Bug#488696: comedi-source build fails (m-a a-i comedi)

2008-08-24 Thread Gudjon I. Gudjonsson
Hi I can confirm that Comedi works on my amd64 computer with kernel 2.6.26. I have tested it with Adlink PCI-9111 AD converter card, reading from it with xoscope. Please don't remove Comedi from Lenny. Cheers Gudjon -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsub

Bug#496125: libxml2 problem confirmed on different platform: etch ppc

2008-08-24 Thread Emmanuel Kasper
Package: libxml2 Followup-For: Bug #496125 Hello Sorry for the me-too of this report, but I can confirm this bug on debian etch running on a single processor ppc (G4) 32 bits platform. It happens I also use the Gorilla theme, and the symptoms were exactly those reported in message 39 of this bug r

Bug#496490: adolc_1.10.2-3(sparc/unstable): FTBFS, fails while dpkg-gensymbols

2008-08-24 Thread Martin Zobel-Helas
Package: adolc Version: 1.10.2-3 Severity: serious There was an error while trying to autobuild your package: > Automatic build of adolc_1.10.2-3 on spontini by sbuild/sparc 99.99 > Build started at 20080819-1358 [...] > ** Using build dependencies supplied by package: > Build-Depends: debhelpe

Bug#496421: marked as done (The possibility of attack with the help of symlinks in some Debian packages)

2008-08-24 Thread Debian Bug Tracking System
Your message dated Mon, 25 Aug 2008 06:02:26 + with message-id <[EMAIL PROTECTED]> and subject line Bug#496421: fixed in vdr 1.6.0-6 has caused the Debian Bug report #496421, regarding The possibility of attack with the help of symlinks in some Debian packages to be marked as done. This mean

Bug#496272: xserver-xorg: fonts and menu icons are blank in pristine lenny install

2008-08-24 Thread Brice Goglin
Mark Hedges wrote: > But I just re-installed and now it is fine. Weird. > What did you reinstall? The whole machine? Can you send the corresponding config and log? Brice -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Bug#496486: synce-kpm: Program does not do anything

2008-08-24 Thread Alex Hermann
Package: synce-kpm Version: 0.11.1-1 Severity: grave Justification: renders package unusable After installing I started the program. It just sits around doing absolutely nothing. ActiveSync Status says: "Make sure Sync-Engine is running...". (No hint as to how to make it running) Connecting the P

Bug#496272: xserver-xorg: fonts and menu icons are blank in pristine lenny install

2008-08-24 Thread Mark Hedges
Actually it happened whether I used the intel driver or the generic driver, framebuffer or not. But I just re-installed and now it is fine. Weird. Mark On Sun, 24 Aug 2008, Brice Goglin wrote: > Mark Hedges wrote: > > Package: xserver-xorg > > Version: 1:7.3+15 > > Severity: grave > > Justifi

Bug#496484: gnu-smalltalk_3.1~rc3-1(experimental/alpha/ds10): Testsuite failure (118: ROE)

2008-08-24 Thread Marc 'HE' Brockschmidt
Package: gnu-smalltalk Version: 3.1~rc3-1 Severity: serious Tags: experimental Heya, Building your package failed on my alpha buildd: | Automatic build of gnu-smalltalk_3.1~rc3-1 on ds10 by sbuild/alpha 98-farm | Build started at 20080824-0856

Bug#496480: openoffice.org_1:3.0.0~ooo300m3-2(experimental/i386/demosthenes): gcj-dbtool: command not found

2008-08-24 Thread Marc 'HE' Brockschmidt
Package: openoffice.org Version: 1:3.0.0~ooo300m3-2 Severity: serious Tags: experimental Heya, Building OO.org on i386 failed: | Automatic build of openoffice.org_1:3.0.0~ooo300m3-2 on demosthenes.ayous.org by sbuild/i386 98-farm | Build started at 20080824-1338

Bug#496482: neon25 transitional packages not installable

2008-08-24 Thread Luk Claes
Package: neon27 Version: 0.28.2-3 Severity: serious Hi libneon25, libneon25-dbg and libneon25-dev transitional packages are not installable as the neon27 counterparts conflict with them. You should version the conflict to solve this bug as otherwise the package won't transition to testing beca

Bug#496479: openoffice.org_1:3.0.0~ooo300m3-2(experimental/powerpc/anakreon): /usr/bin/ld: cannot find -ljawt

2008-08-24 Thread Marc 'HE' Brockschmidt
Package: openoffice.org Version: 1:3.0.0~ooo300m3-2 Severity: serious Tags: experimental Heya, Building OO.org on ppc failed: | Automatic build of openoffice.org_1:3.0.0~ooo300m3-2 on anakreon.ayous.org by sbuild/powerpc 98-farm | Build started at 20080824-1134

Processed: severity of 496349 is important

2008-08-24 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > # Automatically generated email from bts, devscripts version 2.10.35 > severity 496349 important Bug#496349: libfcgi-perl: download link in copyright file is broken Severity set to `important' from `serious' > End of message, stopping processing here.

Bug#496361: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Rene Engelhard
Hi again, Rene Engelhard wrote: > I so far thought mktemp was safe enough? (of course, we get > senddoc.mutt., but... Sorry, missed the final sentence: What do you propose instead? Regards, Rene -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact

Bug#496361: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Rene Engelhard
Hi, Dmitry E. Oboukhov wrote: > For example if a script uses in its work a temp file which is created > in /tmp directory, then every user can create symlink with the same > name in this directory in order to destroy or rewrite some system > or user file. Symlink attack may also lead n

Bug#496366: [Debian-med-packaging] Bug#496366: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Charles Plessy
tag 496366 help thanks Le Sun, Aug 24, 2008 at 10:05:28PM +0400, Dmitry E. Oboukhov a écrit : > Package: mafft > Severity: grave > > In some packages I've discovered scripts with errors which may be used > by a user for damaging important system files or user's files. Hi all, I have not followe

Processed: Re: [Debian-med-packaging] Bug#496366: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > tag 496366 help Bug#496366: The possibility of attack with the help of symlinks in some Debian packages There were no tags set. Tags added: help > thanks Stopping processing here. Please contact me if you need assistance. Debian bug tracking system

Bug#495353: gdal-bin: gdalinfo segfaults on a 6.2Mib netCDF file

2008-08-24 Thread Petter Reinholdtsen
merge 495353 495354 thanks [Paulo Marcondes] > when trying gdalinfo 3n24s47w14w.grd, I get a segmentation fault. > data was downloaded from > http://www.bodc.ac.uk/data/online_delivery/gebco/select/ Please try to rund the same command under valgrind, ie valgrind gdalinfo 3n24s47w14w.grd and

Processed: Re: Bug#495353: gdal-bin: gdalinfo segfaults on a 6.2Mib netCDF file

2008-08-24 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > merge 495353 495354 Bug#495353: gdal-bin: gdalinfo segfaults on a 6.2Mib netCDF file Bug#495354: gdalinfo segfaults on a 6.2Mib netCDF file Merged 495353 495354. > thanks Stopping processing here. Please contact me if you need assistance. Debian bug

Bug#496363: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Dirk Eddelbuettel
On 25 August 2008 at 04:11, Nico Golde wrote: | Hi Dirk, | * Dirk Eddelbuettel <[EMAIL PROTECTED]> [2008-08-25 03:07]: | > I think it is a false positive: | > | > # test functionality of the compiler | > javac_works='not present' | > if test -n "$JAVAC"; then | > javac_works='not functional'

Bug#496455: marked as done (kdesktop: user cannot unlock screen with correct password)

2008-08-24 Thread Debian Bug Tracking System
Your message dated Mon, 25 Aug 2008 04:17:39 +0200 with message-id <[EMAIL PROTECTED]> and subject line Re: Bug#496455: Acknowledgement (kdesktop: user cannot unlock screen with correct password) has caused the Debian Bug report #496455, regarding kdesktop: user cannot unlock screen with correct

Bug#495954: libldap bug - related to replaces/conflicts, but no provides?

2008-08-24 Thread David Hall (coding)
I'm wondering if this is related to the issues I had when installing wine from winehq.org (which also involved libldap breakage). The following is from a discussion with Scott Ritchie: David Hall (coding) wrote: > The current problem seems to be due to libldap2 (which is a dependency of > wine). T

Bug#496456: marked as done (kdebase-bin: user cannot unlock screen with correct password)

2008-08-24 Thread Debian Bug Tracking System
Your message dated Mon, 25 Aug 2008 04:17:39 +0200 with message-id <[EMAIL PROTECTED]> and subject line Re: Bug#496455: Acknowledgement (kdesktop: user cannot unlock screen with correct password) has caused the Debian Bug report #496456, regarding kdebase-bin: user cannot unlock screen with corre

Bug#496363: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Nico Golde
Hi Dirk, * Dirk Eddelbuettel <[EMAIL PROTECTED]> [2008-08-25 03:07]: > I think it is a false positive: > > # test functionality of the compiler > javac_works='not present' > if test -n "$JAVAC"; then > javac_works='not functional' > rm -rf /tmp/A.java /tmp/A.class ## <- note the

Bug#477637: marked as done (hangs when running adjtimexconfig during postinst)

2008-08-24 Thread Debian Bug Tracking System
Your message dated Sun, 24 Aug 2008 21:57:44 -0400 with message-id <[EMAIL PROTECTED]> and subject line hangs when running adjtimexconfig during postinst has caused the Debian Bug report #477637, regarding hangs when running adjtimexconfig during postinst to be marked as done. This means that you

Bug#496362: marked as done (The possibility of attack with the help of symlinks in some Debian packages)

2008-08-24 Thread Debian Bug Tracking System
Your message dated Mon, 25 Aug 2008 09:53:10 +0800 with message-id <[EMAIL PROTECTED]> and subject line Re: Bug#496362: The possibility of attack with the help of symlinks in some Debian packages has caused the Debian Bug report #496362, regarding The possibility of attack with the help of symlin

Bug#496362: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Thomas Goirand
Dmitry E. Oboukhov wrote: > Package: dtc-common > Severity: grave > > Hi, maintainer! > > This message about the error concerns a few packages at once. I've > tested all the packages (for Lenny) on my Debian mirror. All scripts > of packages (marked as executable) were tested. > > In some

Bug#496418: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Stephen Gran
This one time, at band camp, Dirk Eddelbuettel said: > > On 25 August 2008 at 01:43, Stephen Gran wrote: > | This one time, at band camp, Dirk Eddelbuettel said: > | > > | > This is the same as the one I just answered for r-base-core-ra as > | > r-base-core-ra is an extension/specialisation of r-

Bug#496418: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Dirk Eddelbuettel
On 25 August 2008 at 01:43, Stephen Gran wrote: | This one time, at band camp, Dirk Eddelbuettel said: | > | > This is the same as the one I just answered for r-base-core-ra as | > r-base-core-ra is an extension/specialisation of r-base-core. | > | > So again: | > | > # test functionality of th

Bug#496432: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread André Luís Lopes
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 André Luís Lopes escreveu: > Hello, > > André Luís Lopes escreveu: >>I'll be following up to this bug with the bug number of the removal >> request as soon as I receive it from BTS. > >As promised, the bug number of the removal request is 496

Bug#496432: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread André Luís Lopes
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hello, André Luís Lopes escreveu: > >I'll be following up to this bug with the bug number of the removal > request as soon as I receive it from BTS. As promised, the bug number of the removal request is 496432. Regards, !DSPAM:1,48b1edc510

Bug#332782: Release Notes: license clarification

2008-08-24 Thread W. Martin Borgert
On 2008-08-24 12:19, Steve Langasek wrote: > I was a release note editor for the last release only; my contributions are > far less than those of many others on that list, it's not really fair to > call me a "main" author... OK. > Legally, there is no reason to require GPG-signed email; and there

Bug#496418: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Stephen Gran
This one time, at band camp, Dirk Eddelbuettel said: > > This is the same as the one I just answered for r-base-core-ra as > r-base-core-ra is an extension/specialisation of r-base-core. > > So again: > > # test functionality of the compiler > javac_works='not present' > if test -n "$JAVAC"; the

Bug#494224: marked as done (perlipq: FTBFS: IPQueue.xs:11:20: error: libipq.h: No such file or directory)

2008-08-24 Thread Debian Bug Tracking System
Your message dated Mon, 25 Aug 2008 00:17:03 + with message-id <[EMAIL PROTECTED]> and subject line Bug#494216: fixed in iptables 1.4.1.1-3 has caused the Debian Bug report #494216, regarding perlipq: FTBFS: IPQueue.xs:11:20: error: libipq.h: No such file or directory to be marked as done. T

Bug#494216: marked as done (shaperd: FTBFS: packet.hpp:10:21: error: libipq.h: No such file or directory)

2008-08-24 Thread Debian Bug Tracking System
Your message dated Mon, 25 Aug 2008 00:17:03 + with message-id <[EMAIL PROTECTED]> and subject line Bug#494216: fixed in iptables 1.4.1.1-3 has caused the Debian Bug report #494216, regarding shaperd: FTBFS: packet.hpp:10:21: error: libipq.h: No such file or directory to be marked as done. T

Bug#496363: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Dirk Eddelbuettel
I think it is a false positive: # test functionality of the compiler javac_works='not present' if test -n "$JAVAC"; then javac_works='not functional' rm -rf /tmp/A.java /tmp/A.class ## <- note the rm -rf echo "public class A { }" > /tmp/A.java if test -e /tmp/A.java; the

Bug#496418: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Dirk Eddelbuettel
This is the same as the one I just answered for r-base-core-ra as r-base-core-ra is an extension/specialisation of r-base-core. So again: # test functionality of the compiler javac_works='not present' if test -n "$JAVAC"; then javac_works='not functional' rm -rf /tmp/A.java /tmp/A.class

Bug#496389: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Stephen Gran
This one time, at band camp, Dmitry E. Oboukhov said: > Hi, maintainer! > > This message about the error concerns a few packages at once. I've > tested all the packages (for Lenny) on my Debian mirror. All scripts > of packages (marked as executable) were tested. So, what is the error that

Bug#474909: marked as done (maxima: FTBFS: /bin/sh: ./maxima: No such file or directory)

2008-08-24 Thread Debian Bug Tracking System
Your message dated Sun, 24 Aug 2008 23:47:09 + with message-id <[EMAIL PROTECTED]> and subject line Bug#474909: fixed in maxima 5.16.2-1 has caused the Debian Bug report #474909, regarding maxima: FTBFS: /bin/sh: ./maxima: No such file or directory to be marked as done. This means that you cl

Bug#495257: [Pkg-utopia-maintainers] Bug#495257: dbus: System bus must not be restarted during package upgrades

2008-08-24 Thread Tyson Clugg
On Fri, 2008-08-22 at 22:11 +0200, Michael Biebl wrote: ... > As much as I disagree with upstream, that dbus should never be restarted > (I find the argument bogus, that a dbus restart is equivalent to a > kernel live-restart), I agree with Sam, that given the current > situation, and the many brea

Bug#495257: [Pkg-utopia-maintainers] Bug#495257: dbus: System bus must not be restarted during package upgrades

2008-08-24 Thread Tyson Clugg
On Fri, 2008-08-22 at 22:11 +0200, Michael Biebl wrote: > Sam Morris wrote: > > On Tue, 19 Aug 2008 15:13:14 +1000, Tyson Clugg wrote: > > > > > > > Given the current release situation, I think we should just not restart > > the bus for now. > > ...snip. That statement should not have been at

Bug#496432: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread André Luís Lopes
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hello, Moritz Muehlenhoff escreveu: > retitle 496432 ibackup: Several symlinks vulnerabilities > thanks > > On Sun, Aug 24, 2008 at 10:05:28PM +0400, Dmitry E. Oboukhov wrote: >> Package: ibackup >> Severity: grave >> >> Hi, maintainer! > > ibackup

Bug#494227: xmlroff: diff for NMU version 0.6.0-1.1

2008-08-24 Thread W. Martin Borgert
On 2008-08-25 00:13, Thomas Viehmann wrote: > Unfortunately, Martin, it makes the Debian refcard look ugly. > Nonetheless, I believe moving from segfault to quirky output > warrants closing the RC bug here. As such, I'll upload in the > next days unless someone objects. No objection from my side.

Bug#332782: Release Notes: license clarification

2008-08-24 Thread W. Martin Borgert
On 2008-08-24 20:36, Luk Claes wrote: > I guess bug submitters and/or patch providers would also count as > contributor? Yes. There are 16 bugs with a "patch" tag: #404891 - patch by Steve Langasek <[EMAIL PROTECTED]> #339081, #363056 - Japanese translation fixes by Kobayashi Noritada <[EMAIL

Bug#496378: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Moritz Muehlenhoff
On Sun, Aug 24, 2008 at 10:05:30PM +0400, Dmitry E. Oboukhov wrote: > Package: gdrae > Severity: grave > > Hi, maintainer! gdrae is indeed vulnerable to temp file attacks through /tmp/gdrae/palabra However, I have some doubts whether this should be fixed or gdrae rather be removed altogether: It

Bug#495530: [evolution] Evolution craches on startup

2008-08-24 Thread Marius Konitzer
On Sat, 2008-08-23 at 10:24 +0200, H.A.J. Koster wrote: > I did an strace, but my output looks different from that of the OP. I > don't want to hijack his bug report, so just ignore this message if you > think it doesn't relate. Same here. Looks like a quite similar problem with the same effect: Ev

Processed: Confirm bug.

2008-08-24 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > tags 496324 +confirmed Bug#496324: libglc-dev: dependencies missing There were no tags set. Tags added: confirmed > thanks Stopping processing here. Please contact me if you need assistance. Debian bug tracking system administrator (administrator, De

Bug#496462: nvi: security vulnerability in creation of shared directory in postinst

2008-08-24 Thread Jan Christoph Nordholz
Hi Raphael, your report is correct, but if /var/tmp/vi.recover was really a symlink to some existing directory (like /), mkdir -p won't fail at all - in fact, it won't even be executed because the [ -d ] test will already succeed. I'll fix it properly - thanks for catching it. Regards, Jan -

Bug#475036: removal doesnt seem an option atm, or?

2008-08-24 Thread Bastian Blank
On Mon, Aug 25, 2008 at 12:00:23AM +0200, Holger Levsen wrote: > linux-2.6 build-depends on kernel-package (>= 10.063). If the code still uses > kernel-package, and I have no reason to not believe the control file, removal > of kernel-package is not really an option at this time. This code is s

Bug#496424: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Moritz Muehlenhoff
severity 496424 wishlist retitle 496424 Generate temporary directory with mktemp thanks Dmitry E. Oboukhov wrote: > Package: firehol > Severity: grave > > Hi, maintainer! > Even if you create files or directories with help of function 'RANDOM' > or pid(), then your system is not protected. Attac

Bug#496456: Acknowledgement (kdebase-bin: user cannot unlock screen with correct password)

2008-08-24 Thread Steve Lane
Problem solved - please see Bug#496457. Please close. Thank you, -- Steve Lane System, Network and Security Administrator Doudna Lab Biomolecular Structure and Mechanism Group UC Berkeley -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL

Processed: Re: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > severity 496424 wishlist Bug#496424: The possibility of attack with the help of symlinks in some Debian packages Severity set to `wishlist' from `grave' > retitle 496424 Generate temporary directory with mktemp Bug#496424: The possibility of attack wi

Bug#496455: Acknowledgement (kdesktop: user cannot unlock screen with correct password)

2008-08-24 Thread Steve Lane
Problem solved - please see Bug#496457. Please close. Thank you, -- Steve Lane System, Network and Security Administrator Doudna Lab Biomolecular Structure and Mechanism Group UC Berkeley -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL

Bug#496462: nvi: security vulnerability in creation of shared directory in postinst

2008-08-24 Thread Raphael Geissert
Package: nvi Version: 1.79-25 Severity: grave Tags: security patch Hi everyone, Going through the list of packages listed at [1] I noticed the overrides are completely wrong and it *is* a security issue. I verified versions 1.79-25 and 1.81.6-3 (etch and lenny, respectively) of the package and

Bug#494227: xmlroff: diff for NMU version 0.6.0-1.1

2008-08-24 Thread Thomas Viehmann
tags 494227 + patch pending thanks Hi, The following is the diff for my proposed xmlroff 0.6.0-1.1 NMU. Unfortunately, Martin, it makes the Debian refcard look ugly. Nonetheless, I believe moving from segfault to quirky output warrants closing the RC bug here. As such, I'll upload in the next day

Processed: xmlroff: diff for NMU version 0.6.0-1.1

2008-08-24 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > tags 494227 + patch pending Bug#494227: xmlroff: Segmentation fault xmlroff --backend cairo There were no tags set. Tags added: patch, pending > thanks Stopping processing here. Please contact me if you need assistance. Debian bug tracking system adm

Bug#484463: marked as done (.pc files indirectly adds --export-dynamic to the linker flags)

2008-08-24 Thread Debian Bug Tracking System
Your message dated Sun, 24 Aug 2008 21:47:09 + with message-id <[EMAIL PROTECTED]> and subject line Bug#484463: fixed in enchant 1.4.2-3.1 has caused the Debian Bug report #484463, regarding .pc files indirectly adds --export-dynamic to the linker flags to be marked as done. This means that y

Bug#496426: marked as done (The possibility of attack with the help of symlinks in some Debian packages)

2008-08-24 Thread Debian Bug Tracking System
Your message dated Sun, 24 Aug 2008 22:02:03 + with message-id <[EMAIL PROTECTED]> and subject line Bug#496426: fixed in rancid 2.3.2~a8-2 has caused the Debian Bug report #496426, regarding The possibility of attack with the help of symlinks in some Debian packages to be marked as done. Thi

Bug#491182: marked as done (byacc: CVE-2008-3196: out of bound access)

2008-08-24 Thread Debian Bug Tracking System
Your message dated Sun, 24 Aug 2008 21:47:07 + with message-id <[EMAIL PROTECTED]> and subject line Bug#491182: fixed in byacc 20070509-1.1 has caused the Debian Bug report #491182, regarding byacc: CVE-2008-3196: out of bound access to be marked as done. This means that you claim that the pr

Bug#491505: [package varmon] varmon segfaults on Etch i386

2008-08-24 Thread Christoph Franzen
Am Sun, 17 Aug 2008 09:52:56 +0200 schrieb Julien Danjou <[EMAIL PROTECTED]>: > I'm preparing a new upstream release and will push it back to Debian > ASAP (expect everything tomorrow). Thank you for fixing the bug, it works for me now, no problems so far. > Thanks for the box Christoph. It was

Bug#475036: removal doesnt seem an option atm, or?

2008-08-24 Thread Holger Levsen
Hi, today there are still two packages depending on kernel-package, cdfs-src and linux-2.6. dphys-kernel-packages has beem removed from sid and lenny. cdfs-src suffers from #482075, so it might be a removal candidate too. linux-2.6 build-depends on kernel-package (>= 10.063). If the code still

Bug#496432: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Moritz Muehlenhoff
retitle 496432 ibackup: Several symlinks vulnerabilities thanks On Sun, Aug 24, 2008 at 10:05:28PM +0400, Dmitry E. Oboukhov wrote: > Package: ibackup > Severity: grave > > Hi, maintainer! ibackup indeed needs to be fixed, it is vulnerable to several symlink attacks. And it should be orphaned,

Processed: tagging 496426

2008-08-24 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > # Automatically generated email from bts, devscripts version 2.10.35 > tags 496426 + pending Bug#496426: The possibility of attack with the help of symlinks in some Debian packages There were no tags set. Tags added: pending > End of message, stopping

Bug#496349: libfcgi-perl: download link in copyright file is broken

2008-08-24 Thread Moritz Muehlenhoff
[EMAIL PROTECTED] wrote: > Package: libfcgi-perl > Severity: serious > Justification: Policy 12.5 > > > Hi, > > the download link mentioned in the copyright file does no longer > resolve. Also, although the package is on CPAN, the CPAN search does > not find it. I don't think the severity is wa

Processed: byacc: diff for NMU version 20070509-1.1

2008-08-24 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > tags 491182 + patch pending Bug#491182: byacc: CVE-2008-3196: out of bound access Tags were: patch security Tags added: patch, pending > thanks Stopping processing here. Please contact me if you need assistance. Debian bug tracking system administrat

Processed: Re: Bug#496457: libpam-modules: user cannot unlock screen with correct password

2008-08-24 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > severity 496457 normal Bug#496457: libpam-modules: user cannot unlock screen with correct password Severity set to `normal' from `critical' > tags 496457 unreproducible moreinfo Bug#496457: libpam-modules: user cannot unlock screen with correct passwor

Bug#464382: marked as done (bongoproject_0.3.0-1(experimental/amd64/xenophanes): error: Compiling against CLucene system libraries on x86_64 is known to be buggy)

2008-08-24 Thread Debian Bug Tracking System
Your message dated Sun, 24 Aug 2008 21:32:06 + with message-id <[EMAIL PROTECTED]> and subject line Bug#464382: fixed in bongoproject 0.3.1-3 has caused the Debian Bug report #464382, regarding bongoproject_0.3.0-1(experimental/amd64/xenophanes): error: Compiling against CLucene system librar

Bug#496457: libpam-modules: user cannot unlock screen with correct password

2008-08-24 Thread Steve Langasek
severity 496457 normal tags 496457 unreproducible moreinfo thanks On Sun, Aug 24, 2008 at 02:13:53PM -0700, Steve Lane wrote: > Justification: breaks unrelated software False. Software that invokes PAM is not "unrelated". > Aug 24 13:22:23 aspen unix_chkpwd[3472]: check pass; user unknown > Aug

Bug#491182: byacc: diff for NMU version 20070509-1.1

2008-08-24 Thread Thomas Viehmann
tags 491182 + patch pending thanks Hi, The following is the diff for my byacc 20070509-1.1 NMU on its way. Kind regards T. diff -u byacc-20070509/debian/changelog byacc-20070509/debian/changelog --- byacc-20070509/debian/changelog +++ byacc-20070509/debian/changelog @@ -1,3 +1,11 @@ +byacc (20

Bug#496393: marked as done (The possibility of attack with the help of symlinks in some Debian packages)

2008-08-24 Thread Debian Bug Tracking System
Your message dated Sun, 24 Aug 2008 21:32:08 + with message-id <[EMAIL PROTECTED]> and subject line Bug#496393: fixed in xcal 4.1-18.5 has caused the Debian Bug report #496393, regarding The possibility of attack with the help of symlinks in some Debian packages to be marked as done. This me

Processed: tagging 496421

2008-08-24 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > # Automatically generated email from bts, devscripts version 2.10.35 > tags 496421 + pending Bug#496421: The possibility of attack with the help of symlinks in some Debian packages There were no tags set. Tags added: pending > End of message, stopping

Bug#496457: libpam-modules: user cannot unlock screen with correct password

2008-08-24 Thread Steve Lane
Package: libpam-modules Version: 1.0.1-3 Severity: critical Justification: breaks unrelated software After a recent upgrade (since 23 Aug 2008), our users, who can login fine, cannot unlock the terminal after kdesktop_lock has locked it. This appears to (possibly) be a PAM-related issue - here is

Processed: Re: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > severity 496376 minor Bug#496376: The possibility of attack with the help of symlinks in some Debian packages Severity set to `minor' from `grave' > thanks Stopping processing here. Please contact me if you need assistance. Debian bug tracking syste

Bug#496456: kdebase-bin: user cannot unlock screen with correct password

2008-08-24 Thread Steve Lane
Package: kdebase-bin Version: 4:3.5.9.dfsg.1-5 Severity: critical Justification: breaks unrelated software After a recent upgrade (since 23 Aug 2008), our users, who can login fine, cannot unlock the terminal after kdesktop_lock has locked it. This appears to (possibly) be a PAM-related issue - h

Bug#496376: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Steve Langasek
severity 496376 minor thanks The vulnerable scripts are unused bits of packaging that a user should never have occasion to run by hand. Downgrading severity. -- Steve Langasek Give me a lever long enough and a Free OS Debian Developer to set it on, and I can

Bug#496455: kdesktop: user cannot unlock screen with correct password

2008-08-24 Thread Steve Lane
Package: kdesktop Version: 4:3.5.9.dfsg.1-5 Severity: critical Justification: breaks unrelated software After a recent upgrade (since 23 Aug 2008), our users, who can login fine, cannot unlock the terminal after kdesktop_lock has locked it. This appears to (possibly) be a PAM-related issue - here

Processed: Re: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > severity 496360 normal Bug#496360: The possibility of attack with the help of symlinks in some Debian packages Severity set to `normal' from `grave' > tags 496360 moreinfo unreproducible Bug#496360: The possibility of attack with the help of symlinks

Processed: Re: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > severity 496377 normal Bug#496377: The possibility of attack with the help of symlinks in some Debian packages Severity set to `normal' from `grave' > thanks Stopping processing here. Please contact me if you need assistance. Debian bug tracking sys

Processed: fixed 484463 in 1.3.0-5.1

2008-08-24 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > # Automatically generated email from bts, devscripts version 2.10.35 > fixed 484463 1.3.0-5.1 Bug#484463: .pc files indirectly adds --export-dynamic to the linker flags Bug marked as fixed in version 1.3.0-5.1. > End of message, stopping processing her

Bug#496377: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Steve Langasek
severity 496377 normal thanks Another false positive. file: /usr/lib/lazarus/tools/install/create_lazarus_export_tgz.sh This script does: if [ "x$Download" = "xyes" ]; then echo "downloading lazarus svn ..." cd /tmp rm -rf /tmp/lazarus svn export http://svn.freepascal.org/svn/lazaru

Bug#496360: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Steve Langasek
severity 496360 normal tags 496360 moreinfo unreproducible thanks Your bug report contains *no* information about the liquidsoap package. Where is the vulnerability? -- Steve Langasek Give me a lever long enough and a Free OS Debian Developer to set it on, an

Processed: found 484463 in 1.4.2-3

2008-08-24 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > # Automatically generated email from bts, devscripts version 2.10.35 > found 484463 1.4.2-3 Bug#484463: .pc files indirectly adds --export-dynamic to the linker flags Bug marked as found in version 1.4.2-3. > End of message, stopping processing here.

Bug#495484: Is the rest of the data free?

2008-08-24 Thread Guus Sliepen
On Sun, Aug 24, 2008 at 10:39:12PM +0200, Raphael Champeimont (Almacha) wrote: > As the upstream website says "Resources are Non Free." and the original > tar.gz does not contain information about copyright of graphics files > (at least I didn't find any), I was wondering if these were DFSG-free?

Processed: reopening 484463

2008-08-24 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > # Automatically generated email from bts, devscripts version 2.10.35 > reopen 484463 Bug#484463: .pc files indirectly adds --export-dynamic to the linker flags 'reopen' may be inappropriate when a bug has been closed with a version; you may need to use

Bug#487629: further bugfix information

2008-08-24 Thread Bernd Schubert
Neil asked me to send futher information about the bug fix, so here it is. 1) Way to reproduce: No idea what needs to be done to trigger this bug, I only know that after I installed keytouch log-out and system shutdown from KDE didn't work anymore. 2) Killing keytouchd is one possibility to wo

Bug#495484: Is the rest of the data free?

2008-08-24 Thread Raphael Champeimont (Almacha)
As the upstream website says "Resources are Non Free." and the original tar.gz does not contain information about copyright of graphics files (at least I didn't find any), I was wondering if these were DFSG-free? Almacha -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscr

Bug#496377: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Christoph Donges
unsubscribe On Mon, Aug 25, 2008 at 5:48 AM, Torsten Werner <[EMAIL PROTECTED] > wrote: > Hi Mazen, > > > On Sun, Aug 24, 2008 at 8:05 PM, Dmitry E. Oboukhov <[EMAIL PROTECTED]> wrote: > > In some packages I've discovered scripts with errors which may be used > > by a user for damaging important

Processed: notfixed 484463 in 1.4.2-3

2008-08-24 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > # Automatically generated email from bts, devscripts version 2.10.35 > notfixed 484463 1.4.2-3 Bug#484463: .pc files indirectly adds --export-dynamic to the linker flags Bug no longer marked as fixed in version 1.4.2-3. > End of message, stopping proce

Processed: unarchiving 484463

2008-08-24 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > # Automatically generated email from bts, devscripts version 2.10.35 > unarchive 484463 Bug 484463 [libenchant-dev] .pc files indirectly adds --export-dynamic to the linker flags Unarchived Bug 484463 > End of message, stopping processing here. Please

Processed: forwarded

2008-08-24 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > forwarded 496422 http://sf.net/support/tracker.php?aid=2072147 Bug#496422: The possibility of attack with the help of symlinks in some Debian packages Noted your statement that Bug has been forwarded to http://sf.net/support/tracker.php?aid=2072147.

Bug#496410: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Steve Langasek
severity 496410 important thanks On Sun, Aug 24, 2008 at 10:05:29PM +0400, Dmitry E. Oboukhov wrote: > Package: cman > Severity: grave > Binary-package: cman (2.20080629-1) > file: /usr/sbin/fence_egenera The broken usage is: local *egen_log; open(egen_log,">/tmp/eglog");

Processed: Re: Bug#496410: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > severity 496410 important Bug#496410: The possibility of attack with the help of symlinks in some Debian packages Severity set to `important' from `grave' > thanks Stopping processing here. Please contact me if you need assistance. Debian bug tracki

Bug#495684: /proc/fb is empty

2008-08-24 Thread Stefano Costa
I have checked and /proc/fb is empty even though I'm using a framebuffer kernel driver. Best, Steko -- Stefano Costa http://www.iosa.it/ -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Processed: Re: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > severity 496358 important Bug#496358: The possibility of attack with the help of symlinks in some Debian packages Severity set to `important' from `grave' > thanks Stopping processing here. Please contact me if you need assistance. Debian bug tracki

Bug#496358: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Steve Langasek
severity 496358 important thanks The vulnerable script in this package is /usr/share/games/crossfire/maps/Info/combine.pl, which is not used by default; it's provided only as a utility for possible use. I don't think this should be considered grave. -- Steve Langasek Give me a

Bug#496358: marked as done (The possibility of attack with the help of symlinks in some Debian packages)

2008-08-24 Thread Debian Bug Tracking System
Your message dated Sun, 24 Aug 2008 19:32:09 + with message-id <[EMAIL PROTECTED]> and subject line Bug#496358: fixed in crossfire-maps 1.11.0-2 has caused the Debian Bug report #496358, regarding The possibility of attack with the help of symlinks in some Debian packages to be marked as done

Bug#496386: marked as done (The possibility of attack with the help of symlinks in some Debian packages)

2008-08-24 Thread Debian Bug Tracking System
Your message dated Sun, 24 Aug 2008 13:00:16 -0700 with message-id <[EMAIL PROTECTED]> and subject line Re: Bug#496386: The possibility of attack with the help of symlinks in some Debian packages has caused the Debian Bug report #496386, regarding The possibility of attack with the help of symlin

Bug#496442: phpmyadmin package should ensure mysql has a password

2008-08-24 Thread Thijs Kinkhorst
severity 496442 wishlist retitle 496442 Could prevent logging in as root without password by default tags 496442 upstream thanks Hi, On Sun, August 24, 2008 20:53, Sylvain Avril wrote: > The debian mysql package configure the root user with no password by > default. It is not a problem (and rathe

Processed: Re: Bug#496442: phpmyadmin package should ensure mysql has a password

2008-08-24 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > severity 496442 wishlist Bug#496442: phpmyadmin package should ensure mysql has a password Severity set to `wishlist' from `critical' > retitle 496442 Could prevent logging in as root without password by default Bug#496442: phpmyadmin package should en

Bug#496377: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Torsten Werner
Hi Mazen, On Sun, Aug 24, 2008 at 8:05 PM, Dmitry E. Oboukhov <[EMAIL PROTECTED]> wrote: > In some packages I've discovered scripts with errors which may be used > by a user for damaging important system files or user's files. That should be fixed upstream. I'll check all files matching *.sh and

Bug#496391: The possibility of attack with the help of symlinks in some Debian packages

2008-08-24 Thread Steve M. Robbins
severity 496391 normal thanks On Sun, Aug 24, 2008 at 10:05:30PM +0400, Dmitry E. Oboukhov wrote: > In some packages I've discovered scripts with errors which may be used > by a user for damaging important system files or user's files. > Binary-package: gccxml (0.9.0+cvs20080525-1) > file: /

  1   2   3   >