Bug#776538: Uses SSLv3, which Apple disabled support for

2015-01-28 Thread Luke Faraone
Package: python-apns-client Version: 0.1.8-1 Severity: grave Tags: upstream Apple disabled SSLv3, so this client fails to send messages. -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#776530: dnsmasq: fails to start when dbus is not installed and running systemd

2015-01-28 Thread Vagrant Cascadian
Package: dnsmasq Version: 2.72-2 Severity: serious Justification: fails to start with default init system Thanks for maintaining dnsmasq! When runnning dnsmasq with systemd on a freshly installed system, without dbus installed, dnsmasq fails to start. It seems like dnsmasq should depend or at le

Bug#776528: BackendException: ssh connection to user@hostname:22 failed: No authentication methods available

2015-01-28 Thread Francois Marier
Package: duplicity Version: 0.7.01-1 Severity: grave Justification: renders package unusable After upgrading from duplicity 0.6.24-2 to 0.7.01-1, my backups to an ssh host stopped working. Now, if I try to run any of the duplicity commands, I get the following: BackendException: ssh connection

Bug#776525: scilab: failed to build on ppc64el

2015-01-28 Thread Michael Gilbert
package: src:scilab version: 5.5.1-5 severity: serious The latest upload failed to build on the ppc64el buildd: https://buildd.debian.org/status/package.php?p=scilab Best wishes, Mike -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of "unsubscribe". Trouble?

Bug#776523: elfutils: fails to build with newer glibc

2015-01-28 Thread Michael Gilbert
package: src:elfutils version: 0.159-4 severity: serious tags: patch, fixed-upstream elfutils fails to build on arm64. This is fixed in upstream commit c1e0fcb9311. Best wishes, Mike -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of "unsubscribe". Trouble?

Bug#776520: testng: jquery-1.7.1.min.js is missing from testng.jar

2015-01-28 Thread Emmanuel Bourg
Package: testng Version: 6.8.8-3 Severity: grave Justification: renders package unusable When executing the unit tests of Apache Curator with testng/6.8.8-3 I got the following exception: org.apache.maven.surefire.util.SurefireReflectionException: java.lang.reflect.InvocationTargetException;

Bug#775990: [akonadi-backend-sqlite] Akonadi reports deadlocks

2015-01-28 Thread David Goodenough
On Wednesday 28 January 2015 14:21:03 you wrote: > tag 775990 -patch +moreinfo > thanks > > hey, > > the mentioned patch in http://osdir.com/ml/kde-commits/2014-07/msg02228.html > is already part of current akonadi version in unstable. > > > In the ~/.local/share/akonadi/akonadiserver.error ther

Processed: Re: sudo: fails to switch between sudo and sudo-ldap: chown: cannot access '/etc/sudoers': No such file or directory

2015-01-28 Thread Debian Bug Tracking System
Processing control commands: > tags -1 + patch Bug #776137 [sudo] sudo: fails to switch between sudo and sudo-ldap: chown: cannot access '/etc/sudoers': No such file or directory Added tag(s) patch. -- 776137: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=776137 Debian Bug Tracking System Co

Bug#776137: sudo: fails to switch between sudo and sudo-ldap: chown: cannot access '/etc/sudoers': No such file or directory

2015-01-28 Thread Christian Kastner
Control: tags -1 + patch On Sat, 24 Jan 2015 12:05:52 +0100 Andreas Beckmann wrote: > The upgrade to jessie with sudo-ldap/jessie went smooth, and thereafter > I wanted to switch to sudo/jessie, which failed due to missing > /etc/sudoers, the problem is reproducible in plain jessie, too: > > # a

Bug#770009: Backtrace for the hang

2015-01-28 Thread Vincent Fourmond
On Wed, Jan 28, 2015 at 8:14 AM, Bastien ROUCARIES wrote: > > Le 28 janv. 2015 08:00, "roucaries bastien" > a écrit : > > >> >> >> Le 27 janv. 2015 22:15, "Vincent Fourmond" a écrit : >> >> > >> > I've run the build on the MIPS portebox. It hangs on the first SVG >> > to PNG conversion. Here i

Processed: fix commited to vcs...

2015-01-28 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tag 776431 + pending Bug #776431 [intel-microcode] intel-microcode: Haswell-E (306f2) microcode broken in 20150107 Added tag(s) pending. > thanks Stopping processing here. Please contact me if you need assistance. -- 776431: http://bugs.debian.

Bug#776416: marked as done (kfreebsd-10: CVE-2014-8613: SCTP stream reset vulnerability)

2015-01-28 Thread Debian Bug Tracking System
Your message dated Wed, 28 Jan 2015 22:04:12 + with message-id and subject line Bug#776416: fixed in kfreebsd-10 10.1~svn274115-2 has caused the Debian Bug report #776416, regarding kfreebsd-10: CVE-2014-8613: SCTP stream reset vulnerability to be marked as done. This means that you claim tha

Bug#776415: marked as done (kfreebsd-10: CVE-2014-8612: SCTP kernel mem disclosure/corruption)

2015-01-28 Thread Debian Bug Tracking System
Your message dated Wed, 28 Jan 2015 22:04:12 + with message-id and subject line Bug#776415: fixed in kfreebsd-10 10.1~svn274115-2 has caused the Debian Bug report #776415, regarding kfreebsd-10: CVE-2014-8612: SCTP kernel mem disclosure/corruption to be marked as done. This means that you cla

Bug#776488: regression: arm map_hardware[] not NULL terminated

2015-01-28 Thread Ian Campbell
On Wed, 2015-01-28 at 18:38 +0100, Cyril Brulebois wrote: > dann frazier (2015-01-28): > > On Wed, Jan 28, 2015 at 06:10:49PM +0100, Cyril Brulebois wrote: > > > I was about to push it but you apparently already did; adjusting tags > > > accordingly. > > > > Cool, thanks :) Do you +1 me uploading

Bug#775375: marked as pending

2015-01-28 Thread Raphaël Hertzog
tag 775375 pending thanks Hello, Bug #775375 reported by you has been fixed in the Git repository. You can see the changelog below, and you can check the diff of the fix at: http://git.debian.org/?p=python-modules/packages/python-django.git;a=commitdiff;h=3f5c481 --- commit 3f5c481b72dac39

Processed: Bug#775375 marked as pending

2015-01-28 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tag 775375 pending Bug #775375 {Done: Raphaël Hertzog } [src:python-django] python-django: CVE-2015-0219 CVE-2015-0220 CVE-2015-0221 CVE-2015-0222 Added tag(s) pending. > thanks Stopping processing here. Please contact me if you need assistance.

Bug#775681: multiple /tmp file vulnerabilities

2015-01-28 Thread Victor Seva
On 01/25/2015 09:52 PM, Helmut Grohne wrote: > On Sat, Jan 24, 2015 at 02:30:37PM +0100, Victor Seva wrote: >> On 01/18/2015 05:16 PM, Helmut Grohne wrote: [snip] > All of these fixes are appropriate for a Debian Security Advisory. Thus > they should also be appropriate for a freeze unblock. Please

Processed: confirmed issue

2015-01-28 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tag 776431 + confirmed fixed-upstream Bug #776431 [intel-microcode] intel-microcode: Haswell-E (306f2) microcode broken in 20150107 Added tag(s) confirmed and fixed-upstream. > thanks Stopping processing here. Please contact me if you need assis

Bug#776431: confirmed issue

2015-01-28 Thread Henrique de Moraes Holschuh
tag 776431 + confirmed fixed-upstream thanks Bug submitter was quite clear that revision 0x2a is the one in his BIOS, I failed to notice that. Issue with microcode sig 0x306f2, pf_mask 0x7f, revision 0x2d confirmed. -- "One disk to rule them all, One disk to find them. One disk to bring the

Processed: retitling bug

2015-01-28 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > retitle 776431 intel-microcode: Haswell-E (306f2) microcode broken in 20150107 Bug #776431 [intel-microcode] Rebooting with intel-microcode 3.20150107.1~bpo70+1 causing CPU lockups Changed Bug title to 'intel-microcode: Haswell-E (306f2) microcod

Bug#776490: marked as done (privoxy: CVE-2015-1380 CVE-2015-1381 CVE-2015-1382)

2015-01-28 Thread Debian Bug Tracking System
Your message dated Wed, 28 Jan 2015 19:04:05 + with message-id and subject line Bug#776490: fixed in privoxy 3.0.21-7 has caused the Debian Bug report #776490, regarding privoxy: CVE-2015-1380 CVE-2015-1381 CVE-2015-1382 to be marked as done. This means that you claim that the problem has bee

Bug#774607: gitweb breaks apache upgrade

2015-01-28 Thread Niels Thykier
On 2015-01-28 19:34, Jonathan Nieder wrote: > (dpkg -> bcc) > Niels Thykier wrote: > >> Any updates on this bug? The gitweb trigger cycle is currently the last >> trigger cycle left[1]. > > It should be interest-noawait. I was preparing an upload to do that, > but other things preempted that :/

Bug#774607: gitweb breaks apache upgrade

2015-01-28 Thread Jonathan Nieder
(dpkg -> bcc) Niels Thykier wrote: > Any updates on this bug? The gitweb trigger cycle is currently the last > trigger cycle left[1]. It should be interest-noawait. I was preparing an upload to do that, but other things preempted that :/. I will try to make the upload tonight and don't mind if

Bug#776316: [Pkg-samba-maint] Bug#776316: samba: failed to build on mips

2015-01-28 Thread Dejan Latinovic
Hi, I had tried to build samba locally for mips and mipsel on four different machines, and I was not able to reproduce this error. Maybe we should ask for give back and see the result. Regards, Dejan -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of "unsu

Bug#776488: marked as done (regression: arm map_hardware[] not NULL terminated)

2015-01-28 Thread Debian Bug Tracking System
Your message dated Wed, 28 Jan 2015 18:18:38 + with message-id and subject line Bug#776488: fixed in libdebian-installer 0.99 has caused the Debian Bug report #776488, regarding regression: arm map_hardware[] not NULL terminated to be marked as done. This means that you claim that the problem

Bug#776490: marked as done (privoxy: CVE-2015-1380 CVE-2015-1381 CVE-2015-1382)

2015-01-28 Thread Debian Bug Tracking System
Your message dated Wed, 28 Jan 2015 18:18:50 + with message-id and subject line Bug#776490: fixed in privoxy 3.0.21-6 has caused the Debian Bug report #776490, regarding privoxy: CVE-2015-1380 CVE-2015-1381 CVE-2015-1382 to be marked as done. This means that you claim that the problem has bee

Bug#774607: gitweb breaks apache upgrade

2015-01-28 Thread Niels Thykier
On 2015-01-08 09:56, Guillem Jover wrote: > Hi! > > On Wed, 2015-01-07 at 17:07:14 -0800, Jonathan Nieder wrote: >> Guillem Jover wrote: >>> In this case though, it seems switching to interest-noawait is the >>> correct fix, because gitweb just wants to be notified when the >>> apache2-maintscript

Bug#776488: regression: arm map_hardware[] not NULL terminated

2015-01-28 Thread Cyril Brulebois
dann frazier (2015-01-28): > On Wed, Jan 28, 2015 at 06:10:49PM +0100, Cyril Brulebois wrote: > > I was about to push it but you apparently already did; adjusting tags > > accordingly. > > Cool, thanks :) Do you +1 me uploading this? If so, should I request an > unblock or does that need to come

Bug#769342: marked as done (bash-static is statically linked against libc6, but doesn't have a Built-Using: field)

2015-01-28 Thread Debian Bug Tracking System
Your message dated Wed, 28 Jan 2015 17:18:43 + with message-id and subject line Bug#769342: fixed in bash 4.3-12 has caused the Debian Bug report #769342, regarding bash-static is statically linked against libc6, but doesn't have a Built-Using: field to be marked as done. This means that you

Bug#775871: [Pkg-anonymity-tools] Bug#775871: Any updates to the TBB bundle people ?

2015-01-28 Thread shirish शिरीष
in-line :- On 1/28/15, Holger Levsen wrote: > Hi shirish शिरीष, > > On Mittwoch, 28. Januar 2015, shirish शिरीष wrote: >> Thank you for that fast upload. I was able to use TBB >> It downloaded the latest bundle 4.0.3 instead of going for the alpha >> and signature check matched so that's all good

Bug#776488: regression: arm map_hardware[] not NULL terminated

2015-01-28 Thread dann frazier
On Wed, Jan 28, 2015 at 06:10:49PM +0100, Cyril Brulebois wrote: > dann frazier (2015-01-28): > > Package: libdebian-installer4 > > Version: 0.98 > > Severity: serious > > Tags: d-i patch > > > > The map_hardware[] table in src/system/subarch-arm-linux.c is no longer NULL > > terminated. I believ

Bug#776488: regression: arm map_hardware[] not NULL terminated

2015-01-28 Thread Cyril Brulebois
Control: tag -1 - d-i + pending dann frazier (2015-01-28): > Package: libdebian-installer4 > Version: 0.98 > Severity: serious > Tags: d-i patch > > The map_hardware[] table in src/system/subarch-arm-linux.c is no longer NULL > terminated. I believe this could lead to a segfault on armel/armhf p

Processed: Re: Bug#776488: regression: arm map_hardware[] not NULL terminated

2015-01-28 Thread Debian Bug Tracking System
Processing control commands: > tag -1 - d-i + pending Bug #776488 [libdebian-installer4] regression: arm map_hardware[] not NULL terminated Removed tag(s) d-i. Bug #776488 [libdebian-installer4] regression: arm map_hardware[] not NULL terminated Added tag(s) pending. -- 776488: http://bugs.deb

Bug#776494: mariadb-server-10.0: fails to install: preinst: line 49: this_version: command not found

2015-01-28 Thread Andreas Beckmann
Package: mariadb-server-10.0 Version: 10.0.16-1~exp1 Severity: serious User: debian...@lists.debian.org Usertags: piuparts Hi, during a test with piuparts I noticed your package failed to install. As per definition of the release team this makes the package too buggy for a release, thus the sever

Bug#775882: [debian-mysql] Bug#775882: mariadb-10.0: affected by CVEs of the Oracle Patch Update for January 2015?

2015-01-28 Thread Otto Kekäläinen
Status: The test suite failed. I found out that the cacert.pem that is part of the test suite expired today at 6 am UTC. I am working with devs to get this cert re-issued and test suite successful again. I did upload https://buildd.debian.org/status/package.php?p=mariadb-10.0&suite=experimental

Bug#690648: marked as done (4store: bashism in /bin/sh script)

2015-01-28 Thread Debian Bug Tracking System
Your message dated Wed, 28 Jan 2015 16:18:40 + with message-id and subject line Bug#690648: fixed in 4store 1.1.5-1 has caused the Debian Bug report #690648, regarding 4store: bashism in /bin/sh script to be marked as done. This means that you claim that the problem has been dealt with. If th

Bug#776490: privoxy: CVE-2015-1380 CVE-2015-1381 CVE-2015-1382

2015-01-28 Thread Salvatore Bonaccorso
Source: privoxy Version: 3.0.21-5 Severity: grave Tags: security upstream patch fixed-upstream Hi, the following vulnerabilities were published for privoxy. CVE-2015-1380[0]: denial of service CVE-2015-1381[1]: multiple segmentation faults and memory leaks in the pcrs code CVE-2015-1382[2]: in

Bug#690648: Relevance to Ubuntu bug #1096113

2015-01-28 Thread Jonas Smedegaard
Quoting Kjetil Kjernsmo (2015-01-28 16:28:41) > I suspect this bug is pretty much the same bug as this Ubuntu issue: > https://bugs.launchpad.net/ubuntu/+source/4store/+bug/1096113 Thanks for the suggestion. Might be related, but by now I have patched all shell scripts to conform with plain sh.

Bug#776489: shinken: no smooth upgrade from wheezy: the old packages are kept installed

2015-01-28 Thread Andreas Beckmann
Package: shinken Version: 2.0.3-3 Severity: serious Tags: patch User: debian...@lists.debian.org Usertags: piuparts Hi, during a test with piuparts I noticed your package fails to upgrade from 'wheezy'. It installed fine in 'wheezy', then the upgrade to 'jessie' fails, i.e. the old packages from

Bug#776488: regression: arm map_hardware[] not NULL terminated

2015-01-28 Thread dann frazier
Package: libdebian-installer4 Version: 0.98 Severity: serious Tags: d-i patch The map_hardware[] table in src/system/subarch-arm-linux.c is no longer NULL terminated. I believe this could lead to a segfault on armel/armhf platforms, resulting in a failed install. This bug was introduced back in v

Bug#759622: marked as done (guacamole-tomcat: Please depend on tomcat8)

2015-01-28 Thread Debian Bug Tracking System
Your message dated Wed, 28 Jan 2015 15:35:01 + with message-id and subject line Bug#759621: fixed in guacamole-client 0.8.3-1.1 has caused the Debian Bug report #759621, regarding guacamole-tomcat: Please depend on tomcat8 to be marked as done. This means that you claim that the problem has b

Bug#759621: marked as done (guacamole: Please depend on tomcat8)

2015-01-28 Thread Debian Bug Tracking System
Your message dated Wed, 28 Jan 2015 15:35:01 + with message-id and subject line Bug#759621: fixed in guacamole-client 0.8.3-1.1 has caused the Debian Bug report #759621, regarding guacamole: Please depend on tomcat8 to be marked as done. This means that you claim that the problem has been dea

Bug#690648: Relevance to Ubuntu bug #1096113

2015-01-28 Thread Kjetil Kjernsmo
Hi! I suspect this bug is pretty much the same bug as this Ubuntu issue: https://bugs.launchpad.net/ubuntu/+source/4store/+bug/1096113 Cheers, Kjetil -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.

Bug#776483: python-imaging: no smooth upgrade path from wheezy due to python-imaging-tk becoming a virtual package

2015-01-28 Thread Andreas Beckmann
Package: python-imaging Version: 2.6.1-1 Severity: serious User: debian...@lists.debian.org Usertags: piuparts Hi, during a test with piuparts I noticed your package fails to upgrade from 'wheezy'. It installed fine in 'wheezy', then the upgrade to 'jessie' fails, i.e. python-imaging is kept at t

Bug#759621: guacamole: Please depend on tomcat8

2015-01-28 Thread Emmanuel Bourg
I'm going to upload a NMU to fix this issue. I tested with tomcat8 and the webapp was properly installed and available at http://localhost:8080/guacamole Here is the debdiff: dpkg-source: warning: failed to verify signature on /home/ebourg/packaging/guacamole-client_0.8.3-1.dsc diff -Nru guacamo

Bug#775795: puppet: Service's debian provider assumes SysV init

2015-01-28 Thread Robert Bihlmeyer
Hi, > This is especially broken for jessie default installs, which are systemd > now. Service definitions -probably amongst the most used ones- are > assuming init.d semantics, unless "provider => systemd" is supplied as > an argument. The only reason puppet is not completely broken on jessie > is

Bug#776477: tomcat7: fails to switch from tomcat6 to tomcat7 on upgrades

2015-01-28 Thread Emmanuel Bourg
Le 28/01/2015 15:25, Andreas Beckmann a écrit : > You also need to fix guacamole-tomcat for getting rid of tomcat6 > (#759621), I just fixed the incorrect tagging ... Yes I just noticed that one, I'm preparing a NMU. Emmanuel Bourg -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debi

Bug#776477: tomcat7: fails to switch from tomcat6 to tomcat7 on upgrades

2015-01-28 Thread Andreas Beckmann
On 2015-01-28 14:29, Emmanuel Bourg wrote: > tomcat6 is going to be removed from Jessie but the update hasn't > migrated yet (see #770769). src:tomcat6 will only build > libservlet2.5-java. Will that solve this upgrade issue? It might, but that's really hard to test (adding newer packge versions a

Processed: found 682739 in jessie/None, reassign 759621 to guacamole-tomcat, merging 759621 759622 ...

2015-01-28 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > found 682739 jessie/None Bug #682739 [piuparts-master] pre_test_* custom script should signal "untestable, don't try" via exit code The source jessie and version None do not appear to match any binary packages Marked as found in versions jessie/N

Bug#775356: Please test

2015-01-28 Thread Axel Beckert
Hi, Thomas Hood wrote: > Axel, can you please install resolvconf 1.76.1 and check that it works > properly? Will do. Was out of office for a few days, hence the silence from me on that topic... Regards, Axel -- ,''`. | Axel Beckert , http://people.debian.org/~abe/ : :' : |

Bug#776477: tomcat7: fails to switch from tomcat6 to tomcat7 on upgrades

2015-01-28 Thread Emmanuel Bourg
Le 28/01/2015 14:17, Andreas Beckmann a écrit : > The upgrade situation might clear up if the tomcat6, tomcat6-common binary > packages get removed from jessie (src:tomcat6 in sid only build some java > libraries, but no longer tomcat6 etc). > But as long as tomcat6 is installed and a valid instal

Bug#775990: [akonadi-backend-sqlite] Akonadi reports deadlocks

2015-01-28 Thread Sandro Knauß
tag 775990 -patch +moreinfo thanks hey, the mentioned patch in http://osdir.com/ml/kde-commits/2014-07/msg02228.html is already part of current akonadi version in unstable. > In the ~/.local/share/akonadi/akonadiserver.error there are repeated > deadlock errors reported. Can you give us more

Processed: Re: [akonadi-backend-sqlite] Akonadi reports deadlocks

2015-01-28 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tag 775990 -patch +moreinfo Bug #775990 [akonadi-backend-sqlite] [akonadi-backend-sqlite] Akonadi reports deadlocks Removed tag(s) patch. Bug #775990 [akonadi-backend-sqlite] [akonadi-backend-sqlite] Akonadi reports deadlocks Added tag(s) morein

Bug#775356: Please test

2015-01-28 Thread Thomas Hood
Axel, can you please install resolvconf 1.76.1 and check that it works properly? -- Thomas -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Processed: tomcat7: fails to switch from tomcat6 to tomcat7 on upgrades

2015-01-28 Thread Debian Bug Tracking System
Processing control commands: > affects -1 + solr-tomcat Bug #776477 [tomcat7] tomcat7: fails to switch from tomcat6 to tomcat7 on upgrades Added indication that 776477 affects solr-tomcat -- 776477: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=776477 Debian Bug Tracking System Contact ow...

Bug#776477: tomcat7: fails to switch from tomcat6 to tomcat7 on upgrades

2015-01-28 Thread Andreas Beckmann
Package: tomcat7 Version: 7.0.56-1 Severity: serious Tags: patch User: debian...@lists.debian.org Usertags: piuparts Control: affects -1 + solr-tomcat Hi, during a test with piuparts I noticed your package fails to upgrade from 'wheezy'. It installed fine in 'wheezy', then the upgrade to 'jessie'

Bug#774772: New Version is not available

2015-01-28 Thread Florian Kaiser
Bug was marked as "Done" 10 days ago but no new Packages have hit archives / mirrors yet, see https://packages.debian.org/wheezy/policyd-weight This is not acceptable for a bug that causes serious data loss and I frankly do not understand why this takes so long. Regards Florian signature.asc

Bug#776468: marked as done (squid3: Incorrect security permissions for TOS/DiffServ packet marking)

2015-01-28 Thread Debian Bug Tracking System
Your message dated Wed, 28 Jan 2015 12:19:41 + with message-id and subject line Bug#776468: fixed in squid3 3.4.8-6 has caused the Debian Bug report #776468, regarding squid3: Incorrect security permissions for TOS/DiffServ packet marking to be marked as done. This means that you claim that t

Bug#776461: marked as done (squid3: Excessive CPU consumption (or crash) when contacting servers with many IP addresses)

2015-01-28 Thread Debian Bug Tracking System
Your message dated Wed, 28 Jan 2015 12:19:40 + with message-id and subject line Bug#776461: fixed in squid3 3.4.8-6 has caused the Debian Bug report #776461, regarding squid3: Excessive CPU consumption (or crash) when contacting servers with many IP addresses to be marked as done. This means

Bug#776464: marked as done (squid3: Nonce replay vulnerability in Digest authentication)

2015-01-28 Thread Debian Bug Tracking System
Your message dated Wed, 28 Jan 2015 12:19:41 + with message-id and subject line Bug#776464: fixed in squid3 3.4.8-6 has caused the Debian Bug report #776464, regarding squid3: Nonce replay vulnerability in Digest authentication to be marked as done. This means that you claim that the problem

Bug#776463: marked as done (squid3: Excessive memory and CPU consumption when performing NTLM or Negotiate authentication)

2015-01-28 Thread Debian Bug Tracking System
Your message dated Wed, 28 Jan 2015 12:19:40 + with message-id and subject line Bug#776463: fixed in squid3 3.4.8-6 has caused the Debian Bug report #776463, regarding squid3: Excessive memory and CPU consumption when performing NTLM or Negotiate authentication to be marked as done. This mea

Bug#683757: no harm

2015-01-28 Thread Holger Levsen
control: severity -1 important Hi Jörg, it's a policy violation, sure, but not a serious one, as the effect is rather harmless, thus downgrading the severity. https://piuparts.debian.org/templates/mail/unowned_files_after_purge_policy_6.8_and_10.8.mail and https://piuparts.debian.org/templates

Processed: no harm

2015-01-28 Thread Debian Bug Tracking System
Processing control commands: > severity -1 important Bug #683757 [bamfdaemon] bamfdaemon: unowned directory after purge: /usr/share/applications/ Severity set to 'important' from 'serious' -- 683757: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=683757 Debian Bug Tracking System Contact ow..

Processed: jessie

2015-01-28 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tags 776409 + sid jessie Bug #776409 [initramfs-tools] —Bug#767832— not fixed in cryptsetup 2:1.6.6-4 nor 2:1.6.6-5 Added tag(s) sid and jessie. > thanks Stopping processing here. Please contact me if you need assistance. -- 776409: http://bugs

Processed: fixed in LTS too

2015-01-28 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > fixed 776391 2.11.3-4+deb6u4 Bug #776391 [eglibc] [CVE-2015-0235]: heap-based buffer overflow in __nss_hostname_digits_dots() There is no source info for the package 'eglibc' at version '2.11.3-4+deb6u4' with architecture '' Unable to make a sou

Bug#776463: squid3: Excessive memory and CPU consumption when performing NTLM or Negotiate authentication

2015-01-28 Thread Amos Jeffries
Severity: grave Amos -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Processed: Re: Bug#776463: squid3: Excessive memory and CPU consumption when performing NTLM or Negotiate authentication

2015-01-28 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > severity 776463 grave Bug #776463 [squid3] squid3: Excessive memory and CPU consumption when performing NTLM or Negotiate authentication Severity set to 'grave' from 'normal' > thanks Stopping processing here. Please contact me if you need assis

Bug#776468: squid3: Incorrect security permissions for TOS/DiffServ packet marking

2015-01-28 Thread Luigi Gangitano
Package: squid3 Version: 3.4.8-5 Severity: grave Tags: patch upstream Upstream fixed an issue with missing capabilities while squid sets TOS/DiffServ marks on outgoing packets, which can lead to missing marks and unwanted behavior in security devices handling those packages -- System Informatio

Bug#775871: [Pkg-anonymity-tools] Bug#775871: Any updates to the TBB bundle people ?

2015-01-28 Thread Holger Levsen
Hi shirish शिरीष, On Mittwoch, 28. Januar 2015, shirish शिरीष wrote: > Thank you for that fast upload. I was able to use TBB > It downloaded the latest bundle 4.0.3 instead of going for the alpha > and signature check matched so that's all good :) yay. that's on wheezy/jessie/sid? > Thank you f

Bug#776464: squid3: Nonce replay vulnerability in Digest authentication

2015-01-28 Thread Luigi Gangitano
Package: squid3 Version: 3.4.8-5 Severity: grave Tags: security patch upstream Upstream fixed a security issue in digest_authentication that can allow disabled user or users with changed password to access the squid service with old credentials. See http://bugs.squid-cache.org/show_bug.cgi?id=40

Bug#776461: squid3: Excessive CPU consumption (or crash) when contacting servers with many IP addresses

2015-01-28 Thread Luigi Gangitano
Package: squid3 Version: 3.4.8-5 Severity: grave Tags: patch upstream Justification: renders package unusable Upstream fixed an issue with server with multiple IP addesses (>10 IPs in current Debian package version) that can make squid3 crash or consume excessive CPU. -- System Information: Deb

Bug#775871: [Pkg-anonymity-tools] Bug#775871: Any updates to the TBB bundle people ?

2015-01-28 Thread shirish शिरीष
In-line :- On 1/27/15, Holger Levsen wrote: > Hi shirish शिरीष, Hi Holger, > On Dienstag, 27. Januar 2015, shirish शिरीष wrote: >> Also Micha Lee made a new 0.1.9 release around 4 days back so guessing >> the new one would be the best. > > I'm well aware - just not sure whether I think 0.1.9 is

Bug#772410: scilab : uploading the proposed patch fixing bashism ?

2015-01-28 Thread Vincent COUVERT
Hello, On 01/25/2015 06:51 PM, Sylvestre Ledru wrote: Salut Ralf! On 25/01/2015 12:07, Ralf Treinen wrote: Hi Sylvestre, I can upload the proposed patch for #772410 (scilab: bashism in /bin/sh script) if you don't have the time. Sorry, I just forgot that. I uploaded it. The patch has also bee

Bug#776257: Fails to apply patch with dangling symlink

2015-01-28 Thread Andreas Grünbacher
This is also causing problems with kernel patches: http://thread.gmane.org/gmane.linux.kernel/1874498/ It's a bit of a hairy problem; we are currently trying to find a better solution that doesn't break too many other things. Thanks, Andreas -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...

Processed: Re: Bug#776257: Fails to apply patch with dangling symlink

2015-01-28 Thread Debian Bug Tracking System
Processing control commands: > tags -1 upstream Bug #776257 [patch] Fails to apply patch with dangling symlink Added tag(s) upstream. -- 776257: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=776257 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems -- To UNSUBSCRIBE, ema

Bug#776257: Fails to apply patch with dangling symlink

2015-01-28 Thread GCS
Control: tags -1 upstream Hi, On Wed, Jan 28, 2015 at 8:10 AM, Martin Pitt wrote: > Michael Biebl [2015-01-26 1:55 +0100]: >> the latest update of patch broke the systemd package and causes it to >> FTBFS: > > BTW, at least glibc is also affected, and judging by the recent slew > of autopkgtest