Processed: your mail

2009-11-08 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > severity 555259 minor Bug #555259 [scriptaculous] scriptaculous: CVE-2007-2383 and CVE-2008-7720 prototypejs vulnerabilities Severity set to 'minor' from 'serious' > thanks Stopping processing here. Please contact me if you need assistance. De

Bug#555259: scriptaculous: CVE-2007-2383 and CVE-2008-7720

2009-11-08 Thread Daniel Baumann
severity: minor thanks scriptaculous doesn't include prototype in the binaries (and never has), it's just in the source tarball, making it a cosmetical problem only. -- Address:Daniel Baumann, Burgunderstrasse 3, CH-4562 Biberist Email: daniel.baum...@panthera-systems.net Intern

Bug#555231: mt-daapd: CVE-2007-2383 and CVE-2008-7720 prototypejs vulnerabilities

2009-11-08 Thread Julien BLACHE
Michael Gilbert wrote: Hi, > Your package embeds the following prototype.js versions: > etch: 1.4.0 I'll prepare an oldstable-security upload upgrading the embedded prototype.js to 1.6.1. If that's OK with you, it'll be there in 2-3 days max. Thanks, JB. -- Julien BLACHE - Debian & GNU/

Processed: your mail

2009-11-08 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > fixed 555223 1.1.4-1 Bug #555223 [libjson-ruby] libjson-ruby: CVE-2007-2383 and CVE-2008-7720 prototypejs vulnerabilities Bug Marked as fixed in versions libjson-ruby/1.1.4-1. > quit Stopping processing here. Please contact me if you need assist

Processed: tagging 554197

2009-11-08 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tags 554197 + patch Bug #554197 [bacula] bacula: usr-share-doc-symlink-without-dependency Added tag(s) patch. > End of message, stopping processing here. Please contact me if you need assistance. Debian bug tracking system administrator (adminis

Bug#555223: libjson-ruby: CVE-2007-2383 and CVE-2008-7720 prototypejs vulnerabilities

2009-11-08 Thread Ryan Niebur
On Sun, Nov 08, 2009 at 07:22:57PM -0500, Michael Gilbert wrote: > package: libjson-ruby > version: 1.1.2-1 > severity: serious > tags: security > > Hi, > > Your package contains an embedded version of prototype.js that is > vulnerable to either CVE-2007-2383 (affecting prototype.js before 1.5.1)

Bug#545472: marked as done (bugzilla3: Crashes with "SESSION variable 'max_allowed_packet' is read-only.")

2009-11-08 Thread Debian Bug Tracking System
Your message dated Mon, 9 Nov 2009 07:18:17 +0100 with message-id and subject line Bug#545472: fixed in bugzilla 3.2.5.0-1 has caused the Debian Bug report #545472, regarding bugzilla3: Crashes with "SESSION variable 'max_allowed_packet' is read-only." to be marked as done. This means that you c

Bug#554197: Fix for /usr/share/doc/bacula symlink

2009-11-08 Thread Stephen Kitt
Package: bacula Severity: normal Tags: patch Hi, The attached patch fixes this by adding the appropriate dependency on bacula-common. It also fixes #545313 and #545473. Regards, Stephen -- System Information: Debian Release: squeeze/sid APT prefers testing APT policy: (500, 'testing'), (5

Bug#540961: marked as done (xulrunner: CVE-2009-2663 vulnerability)

2009-11-08 Thread Debian Bug Tracking System
Your message dated Mon, 9 Nov 2009 00:32:31 -0500 with message-id <20091109003231.06caa9b0.michael.s.gilb...@gmail.com> and subject line close has caused the Debian Bug report #540961, regarding xulrunner: CVE-2009-2663 vulnerability to be marked as done. This means that you claim that the problem

Bug#553195: os-prober-1.35

2009-11-08 Thread BandiPat
On Saturday 07 November 2009, Iustin Pop wrote: > > /usr/lib/os-prober/newns: line 8: syntax error near unexpected > > token `(' /usr/lib/os-prober/newns: line 8: `int main(int argc, > > char **argv)' > > This sounds like the contents of the newns file is corrupted. Can you > try to reinstall the

Processed: reassign 555157 to libcv-dev, affects 555157, merging 543546 555157

2009-11-08 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > reassign 555157 libcv-dev Bug #555157 [src:freej] freej: FTBFS: error: conflicting declaration 'typedef long long int int64' Bug reassigned from package 'src:freej' to 'libcv-dev'. Bug No longer marked as found in versions freej/0.10git20090824-1

Bug#555155: marked as done (passenger: FTBFS: Could not find the Apache web server binary.)

2009-11-08 Thread Debian Bug Tracking System
Your message dated Mon, 09 Nov 2009 03:33:08 + with message-id and subject line Bug#555155: fixed in passenger 2.2.5debian-5 has caused the Debian Bug report #555155, regarding passenger: FTBFS: Could not find the Apache web server binary. to be marked as done. This means that you claim that

Processed: your mail

2009-11-08 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > found 551689 atlas/3.8.3-4 Bug #551689 {Done: Sylvestre Ledru } [atlas] atlas (experimental) - packaging error Bug Marked as found in versions atlas/3.8.3-4; no longer marked as fixed in versions atlas/3.8.3-4 and reopened. > severity 551689 ser

Bug#552662: marked as done (debian-rules-not-a-makefile)

2009-11-08 Thread Debian Bug Tracking System
Your message dated Mon, 09 Nov 2009 01:48:14 + with message-id and subject line Bug#552662: fixed in vdr-plugin-xineliboutput 1.0.4+cvs20091016.1108-3 has caused the Debian Bug report #552662, regarding debian-rules-not-a-makefile to be marked as done. This means that you claim that the prob

Bug#552661: marked as done (debian-rules-not-a-makefile)

2009-11-08 Thread Debian Bug Tracking System
Your message dated Mon, 09 Nov 2009 01:47:57 + with message-id and subject line Bug#552661: fixed in vdr-plugin-weather 0.2.1e-52 has caused the Debian Bug report #552661, regarding debian-rules-not-a-makefile to be marked as done. This means that you claim that the problem has been dealt wit

Bug#552660: marked as done (debian-rules-not-a-makefile)

2009-11-08 Thread Debian Bug Tracking System
Your message dated Mon, 09 Nov 2009 01:47:35 + with message-id and subject line Bug#552660: fixed in vdr-plugin-svdrpservice 0.0.4-3 has caused the Debian Bug report #552660, regarding debian-rules-not-a-makefile to be marked as done. This means that you claim that the problem has been dealt

Bug#552657: marked as done (debian-rules-not-a-makefile)

2009-11-08 Thread Debian Bug Tracking System
Your message dated Mon, 09 Nov 2009 01:47:46 + with message-id and subject line Bug#552657: fixed in vdr-plugin-vcd 0.9-10 has caused the Debian Bug report #552657, regarding debian-rules-not-a-makefile to be marked as done. This means that you claim that the problem has been dealt with. If t

Bug#552658: marked as done (debian-rules-not-a-makefile)

2009-11-08 Thread Debian Bug Tracking System
Your message dated Mon, 09 Nov 2009 01:20:48 + with message-id and subject line Bug#552658: fixed in vdr-plugin-sudoku 0.3.4-3 has caused the Debian Bug report #552658, regarding debian-rules-not-a-makefile to be marked as done. This means that you claim that the problem has been dealt with.

Bug#552650: marked as done (debian-rules-not-a-makefile)

2009-11-08 Thread Debian Bug Tracking System
Your message dated Mon, 09 Nov 2009 01:19:13 + with message-id and subject line Bug#552650: fixed in vdr-plugin-osdserver 0.1.2-4 has caused the Debian Bug report #552650, regarding debian-rules-not-a-makefile to be marked as done. This means that you claim that the problem has been dealt wit

Bug#552643: marked as done (debian-rules-not-a-makefile)

2009-11-08 Thread Debian Bug Tracking System
Your message dated Mon, 09 Nov 2009 01:18:17 + with message-id and subject line Bug#552643: fixed in vdr-plugin-freecell 0.0.2-47 has caused the Debian Bug report #552643, regarding debian-rules-not-a-makefile to be marked as done. This means that you claim that the problem has been dealt wit

Bug#552651: marked as done (debian-rules-not-a-makefile)

2009-11-08 Thread Debian Bug Tracking System
Your message dated Mon, 09 Nov 2009 01:19:35 + with message-id and subject line Bug#552651: fixed in vdr-plugin-prefermenu 0.6.6-26 has caused the Debian Bug report #552651, regarding debian-rules-not-a-makefile to be marked as done. This means that you claim that the problem has been dealt w

Bug#552644: marked as done (debian-rules-not-a-makefile)

2009-11-08 Thread Debian Bug Tracking System
Your message dated Mon, 09 Nov 2009 01:17:54 + with message-id and subject line Bug#552644: fixed in vdr-plugin-epgsync 0.0.3-3 has caused the Debian Bug report #552644, regarding debian-rules-not-a-makefile to be marked as done. This means that you claim that the problem has been dealt with.

Bug#552645: marked as done (debian-rules-not-a-makefile)

2009-11-08 Thread Debian Bug Tracking System
Your message dated Mon, 09 Nov 2009 01:18:50 + with message-id and subject line Bug#552645: fixed in vdr-plugin-live 0.2.0-7 has caused the Debian Bug report #552645, regarding debian-rules-not-a-makefile to be marked as done. This means that you claim that the problem has been dealt with. If

Bug#552641: marked as done (debian-rules-not-a-makefile)

2009-11-08 Thread Debian Bug Tracking System
Your message dated Mon, 09 Nov 2009 01:18:39 + with message-id and subject line Bug#552641: fixed in vdr-plugin-games 0.6.3-25 has caused the Debian Bug report #552641, regarding debian-rules-not-a-makefile to be marked as done. This means that you claim that the problem has been dealt with.

Bug#552580: marked as done (debian-rules-not-a-makefile)

2009-11-08 Thread Debian Bug Tracking System
Your message dated Mon, 09 Nov 2009 01:18:06 + with message-id and subject line Bug#552580: fixed in vdr-plugin-femon 1.6.7-2 has caused the Debian Bug report #552580, regarding debian-rules-not-a-makefile to be marked as done. This means that you claim that the problem has been dealt with. I

Bug#552654: marked as done (debian-rules-not-a-makefile)

2009-11-08 Thread Debian Bug Tracking System
Your message dated Mon, 09 Nov 2009 01:19:46 + with message-id and subject line Bug#552654: fixed in vdr-plugin-remote 0.4.0-18 has caused the Debian Bug report #552654, regarding debian-rules-not-a-makefile to be marked as done. This means that you claim that the problem has been dealt with.

Bug#552656: marked as done (debian-rules-not-a-makefile)

2009-11-08 Thread Debian Bug Tracking System
Your message dated Mon, 09 Nov 2009 01:20:37 + with message-id and subject line Bug#552656: fixed in vdr-plugin-streamdev 0.5.0~pre20090706+cvs20091108.2341-1 has caused the Debian Bug report #552656, regarding debian-rules-not-a-makefile to be marked as done. This means that you claim that

Bug#552640: marked as done (debian-rules-not-a-makefile)

2009-11-08 Thread Debian Bug Tracking System
Your message dated Mon, 09 Nov 2009 01:17:32 + with message-id and subject line Bug#552640: fixed in vdr-plugin-dvd 0.3.6~b03+cvs20090426.0013-2 has caused the Debian Bug report #552640, regarding debian-rules-not-a-makefile to be marked as done. This means that you claim that the problem ha

Bug#552648: marked as done (debian-rules-not-a-makefile)

2009-11-08 Thread Debian Bug Tracking System
Your message dated Mon, 09 Nov 2009 01:20:24 + with message-id and subject line Bug#552648: fixed in vdr-plugin-spider 0.2.2-3 has caused the Debian Bug report #552648, regarding debian-rules-not-a-makefile to be marked as done. This means that you claim that the problem has been dealt with.

Bug#552652: marked as done (debian-rules-not-a-makefile)

2009-11-08 Thread Debian Bug Tracking System
Your message dated Mon, 09 Nov 2009 01:19:24 + with message-id and subject line Bug#552652: fixed in vdr-plugin-osdteletext 0.8.3-2 has caused the Debian Bug report #552652, regarding debian-rules-not-a-makefile to be marked as done. This means that you claim that the problem has been dealt w

Bug#552642: marked as done (debian-rules-not-a-makefile)

2009-11-08 Thread Debian Bug Tracking System
Your message dated Mon, 09 Nov 2009 01:18:28 + with message-id and subject line Bug#552642: fixed in vdr-plugin-fritzbox 1.2.1-3 has caused the Debian Bug report #552642, regarding debian-rules-not-a-makefile to be marked as done. This means that you claim that the problem has been dealt with

Bug#552655: marked as done (debian-rules-not-a-makefile)

2009-11-08 Thread Debian Bug Tracking System
Your message dated Mon, 09 Nov 2009 01:20:01 + with message-id and subject line Bug#552655: fixed in vdr-plugin-skinenigmang 0.1.0-2 has caused the Debian Bug report #552655, regarding debian-rules-not-a-makefile to be marked as done. This means that you claim that the problem has been dealt

Bug#552637: marked as done (debian-rules-not-a-makefile)

2009-11-08 Thread Debian Bug Tracking System
Your message dated Mon, 09 Nov 2009 01:17:21 + with message-id and subject line Bug#552637: fixed in vdr-plugin-bitstreamout 0.89c-4 has caused the Debian Bug report #552637, regarding debian-rules-not-a-makefile to be marked as done. This means that you claim that the problem has been dealt

Bug#552639: marked as done (debian-rules-not-a-makefile)

2009-11-08 Thread Debian Bug Tracking System
Your message dated Mon, 09 Nov 2009 01:17:43 + with message-id and subject line Bug#552639: fixed in vdr-plugin-epgsearch 0.9.24-6 has caused the Debian Bug report #552639, regarding debian-rules-not-a-makefile to be marked as done. This means that you claim that the problem has been dealt wi

Bug#552646: marked as done (debian-rules-not-a-makefile)

2009-11-08 Thread Debian Bug Tracking System
Your message dated Mon, 09 Nov 2009 01:19:02 + with message-id and subject line Bug#552646: fixed in vdr-plugin-mp3 0.10.1-14 has caused the Debian Bug report #552646, regarding debian-rules-not-a-makefile to be marked as done. This means that you claim that the problem has been dealt with. I

Bug#552649: marked as done (debian-rules-not-a-makefile)

2009-11-08 Thread Debian Bug Tracking System
Your message dated Mon, 09 Nov 2009 01:20:13 + with message-id and subject line Bug#552649: fixed in vdr-plugin-solitaire 0.0.2-45 has caused the Debian Bug report #552649, regarding debian-rules-not-a-makefile to be marked as done. This means that you claim that the problem has been dealt wi

Bug#555268: webcalendar: CVE-2007-2383 and CVE-2008-7720 prototypejs vulnerabilities

2009-11-08 Thread Michael Gilbert
package: webcalendar version: 1.2.0+dfsg-4 severity: serious tags: security Hi, Your package contains an embedded version of prototype.js that is vulnerable to either CVE-2007-2383 (affecting prototype.js before 1.5.1) [0], CVE-2008-7220 (affecting prototype.js before 1.6.0.2) [1], or both. Your

Bug#555276: wesnoth: CVE-2007-2383 and CVE-2008-7720 prototypejs vulnerabilities

2009-11-08 Thread Michael Gilbert
package: wesnoth version: 1:1.6.5-1 severity: serious tags: security Hi, Your package contains an embedded version of prototype.js that is vulnerable to either CVE-2007-2383 (affecting prototype.js before 1.5.1) [0], CVE-2008-7220 (affecting prototype.js before 1.6.0.2) [1], or both. Your packag

Bug#555274: plone3: CVE-2007-2383 and CVE-2008-7720 prototypejs vulnerabilities

2009-11-08 Thread Michael Gilbert
package: plone3 version: 3.1.3-1 severity: serious tags: security Hi, Your package contains an embedded version of prototype.js that is vulnerable to either CVE-2007-2383 (affecting prototype.js before 1.5.1) [0], CVE-2008-7220 (affecting prototype.js before 1.6.0.2) [1], or both. Your package e

Bug#555266: otrs2: CVE-2007-2383 and CVE-2008-7720 prototypejs vulnerabilities

2009-11-08 Thread Michael Gilbert
package: otrs2 version: 2.3.4-5 severity: serious tags: security Hi, Your package contains an embedded version of prototype.js that is vulnerable to either CVE-2007-2383 (affecting prototype.js before 1.5.1) [0], CVE-2008-7220 (affecting prototype.js before 1.6.0.2) [1], or both. Your package em

Bug#555263: activeldap: CVE-2007-2383 and CVE-2008-7720 prototypejs vulnerabilities

2009-11-08 Thread Michael Gilbert
package: activeldap version: 1.0.1-1 severity: serious tags: security Hi, Your package contains an embedded version of prototype.js that is vulnerable to either CVE-2007-2383 (affecting prototype.js before 1.5.1) [0], CVE-2008-7220 (affecting prototype.js before 1.6.0.2) [1], or both. Your packa

Bug#555264: mantis: CVE-2007-2383 and CVE-2008-7720 prototypejs vulnerabilities

2009-11-08 Thread Michael Gilbert
package: mantis version: 1.1.6+dfsg-2 severity: serious tags: security Hi, Your package contains an embedded version of prototype.js that is vulnerable to either CVE-2007-2383 (affecting prototype.js before 1.5.1) [0], CVE-2008-7220 (affecting prototype.js before 1.6.0.2) [1], or both. Your pack

Bug#552178: Possibly a profile related problem

2009-11-08 Thread Simon Ruggier
Have you tried starting firefox 3.5 using a new profile? I'm using the iceweasel 3.5.4-1 right now on an x86_64 Debian testing system, and it works fine for me. Of course, it's still a bug even if it's profile related, but it wouldn't be as severe of a bug.

Bug#555259: scriptaculous: CVE-2007-2383 and CVE-2008-7720 prototypejs vulnerabilities

2009-11-08 Thread Michael Gilbert
package: scriptaculous version: 1.8.1-5 severity: serious tags: security Hi, Your package contains an embedded version of prototype.js that is vulnerable to either CVE-2007-2383 (affecting prototype.js before 1.5.1) [0], CVE-2008-7220 (affecting prototype.js before 1.6.0.2) [1], or both. Your pa

Bug#555258: rt-extension-emailcompletion: CVE-2007-2383 and CVE-2008-7720 prototypejs vulnerabilities

2009-11-08 Thread Michael Gilbert
package: rt-extension-emailcompletion version: 0.06-3 severity: serious tags: security Hi, Your package contains an embedded version of prototype.js that is vulnerable to either CVE-2007-2383 (affecting prototype.js before 1.5.1) [0], CVE-2008-7220 (affecting prototype.js before 1.6.0.2) [1], or

Bug#555016: Is libgl1-mesa-dev installed?

2009-11-08 Thread Matt Kraai
Hi, vlc builds in a fresh pbuilder chroot on my system. vlc build-depends on libgl1-mesa-dev, which provides /usr/lib/libGL.so. Is libgl1-mesa-dev installed on your system? -- Matthttp://ftbfs.org/kraai -- To UNSUBSCRIBE, email to debian-bugs-rc-

Bug#555255: jscropperui: CVE-2007-2383 and CVE-2008-7720 prototypejs vulnerabilities

2009-11-08 Thread Michael Gilbert
package: jscropperui version: 1.2.0-1 severity: serious tags: security Hi, Your package contains an embedded version of prototype.js that is vulnerable to either CVE-2007-2383 (affecting prototype.js before 1.5.1) [0], CVE-2008-7220 (affecting prototype.js before 1.6.0.2) [1], or both. Your pack

Bug#555244: exaile: CVE-2007-2383 and CVE-2008-7720 prototypejs vulnerabilities

2009-11-08 Thread Michael Gilbert
package: exaile version: 0.2.11.1+debian-2 severity: serious tags: security Hi, Your package contains an embedded version of prototype.js that is vulnerable to either CVE-2007-2383 (affecting prototype.js before 1.5.1) [0], CVE-2008-7220 (affecting prototype.js before 1.6.0.2) [1], or both. Your

Bug#555248: pixelpost: CVE-2007-2383 and CVE-2008-7720 prototypejs vulnerabilities

2009-11-08 Thread Michael Gilbert
package: pixelpost version: 1.7.1-5 severity: serious tags: security Hi, Your package contains an embedded version of prototype.js that is vulnerable to either CVE-2007-2383 (affecting prototype.js before 1.5.1) [0], CVE-2008-7220 (affecting prototype.js before 1.6.0.2) [1], or both. Your packag

Bug#555246: hobix: CVE-2007-2383 and CVE-2008-7720 prototypejs vulnerabilities

2009-11-08 Thread Michael Gilbert
package: hobix version: 0.5~svn20070319-3 severity: serious tags: security Hi, Your package contains an embedded version of prototype.js that is vulnerable to either CVE-2007-2383 (affecting prototype.js before 1.5.1) [0], CVE-2008-7220 (affecting prototype.js before 1.6.0.2) [1], or both. Your

Bug#555249: symfony: CVE-2007-2383 and CVE-2008-7720 prototypejs vulnerabilities

2009-11-08 Thread Michael Gilbert
package: symfony version: 1.0.17-4 severity: serious tags: security Hi, Your package contains an embedded version of prototype.js that is vulnerable to either CVE-2007-2383 (affecting prototype.js before 1.5.1) [0], CVE-2008-7220 (affecting prototype.js before 1.6.0.2) [1], or both. Your package

Bug#555242: wordpress: CVE-2007-2383 and CVE-2008-7720 prototypejs vulnerabilities

2009-11-08 Thread Michael Gilbert
package: wordpress version: 2.5.1-11 severity: serious tags: security Hi, Your package contains an embedded version of prototype.js that is vulnerable to either CVE-2007-2383 (affecting prototype.js before 1.5.1) [0], CVE-2008-7220 (affecting prototype.js before 1.6.0.2) [1], or both. Your packa

Bug#555239: webhelpers: CVE-2007-2383 and CVE-2008-7720 prototypejs vulnerabilities

2009-11-08 Thread Michael Gilbert
package: webhelpers version: 0.6-1 severity: serious tags: security Hi, Your package contains an embedded version of prototype.js that is vulnerable to either CVE-2007-2383 (affecting prototype.js before 1.5.1) [0], CVE-2008-7220 (affecting prototype.js before 1.6.0.2) [1], or both. Your package

Bug#555237: python-poker-network: CVE-2007-2383 and CVE-2008-7720 prototypejs vulnerabilities

2009-11-08 Thread Michael Gilbert
package: python-poker-network version: 1.0.30-1 severity: serious tags: security Hi, Your package contains an embedded version of prototype.js that is vulnerable to either CVE-2007-2383 (affecting prototype.js before 1.5.1) [0], CVE-2008-7220 (affecting prototype.js before 1.6.0.2) [1], or both.

Bug#555240: qwik: CVE-2007-2383 and CVE-2008-7720 prototypejs vulnerabilities

2009-11-08 Thread Michael Gilbert
package: qwik version: 0.8.4.4 severity: serious tags: security Hi, Your package contains an embedded version of prototype.js that is vulnerable to either CVE-2007-2383 (affecting prototype.js before 1.5.1) [0], CVE-2008-7220 (affecting prototype.js before 1.6.0.2) [1], or both. Your package em

Processed: Re: Bug#555220: asterisk: CVE-2007-2383 and CVE-2008-7720 prototypejs vulnerabilities

2009-11-08 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > forcemerge 554486 555220 Bug#554486: AST-2009-009: Cross-site AJAX request vulnerability Bug#555220: asterisk: CVE-2007-2383 and CVE-2008-7720 prototypejs vulnerabilities Forcibly Merged 554486 555220. > thanks Stopping processing here. Please

Bug#555235: ebug-http: CVE-2007-2383 and CVE-2008-7720 prototypejs vulnerabilities

2009-11-08 Thread Michael Gilbert
package: ebug-http version: 0.31-2 severity: serious tags: security Hi, Your package contains an embedded version of prototype.js that is vulnerable to either CVE-2007-2383 (affecting prototype.js before 1.5.1) [0], CVE-2008-7220 (affecting prototype.js before 1.6.0.2) [1], or both. Your package

Bug#555231: mt-daapd: CVE-2007-2383 and CVE-2008-7720 prototypejs vulnerabilities

2009-11-08 Thread Michael Gilbert
package: mt-daapd version: 0.2.4+r1376-1.1+etch2 severity: serious tags: security Hi, Your package contains an embedded version of prototype.js that is vulnerable to either CVE-2007-2383 (affecting prototype.js before 1.5.1) [0], CVE-2008-7220 (affecting prototype.js before 1.6.0.2) [1], or both.

Bug#555227: menu items fails to launch pppoeconf unless started as root (missing dependency)

2009-11-08 Thread Filipus Klutiero
Package: pppoeconf Version: 1.19 Severity: serious Unless launched as root, pppoeconf tries obtaining root privileges via gksu, sudo or su-to-root (from the menu package). This would be OK since pppoeconf is in /usr/sbin/, except a menu item always displayed offers to launch and will fails if n

Bug#555234: op-panel: CVE-2007-2383 and CVE-2008-7720 prototypejs vulnerabilities

2009-11-08 Thread Michael Gilbert
package: op-panel version: 0.27.dfsg-2 severity: serious tags: security Hi, Your package contains an embedded version of prototype.js that is vulnerable to either CVE-2007-2383 (affecting prototype.js before 1.5.1) [0], CVE-2008-7220 (affecting prototype.js before 1.6.0.2) [1], or both. Your pac

Bug#555228: glpi: CVE-2007-2383 and CVE-2008-7720 prototypejs vulnerabilities

2009-11-08 Thread Michael Gilbert
package: glpi version: 0.68.2-1etch0.2 severity: serious tags: security Hi, Your package contains an embedded version of prototype.js that is vulnerable to either CVE-2007-2383 (affecting prototype.js before 1.5.1) [0], CVE-2008-7220 (affecting prototype.js before 1.6.0.2) [1], or both. Your pac

Bug#555232: mediatomb: CVE-2007-2383 and CVE-2008-7720 prototypejs vulnerabilities

2009-11-08 Thread Michael Gilbert
package: mediatomb version: 0.11.0-3 severity: serious tags: security Hi, Your package contains an embedded version of prototype.js that is vulnerable to either CVE-2007-2383 (affecting prototype.js before 1.5.1) [0], CVE-2008-7220 (affecting prototype.js before 1.6.0.2) [1], or both. Your packa

Bug#555229: knowledgeroot: CVE-2007-2383 and CVE-2008-7720 prototypejs vulnerabilities

2009-11-08 Thread Michael Gilbert
package: knowledgeroot version: 0.9.7.3-2 severity: serious tags: security Hi, Your package contains an embedded version of prototype.js that is vulnerable to either CVE-2007-2383 (affecting prototype.js before 1.5.1) [0], CVE-2008-7220 (affecting prototype.js before 1.6.0.2) [1], or both. Your

Bug#555225: lucene2: CVE-2007-2383 and CVE-2008-7720 prototypejs vulnerabilities

2009-11-08 Thread Michael Gilbert
package: lucene2 version: 2.3.1+ds1-1 severity: serious tags: security Hi, Your package contains an embedded version of prototype.js that is vulnerable to either CVE-2007-2383 (affecting prototype.js before 1.5.1) [0], CVE-2008-7220 (affecting prototype.js before 1.6.0.2) [1], or both. Your pack

Bug#555223: libjson-ruby: CVE-2007-2383 and CVE-2008-7720 prototypejs vulnerabilities

2009-11-08 Thread Michael Gilbert
package: libjson-ruby version: 1.1.2-1 severity: serious tags: security Hi, Your package contains an embedded version of prototype.js that is vulnerable to either CVE-2007-2383 (affecting prototype.js before 1.5.1) [0], CVE-2008-7220 (affecting prototype.js before 1.6.0.2) [1], or both. Your pac

Bug#555221: libaws: CVE-2007-2383 and CVE-2008-7720 prototypejs vulnerabilities

2009-11-08 Thread Michael Gilbert
package: libaws version: 2.2dfsg-1 severity: serious tags: security Hi, Your package contains an embedded version of prototype.js that is vulnerable to either CVE-2007-2383 (affecting prototype.js before 1.5.1) [0], CVE-2008-7220 (affecting prototype.js before 1.6.0.2) [1], or both. Your package

Bug#555220: asterisk: CVE-2007-2383 and CVE-2008-7720 prototypejs vulnerabilities

2009-11-08 Thread Michael Gilbert
package: asterisk version: 1:1.4.21.2~dfsg-3 severity: serious tags: security Hi, Your package contains an embedded version of prototype.js that is vulnerable to either CVE-2007-2383 (affecting prototype.js 1.5.1 and earlier) [0], CVE-2008-7220 (affecting prototype.js 1.6.0.2 and earlier) [1], or

Bug#555217: auth2db: CVE-2007-2383 and CVE-2008-7720 prototypejs vulnerabilities

2009-11-08 Thread Michael Gilbert
package: auth2db version: 0.2.5-2+dfsg-1 severity: serious tags: security Hi, Your package contains an embedded version of prototype.js that is vulnerable to either CVE-2007-2383 (affecting prototype.js 1.5.1 and earlier) [0], CVE-2008-7220 (affecting prototype.js 1.6.0.2 and earlier) [1], or bot

Bug#555156: marked as done (maildrop: invocation of update-alternatives by postinst script fails)

2009-11-08 Thread Debian Bug Tracking System
Your message dated Mon, 09 Nov 2009 00:02:54 + with message-id and subject line Bug#555156: fixed in maildrop 2.2.0-3 has caused the Debian Bug report #555156, regarding maildrop: invocation of update-alternatives by postinst script fails to be marked as done. This means that you claim that t

Bug#551775: bitlbee: Uninstallable package due to conflict with libc6

2009-11-08 Thread Wilmer van der Gaast
peter green wrote: >> It looks like you forgot to really Cc them BTW? > I did but I resent the mail seperately to them afterwards. Ah, found it. Looks like I'm not CC'ed on that anymore though. I think "it used to not work otherwise" seems like a very good reason for me to use the static lib. :-)

Bug#546016: Adding pending tag

2009-11-08 Thread Matt Kraai
tag 546016 pending thanks Hi, Since you've included a fix for this bug in the diff for the next upload, I'm tagging it as pending for now. -- Matthttp://ftbfs.org/kraai -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a sub

Bug#555156: maildrop: invocation of update-alternatives by postinst script fails

2009-11-08 Thread Josip Rodin
On Sun, Nov 08, 2009 at 09:17:01PM +0100, Serafeim Zanikolas wrote: > Hi, > > update-alternatives fails because the binary in the unstable archive doesn't > ship /usr/bin/*.maildrop: > > dpkg -$ dpkg -c /var/cache/apt/archives/maildrop_2.2.0-2_i386.deb | grep > usr\/bin > drwxr-xr-x root/root

Bug#541381: marked as done (canto: please migrate to python-multiprocessing)

2009-11-08 Thread Debian Bug Tracking System
Your message dated Sun, 08 Nov 2009 23:32:42 + with message-id and subject line Bug#541381: fixed in canto 0.7.5-1 has caused the Debian Bug report #541381, regarding canto: please migrate to python-multiprocessing to be marked as done. This means that you claim that the problem has been deal

Processed: severity of 555195 is critical, tagging 555195, bug 555195 is forwarded to irc.gnu.org/#grub

2009-11-08 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > # Automatically generated email from bts, devscripts version 2.10.35lenny7 > severity 555195 critical Bug #555195 [grub2] grub2: password checking oddity Severity set to 'critical' from 'serious' > tags 555195 security Bug #555195 [grub2] grub2:

Processed: Adding pending tag

2009-11-08 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tag 546016 pending Bug #546016 [coreutils] coreutils: Package built from source contains /usr/share/info/dir.gz Added tag(s) pending. > thanks Stopping processing here. Please contact me if you need assistance. Debian bug tracking system admini

Processed: severity of 555195 is serious, tagging 555195

2009-11-08 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > severity 555195 serious Bug #555195 [grub2] grub2: password checking oddity Severity set to 'serious' from 'important' > tags 555195 security Bug #555195 [grub2] grub2: password checking oddity Added tag(s) security. > End of message, stopping pr

Bug#555205: libc6: segfault when upgrading from 2.9-25 -> 2.10.1-5 on squeeze renders system unusable

2009-11-08 Thread bjn
Package: libc6 Version: 2.9-25 Severity: critical Justification: breaks the whole system I tried to upgrade to the current "testing" version of libc6: 2.10.1-5 Below is the output from aptitude: - Preparing to replace libc-bin 2.9-25 (using .../libc-bin_2.10.1-5_i386.deb) ... Unpacking repl

Bug#555120: Reassign to aptitude-gtk

2009-11-08 Thread Matt Kraai
reassign 555120 aptitude-gtk thanks Hi, Since /usr/bin/aptitude-gtk is provided by the aptitude-gtk package, I'm reassigning this bug to that package. -- Matthttp://ftbfs.org/kraai -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.or

Bug#555149: marked as done (gnat: error: cannot read files list file: No such file or directory)

2009-11-08 Thread Debian Bug Tracking System
Your message dated Sun, 08 Nov 2009 22:49:24 + with message-id and subject line Bug#555149: fixed in gnat 4.4+1 has caused the Debian Bug report #555149, regarding gnat: error: cannot read files list file: No such file or directory to be marked as done. This means that you claim that the prob

Processed: Reassign to aptitude-gtk

2009-11-08 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > reassign 555120 aptitude-gtk Bug #555120 [aptitude] aptitude-gtk doesn't start Bug reassigned from package 'aptitude' to 'aptitude-gtk'. Bug No longer marked as found in versions aptitude/0.6.0.1-1. > thanks Stopping processing here. Please conta

Bug#555200: ninja: postinst fails

2009-11-08 Thread Mario 'BitKoenig' Holbe
Package: ninja Version: 0.1.2-4 Severity: serious Hello, ninja's postinst fails due to the shipped conffile: Preparing to replace ninja 0.1.2-3 (using .../ninja_0.1.2-4_i386.deb) ... Unpacking replacement ninja ... Setting up ninja (0.1.2-4) ... /etc/init.d/ninja: 27: escalation: not found Start

Bug#538286: marked as done (bugzilla3 from SID install on Lenny, fsck's db_pass in localconfig)

2009-11-08 Thread Debian Bug Tracking System
Your message dated Sun, 08 Nov 2009 22:32:46 + with message-id and subject line Bug#538286: fixed in bugzilla 3.2.5.0-1 has caused the Debian Bug report #538286, regarding bugzilla3 from SID install on Lenny, fsck's db_pass in localconfig to be marked as done. This means that you claim that t

Bug#544870: marked as done (bugzilla3: Broken dependency to yui)

2009-11-08 Thread Debian Bug Tracking System
Your message dated Sun, 08 Nov 2009 22:32:46 + with message-id and subject line Bug#544870: fixed in bugzilla 3.2.5.0-1 has caused the Debian Bug report #544870, regarding bugzilla3: Broken dependency to yui to be marked as done. This means that you claim that the problem has been dealt with.

Bug#547132: marked as done (CVE-2009-3165: SQL injection vulnerability)

2009-11-08 Thread Debian Bug Tracking System
Your message dated Sun, 08 Nov 2009 22:32:46 + with message-id and subject line Bug#547132: fixed in bugzilla 3.2.5.0-1 has caused the Debian Bug report #547132, regarding CVE-2009-3165: SQL injection vulnerability to be marked as done. This means that you claim that the problem has been deal

Bug#542975: pathfinder and wvstreams update (Re: Bug#542975: pathfinder: FTBFS)

2009-11-08 Thread Hideki Yamane
Hi Patrick, On Thu, 22 Oct 2009 13:29:42 +0900 Hideki Yamane wrote: > > Pathfinder no longer has it's own DBus client implementation, but rather > > uses the new WvDBus in WvStreams > 4.5.1. > > > > However, we're now blocked on this, since WvStreams is orphaned, my keys are > > out of the loop

Bug#551248: marked as done (matplotlib: FTBFS: cp: cannot stat `doc/build/latex/Matplotlib.pdf': No such file or directory)

2009-11-08 Thread Debian Bug Tracking System
Your message dated Sun, 08 Nov 2009 22:18:52 + with message-id and subject line Bug#551248: fixed in matplotlib 0.99.1.1-1 has caused the Debian Bug report #551248, regarding matplotlib: FTBFS: cp: cannot stat `doc/build/latex/Matplotlib.pdf': No such file or directory to be marked as done.

Bug#554574: libstdc++6: apt segfaults on hppa

2009-11-08 Thread John David Anglin
> On 08.11.2009 21:38, John David Anglin wrote: > >> test results for 4.4.2-1: > >> http://gcc.gnu.org/ml/gcc-testresults/2009-10/msg01919.html > >> for 4.4.2-2: > >> http://gcc.gnu.org/ml/gcc-testresults/2009-11/msg00351.html > >> > >> there are some differences, which are not seen in Dave

Bug#552638: (package vdr) debian-rules-not-a-makefile

2009-11-08 Thread Tobias Grimm
Sven Mueller wrote: > In the end, I think that debian/rules should be changed so that it can, > itself, build the special vdr variant (most importantly the vdr-devel > and associated plugin packages). This is simply not that easy and would make debian/rules ugly and hard to understand. > So exce

Bug#551775: bitlbee: Uninstallable package due to conflict with libc6

2009-11-08 Thread peter green
It looks like you forgot to really Cc them BTW? I did but I resent the mail seperately to them afterwards. So yeah, we'd need a libresolv.so that exports these: lib/lib.o: In function `srv_lookup': /home/wilmer/src/bitlbee/devel/lib/misc.c:483: undefined reference to `__res_query' /home/wi

Bug#554574: libstdc++6: apt segfaults on hppa

2009-11-08 Thread Matthias Klose
On 08.11.2009 21:38, John David Anglin wrote: test results for 4.4.2-1: http://gcc.gnu.org/ml/gcc-testresults/2009-10/msg01919.html for 4.4.2-2: http://gcc.gnu.org/ml/gcc-testresults/2009-11/msg00351.html there are some differences, which are not seen in Dave's build: http://gcc.gnu.

Bug#552638: marked as done (debian-rules-not-a-makefile)

2009-11-08 Thread Debian Bug Tracking System
Your message dated Sun, 08 Nov 2009 21:39:16 + with message-id and subject line Bug#552638: fixed in vdr 1.6.0-13 has caused the Debian Bug report #552638, regarding debian-rules-not-a-makefile to be marked as done. This means that you claim that the problem has been dealt with. If this is no

Processed: found 555168 in 2.1-1

2009-11-08 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > found 555168 2.1-1 Bug #555168 [locales] Many locales files do not permit modification There is no source info for the package 'locales' at version '2.1-1' with architecture '' Unable to make a source version for version '2.1-1' Bug Marked as fou

Bug#552010: marked as done (libc6: After upgrade many applications become unusable)

2009-11-08 Thread Debian Bug Tracking System
Your message dated Sun, 08 Nov 2009 21:35:21 + with message-id and subject line Bug#552010: fixed in eglibc 2.10.1-6 has caused the Debian Bug report #552010, regarding libc6: After upgrade many applications become unusable to be marked as done. This means that you claim that the problem has

Bug#533888: Bug: 533888

2009-11-08 Thread Adam D. Barratt
On Sun, 2009-11-08 at 13:53 -0500, Jonathan Niehof wrote: > Attached is a simple patch against 3.8.0-5. With this patch, the > install completes and config files are installed, but of course > ddclient won't function without the user editing the configuration > files appropriately. [...] -db_in

Bug#533888: Bug: 533888

2009-11-08 Thread Jonathan Niehof
Corrected patch attached (supposed to be ||, not |...thanks to Adam Barratt for pointing out the braino.) diff -u -r ddclient_3.8.0.orig/debian/postinst ddclient_3.8.0/debian/postinst --- ddclient_3.8.0.orig/debian/postinst 2009-11-08 13:08:31.0 -0500 +++ ddclient_3.8.0/debian/postinst 2009

Bug#555093: Missing kernel-img.conf makes a debian kernel not installable

2009-11-08 Thread maximilian attems
On Sun, 08 Nov 2009, Sebastian Andrzej Siewior wrote: > Package: linux-2.6 > Version: 2.6.31-1 > Severity: normal > Tags: patch > > There is no /etc/kernel-img.con on a fresh debootstrap sid. Installing a > kernel leads to: > thanks perfect analysis and patch, applied. nuked that templated whe

Bug#555168: Many locales files do not permit modification

2009-11-08 Thread Josh Triplett
Package: locales Version: 2.10.1-5 Severity: serious Justification: Policy 2.2.1, 2.1 Many locales contain the following license: # Distribution and use is free, also for # commercial purposes. This does not permit modification, and thus fails DFSG 3. I'd guess that almost all of these come fro

Bug#554574: libstdc++6: apt segfaults on hppa

2009-11-08 Thread John David Anglin
> test results for 4.4.2-1: >http://gcc.gnu.org/ml/gcc-testresults/2009-10/msg01919.html > for 4.4.2-2: >http://gcc.gnu.org/ml/gcc-testresults/2009-11/msg00351.html > > there are some differences, which are not seen in Dave's build: >http://gcc.gnu.org/ml/gcc-testresults/2009-11/msg000

Processed: your mail

2009-11-08 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tag 551248 + pending Bug #551248 [src:matplotlib] matplotlib: FTBFS: cp: cannot stat `doc/build/latex/Matplotlib.pdf': No such file or directory Ignoring request to alter tags of bug #551248 to the same tags previously set > thanks Stopping proce

Processed: tagging 555093

2009-11-08 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > # Automatically generated email from bts, devscripts version 2.10.35lenny7 > tags 555093 + pending Bug #555093 [linux-2.6] Missing kernel-img.conf makes a debian kernel not installable Added tag(s) pending. > End of message, stopping processing h

  1   2   3   >