Bug#1107926: cloud.debian.org: console-setup required for virtual console keymap config to work

2025-06-17 Thread Bastien Traverse
Package: cloud.debian.org Severity: important Tags: l10n X-Debbugs-Cc: neit...@archlinux.org Dear Maintainer, Trying to use the `keyboard: layout:` directive[0] in cloud-init config doesn't result in the virtual console using it and the following error appears in the logs: ``` $ cloud-init stat

Bug#1107636: cloud.debian.org: use /etc/locale.conf instead of /etc/default/locale

2025-06-17 Thread Bastien Traverse
Package: cloud.debian.org Followup-For: Bug #1107636 X-Debbugs-Cc: neit...@archlinux.org Indeed, getting the desired locale to work properly is a pretty annoying aspect of Debian cloud images. >From your suggestion I thought of using `locale_configfile: /etc/locale.conf` >from [1], but it didn'

Bug#1107087: unblock: twitter-bootstrap3/3.4.1+dfsg-6

2025-06-01 Thread Bastien Roucaries
-01 15:39:35.0 +0200 @@ -1,3 +1,26 @@ +twitter-bootstrap3 (3.4.1+dfsg-6) unstable; urgency=medium + + * Team upload + * Do not refresh patches compared to 3.4.1+dfsg-4 in order +to ease unblock to trixie. + + -- Bastien Roucariès Sun, 01 Jun 2025 15:39:35 +0200 + +twitter-bootstrap3

Bug#1107088: bookworm-pu: package twitter-bootstrap3/3.4.1+dfsg-3+deb12u2

2025-06-01 Thread Bastien Roucaries
cripts, particularly +document.implementation variable. + + -- Bastien Roucariès Fri, 30 May 2025 18:17:56 +0200 + twitter-bootstrap3 (3.4.1+dfsg-3+deb12u1) bookworm; urgency=medium * Team upload diff -Nru twitter-bootstrap3-3.4.1+dfsg/debian/patches/CVE-2025-1647.patch twitter-bootstrap3-3.4.1+dfs

Bug#1103190: Bug#1104632: src:imagemagick: fails to migrate to testing for too long

2025-05-18 Thread Bastien Roucaries
Le dimanche 18 mai 2025, 09:26:39 heure d’été d’Europe centrale Paul Gevers a écrit : > Hi ImageMagick Packaging Team, Bastien, > > [Release Team member hat on] > > On Sat, 3 May 2025 13:58:21 +0200 Paul Gevers wrote: > > > The Release Team considers packages that

Bug#1105051: imagemagick breaks xplanet autopkgtest: test_compare_images() returned non-zero return code

2025-05-16 Thread Bastien Roucaries
Le vendredi 16 mai 2025, 13:31:55 heure d’été d’Europe centrale Jochen Sprickerhof a écrit : > Hi, > > * Paul Gevers [2025-05-10 14:24]: > >With a recent upload of imagemagick the autopkgtest of xplanet fails > >in testing when that autopkgtest is run with the binary packages of > >imagemagick f

Bug#1104882: bookworm-pu: package krb5/1.20.1-2+deb12u4

2025-05-07 Thread Bastien Roucaries
negotiating session keys with acceptable security, +assume that services support aes256-cts-hmac-sha1 unless a +session_enctypes string attribute says otherwise. + + -- Bastien Roucariès Wed, 07 May 2025 19:06:22 +0200 + krb5 (1.20.1-2+deb12u3) bookworm; urgency=medium * Non Maintainer

Bug#1104819: Please deembed bootstrap

2025-05-06 Thread Bastien Roucaries
Source: python-xstatic-bootstrap-scss Severity: serious Justification: embed/security issue Could you deembed bootstrap3 using the js packaged lib ? It will ease transition and security fixes signature.asc Description: This is a digitally signed message part.

Bug#1104818: python-xstatic-angular: Please deembed angular

2025-05-06 Thread Bastien Roucaries
Source: python-xstatic-angular Severity: serious Justification: embed Could you deembed angular using the js packaged lib ? It will ease transition and security fixes signature.asc Description: This is a digitally signed message part.

Bug#1104813: sogo: embed js file

2025-05-06 Thread Bastien Roucaries
Source: sogo Severity: serious Justification: embded compiled file UI / WebServerResources / js / vendor / contains a few js library, some not even packaged for debian signature.asc Description: This is a digitally signed message part.

Bug#1104810: openshot-qt: embded outdated js library

2025-05-06 Thread Bastien Roucaries
Source: openshot-qt Severity: serious Justification: embded code src / timeline / media / js / include a few js library minified (without source) outdated, and likely insecure signature.asc Description: This is a digitally signed message part.

Bug#1104797: civicrm: Embed javascript library including security problem

2025-05-06 Thread Bastien Roucaries
Source: civicrm Version: Embed a few javascript library Severity: serious X-Debbugs-Cc: Debian Security Team Your package include a lot of prebuild library, please deembed -- System Information: Debian Release: trixie/sid APT prefers testing-debug APT policy: (900, 'testing-debug'), (900, '

Bug#1104135: CVE-2025-3573

2025-04-25 Thread Bastien Roucaries
Source: znuny Version: 6.5.14-1 Severity: important Tags: security upstream X-Debbugs-Cc: ro...@debian.org, Debian Security Team Hi, The following vulnerability was published for src:znuny CVE-2025-3573[0]: | Versions of the package jquery-validation before 1.20.0 are | vulnerable to Cross-sit

Bug#1104136: CVE-2025-3573

2025-04-25 Thread Bastien Roucaries
Source: phpmyadmin Version: 4:5.2.2-really+dfsg-1 Severity: important Tags: security upstream X-Debbugs-Cc: ro...@debian.org, Debian Security Team Hi, The following vulnerability was published for src:phpmyadmin CVE-2025-3573[0]: | Versions of the package jquery-validation before 1.20.0 are | v

Bug#1104145: Embded jquery-validation

2025-04-25 Thread Bastien Roucaries
Source: civicrm Version: 5.68.1+dfsg1-1 Severity: important control: block -1 by 622257 Hi, You should deembed jquery-validation Thanks Bastien signature.asc Description: This is a digitally signed message part.

Bug#1104140: phpmyadmin: Embded jquery-validation

2025-04-25 Thread Bastien Roucaries
Source: phpmyadmin Version: 4:5.2.2-really+dfsg-1 Severity: important control: block -1 by 622257 Hi, You should deembed jquery-validation Thanks Bastien signature.asc Description: This is a digitally signed message part.

Bug#1104144: Embded jquery-validation

2025-04-25 Thread Bastien Roucaries
Source: kalkun Version: 0.8.3.1-1 Severity: important control: block -1 by 622257 Hi, You should deembed jquery-validation Thanks Bastien signature.asc Description: This is a digitally signed message part.

Bug#1104143: Embded jquery-validation

2025-04-25 Thread Bastien Roucaries
Source: znuny Version: 6.5.14-1 Severity: important control: block -1 by 622257 Hi, You should deembed jquery-validation Thanks Bastien signature.asc Description: This is a digitally signed message part.

Bug#1104142: phpmyadmin: Embded jquery-validation

2025-04-25 Thread Bastien Roucaries
Source: znuny Version: 6.5.14-1 Severity: important control: block -1 by 622257 Hi, You should deembed jquery-validation Thanks Bastien signature.asc Description: This is a digitally signed message part.

Bug#1104134: CVE-2025-3573

2025-04-25 Thread Bastien Roucaries
Source: kalkun Version: 0.8.3.1-1 Severity: important Tags: security upstream X-Debbugs-Cc: ro...@debian.org, Debian Security Team Hi, The following vulnerability was published for kalkun CVE-2025-3573[0]: | Versions of the package jquery-validation before 1.20.0 are | vulnerable to Cross-site

Bug#1103018: ruby-rmagick fails to coinstall

2025-04-21 Thread Bastien Roucaries
Le lundi 21 avril 2025, 12:03:52 heure d’été d’Europe centrale Chris Hofstaedtler a écrit : > On Sun, Apr 13, 2025 at 10:50:03PM +0200, Bastien Roucaries wrote: > > Le dimanche 13 avril 2025, 22:47:54 heure d’été d’Europe centrale Chris > > > > Hofstaedtler a écrit : >

Bug#1076350: nodejs i386 affects node-glob

2025-04-21 Thread Bastien Roucaries
Le lundi 21 avril 2025, 10:10:26 heure d’été d’Europe centrale Bastien Roucaries a écrit : > Le lundi 21 avril 2025, 02:06:51 heure d’été d’Europe centrale Jérémy Lal a > > écrit : > > Le lun. 21 avr. 2025 à 02:04, Jérémy Lal a écrit : > > > Le lun. 21 avr. 2025 à 02:

Bug#1076350: nodejs i386 affects node-glob

2025-04-20 Thread Bastien Roucaries
Le lundi 21 avril 2025, 01:51:23 heure d’été d’Europe centrale Jérémy Lal a écrit : > Le lun. 21 avr. 2025 à 00:09, Bastien Roucaries a écrit : > > control: affects -1 node-glob > > > > See https://salsa.debian.org/js-team/node-glob/-/jobs/7463824 > > > >

Bug#1076350: nodejs i386 affects node-glob

2025-04-20 Thread Bastien Roucaries
control: affects -1 node-glob See https://salsa.debian.org/js-team/node-glob/-/jobs/7463824 Kapouer did you try to run under valgrind ? valgrind may be help here or electric fence. Bastien signature.asc Description: This is a digitally signed message part.

Bug#1103686: RM: node-mkdirp-classic -- ROM; RC buggy/no depends

2025-04-20 Thread Bastien Roucaries
Package: ftp.debian.org Severity: normal X-Debbugs-Cc: node-mkdirp-clas...@packages.debian.org Control: affects -1 + src:node-mkdirp-classic User: ftp.debian@packages.debian.org Usertags: remove Could you please remove this package ? THanks signature.asc Description: This is a digitally si

Bug#1103685: RM: RC buggy

2025-04-20 Thread Bastien Roucaries
Source: node-mkdirp-classic Severity: serious This package should be RM this is an old fork of mkdirp with all CVE on it signature.asc Description: This is a digitally signed message part.

Bug#1103668: whalebuilder: Could not run

2025-04-20 Thread Bastien Roucaries
Package: whalebuilder Version: 0.11 Severity: grave Tags: upstream Justification: renders package unusable Fail to run whalebuilder create --debootstrap whalebuilder_debian_debootstrap:sid /usr/bin/whalebuilder:30:in `': undefined method `exists?' for class File (NoMethodError) if

Bug#1103018: ruby-rmagick fails to coinstall

2025-04-13 Thread Bastien Roucaries
Le dimanche 13 avril 2025, 22:47:54 heure d’été d’Europe centrale Chris Hofstaedtler a écrit : > * Bastien Roucaries [250413 22:09]: > >Le dimanche 13 avril 2025, 20:55:07 heure d’été d’Europe centrale Helmut > > > >Grohne a écrit : > >> Package: ruby-rm

Bug#1103018: ruby-rmagick fails to coinstall

2025-04-13 Thread Bastien Roucaries
uby extensions. Can I get a diff of these files between arch ? They are no arch path on it. May be date is different ? if so it is a reproductible bug problem Bastien > > Helmut signature.asc Description: This is a digitally signed message part.

Bug#1102974: bookworm-pu: package twitter-bootstrap4/4.6.1+dfsg1-4+deb12u1

2025-04-13 Thread Bastien Roucaries
result, restrictions are not applied to the data +that is evaluated, which can lead to potential +XSS vulnerabilities. +(Closes: #1084059) + + -- Bastien Roucariès Sun, 13 Apr 2025 13:42:02 +0200 + twitter-bootstrap4 (4.6.1+dfsg1-4) unstable; urgency=medium * Team upload diff -Nru

Bug#1102923: bookworm-pu: package twitter-bootstrap3/3.4.1+dfsg-3+deb12u1

2025-04-13 Thread Bastien Roucaries
e and data-slide-to attributes can be exploited +through the href attribute of an tag due to inadequate +sanitization. This vulnerability could potentially enable +attackers to execute arbitrary JavaScript within +the victim's browser. +(Closes: #1084060) + + -- Bastien

Bug#1102677: ckeditor4: EOL upstream commercial support only

2025-04-11 Thread Bastien Roucaries
/LICENSE.md Bastien signature.asc Description: This is a digitally signed message part.

Bug#1102675: bookworm-pu: package wpa/2:2.10-12+deb12u3

2025-04-11 Thread Bastien Roucaries
future bootstrapping by +passively observing public keys, re-using the encrypting +element Qi and subtracting it from the captured message +M (X = M - Qi). This will result in the public ephemeral +key X; the only element required to subvert the PKEX association + + -- Bastien

Bug#1095690: Not ready

2025-04-05 Thread Bastien Roucariès
Hi, I merge partially your patch, the problem is that I need a svg backend during build in order to generate the icons... Any idea to solve is welcomed Bastien signature.asc Description: This is a digitally signed message part.

Bug#1100421: bookworm-pu: package krb5/1.20.1-2+deb12u3

2025-03-13 Thread Bastien Roucariès
-2024-26462 (Closes: #1064965) +A memory leak vulnerability was found in /krb5/src/kdc/ndr.c. + * Fixes CVE-2025-24528 (Closes: #1094730) +Prevent overflow when calculating ulog block size + * Add Salsa CI + + -- Bastien Roucariès Sun, 23 Feb 2025 17:42:24 + + krb5 (1.20.1-2+deb12u2

Bug#1094730: News of this bug

2025-03-09 Thread Bastien Roucariès
Hi, I can NMU this bug for SID if needed Bastien signature.asc Description: This is a digitally signed message part.

Bug#1099340: retitle

2025-03-02 Thread Bastien Roucariès
control: retitle -1 samba-security-private-samba needed by freeipa Hi See https://github.com/freeipa/freeipa/blob/cbe863bf15ed3c0091256f86e9da3fe382b658f1/server.m4#L193C14-L193C44 only used for test https://github.com/freeipa/freeipa/blob/cbe863bf15ed3c0091256f86e9da3fe382b658f1/daemons/ipa

Bug#1099340: samba: need libsamba-net-private-samba.so dev for freeipa

2025-03-02 Thread Bastien Roucariès
Source: samba Version: need samba-libs.install: new private library: libsamba-net-private-samba.so link for dev for freeipa Severity: important Dear Maintainer, For freeipa we need that libsamba-net-private-samba.so.0 is added to the dev lib and a libsamba-net-private-samba.so link is created ?

Bug#1095690: src:imagemagick: Please consider restricting librsvg B-D to architectures where it is available

2025-02-10 Thread Bastien Roucariès
Le lundi 10 février 2025, 19:45:18 UTC Yavor Doganov a écrit : > Source: imagemagick > Version: 8:7.1.1.43+dfsg1-1 > Severity: important > Control: affects -1 + src:gnustep-gui > > [ I am filing this bug with severity:important because bugs affecting > non-release architectures were traditionally

Bug#1070998: bookworm-pu: package fossil/2.24-5~deb11u1

2025-02-03 Thread Bastien Roucariès
Le lundi 3 février 2025, 20:18:16 UTC Jonathan Wiltshire a écrit : > Control: tag -1 moreinfo > > On Sun, Jun 16, 2024 at 10:29:09AM +, Bastien Roucariès wrote: > > Control: tag -1 - moreinfo > > Le samedi 15 juin 2024, 21:53:51 UTC Jonathan Wiltshire a écrit : > >

Bug#1091932: debootstrap: Remove support for discontinued Tanglu derivative

2025-01-02 Thread Bastien Traverse
Package: debootstrap Severity: normal Tags: patch upstream Dear Maintainer, The Tanglu distribution has been discontinued since 2017. As such it should be removed (patch attached). All the best and happy new year, Bastien -- System Information: Debian Release: 12.8 APT prefers stable-updates

Bug#1091460: bookworm-pu: package node-postcss/8.4.20+~cs8.0.23-1+deb12u1

2024-12-27 Thread Bastien Roucariès
Le vendredi 27 décembre 2024, 15:48:30 UTC Salvatore Bonaccorso a écrit : > Hi Bastian, > > Just a small remark below: > > On Thu, Dec 26, 2024 at 09:38:26PM +, Bastien Roucariès wrote: > > Package: release.debian.org > > Severity: normal > > Tags: boo

Bug#1091460: bookworm-pu: package node-postcss/8.4.20+~cs8.0.23-1+deb12u1

2024-12-26 Thread Bastien Roucariès
loop. + + -- Bastien Roucari??s Thu, 26 Dec 2024 21:13:18 + + node-postcss (8.4.20+~cs8.0.23-1) unstable; urgency=medium * Team upload diff -Nru node-postcss-8.4.20+~cs8.0.23/debian/patches/CVE-2023-44270.patch node-postcss-8.4.20+~cs8.0.23/debian/patches/CVE-2023-44270.patch --- node

Bug#1091084: bookworm-pu: package libxstream-java 1.4.20-1+deb12u1

2024-12-22 Thread Bastien Roucariès
) bookworm; urgency=medium + + * Team upload + * Fix CVE-2024-47072: XStream is vulnerable to a +Denial of Service attack due to stack overflow +from a manipulated binary input stream. +(Closes: #1087274) + + -- Bastien Roucari??s Sun, 22 Dec 2024 10:12:11 + + libxstream-java (1.4.20

Bug#1090759: systemd-ukify depends on third party 'cryptography' Python package which is not installed by default

2024-12-18 Thread bastien
Package: systemd-ukify Version: 257-2 Severity: important X-Debbugs-Cc: bast...@gandouet.fr A call to `ukify genkey` (after having installed `systemd-ukify`) will result in a Python stacktrace highlighting the fact that the `cryptography` module is not available Installing this module to the gl

Bug#1084167: postfix: should not enable chroot by default, like upstream

2024-12-01 Thread Bastien Roucariès
s various issues: see the postfix bug reports mentioning chroot. > > Please disable chroot for all services (upstream's default). I think we should move to bind mount or something like unshare Bastien > > -- System Information: > Debian Release: trixie/sid > APT

Bug#1088649: imagick autopkgtest

2024-11-29 Thread Bastien Roucariès
control: tags -1 + patch Hi, You forget to upgrade the test dependency to newer imagemagick and imagemagick library Bastien signature.asc Description: This is a digitally signed message part.

Bug#1086262: Use pkg-conf

2024-11-24 Thread Bastien Roucariès
Hi, This kind of error is likely due because you do not use pkg-conf to get the config flags. Please use it Bastien

Bug#1086224: RC: Argument " " isn't numeric in division (/) at /usr/share/perl5/GD/SecurityImage/Magick.pm

2024-11-05 Thread Bastien Roucariès
control: tags -1 + important Le mardi 29 octobre 2024, 17:18:03 UTC gregor herrmann a écrit : > On Tue, 29 Oct 2024 16:08:30 +, Niko Tyni wrote: > > > This gives a list of thirteen integers on trixie, but > > just one undef on sid. > > > > Is this an intentional API change in ImageMagick 7 t

Bug#1086503: The underlying request may be to add 32 bit equivalents of 64 bit caps where the feature is actually accessible from 32 bits

2024-11-05 Thread Bastien Roucariès
control: forwarded -1 http://lists.infradead.org/pipermail/linux-arm-kernel/2024-November/976054.html signature.asc Description: This is a digitally signed message part.

Bug#1086502: libc6-dev: Please add newer hwcap hwcap2 particularly for ARM*

2024-11-01 Thread Bastien Roucariès
Le vendredi 1 novembre 2024, 11:57:17 UTC Aurelien Jarno a écrit : Hi aurelien, > control: severity -1 wishlist > > Hi, > > On 2024-10-31 11:24, Bastien Roucariès wrote: > > Package: libc6-dev > > Version: 2.40-3 > > Severity: normal > > Tags: upstream &

Bug#1086503: The underlying request may be to add 32 bit equivalents of 64 bit caps where the feature is actually accessible from 32 bits

2024-10-31 Thread Bastien Roucariès
Hi; In order to be clear the underlying request is to add 32 bit equivalents of 64 bit caps where the feature is actually accessible from 32 bits and make sense the second wave of crypto instructions (sha3, sha512) was not added to arm32 Bastien signature.asc Description: This is a digitally

Bug#1086503: linux: Please get HWCAP and HWCAP2 in sync between 32bits and 64bits architecture

2024-10-31 Thread Bastien Roucariès
Source: linux Severity: wishlist Tags: upstream affects: src:isa-support Dear Maintainer, HWCAP and HWCAP2 (used by getauxval) are not in sync between 32bits and 64bits arch for the same processor. for arm64 for instance see https://docs.kernel.org/arch/arm64/elf_hwcaps.html they are more hardw

Bug#1086502: libc6-dev: Please add newer hwcap hwcap2 particularly for ARM*

2024-10-31 Thread Bastien Roucariès
Package: libc6-dev Version: 2.40-3 Severity: normal Tags: upstream Dear Maintainer, Newer hwcap/hwcap2 are not in sync for arm* particularly arm32 (including crc32 flags) Can you add it. Thanks Bastien signature.asc Description: This is a digitally signed message part.

Bug#1060103: New of imagemagick7

2024-10-30 Thread Bastien Roucariès
Le mercredi 23 octobre 2024, 12:03:21 UTC Emilio Pozuelo Monfort a écrit : Hi, > Control: tags -1 confirmed > > On 20/10/2024 11:04, Bastien Roucariès wrote: > > Le jeudi 17 octobre 2024, 20:02:56 UTC Johannes Schauer Marin Rodrigues a > > écrit : > >> Hi, > >

Bug#1086224: RC: Argument " " isn't numeric in division (/) at /usr/share/perl5/GD/SecurityImage/Magick.pm

2024-10-29 Thread Bastien Roucariès
Le mardi 29 octobre 2024, 16:08:30 UTC Niko Tyni a écrit : > On Tue, Oct 29, 2024 at 07:59:25AM +0000, Bastien Roucariès wrote: > > Package: libgd-securityimage-perl > > Version: 1.75-3 > > Severity: serious > > Justification: Break transition imagemagick 7 > > &

Bug#1086224: RC: Argument " " isn't numeric in division (/) at /usr/share/perl5/GD/SecurityImage/Magick.pm

2024-10-29 Thread Bastien Roucariès
Package: libgd-securityimage-perl Version: 1.75-3 Severity: serious Justification: Break transition imagemagick 7 Dear Maintainer, Last autopkgtest for imagemagick7 fail with a lot of message on stderr. I suppose a depends on fonts is missing: 30s Argument " " isn't numeric in division (/) at /

Bug#1060103: New of imagemagick7

2024-10-20 Thread Bastien Roucariès
Le jeudi 17 octobre 2024, 20:02:56 UTC Johannes Schauer Marin Rodrigues a écrit : > Hi, > > On Tue, 24 Sep 2024 12:58:48 +0000 Bastien =?ISO-8859-1?Q?Roucari=E8s?= > wrote: > > Le mardi 20 août 2024, 07:11:13 UTC Emilio Pozuelo Monfort a écrit : > > > On 28/07/20

Bug#1085453: dompurify

2024-10-19 Thread Bastien Roucariès
to use last debian version moreover could you document in the security tracker that you embed for old version dompurify ? Bastien signature.asc Description: This is a digitally signed message part.

Bug#1085455: form-history-control: dompurify

2024-10-19 Thread Bastien Roucariès
Source: form-history-control Version: dompurify Severity: serious Tags: security Justification: security X-Debbugs-Cc: Debian Security Team Dear Maintainer, you include a copy a dompurify that seems to be affected by recent CVE https://sources.debian.org/src/form-history-control/2.5.1.0-1/commo

Bug#1085026: bookworm-pu: package docker.io/20.10.24+dfsg1+deb12u1

2024-10-13 Thread Bastien Roucariès
Docker Engine, +which could allow an attacker +to bypass authorization plugins (AuthZ) under specific +circumstances. The base likelihood of this being exploited is low. +(Closes: #1084993) + + -- Bastien Roucari??s Sat, 12 Oct 2024 15:19:49 + + docker.io (20.10.24+dfsg1-1

Bug#1085009: bookworm-pu: package python-reportlab/3.6.12-1+deb12u1

2024-10-13 Thread Bastien Roucariès
Le dimanche 13 octobre 2024, 11:18:12 UTC Moritz Mühlenhoff a écrit : > On Sat, Oct 12, 2024 at 07:36:46PM +0000, Bastien Roucariès wrote: > > Package: release.debian.org > > Severity: normal > > Tags: bookworm > > X-Debbugs-Cc: python-report...@packages.debian.org, secu

Bug#1085009: bookworm-pu: package python-reportlab/3.6.12-1+deb12u1

2024-10-12 Thread Bastien Roucariès
/changelog 2024-10-12 17:14:35.0 + @@ -1,3 +1,13 @@ +python-reportlab (3.6.12-1+deb12u1) bookworm-security; urgency=high + + * Team upload + * Fix CVE-2023-33733 +Reportlab was vulnerable to Remote Code Execution (RCE) +via crafted PDF file. + * Add SalsaCI + + -- Bastien Roucari??s

Bug#1084993: docker.io: CVE-2024-41110

2024-10-12 Thread Bastien Roucariès
Engine v18.09.1 in January 2019, the fix was not carried forward to later major versions, resulting in a regression. Anyone who depends on authorization plugins that introspect the request and/or response body to make access control decisions is potentially impacted. I plan to prepare a PU Bastien

Bug#1084222: elpa-org: can no longer export to beamer

2024-10-06 Thread Bastien
"IOhannes m zmölnig (Debian/GNU)" writes: > since i've upgraded elpa-org to 9.7.11+dfsg-1, I can no longer export my > presentations to LaTeX/beamer. Can you report this bug to the Org-mode mailing list using M-x org-submit-bug-report RET? Thanks! -- Bastien

Bug#799105: Moreinfo: SPNEGO authentication headers can be up to 12392 bytes.

2024-10-06 Thread Bastien Roucariès
control: tags -1 + moreinfo According to a quick research: The solution was to raise the HTTP request header field size with the following directive: LimitRequestFieldSize 65536 Have a look at the official Apache HTTPD documentation of this directive: The LimitRequestFieldSize directive

Bug#1082761: lintian: libjs-async no longer exists in unstable; please change embedded-javascript-library please use libjs-async warning

2024-09-27 Thread Bastien Roucariès
o make the change you propose if I'm wrong though. > > > > Cheers, > > Hi Louis-Philippe, > > Good question! Presumably people would have hand-modified their code > to include a symlink to the file in /usr/share/javascript; the > equivalent file in node-async

Bug#1060103: New of imagemagick7

2024-09-24 Thread Bastien Roucariès
Le mardi 20 août 2024, 07:11:13 UTC Emilio Pozuelo Monfort a écrit : > On 28/07/2024 20:56, Bastien Roucariès wrote: > > control: tags -1 - moreinfo > > > > Hi, > > > > Last reverse deps of lib magick pipeline is not really bad > > https://salsa.debian.or

Bug#1081266: apache2: Reverse proxy via mod_rewrite broken after upgrade to 2.4.62-1~deb12u1

2024-09-10 Thread Bastien Roucariès
downgrades install apache2=2.4.61-1~deb12u1 > > > apache2-data=2.4.61-1~deb12u1 apache2-bin=2.4.61-1~deb12u1 > > > apache2-utils=2.4.61-1~deb12u1 > > > > > > After the downgrade, the RewriteRule with the proxy directive is back to > > > working as exp

Bug#1079558: HDRI16 is not the default: Magick++.pc

2024-08-30 Thread Bastien Roucariès
control: tags -1 + upstream Le vendredi 30 août 2024, 12:59:12 UTC Christian Marillat a écrit : > On 30 août 2024 12:45, Bastien Roucariès wrote: > > > [...] > > >> >> Yes, as Magick++-7.Q16HDRI isn't the expected name. > >> > >

Bug#1079558: HDRI16 is not the default: Magick++.pc

2024-08-30 Thread Bastien Roucariès
Le vendredi 30 août 2024, 12:43:24 UTC Christian Marillat a écrit : > On 30 août 2024 12:39, Bastien Roucariès wrote: > > > Le vendredi 30 août 2024, 12:33:31 UTC Christian Marillat a écrit : > >> On 30 août 2024 12:23, Bastien Roucariès wrote: > >> > >&g

Bug#1079558: HDRI16 is not the default: Magick++.pc

2024-08-30 Thread Bastien Roucariès
Le vendredi 30 août 2024, 12:33:31 UTC Christian Marillat a écrit : > On 30 août 2024 12:23, Bastien Roucariès wrote: > > > Le vendredi 30 août 2024, 12:12:43 UTC Christian Marillat a écrit : > >> On 30 août 2024 09:33, Bastien Roucariès wrote: > >> > >> [

Bug#1079558: HDRI16 is not the default: Magick++.pc

2024-08-30 Thread Bastien Roucariès
Le vendredi 30 août 2024, 12:12:43 UTC Christian Marillat a écrit : > On 30 août 2024 09:33, Bastien Roucariès wrote: > > > [...] > > > pkgconf with the HDRI name coded in it should work > > pkgconf --libs Magick++-7.Q16HDRI > > But as I'm saying befo

Bug#1079558: HDRI16 is not the default: Magick++.pc

2024-08-30 Thread Bastien Roucariès
Le vendredi 30 août 2024, 09:33:29 UTC Bastien Roucariès a écrit : > Le vendredi 30 août 2024, 09:26:54 UTC Christian Marillat a écrit : > > On 30 août 2024 08:23, Bastien Roucariès wrote: > > > > > control: tags -1 + moreinfo > > > > > > Hi, > >

Bug#1079558: HDRI16 is not the default: Magick++.pc

2024-08-30 Thread Bastien Roucariès
Le vendredi 30 août 2024, 09:26:54 UTC Christian Marillat a écrit : > On 30 août 2024 08:23, Bastien Roucariès wrote: > > > control: tags -1 + moreinfo > > > > Hi, > > > > Magick++.pc is the name of the default config that is shipped by the Q16 > &

Bug#1079558: HDRI16 is not the default: Magick++.pc

2024-08-30 Thread Bastien Roucariès
o use alternative system. Bastien signature.asc Description: This is a digitally signed message part.

Bug#1079579: bookworm-pu: package cacti/1.2.24+ds1-1+deb12u4

2024-08-24 Thread Bastien Roucariès
-maintainer upload by the LTS Security Team. + * Add SALSA-CI. + * Backport autopkgtest from trixie. + + -- Bastien Roucari??s Sat, 24 Aug 2024 14:04:49 + + cacti (1.2.24+ds1-1+deb12u3) bookworm; urgency=medium * Non-maintainer upload by the LTS Security Team. diff -Nru cacti-1.2.24

Bug#1079353: bookworm-pu: package cacti/1.2.24+ds1-1+deb12u3

2024-08-24 Thread Bastien Roucariès
Le samedi 24 août 2024, 13:35:03 UTC Paul Gevers a écrit : > Hi Bastien, > > On 24-08-2024 15:18, Bastien Roucariès wrote: > > Le samedi 24 août 2024, 11:03:38 UTC Paul Gevers a écrit : > >> I'm wondering if you may have hardened cacti and that if fails on that > &

Bug#1079353: bookworm-pu: package cacti/1.2.24+ds1-1+deb12u3

2024-08-24 Thread Bastien Roucariès
Le samedi 24 août 2024, 11:03:38 UTC Paul Gevers a écrit : > Hi, > > On 24-08-2024 10:31, Bastien Roucariès wrote: > > Could you reject the time of investigation ? > > I'm wondering if you may have hardened cacti and that if fails on that > now. If this is to b

Bug#1079353: bookworm-pu: package cacti/1.2.24+ds1-1+deb12u3

2024-08-24 Thread Bastien Roucariès
Le samedi 24 août 2024, 06:04:39 UTC Paul Gevers a écrit : > Hi, > > On 22-08-2024 17:38, Bastien Roucariès wrote: > > [ Tests ] > > Automated test and manual test of the application by myself and others, > > including users. > > Did you run the autopk

Bug#1060103: New of imagemagick7

2024-08-23 Thread Bastien Roucariès
Hi, Le mercredi 21 août 2024, 12:53:39 UTC Bastien Roucariès a écrit : > Le mardi 20 août 2024, 07:37:46 UTC Bastien Roucariès a écrit : > > Le mardi 20 août 2024, 07:11:13 UTC Emilio Pozuelo Monfort a écrit : > > > On 28/07/2024 20:56, Bastien Roucariès wrote: > > > &g

Bug#1079465: FTBFS with newer imagemagick7

2024-08-23 Thread Bastien Roucariès
Source: ruby-mojo-magick Tags: ftbfs Control: block 1060103 by -1 Control: tag -1 + sid Dear Maintainer, You package FTBFS with newer imagemagick Could you help the transition Full log could be found here https://salsa.debian.org/debian/imagemagick/-/jobs/6167776 Thanks Rouca signature.asc

Bug#1079455: Moreinfo

2024-08-23 Thread Bastien Roucariès
control: tags -1 + moreinfo We get information that this upgrade may break some unrelated software Could you wait a little bit ? Thanks Bastien signature.asc Description: This is a digitally signed message part.

Bug#1079353: bookworm-pu: package cacti/1.2.24+ds1-1+deb12u3

2024-08-22 Thread Bastien Roucariès
Le jeudi 22 août 2024, 18:01:02 UTC Adam D. Barratt a écrit : > Control: tags -1 + moreinfo > > On Thu, 2024-08-22 at 15:38 +, Bastien Roucariès wrote: > > [ Reason ] > > Security upload. Except CVE-2024-27082 that need > > coordination with other packages. >

Bug#1079353: bookworm-pu: package cacti/1.2.24+ds1-1+deb12u3

2024-08-22 Thread Bastien Roucariès
Package: release.debian.org Severity: normal Tags: bookworm X-Debbugs-Cc: ca...@packages.debian.org Control: affects -1 + src:cacti User: release.debian@packages.debian.org Usertags: pu [ Reason ] Security upload. Except CVE-2024-27082 that need coordination with other packages. [ Impact ] CV

Bug#1079348: FTBFS with newer imagemagick7

2024-08-22 Thread Bastien Roucariès
Source: converseen Severity: important Tags: ftbfs Control: block 1060103 by -1 Control: tag -1 + sid Dear Maintainer, You package FTBFS with newer imagemagick Could you help the transition Full log could be found here https://salsa.debian.org/debian/imagemagick/-/jobs/6158068 rouca signature

Bug#1079342: FTBFS with newer imagemagick7

2024-08-22 Thread Bastien Roucariès
Source: lebiniou Tags: ftbfs Control: block 1060103 by -1 Control: tag -1 + sid Dear Maintainer, You package FTBFS with newer imagemagick Could you help the transition Full log could be found here https://salsa.debian.org/debian/imagemagick/-/jobs/6158076 Thanks Rouca signature.asc Descript

Bug#1079339: FTBFS with newer imagemagick7

2024-08-22 Thread Bastien Roucariès
Source: pythonmagick Severity: important Tags: ftbfs Control: block 1060103 by -1 Control: tag -1 + sid Dear Maintainer, You package FTBFS with newer imagemagick Could you help the transition Full log could be found here https://salsa.debian.org/debian/imagemagick/-/jobs/6164324 signature.asc

Bug#1079343: FTBFS with newer imagemagick7

2024-08-22 Thread Bastien Roucariès
Source: jmagick Severity: important Tags: ftbfs Control: block 1060103 by -1 Control: tag -1 + sid Dear Maintainer, You package FTBFS with newer imagemagick Could you help the transition Full log could be found here https://salsa.debian.org/debian/imagemagick/-/jobs/6158077 signature.asc Descr

Bug#1079337: FTBFS with newer imagemagick7

2024-08-22 Thread Bastien Roucariès
Source: ruby-rmagick Severity: important Tags: ftbfs Control: block 1060103 by -1 Control: tag -1 + sid Dear Maintainer, You package FTBFS with newer imagemagick Could you help the transition Full log could be found here https://salsa.debian.org/debian/imagemagick/-/jobs/6164327 signature.asc

Bug#1079338: FTBFS with newer imagemagick7

2024-08-22 Thread Bastien Roucariès
Source: rss-glx Severity: important Tags: ftbfs Control: block 1060103 by -1 Control: tag -1 + sid Dear Maintainer, You package FTBFS with newer imagemagick Could you help the transition Full log could be found here https://salsa.debian.org/debian/imagemagick/-/jobs/6164326 signature.asc Des

Bug#1079336: vdr-plugin-skinenigmang: FTBFS with newer imagemagick7

2024-08-22 Thread Bastien Roucariès
Source: vdr-plugin-skinenigmang Severity: important Tags: ftbfs Control: block 1060103 by -1 Control: tag -1 + sid Dear Maintainer, You package FTBFS with newer imagemagick Could you help the transition Full log could be found here https://salsa.debian.org/debian/imagemagick/-/jobs/6164331 si

Bug#1079335: synfig: FTBFS ffmpeg

2024-08-22 Thread Bastien Roucariès
Source: synfig Severity: serious Tags: ftbfs Justification: ftbfs Dear Maintainer, Your package fail to build from source, and seems to be related to ffmpeg Tested during rebuild for imagemagick could be found here https://salsa.debian.org/debian/imagemagick/-/jobs/6164328 configure:22159: resu

Bug#1079288: virtuoso-opensource: FTBFS

2024-08-22 Thread Bastien Roucariès
Source: virtuoso-opensource Severity: serious Tags: ftbfs sid Justification: FTBFS Dear Maintainer, Your package FTBFS: Dksesstr.c: In function 'strdev_free_buf': Dksesstr.c:152:44: warning: unused parameter 'arg' [-Wunused-parameter] 152 | strdev_free_buf (buffer_elt_t * b, caddr_t arg)

Bug#1079164: devscripts: Files-Excluded version of regexp should be documented and if not pcre Files-Excluded-PCRE should be created

2024-08-22 Thread Bastien Roucariès
Le jeudi 22 août 2024, 02:43:41 UTC Yadd a écrit : > On 8/22/24 02:06, Bastien Roucariès wrote: > > Le mercredi 21 août 2024, 11:07:17 UTC Niels Thykier a écrit : > >> On Tue, 20 Aug 2024 18:50:20 + Bastien =?ISO-8859-1?Q?Roucari=E8s?= > >> wrote: > >>

Bug#1079164: devscripts: Files-Excluded version of regexp should be documented and if not pcre Files-Excluded-PCRE should be created

2024-08-21 Thread Bastien Roucariès
Le mercredi 21 août 2024, 11:07:17 UTC Niels Thykier a écrit : > On Tue, 20 Aug 2024 18:50:20 +0000 Bastien =?ISO-8859-1?Q?Roucari=E8s?= > wrote: > > Package: devscripts > > Version: 2.23.7 > > Severity: minor > > > > Dear Maintainer, > > > &g

Bug#1060103: New of imagemagick7

2024-08-21 Thread Bastien Roucariès
Le mardi 20 août 2024, 07:37:46 UTC Bastien Roucariès a écrit : > Le mardi 20 août 2024, 07:11:13 UTC Emilio Pozuelo Monfort a écrit : > > On 28/07/2024 20:56, Bastien Roucariès wrote: > > > control: tags -1 - moreinfo > > > > > > Hi, > > > > >

Bug#1079206: CVE-2024-39884 Regression

2024-08-21 Thread Bastien Roucariès
Package: apache2 Severity: important Forwarded: https://github.com/apache/httpd/pull/475 Control: tags -1 + bullseye Control: tags -1 + bookworm Control: tags -1 + upstream Control: tags -1 + security Dear Maintainer, A tracking bug for a regression https://github.com/apache/httpd/pull/475 Rouca

Bug#1079172: CVE-2024-38474/CVE-2024-38475 Regression

2024-08-20 Thread Bastien Roucariès
plications which contain a %3F > somewhere in the query string. This commonly happens e.g. for search forms > (the user may enter a question mark as part of the search query) and for > scripts that send an URL in a query string (for example > ?referer=https%3A%2F%2Fexample.com%2F%3Ffoo%3Dbar). > > Thanks Bastien signature.asc Description: This is a digitally signed message part.

Bug#1079171: CVE-2024-38473 Regression [2/2]: error parsing URL //: with space

2024-08-20 Thread Bastien Roucariès
01060: set r->filename to >proxy:fcgi://user-php82fpm/path_to_docroot/ja/%E3%82%A2%E3%83%80%E3%83%97%E3%82%BF/index.php > >We fixed it with a symlink for now, which isn´t a good solution. Thanks Bastien signature.asc Description: This is a digitally signed message part.

  1   2   3   4   5   6   7   8   9   10   >