On Wed, Jan 14, 2015 at 04:55:44PM +0100, Vincent Lefevre wrote:
> Package: dctrl-tools
> Version: 2.23
> Severity: normal
>
> grep-aptavail -dI does not output an empty line separating paragraphs:
I've reproduced this. I'll see about fixing it in the near future.
Thank you for the report.
--
close 756731
thanks
I've just uploaded a new policy for Unstable (which may or may not make it to
Jessie) that fixes lots of systemd bugs.
If you have problems with version 2.20140421-8 then please file a new bug
report.
--
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
wit
Control: tags 769388 moreinfo
On Sun, 18 Jan 2015 21:32:31 + Simon McVittie wrote:
> Control: reassign 769388 release-notes
> Control: severity 769388 normal
>
> On 18/01/15 19:38, Michael Gilbert wrote:
> > Isn't this also a documentation issue? A section could be added to
> > the release
Package: awstats
Followup-For: Bug #706076
Both workarounds,
- Use NbOfLinesForCorruptedLog in awstats
- Adopt apache log configuration to hide such messages
have problematic side effects. I agree that the right solution is to:
(1) log invalid request names only on 400 ("Bad Request") response
Package: release.debian.org
Severity: normal
User: release.debian@packages.debian.org
Usertags: unblock
Dear release team,
The package weboob has been marked for autoremoval because of a RC which
reports that weboob applications don't ask user before accepting a new
modules repository's keyri
Control: reassign -1 src:linux 3.16.7-ckt2-1
On Fri, Jan 9, 2015 at 17:14:48 +0100, Thorben Kaufmann wrote:
> Gfx:
> Asus NVIDIA GeForce GTX750TI
> + nouveau driver
> Board:
> Asus Sabertooth 990FX R2.0 + AMD FX8350
>
> Problem:
> When dist-upgrading 3.14-2-amd64 to 3.16.0-4-amd64 grafik mode i
What AVC messages do you get when this happens?
Does it happen with a more recent version of the policy package?
--
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org
Package: libc-bin
Version: 2.19-13
Severity: minor
File: /usr/share/man/man1/catchsegv.1.gz
Dear Maintainer,
reading catchsegv(1):
>>>
$ man 1 catchsegv | grep -iA3 synopsis
SYNOPSIS
catchsegv program [args]
DESCRIPTION
<<<
there are no command line options documented, but the followi
package: libv8-3.14
version: 3.14.5.8-8
severity: grave
tags: security
Hi, the security team has decided that this package will not receive
security support for jessie. This has already been documented in the
debian-security-support package for about two months:
libv8-3.14 Not covered by securit
close 690087
thanks
Already fixed, years ago.
--
My Main Blog http://etbe.coker.com.au/
My Documents Bloghttp://doc.coker.com.au/
--
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org
close 734649
thanks
Your problem is that your root filesystem was not labelled correctly, the
files related to shared objects should not have type file_t
The best thing to do is to create a file named /.autorelabel and then reboot
to relabel it all.
--
My Main Blog http://etbe.coker.c
close 706559
thanks
The current policy runs the X server as unconfined_t if you run "startx" from
an unconfined_t session.
--
My Main Blog http://etbe.coker.com.au/
My Documents Bloghttp://doc.coker.com.au/
--
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
wit
Package: pavucontrol
Version: 1.0-1
Severity: important
Dear Maintainer,
I just installed pavucontrol. Using Xfce and choosing rodent ->
Multimedia -> PulseAudio Volume Control, I get a pop-up:
Volume Control
Connection to PulseAudio failed. Automatic retry in 5s
In this case this is likely
close 756729
thanks
This was fixed in testing ages ago.
--
My Main Blog http://etbe.coker.com.au/
My Documents Bloghttp://doc.coker.com.au/
--
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debi
On 01/18/2015 07:19 PM, Frederik Himpe wrote:
> It looks like I'm hitting exactly the same issue:
> Jan 18 09:19:49 Error: = Begin GnuPG log =
> Jan 18 09:19:49 Error: *** buffer overflow detected ***: gpg terminated
> Jan 18 09:19:49 Error: === Backtrace: =
Thank you for your
Control: reassign -1 770286
For the record, I'd appreciate if you could include more context when
reassigning a bug. The maintainer only sees the message that I've quoted below.
But also after reviewing http://bugs.debian.org/770286, I'm not sure what you
expect keepassx to do. It offers function
Package: src:linux
Version: 3.16.7-ckt4-1
Severity: normal
Dear Maintainer,
I recently purchased a PCIe DVB tuner advertised as a
Hauppauge WinTV-HVR-2250
However, what was in the box was actually a more recent revision of the
hardware known as a:
Hauppauge WinTV-HVR-2255
Looking at my kernel
Package: wnpp
Severity: wishlist
Owner: KURASHIKI Satoru
* Package name: libmodule-install-rtx-perl
Version : 0.37
Upstream Author : Best Practical Solutions
Audrey Tang
* URL : http://search.cpan.org/dist/Module-Install-RTx
* License : MIT
package: src:glibc
version: 2.19-13
severity: important
control: block 767048 by -1
Hi, I was working on building wine for kfreebsd-amd64 and found that
glibc's x86_64 mcontext.h is not in sync with the upstream code that
it is derived from (kfreebsd's amd64 ucontext.h).
One example is that mc_fs
Package: myrepos
Severity: wishlist
The myrepos git status command should show stashes.
--
bye,
pabs
https://wiki.debian.org/PaulWise
signature.asc
Description: This is a digitally signed message part
On 15/01/15, 08:32am, Paul Wise wrote:
> Source: libtorrent
> Severity: wishlist
>
> I've recently had rtorrent segfault a few times. Please add a
> libtorrent-dbg package so that I can report a useful bug.
>
ACK, sadly I'm out of time right now so if anybody wants to pick up
these: the source i
Package: po4a
Version: 0.45-1
Severity: wishlist
Tags: patch
Hi!
gettext 0.19 got support for a new --add-location option in several of
its msg tools, which allows to specify how the source references get
injected into “#: ...” comments in .po files.
The --add-location option accepts as argument
Sebastian Rose wrote:
> if the value of $PATH ends in a colon (':'), skripts in the current directory
> are executed without requiring the './' path-prefix.
Thank you for your report. However what you are seeing is not a bug.
It is required behavior. An empty path is the same as saying '.'.
That
On Mon, 19 Jan 2015, Michael Biebl wrote:
> unfortunately I don't have any selinux knowledge at all, so I don't have
> the slightest idea how this (or your earlier bug #775613) should be
> addressed.
>
> Help is most welcome.
Would you like me to give you root access on a virtual machine that
d
Hi!
On Mon, 2015-01-19 at 02:11:00 +0100, Guillem Jover wrote:
> Package: po4a
> Version: 0.45-1
> Severity: minor
> Tags: patch
> I've been kept confused by the porefs option in the docs, as if it was
> a config file option only or similar. Checking the code, revealed that
> this was an actual c
Hi Michael,
Michael Gilbert wrote:
> I prepared a patch fixing resolvconf's bashisms. Please test.
Thanks for the patch. Will test it later today on the box where I
discovered the issue.
Regards, Axel
--
,''`. | Axel Beckert , http://people.debian.org/~abe/
: :' : | Debian
On Mon, Jan 19, 2015 at 09:26:36AM +0900, Christian Balzer wrote:
>
>
> Well...
>
> Meanwhile, here in what it what we tenuously call reality one can observe
> the following things:
>
> 1. Pacemaker broken in Jessie for more than 2 months now.
> 2. Silence on this bug for more than one month.
>
Control: tag -1 + pending
Hi,
Axel Beckert wrote:
> I've pushed a prelimiary NMU to the git branch "nmu":
> https://anonscm.debian.org/cgit/collab-maint/debsums.git/log/?h=nmu
>
> I intend to upload that one as NMU to DELAYED/2 after some testing.
> Will post a full debdiff here once I'm done wi
Package: po4a
Version: 0.45-1
Severity: minor
Tags: patch
Hi!
I've been kept confused by the porefs option in the docs, as if it was
a config file option only or similar. Checking the code, revealed that
this was an actual command-line option just lacking the -- prefix, which
was missing in the m
Package: awscli
Version: 1.7.0-1
Severity: minor
Dear Maintainer,
I recently upgraded awscli from 1.4.2 to 1.7.0 and found that I could not run
it, instead I got the following error:
$ aws help
Traceback (most recent call last):
File "/usr/bin/aws", line 15, in
import awscli.clidriver
F
Control: forcemerge 766448 -1
Control: tag -1 - moreinfo
On Sun, 2015-01-18 at 23:47 +0100, Paul Menzel wrote:
> Am Sonntag, den 18.01.2015, 15:12 + schrieb Ben Hutchings:
[...]
> > I think I know why this is, but please can you send the fstab line for
> > the root filesystem?
>
> Sure.
>
>
Package: nftables
Version: 0.4-2
Severity: serious
Dear Maintainer,
The init script shipped with the package fails with this error:
/etc/nftables.conf:3:1-14: Error: Could not process rule: Address family not
supported by protocol
flush ruleset
^^
The reason is that “flush ruleset”
Well...
Meanwhile, here in what it what we tenuously call reality one can observe
the following things:
1. Pacemaker broken in Jessie for more than 2 months now.
2. Silence on this bug for more than one month.
3. Pacemaker was recently removed from Jessie.
4. The February 5th deadline is rapidl
Hi, Tony.
On Jan 17 2015, tony mancill wrote:
> On 01/15/2015 01:44 PM, Rogério Brito wrote:
> > That's great and would, at least, make it clear that once installed, at
> > least the basics of clojure would work.
>
> I have updated the dependency - it will be part of the next upload.
Thanks a lo
On 18/01/2015 22:00, Sebastian Andrzej Siewior wrote:
On 2015-01-18 18:59:33 [+0100], Jakub Wilk wrote:
Sorry, it's me again! libmspack crashes on the attached file:
As I've seen your ubsan reports, I assumed you were done. Wrong this
was.
$ gpg -d < crash.chm.asc > crash.chm
$ test/chmd_md5
Package: bash
Version: 4.3-11+b1
Severity: important
Tags: upstream
Dear Maintainer,
if the value of $PATH ends in a colon (':'), skripts in the current directory
are executed without requiring the './' path-prefix.
The current directory is the last one taken into account though.
Here is, how I
Package: docker.io
Version: 1.3.3~dfsg1-2
When you have a external docker group (ex. LDAP group) with same name,
the installation crashs. The shared group in external LDAP Server is a
best pratice.
Follow the patch to fix this possible problem in DEBIAN/postinst file:
6c6
Package: signing-party
Version: 1.1.4-1
Severity: normal
Initially encountered on OS/X with MacPorts
(https://trac.macports.org/ticket/46601), but reported here
because (a) Debian appears to be the upstream for signing-party/caff
(http://pgp-tools.alioth.debian.org/) and (b) AFAICT by inspection
Package: evolution
Severity: important
Myself and others are getting a significant number of crashes due to the
following two upstream bugs. I would like to see a new version in jessie
that fixes these two bugs, either via cherry-picking the patches or via
importing the new upstream version wholes
On Sun, Jan 18, 2015 at 6:18 PM, Shai Berger wrote:
>> Both grave and critical refer to actual data loss. Using the term
>> serious isn't particularly useful since that falls outside those two
>> categories anyway.
>>
>
> Again, you're being tautological, repeating your terms rather than defining
Control: tags -1 + moreinfo
Hi Jaromir
On 2012-02-08 21:08:20, Jaromír Mikeš wrote:
> I just found this bug when searched why my ape file are corrupted when
> converted by "soundcorverter" 1.5.4-1
> Having same problem here ... audible clips and output file is shorter then
> input,
> of course
Hello,
On Thu, Jan 8, 2015 at 3:18 PM, Moshe Yudkowsky wrote:
> Reportbug itself fails to start:
I was unable to replicate it on a clean sid chroot.
> from debian.deb822 import Deb822
> File "/usr/lib/python2.7/dist-packages/debian/deb822.py", line 1481, in
>
> @six.add_metaclass(_Cl
On Monday 19 January 2015 00:54:41 Michael Gilbert wrote:
> On Sun, Jan 18, 2015 at 5:44 PM, Shai Berger wrote:
> > I am asking about "serious" vs. "non-serious" because those are the terms
> > used by reportbug ("non-serious data loss" is a reason to mark a bug
> > "grave").
>
> Both grave and cr
Package: ltspfs
Version: 1.4-1
Severity: normal
Dear Maintainer,
Booting the thin client with the USB DVD drive connected and DVD
inserted the user can see the contents of the DVD. If I remove the DVD
and insert it again whilst logged in, the DVD does not show up in
/media//cdrom.
Booting with t
Package: libgaviotatb-dev
Version: 0.4-1
Severity: grave
Hi,
libgaviotatb-dev seems to be broken:
% gcc main.c -lpthread -lm -lgaviotatb
/usr/lib/gcc/x86_64-linux-gnu/4.9/../../../../lib/libgaviotatb.so: undefined
reference to `z_uncompress'
/usr/lib/gcc/x86_64-linux-gnu/4.9/../../../../lib/libg
On Sun, Jan 18, 2015 at 5:44 PM, Shai Berger wrote:
> I am asking about "serious" vs. "non-serious" because those are the terms used
> by reportbug ("non-serious data loss" is a reason to mark a bug "grave").
Both grave and critical refer to actual data loss. Using the term
serious isn't particul
Am Sonntag, den 18.01.2015, 15:12 + schrieb Ben Hutchings:
> Control: tag -1 moreinfo
>
> On Sun, 21 Dec 2014 12:46:18 +0100 Paul Menzel
> wrote:
> > Package: initramfs-tools
> > Version: 0.118
> > Severity: important
> > since some time, the filesystem type of the LUKS encrypted root
> > p
On Sunday 18 January 2015 23:51:01 Michael Gilbert wrote:
> On Sun, Jan 18, 2015 at 4:14 PM, Shai Berger wrote:
> > Those "easily recreatable" bits represent a significant part of my mail
> > workflow. Almost any data can be recreated by repeating the work that
> > created it. Your claims essentia
Thanks for your help.
That suggests the kernel or the card itself. If alsa cannot play, then
pulseaudio is not the culprit. I am reassigning to the kernel, lets
see if the kernel maintainers can think of something else. I suggest
attaching the alsa-info.sh output[1], as it is usually helpful.
[1]
On Sun, Jan 18, 2015 at 11:37:28AM +, Steve McIntyre wrote:
> The ENOSPC handling has been bad in the past, but it's not clear that
> was the cause of your original bug. :-/ *Now* it's a very bad state to
> be in, and may cause other problems too. On the Dell machine you have,
> I'm not persona
Control: reassign -1 linux-image-3.16.0-4-amd64
On Sun, Jan 18, 2015 at 7:07 PM, lachlan-00 wrote:
>
> > Hmm. Maybe this is a problem with your card or the kernel. Please try
> > the following command:
>
> > pasuspender -- speaker-test -D $cardname -c 2
>
>
> user@lachp:~$ pasuspender -- speake
control: tag -1 patch
On Sun, Jan 18, 2015 at 3:29 PM, Thomas Hood wrote:
> package resolvconf
> tags 775356 confirmed
> stop
>
> Hmm, yes, as you say this arises from the fact that isc-dhcp-client's
> /sbin/dhclient-script switched from #!/bin/bash to #!/bin/sh last
> September.
>
> If you have a
Control: retitle -1 ITA: soundconverter -- GNOME application to convert audio
files into other formats
On 2015-01-18 11:53:37, Lars Wirzenius wrote:
> Package: wnpp
> Severity: normal
>
> I am orphaning the soundconverter package, which I no longer use
> myself. Someone who uses it would be a be
Hmm. Maybe this is a problem with your card or the kernel. Please try
the following command:
pasuspender -- speaker-test -D $cardname -c 2
user@lachp:~$ pasuspender -- speaker-test -D front:CARD=PCH,DEV=0 -c 2
user@lachp:~$ pasuspender -- speaker-test -D front:CARD=PCH -c 2
Produce audio thro
On 2015-01-18 18:59:33 [+0100], Jakub Wilk wrote:
> Sorry, it's me again! libmspack crashes on the attached file:
As I've seen your ubsan reports, I assumed you were done. Wrong this
was.
> $ gpg -d < crash.chm.asc > crash.chm
> $ test/chmd_md5 crash.chm
> *** crash.chm
>
> but it'd be better to
On Jan 18, 2015, at 11:48 PM, Kirill Smelkov wrote:
>To me this whole "let's bundle everything" approach is only justified because
>each package then could specify which version of dependencies to use
>_exactly_.
I don't believe Debian packages are allowed to bundle packages that are also
availab
On Sun, Jan 18, 2015 at 4:14 PM, Shai Berger wrote:
>> > So, the bits marking messages as "read" or "unread" are not data? What,
>> > pray tell, are they?
>>
>> Easily recreatable bit flags.
>>
>
> So data isn't lost if it is "easily recreatable"? Really?
No.
> By that argument, there really sho
Package: playitslowly
Version: 1.4.0-1
Severity: important
I've just freshly installed playitslowly.
It starts, shows the name of the mp3 file to be loaded (it just seems to
me that it does not now the length of the file), but when I press the
"play" button, nothing happens. On the console I see
On Sun, Jan 18, 2015 at 21:35:21 +0100, Paul Gevers wrote:
> Hi Lucas,
>
> Thanks a lot for investigating.
>
> On 18-01-15 10:36, Lucas Nussbaum wrote:
> > This is caused by soffice failing when HOME is set to a non-existent
> > directory,
> > as demonstrated by the log below.
>
> Irony, I had
Thanks for bringing this up again. This should be fixed upstream by:
https://github.com/matplotlib/matplotlib/commit/ba4016014cb4fb4927e36ce8ea429fed47dcb787#diff-51
Regards,
--
Sandro Tosi (aka morph, morpheus, matrixhasu)
My website: http://matrixhasu.altervista.org/
Me at Debian: http://wiki.d
On 2015-01-18 18:48, Niko Tyni wrote:
> a) - make xfonts-traditional 'postinst triggered' survive missing dependencies
>- make perl-base+perl-modules+perl Break xfonts-traditional older than that
What about this rather simple solution:
Package: perl-modules
Breaks: xfonts-traditional (<< 1.7~
Control: reassign 769388 release-notes
Control: severity 769388 normal
On 18/01/15 19:38, Michael Gilbert wrote:
> Isn't this also a documentation issue? A section could be added to
> the release notes on how to preseed a user for this type of
> installation use case?
Yes, I think so. #726661 is
On 18/01/15 14:34, Neil Williams wrote:
> For the benefit of the bug report, I've tried Simon's patch and I do not
> get the expected results.
...
> I rebuilt poppler with the second nmudiff [0] and then built evince
> with that version of poppler installed.
I might be misremembering, but I don't
Hi Riley,
Riley Baird wrote:
> > RMS declaring that something doesn't need to be free is weird.
>
> Yeah, he seems to be upset with Debian, because he says that we
> distribute non-free software.
Yeah, and Debian considers some licenses by the FSF (namely some GFDL
versions) as non-free, too. II
>>> Gah, this anonymous submitter is annoying. His claim that this "is
>>> practically impossible" is yet to be proved as I'm trying to prove the
>>> opposite.
>>
>> I am not anonymous.
>
> Just a first name and an anonymous remailer is more or less anonymous
> for me.
It isn't an anonymous remai
On Sunday 18 January 2015 21:46:52 Michael Gilbert wrote:
> On Fri, Jan 16, 2015 at 8:07 AM, Shai Berger wrote:
> > On Friday 16 January 2015 01:45:53 Michael Gilbert wrote:
> >> > However, the problem reported here is not a usability problem. If a
> >> > mail client losing record of which mails ha
Package: redmine
Version: 2.5.1-2~bpo70+5
Severity: normal
Dear Maintainer,
The example apache config files included with the redmine backports package do
not seem to work as directly as they could.
* What led up to the situation?
Attempting to setup redmine with apache2 and passeng
On 2015-01-18 12:39, Beojan Stanislaus wrote:
> OpenGL and NVIDIA library files installed:
> lrwxrwxrwx 1 root root48 Oct 21 18:35
> /usr/lib/x86_64-linux-gnu/libGL.so ->
> /etc/alternatives/glx--libGL.so-x86_64-linux-gnu
OK
> lrwxrwxrwx 1 root root50 Dec 10 12:45
> /usr/li
Hello,
Trying a bit on Linux with buffer sizes, this really is an issue between
tcl and expect. It happens to work on Linux only by luck because Linux
never returns more than 4095 bytes on ptys. As you described earlier,
what happens is:
- expect has a 6001 bytes buffer
- tcl will read() by 4096
Hey Carl,
Thanks for your interest! I submitted it to the NEW queue, I imagine it is
still there waiting to be reviewed. But please do check it out. The version
I uploaded is relatively old, so it would be good to have it updated. I would
love to have help maintaining this :-)
.hc
--
To UN
On Sun, Jan 18, 2015 at 05:41:10PM +, Jonathan Wiltshire wrote:
> Control: severity -1 normal
> Control: tag -1 - unreproducible
>
> Hi,
>
> On Tue, Dec 30, 2014 at 02:32:17PM +0400, Kirill Smelkov wrote:
> > With zope2.13 I've tried to create a (user) instance and start it, but a
> > `System
On 2015-01-18 21:43, Adam D. Barratt wrote:
> The diff Andreas provided also removed a manpage alternative, which the
> uploaded packages does not; is that intentional?
That was a slave alternative, so separate removal is useless.
Andreas
--
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@li
Hi,
Riley Baird wrote:
> > Gah, this anonymous submitter is annoying. His claim that this "is
> > practically impossible" is yet to be proved as I'm trying to prove the
> > opposite.
>
> I am not anonymous.
Just a first name and an anonymous remailer is more or less anonymous
for me.
> My name
Control: retitle -1 pxz: CVE-2015-1200: race condition in setting permissions
Hi
This has been assigned CVE-2015-1200 by MITRE.
Regards,
Salvatore
--
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.or
On Sun, 2015-01-18 at 12:12 -0800, Vagrant Cascadian wrote:
> Control: tags -1 -moreinfo
>
> On 2015-01-17, Adam D. Barratt wrote:
> > Please go ahead, and remove the "moreinfo" tag once the package has been
> > accepted.
>
> Uploaded.
The diff Andreas provided also removed a manpage alternativ
Control: retitle -1 ppmd: CVE-2015-1199: directory traversal
Hi,
This has been assigned CVE-2015-1199 by MITRE.
Regards,
Salvatore
--
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org
Control: retitle -1 ha: CVE-2015-1198: directory traversal vulnerabilities
Hi,
This has been assigned CVE-2015-1198 by MITRE.
Regards,
Salvatore
--
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org
Control: retitle -1 cpio: CVE-2015-1197: directory traversal
Hi,
This issue has been assigned CVE-2015-1197 by MITRE.
Regards,
Salvatore
--
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org
Hi Lucas,
Thanks a lot for investigating.
On 18-01-15 10:36, Lucas Nussbaum wrote:
> This is caused by soffice failing when HOME is set to a non-existent
> directory,
> as demonstrated by the log below.
Irony, I had to work around a missing HOME in the build-arch target as
well some time ago, r
Control: retitle -1 patch: CVE-2015-1196: directory traversal via symlinks
Hi,
This has been assigned CVE-2015-1196 by MITRE.
Regards,
Salvatore
--
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org
Control: retitle -1 paxtar: directory traversal vulnerabilities (CVE-2015-1193
CVE-2015-1194)
Hi,
According to MITRE the following two CVEs were assigned for pax:
> Use CVE-2015-1193 for the .. path traversal (CWE-22).
>
> Use CVE-2015-1194 for the symlink following, which can allow access out
Control: retitle -1 pigz: CVE-2015-1191: directory traversal vulnerability
Hi,
CVE-2015-1191 was assigned for this issue in pigz.
Regards,
Salvatore
--
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.
On Sun, Jan 18, 2015 at 08:07:20PM +0100, Lucas Nussbaum wrote:
> > Lucas, as the reporter of this bug, would your agree that it is not RC?
>
> Yeah, sure, I have no problem with it being downgraded.
Downgraded to normal. I also decided to reassign it to raxml since this
is finally the package t
control: tags -1 moreinfo help
control: tags 775613 moreinfo help
Am 18.01.2015 um 08:06 schrieb Russell Coker:
> # grep auditallow local.te
> auditallow domain tmpfs_t:dir create;
> # grep granted /var/log/audit/audit.log
> type=AVC msg=audit(1421563773.398:239): avc: granted { create } for
>
Control: retitle -1 kgb: CVE-2015-1192: directory traversal vulnerability
Hi,
CVE-2015-1192 was assigned for this issue.
Regards,
Salvatore
--
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org
Am 2015-01-18 14:07, schrieb Michael Meskes:
Here's an updated patch against the current version. Torsten is there
any
reason why this is not applied?
No specific reason. Sorry, this should be fixed for a long time.
I just applied the patch to a local git repository only to notice that I
can'
Source: getdns
Version: 0.1.5-1
Severity: wishlist
User: reproducible-bui...@lists.alioth.debian.org
Usertags: timestamps
Hi!
While working on the “reproducible builds” effort [1], I have noticed
that getdns could not be built reproducibly.
The file /usr/include/getdns/getdns.h includes the defi
Control: tags -1 -moreinfo
On 2015-01-17, Adam D. Barratt wrote:
> Please go ahead, and remove the "moreinfo" tag once the package has been
> accepted.
Uploaded.
live well,
vagrant
signature.asc
Description: PGP signature
: jessie sid
User: debian...@lists.debian.org
Usertags: qa-ftbfs-20150118 qa-ftbfs
Justification: FTBFS in jessie on i386
Hi,
During a rebuild of all packages in jessie (in a jessie chroot, not a
sid chroot), your package failed to build on i386.
Relevant part (hopefully):
make[1]: Entering
Package: mpd
Version: 0.19.1-1.1
Severity: normal
Tags: d-i
Dear Maintainer,
the /etc/init.d/mpd script checks the existence of DB_FILE variable but from
this version of mpd is possible to use it with a db on another mpd server: see
http://www.musicpd.org/doc/user/advanced_config.html
Attached t
On Fri, Jan 16, 2015 at 8:07 AM, Shai Berger wrote:
> On Friday 16 January 2015 01:45:53 Michael Gilbert wrote:
>> > However, the problem reported here is not a usability problem. If a mail
>> > client losing record of which mails have been read and which haven't
>> > isn't "non-serious data loss",
FWIW, I cannot reproduce with current upstream bash-completion git
with bash 4.2.53(1) or 4.3.33(1) on Fedora 20.
--
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org
Control: retitle -1 matplotlib: CVE-2013-1424: printf buffer overrun
Hi,
On Sun, Jan 18, 2015 at 01:44:36PM -0500, Michael Gilbert wrote:
> package: src:matplotlib
> version: 0.99.3-1
> severity: serious
> tag: security, patch
>
> Matt Giuca reported a matplotlib buffer overrun to the private
>
Thomas Schwinge, le Sun 18 Jan 2015 17:34:00 +0100, a écrit :
> (Can you now reproduce the issue?)
Yes.
> Any comments on that already? (I don't feel like
> committing such a change without understanding it.)
>
> --- term/ptyio.c
> +++ term/ptyio.c
> @@ -331,7 +331,7 @@ pty_io_read (struct triv
> Concrete effects reported in this bug:
>
> * People who were used to the old configuration find the behaviour of new
> installations of jessie confusing. A NEWS.Debian entry would not help here,
> because new installations don't show NEWS.Debian; an entry in the
> jessie release notes would
Control: severity -1 important
On Sat, Jan 17, 2015 at 2:56 PM, Sebastian Ramacher
wrote:
> On 2014-12-20 23:31:11, Michael Gilbert wrote:
>> CVE-2014-8544[4]:
>> | libavcodec/tiff.c in FFmpeg before 2.4.2 does not properly validate
>> | bits-per-pixel fields, which allows remote attackers to cau
On 19/01/15 03:51, Axel Beckert wrote:
> Jonathan Wiltshire wrote:
>> On Sun, Jan 18, 2015 at 04:06:01PM +0100, Axel Beckert wrote:
>>> asr-manpages unfortunately got removed from testing manually without
>>> explicit reason instead of just waiting for the autoremoval period.
>>> That happened desp
Package: mscompress
Version: 0.4-3
Severity: minor
Tags: patch
The attached patch removes the .ll requests from the manpages. They
don't seem to serve any purpose here, other than ruining[0] line
wrapping.
[0] See the attached screenshot.
--
Jakub Wilk
--- mscompress-0.4.orig/src/mscompress
Package: sponsorship-requests
Severity: wishlist
X-Debbugs-CC: pkg-grass-de...@lists.alioth.debian.org
Dear mentors,
I am looking for a sponsor for my package "python-cligj"
Package name: python-cligj
Version : 0.1.0-1
Upstream Author : Sean Gillies
URL : https://gith
One of recent (during ~2 last weeks) updates resolved this issue. Bug can be
closed now.
1 - 100 of 262 matches
Mail list logo