Bug#560957: kmail deleted contents of inbox with dimap

2009-12-12 Thread Florian Aldehoff
Package: kmail Version: 4:3.5.9-5 Severity: grave Justification: causes non-serious data loss Identical to bug 158978 in Launchpad, see https://bugs.launchpad.net/kdepim/+bug/158978 for additional information and reports from other users. The bug was also reported to affect Kmail 1.12.1 in KDE

Bug#560949: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Ola Lundqvist
Hi Michael Thanks for the report. I will look at this. I hardly think that expat is included in any important functions at least. But I'll check. Best regards, // Ola On Sat, Dec 12, 2009 at 10:57:56PM -0500, Michael Gilbert wrote: > package: vnc4 > severity: serious > tags: security > > Hi, >

Bug#560916: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Ron
On Sun, Dec 13, 2009 at 12:25:38AM -0500, Michael Gilbert wrote: > On Sun, 13 Dec 2009 15:46:53 +1030 Ron wrote: > > > > > Hi, > > > > 2.6 should be ok for this. wx does indeed bundle a bunch of embedded > > source, but the debian binary packages avoid using it where possible, > > and expat is

Bug#560915: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Ron
Hi, Unlike 2.6, wx2.4 does indeed seem to be affected by this. Its exposure seems to be limited to the libwx_gtk_xrc-2.4 lib in the libwxgtk2.4-1-contrib binary package. Since xrc is a "resource compiler", used to supply random junk that is provided with an app, for the app, without actually emb

Bug#560924: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Siddhesh Poyarekar
On Sun, Dec 13, 2009 at 11:11 AM, Michael Gilbert wrote: > The optimal solution is to make use of the system expat in case of > future issues. > Absolutely. But that is too much of a rewrite for now :) -- Siddhesh Poyarekar http://siddhesh.in -- To UNSUBSCRIBE, email to debian-bugs-rc-requ

Bug#560924: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Siddhesh Poyarekar
On Sun, Dec 13, 2009 at 11:06 AM, Siddhesh Poyarekar wrote: > On Sun, Dec 13, 2009 at 9:20 AM, Michael Gilbert > wrote: >> CVE-2009-3560[0]: >> | The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, >> | as used in the XML-Twig module for Perl, allows context-dependent >> | attack

Bug#537104: marked as done (iceweasel: critical 0-day remote shellcode injection)

2009-12-12 Thread Debian Bug Tracking System
Your message dated Sun, 13 Dec 2009 00:42:29 -0500 with message-id <20091213004229.4b88b4dc.michael.s.gilb...@gmail.com> and subject line close has caused the Debian Bug report #537104, regarding iceweasel: critical 0-day remote shellcode injection to be marked as done. This means that you claim t

Bug#560924: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
On Sun, 13 Dec 2009 11:06:13 +0530 Siddhesh Poyarekar wrote: > On Sun, Dec 13, 2009 at 9:20 AM, Michael Gilbert > wrote: > > CVE-2009-3560[0]: > > | The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, > > | as used in the XML-Twig module for Perl, allows context-dependent > > | a

Bug#560924: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Siddhesh Poyarekar
On Sun, Dec 13, 2009 at 9:20 AM, Michael Gilbert wrote: > CVE-2009-3560[0]: > | The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, > | as used in the XML-Twig module for Perl, allows context-dependent > | attackers to cause a denial of service (application crash) via an XML > | d

Bug#560916: marked as done (CVE-2009-3560 and CVE-2009-3720 denial-of-services)

2009-12-12 Thread Debian Bug Tracking System
Your message dated Sun, 13 Dec 2009 15:46:53 +1030 with message-id <20091213051653.gr23...@audi.shelbyville.oz> and subject line Re: Bug#560916: CVE-2009-3560 and CVE-2009-3720 denial-of-services has caused the Debian Bug report #560916, regarding CVE-2009-3560 and CVE-2009-3720 denial-of-services

Bug#560916: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
On Sun, 13 Dec 2009 15:46:53 +1030 Ron wrote: > > Hi, > > 2.6 should be ok for this. wx does indeed bundle a bunch of embedded > source, but the debian binary packages avoid using it where possible, > and expat is indeed being sourced from the system in 2.6. > > If you grep the buildd logs you

Bug#560722: marked as done (python-apptools: install failed: can't find jquery.js)

2009-12-12 Thread Debian Bug Tracking System
Your message dated Sun, 13 Dec 2009 05:11:00 + with message-id and subject line Bug#560722: fixed in python-apptools 3.3.0-2 has caused the Debian Bug report #560722, regarding python-apptools: install failed: can't find jquery.js to be marked as done. This means that you claim that the probl

Bug#560944: marked as done (CVE-2009-3560 and CVE-2009-3720 denial-of-services)

2009-12-12 Thread Debian Bug Tracking System
Your message dated Sun, 13 Dec 2009 00:00:12 -0500 with message-id <2009121312.ba2e34dc.michael.s.gilb...@gmail.com> and subject line done has caused the Debian Bug report #560944, regarding CVE-2009-3560 and CVE-2009-3720 denial-of-services to be marked as done. This means that you claim that

Processed: your mail

2009-12-12 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tag 560722 + pending Bug #560722 [python-apptools] python-apptools: install failed: can't find jquery.js Added tag(s) pending. > tag 560725 + pending Bug #560725 [python-apptools] ImportError: No module named configobj Added tag(s) pending. > tha

Bug#560762: OK, All three machines are now 'debian-multimedia' free

2009-12-12 Thread Dominique Brazziel
Totem plays .avi again and no orange balls anywhere. OK to close. :) -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#560910: iptables ignores mask on source ip address: 1.2.3.4/16 treated as 1.2.3.4/0

2009-12-12 Thread Laurence J. Lane
On Sat, Dec 12, 2009 at 10:07 PM, Hugh McDonald wrote: > iptables verson 1.4.5-1 for amd64 ignores the address mask on > source address arguments.  "-s 192.168.1.0/24" is treated as > "-s 192.168.1.0/0" both as reported by "iptables -L -n -v" and as > seen in firewall logs.  Version 1.4.4-2 funct

Bug#560953: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: smart severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many package

Bug#560952: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: vtk severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many packages

Bug#560947: marked as done (CVE-2009-3560 and CVE-2009-3720 denial-of-services)

2009-12-12 Thread Debian Bug Tracking System
Your message dated Sat, 12 Dec 2009 23:19:46 -0500 with message-id <20091212231946.a6ebb889.michael.s.gilb...@gmail.com> and subject line done has caused the Debian Bug report #560947, regarding CVE-2009-3560 and CVE-2009-3720 denial-of-services to be marked as done. This means that you claim that

Bug#551939: marked as done (python-xml: CVE-2009-2625)

2009-12-12 Thread Debian Bug Tracking System
Your message dated Sat, 12 Dec 2009 23:21:34 -0500 with message-id <20091212232134.2d43f887.michael.s.gilb...@gmail.com> and subject line new bug submitted with correct cve number has caused the Debian Bug report #551939, regarding python-xml: CVE-2009-2625 to be marked as done. This means that yo

Processed: reassign

2009-12-12 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > reassign 560941 wbxml2 Bug #560941 [wbxml] CVE-2009-3560 and CVE-2009-3720 denial-of-services Warning: Unknown package 'wbxml' Bug reassigned from package 'wbxml' to 'wbxml2'. > thanks Stopping processing here. Please contact me if you need assis

Bug#560923: marked as done (CVE-2009-3560 and CVE-2009-3720 denial-of-services)

2009-12-12 Thread Debian Bug Tracking System
Your message dated Sat, 12 Dec 2009 23:07:07 -0500 with message-id <20091212230707.8046ceab.michael.s.gilb...@gmail.com> and subject line done has caused the Debian Bug report #560923, regarding CVE-2009-3560 and CVE-2009-3720 denial-of-services to be marked as done. This means that you claim that

Bug#560928: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: coin3 severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many package

Bug#560947: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: apache2 severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many packa

Bug#560938: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: sitecopy severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many pack

Bug#560930: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: ghostscript severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many p

Bug#560942: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: xmlrpc-c severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many pack

Bug#560940: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: tla severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many packages

Bug#560949: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: vnc4 severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many packages

Bug#560929: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: gdcm severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many packages

Bug#560932: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: iceape severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many packag

Bug#560944: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: kompozer severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many pack

Bug#560934: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: libparagui1.1 severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many

Bug#560943: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: iceweasel severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many pac

Bug#560948: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: texlive-bin severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many p

Bug#560950: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: xotcl severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many package

Bug#560936: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: poco severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many packages

Bug#560933: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: insighttoolkit severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so man

Bug#560935: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: paraview severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many pack

Bug#560946: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: xulrunner severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many pac

Bug#560927: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: cmake severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many package

Bug#560945: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: vxl severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many packages

Bug#560951: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: python-xml severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many pa

Bug#560939: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: swish-e severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many packa

Bug#560937: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: simgear severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many packa

Bug#560941: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: wbxml severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many package

Bug#560931: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: grmonitor severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many pac

Bug#560926: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: cadaver severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many packa

Bug#560920: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: matanza severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many packa

Bug#560918: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: celementtree severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many

Bug#560922: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: udunits severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many packa

Bug#560919: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: audacity severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many pack

Bug#560923: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: apr-util severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many pack

Bug#560917: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: wxwidget2.8 severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many p

Bug#560924: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: ayttm severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many package

Bug#560925: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: cableswig severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many pac

Bug#560921: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: tdom severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many packages

Bug#560915: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: wxwindows2.4 severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many

Bug#560916: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: wxwidgets2.6 severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many

Bug#560914: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: python-4suite severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many

Bug#560912: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: python2.5 severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many pac

Bug#560913: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: python2.4 severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many pac

Bug#560869: marked as done (FTBFS: failures in jh_manifest)

2009-12-12 Thread Debian Bug Tracking System
Your message dated Sun, 13 Dec 2009 03:33:33 + with message-id and subject line Bug#560869: fixed in javatools 0.26 has caused the Debian Bug report #560869, regarding FTBFS: failures in jh_manifest to be marked as done. This means that you claim that the problem has been dealt with. If this

Bug#560910: iptables ignores mask on source ip address: 1.2.3.4/16 treated as 1.2.3.4/0

2009-12-12 Thread Hugh McDonald
Package: iptables Version: 1.4.4-2 Severity: critical Justification: breaks unrelated software iptables verson 1.4.5-1 for amd64 ignores the address mask on source address arguments. "-s 192.168.1.0/24" is treated as "-s 192.168.1.0/0" both as reported by "iptables -L -n -v" and as seen in firewa

Bug#560453: fim: FTBFS: DebugConsole.cpp:122: error: invalid conversion from 'const char*' to 'char*'

2009-12-12 Thread Michele Martone
Hi, There are updated fim files (1.2) on : ftp://ftp-master.debian.org:/pub/UploadQueue/fim_0.3-beta-prerelease-1.2.diff.gz ftp://ftp-master.debian.org:/pub/UploadQueue/fim_0.3-beta-prerelease-1.2.dsc ftp://ftp-master.debian.org:/pub/UploadQueue/fim_0.3-beta-prerelease-1.2_i386.deb I hope this was

Bug#560908: openjdk-6: deluge of vulnerabilities

2009-12-12 Thread Michael Gilbert
Package: openjdk-6 Version: 6b16-1.6.1-2 Severity: grave Tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for openjdk-6. I have not had the time to check any of this since there are just way too many issues. Please check whether openjdk is vulnerable

Bug#559831: closed by (John V. Belmonte) (Bug#559831: fixed in xmlsec1 1.2.14-1)

2009-12-12 Thread Michael Gilbert
On Sat, 12 Dec 2009 21:06:30 -0500 John Belmonte wrote: > On closer investigation It turns out that Debian xmlsec1 is not > affected by CVE-2009-3736 since we don't enable dynamic crypto module > loading (--enable-crypto_dl). my mistake. i realize now that the upstream release completely removed

Processed: Re: Bug#559831: closed by (John V. Belmonte) (Bug#559831: fixed in xmlsec1 1.2.14-1)

2009-12-12 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > close 559831 Bug#559831: CVE-2009-3736 local privilege escalation 'close' is deprecated; see http://www.debian.org/Bugs/Developer#closing. Bug closed, send any further explanations to Michael Gilbert > stop Stopping processing here. Please con

Bug#560903: viewvc: CVE-2009-3618 and CVE-2009-3619 xss and character printing vulnerabilities

2009-12-12 Thread Michael Gilbert
Package: viewvc Version: 1.0.9-1 Severity: serious Tags: security Hi, the following CVE (Common Vulnerabilities & Exposures) ids were published for viewvc. CVE-2009-3618[0]: | Cross-site scripting (XSS) vulnerability in viewvc.py in ViewVC 1.0 | before 1.0.9 and 1.1 before 1.1.2 allows remote att

Bug#560534: marked as done (rquantlib: FTBFS: bermudan.cpp:114: error: invalid use of incomplete type 'struct QuantLib::Null

2009-12-12 Thread Debian Bug Tracking System
Your message dated Sat, 12 Dec 2009 20:08:49 -0600 with message-id <19236.19633.802466.590...@ron.nulle.part> and subject line Re: Bug#560534: rquantlib: FTBFS: bermudan.cpp:114: error: invalid use of incomplete type 'struct QuantLib::Null > >' has caused the Debian Bug report #560534, regarding

Bug#559831: closed by (John V. Belmonte) (Bug#559831: fixed in xmlsec1 1.2.14-1)

2009-12-12 Thread John Belmonte
close 559831 stop On Sat, Dec 12, 2009 at 6:52 PM, Michael Gilbert wrote: > i don't think that this has been resolved since there are no depends on > libtool in your control file. On closer investigation It turns out that Debian xmlsec1 is not affected by CVE-2009-3736 since we don't enable dyna

Bug#560869: FTBFS: failures in jh_manifest

2009-12-12 Thread Matthew Johnson
reassign 560869 javahelper tag 560869 pending thanks On Sat Dec 12 23:24, Cyril Brulebois wrote: > Package: libmatthew-java > Version: 0.7.2-2 > Severity: serious > Justification: FTBFS This is a bug in javahelper, I've just fixed it in git and I'll upload (yet another) new version. Should just n

Processed: Re: Bug#560869: FTBFS: failures in jh_manifest

2009-12-12 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > reassign 560869 javahelper Bug #560869 [libmatthew-java] FTBFS: failures in jh_manifest Bug reassigned from package 'libmatthew-java' to 'javahelper'. Bug No longer marked as found in versions 0.7.2-2. > tag 560869 pending Bug #560869 [javahelper]

Bug#560901: expat: CVE-2009-3560

2009-12-12 Thread Michael Gilbert
package: expat version: 1.95.8-3.4 Severity: serious Tags: security Hi, the following CVE (Common Vulnerabilities & Exposures) id was published for xpat. CVE-2009-3560[0]: | The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, | as used in the XML-Twig module for Perl, allows cont

Bug#560898: marked as done (coreutils: insecure temp file usage)

2009-12-12 Thread Debian Bug Tracking System
Your message dated Sat, 12 Dec 2009 20:37:14 -0500 with message-id <5ba963fc-e787-11de-9b6a-001cc0cda...@msgid.mathom.us> and subject line Re: Bug#560898: coreutils: insecure temp file usage has caused the Debian Bug report #560898, regarding coreutils: insecure temp file usage to be marked as done

Bug#552215: marked as done (FTBFS: Error: unrecognized opcode `mfence')

2009-12-12 Thread Debian Bug Tracking System
Your message dated Sun, 13 Dec 2009 01:33:12 + with message-id and subject line Bug#552215: fixed in stressapptest 1.0.1-2 has caused the Debian Bug report #552215, regarding FTBFS: Error: unrecognized opcode `mfence' to be marked as done. This means that you claim that the problem has been d

Bug#560898: coreutils: insecure temp file usage

2009-12-12 Thread Michael Gilbert
package: coreutils version: 8.0-2 severity: serious tags: security hi, it has been disclosed that coreutils uses temp files in an insecure way [0]. note that etch and lenny are also affected. [0] http://www.openwall.com/lists/oss-security/2009/12/08/4 -- To UNSUBSCRIBE, email to debian-bugs-

Bug#560885: texlive-base: Fails to upgrade

2009-12-12 Thread Kurt Roeckx
On Sun, Dec 13, 2009 at 01:20:03AM +0100, Hilmar Preusse wrote: > On 13.12.09 Kurt Roeckx (k...@roeckx.be) wrote: > > Hi, > > > fmtutil-sys failed. Output has been stored in > > /tmp/fmtutil.LHrpVsJ9 > > Please include this file if you report a bug. > > > Please do so. Here it is. Kurt fmtu

Bug#559803: CVE-2009-3736 local privilege escalation

2009-12-12 Thread Michael Gilbert
reopen 559803 thanks On Mon, 07 Dec 2009 22:04:02 +0100 Andreas Tscharner wrote: > Package: cvsnt > Severity: grave > Tags: security > Version: 2.5.04.3236-1 > > > > The following CVE (Common Vulnerabilities & Exposures) id was > > published for libtool. I have determined that this package emb

Bug#560895: gnome-screensaver vulnerability

2009-12-12 Thread Michael Gilbert
package: gnome-screensaver version: 2.28.0-1+b1 severity: serious tags: security hi, ubuntu has issued a usn for gnome-screensaver [0]. it is not clear whether this is an ubuntu-specfic problem or not. please check and close the bug if that is the case. thank you. mike [0] http://www.ubuntu.c

Bug#560511: marked as done (ion3: FTBFS: dock.c:36:34: error: X11/extensions/shape.h: No such file or directory)

2009-12-12 Thread Debian Bug Tracking System
Your message dated Sun, 13 Dec 2009 00:46:58 + with message-id <1260665218.4532.603.ca...@localhost> and subject line Re: Bug#560511: ion3: FTBFS: dock.c:36:34: error: X11/extensions/shape.h: No such file or directory has caused the Debian Bug report #560511, regarding ion3: FTBFS: dock.c:36:3

Bug#533977: marked as done (zzuf: FTBFS: tests failed)

2009-12-12 Thread Debian Bug Tracking System
Your message dated Sun, 13 Dec 2009 00:47:40 + with message-id and subject line Bug#533977: fixed in zzuf 0.12.svn20091212-1 has caused the Debian Bug report #533977, regarding zzuf: FTBFS: tests failed to be marked as done. This means that you claim that the problem has been dealt with. If t

Processed: fixed 560511 in 20070506-1

2009-12-12 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > # Added build-dependency on libxext-dev in preparation for Xorg 7.2 > fixed 560511 20070506-1 Bug #560511 [src:ion3] ion3: FTBFS: dock.c:36:34: error: X11/extensions/shape.h: No such file or directory Bug Marked as fixed in versions ion3/20070506

Bug#559830: CVE-2009-3736 local privilege escalation

2009-12-12 Thread Michael Gilbert
On Sun, 6 Dec 2009 21:19:50 -0800 Steve Langasek wrote: > On Mon, Dec 07, 2009 at 12:04:18AM -0500, Michael Gilbert wrote: > > Package: unixodbc > > Severity: grave > > Tags: security > > > The following CVE (Common Vulnerabilities & Exposures) id was > > published for libtool. I have determined

Bug#559839: CVE-2009-3736 local privilege escalation

2009-12-12 Thread Michael Gilbert
On Mon, 7 Dec 2009 10:18:13 +0100 (CET) Patrick Matthäi wrote: > Hi, > > this is already fixed, also in the Lenny release, look here: > > http://packages.debian.org/changelogs/pool/main/s/sbnc/current/changelog#versionversion1.2-8 > > So I am closing. make sure you are using --without-included

Bug#559805: CVE-2009-3736 local privilege escalation

2009-12-12 Thread Michael Gilbert
On Mon, 7 Dec 2009 19:04:16 +0100 Josip Rodin wrote: > On Mon, Dec 07, 2009 at 11:04:38AM -0500, Michael Gilbert wrote: > > On Mon, 7 Dec 2009 09:16:57 +0100, Josip Rodin wrote: > > > unless this code somehow inexplicalby crept in, there's no bug. > > > > please check your linking process, so tha

Bug#560885: texlive-base: Fails to upgrade

2009-12-12 Thread Hilmar Preusse
On 13.12.09 Kurt Roeckx (k...@roeckx.be) wrote: Hi, > fmtutil-sys failed. Output has been stored in > /tmp/fmtutil.LHrpVsJ9 > Please include this file if you report a bug. > Please do so. H. -- sigmentation fault -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a su

Bug#560594: Does not work with locale de_AT.UTF-8 because of libgcj10 error.

2009-12-12 Thread Johannes Fichtinger
Hallo Johann Felix, I can confirm, setting LANG=C makes pdftk work fine here, too. So it really seems related to the LANG evironment. Thanks for your good work! Johannes -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact lis

Bug#546776: marked as done (Viewing revisions does not work with non-ancient versions of Bazaar)

2009-12-12 Thread Debian Bug Tracking System
Your message dated Sun, 13 Dec 2009 00:04:21 + with message-id and subject line Bug#546776: fixed in trac-bzr 0.2+bzr83-1 has caused the Debian Bug report #546776, regarding Viewing revisions does not work with non-ancient versions of Bazaar to be marked as done. This means that you claim tha

Processed: found 559833 in

2009-12-12 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > found 559833 Bug #559833 [imagemagick] CVE-2009-3736 local privilege escalation Ignoring request to alter fixed versions of bug #559833 to the same values previously set > End of message, stopping processing here. Please contact me if you need a

Processed: found 559833 in 7:6.2.4.5.dfsg1-0.14, found 559833 in 7:6.3.7.9.dfsg2-1~lenny3

2009-12-12 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > found 559833 7:6.2.4.5.dfsg1-0.14 Bug #559833 [imagemagick] CVE-2009-3736 local privilege escalation Bug Marked as found in versions imagemagick/7:6.2.4.5.dfsg1-0.14. > found 559833 7:6.3.7.9.dfsg2-1~lenny3 Bug #559833 [imagemagick] CVE-2009-3736

Bug#523853: marked as done (nvidia-glx-legacy-96xx: conflicts with the xorg stack, causing uninstall)

2009-12-12 Thread Debian Bug Tracking System
Your message dated Sat, 12 Dec 2009 23:50:16 + with message-id and subject line Bug#523853: fixed in nvidia-graphics-drivers-legacy-96xx 96.43.14-1 has caused the Debian Bug report #523853, regarding nvidia-glx-legacy-96xx: conflicts with the xorg stack, causing uninstall to be marked as don

Bug#560885: texlive-base: Fails to upgrade

2009-12-12 Thread Kurt Roeckx
Package: texlive-base Version: 2009-4 Severity: serious Doing an upgrade today resulted in: Setting up texlive-base (2009-4) ... Running mktexlsr. This may take some time... done. Building format(s) --all --cnffile /etc/texmf/fmt.d/10texlive-base.cnf. This may take some time... fmtutil-sys

Bug#560013: marked as done (nvidia-glx-legacy-96xx: conflicts with xserver)

2009-12-12 Thread Debian Bug Tracking System
Your message dated Sat, 12 Dec 2009 23:50:16 + with message-id and subject line Bug#560013: fixed in nvidia-graphics-drivers-legacy-96xx 96.43.14-1 has caused the Debian Bug report #560013, regarding nvidia-glx-legacy-96xx: conflicts with xserver to be marked as done. This means that you cla

Bug#559831: closed by (John V. Belmonte) (Bug#559831: fixed in xmlsec1 1.2.14-1)

2009-12-12 Thread Michael Gilbert
reopen 559831 thanks On Wed, 09 Dec 2009 04:21:04 + Debian Bug Tracking System wrote: > This is an automatic notification regarding your Bug report > which was filed against the xmlsec1 package: > > #559831: CVE-2009-3736 local privilege escalation i don't think that this has been resolved

Processed: Re: Bug#559831 closed by (John V. Belmonte) (Bug#559831: fixed in xmlsec1 1.2.14-1)

2009-12-12 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > reopen 559831 Bug #559831 {Done: jbelmo...@debian.org (John V. Belmonte)} [xmlsec1] CVE-2009-3736 local privilege escalation 'reopen' may be inappropriate when a bug has been closed with a version; you may need to use 'found' to remove fixed vers

Bug#523806: marked as done (nvidia-kernel-legacy-96xx: Conflicts with new xserver-xorg-core)

2009-12-12 Thread Debian Bug Tracking System
Your message dated Sat, 12 Dec 2009 23:50:16 + with message-id and subject line Bug#523806: fixed in nvidia-graphics-drivers-legacy-96xx 96.43.14-1 has caused the Debian Bug report #523806, regarding nvidia-kernel-legacy-96xx: Conflicts with new xserver-xorg-core to be marked as done. This m

Bug#547463: marked as done (nvidia-glx-legacy-96xx: cannot install because of conflicts with current X.org and Linux kernel)

2009-12-12 Thread Debian Bug Tracking System
Your message dated Sat, 12 Dec 2009 23:50:16 + with message-id and subject line Bug#547463: fixed in nvidia-graphics-drivers-legacy-96xx 96.43.14-1 has caused the Debian Bug report #547463, regarding nvidia-glx-legacy-96xx: cannot install because of conflicts with current X.org and Linux ker

Processed: block 560238 with 560137 560056

2009-12-12 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > block 560238 with 560137 560056 Bug #560238 [netbase] netbase: new setting breaks RFC compliant software Was not blocked by any bugs. Added blocking bug(s) of 560238: 560137, 560056, and 560142 > End of message, stopping processing here. Please c

Bug#560238: net.ipv6.bindv6only configuration breaks xdmcp

2009-12-12 Thread Marco d'Itri
On Dec 13, Martin Roll wrote: > a similar problem now appears in sun-java6-plugin (6-17-1). http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=560056 -- ciao, Marco signature.asc Description: Digital signature

  1   2   3   >