http://www.openwall.com/lists/oss-security/2009/12/08/4 -- To UNSUBSCRIBE, email to debian-bugs-

Bug#559784: qutecom: CVE-2008-4776 denial-of-service

2009-12-12 Thread Michael Gilbert
On Sat, 12 Dec 2009 17:02:47 -0800 Ludovico Cavedon wrote: > Michael Gilbert wrote: > > On Sat, 12 Dec 2009 16:05:55 -0800 Ludovico Cavedon wrote: > >> Michael Gilbert wrote: > >>> the following CVE (Common Vulnerabilities & Exposures) id was published > >>> for libgadu. Centerim embeds libpurple

Bug#560897: whohas: massive memory consumption for searches (0.5G per run)

2009-12-12 Thread Jari Aalto
Package: whohas Version: 0.23-3 Severity: normal Please reduce the memory consumption of the program. It seems that the algorithm used pays no attention to memory consumptio as seen from htop(1) listing: $ whohas luit PID USER PRI NI VIRT RES SHR S CPU% MEM% TIME+ Command 12012

Bug#560894: Openoffice.org hangs on "Insert -> Header/Footnote"

2009-12-12 Thread Rene Engelhard
On Sat, Dec 12, 2009 at 04:34:14PM -0800, Daniel Moerner wrote: > oowriter is just hanging when I "Insert -> Header/Footnote". There is no > segfault or backtrace in gdb. I have no idea how to debug this. This issue And strace/ltrace? Grüße/Regards, Rene -- .''`. René Engelhard -- Debian GNU/

Bug#559784: qutecom: CVE-2008-4776 denial-of-service

2009-12-12 Thread Ludovico Cavedon
Michael Gilbert wrote: > On Sat, 12 Dec 2009 16:05:55 -0800 Ludovico Cavedon wrote: >> Michael Gilbert wrote: >>> the following CVE (Common Vulnerabilities & Exposures) id was published >>> for libgadu. Centerim embeds libpurple, which embeds libgadu, so it is >>> affected. >> I am sure what state

Bug#560885: texlive-base: Fails to upgrade

2009-12-12 Thread Kurt Roeckx
On Sun, Dec 13, 2009 at 01:20:03AM +0100, Hilmar Preusse wrote: > On 13.12.09 Kurt Roeckx (k...@roeckx.be) wrote: > > Hi, > > > fmtutil-sys failed. Output has been stored in > > /tmp/fmtutil.LHrpVsJ9 > > Please include this file if you report a bug. > > > Please do so. Here it is. Kurt fmtu

Bug#560896: E: unable to schedule circular actions 'unpack tex-common 2.02, unpack texlive-common 2009-4'

2009-12-12 Thread Cyril Brulebois
Package: libcupt-perl Version: 1.3.2 Severity: normal Hi, (this is still on my kfreebsd-i386 porterbox) I can't upgrade my system today, due to: | $ sudo cupt full-upgrade | Building the package cache... [done] | Initializing package resolver and worker... [done] | Scheduling requested actions..

  1   2   3   4   5   >