Processed: bug 780507 is forwarded to https://github.com/librsync/librsync/issues/25

2015-03-14 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > forwarded 780507 https://github.com/librsync/librsync/issues/25 Bug #780507 [src:librsync] src:librsync: FTBFS on BE Set Bug forwarded-to-address to 'https://github.com/librsync/librsync/issues/25'. > thanks Stopping processing here. Please cont

Bug#780507: src:librsync: FTBFS on BE

2015-03-14 Thread Andrey Rahmatullin
Package: src:librsync Version: 1.0.0-1~exp1 Severity: serious Tags: upstream Justification: fails to build from source (but built successfully in the past) signature.test fails on BE arches. -- System Information: Debian Release: 8.0 APT prefers unstable APT policy: (500, 'unstable'), (500,

Bug#780506: requests: CVE-2015-2296: session fixation and cookie stealing issue

2015-03-14 Thread Salvatore Bonaccorso
Source: requests Version: 2.4.3-4 Severity: grave Tags: security upstream patch fixed-upstream Hi, the following vulnerability was published for requests. CVE-2015-2296[0]: session fixation and cookie stealing If you fix the vulnerability please also make sure to include the CVE (Common Vulnera

Bug#778599: Vulnerabilities in nanohttp

2015-03-14 Thread Salvatore Bonaccorso
Hi, On Tue, Feb 17, 2015 at 10:07:06AM +, Patrick Coleman wrote: > * Remote null pointer dereference > A remote user can cause a null pointer dereference by sending a > malformed Authorization: header. > http://patrick.ld.net.au/libcsoap/nanohttp-nullp-1.patch For this issue CVE-2015-2297 was

Bug#780503: icu: incomplete fix for CVE-2014-7940

2015-03-14 Thread Michael Gilbert
control: tag -1 patch, pending On Sat, Mar 14, 2015 at 9:48 PM, Michael Gilbert wrote: > Google added another check in a later patch for this issue, which > wasn't included in the previous nmu: Hi, I uploaded an nmu to delayed/3 fixing this problem. Please see attached. Best wishes, Mike diff

Processed: Re: Bug#780503: icu: incomplete fix for CVE-2014-7940

2015-03-14 Thread Debian Bug Tracking System
Processing control commands: > tag -1 patch, pending Bug #780503 [src:icu] icu: incomplete fix for CVE-2014-7940 Added tag(s) pending and patch. -- 780503: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=780503 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems -- To UNSUB

Bug#780503: icu: incomplete fix for CVE-2014-7940

2015-03-14 Thread Michael Gilbert
package: src:icu version: 52.1-7.1 severity: serious tags: security Google added another check in a later patch for this issue, which wasn't included in the previous nmu: https://chromium.googlesource.com/chromium/deps/icu/+/a626a75aad2675254073366fcaa9465dacf17100/patches/col.patch Best wishes,

Bug#778634: CVE-2008-7313 / CVE-2014-5008

2015-03-14 Thread Marcelo Jorge Vieira
Hi Moritz, On Sat, 2015-03-14 at 13:50 -0300, Marcelo Jorge Vieira wrote: > Hi Moritz, > > On Thu, 2015-03-05 at 19:13 +0100, Moritz Mühlenhoff wrote: > > Did you test the reverse deps in wheezy and jessie to check whether > > they are compatible? > > > > wordpress (wheezy) > > libphp-magpierss

Bug#765490: marked as done (xserver-xorg-video-vmware: resizing issues)

2015-03-14 Thread Debian Bug Tracking System
Your message dated Sat, 14 Mar 2015 22:36:57 + with message-id and subject line Bug#765490: fixed in xserver-xorg-video-vmware 1:13.0.2-3.1 has caused the Debian Bug report #765490, regarding xserver-xorg-video-vmware: resizing issues to be marked as done. This means that you claim that the p

Bug#763900: marked as done (iceweasel/ppc: Compile-time page size does not divide the runtime one.)

2015-03-14 Thread Debian Bug Tracking System
Your message dated Sat, 14 Mar 2015 22:34:09 + with message-id and subject line Bug#763900: fixed in iceweasel 31.5.0esr-1~deb7u1 has caused the Debian Bug report #763900, regarding iceweasel/ppc: Compile-time page size does not divide the runtime one. to be marked as done. This means that y

Processed: xserver-xorg-video-vmware: diff for NMU version 1:13.0.2-3.1

2015-03-14 Thread Debian Bug Tracking System
Processing control commands: > tags 765490 + pending Bug #765490 [xserver-xorg-video-vmware] xserver-xorg-video-vmware: resizing issues Added tag(s) pending. -- 765490: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=765490 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems

Bug#765490: xserver-xorg-video-vmware: diff for NMU version 1:13.0.2-3.1

2015-03-14 Thread Bernd Zeimetz
Control: tags 765490 + pending Dear maintainer, I've prepared an NMU for xserver-xorg-video-vmware (versioned as 1:13.0.2-3.1) and uploaded it to unstable. I'll ask for an unblock. Regards. Bernd diff -u xserver-xorg-video-vmware-13.0.2/debian/changelog xserver-xorg-video-vmware-13.0.2/debia

Processed: Rising severity

2015-03-14 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > severity 765490 grave Bug #765490 [xserver-xorg-video-vmware] xserver-xorg-video-vmware: resizing issues Severity set to 'grave' from 'important' > thanks Stopping processing here. Please contact me if you need assistance. -- 765490: http://bug

Bug#780473: marked as done (Architecture attribute must be a single line, not multiple lines)

2015-03-14 Thread Debian Bug Tracking System
Your message dated Sat, 14 Mar 2015 21:48:38 + with message-id and subject line Bug#780473: fixed in kissplice 2.2.1-3 has caused the Debian Bug report #780473, regarding Architecture attribute must be a single line, not multiple lines to be marked as done. This means that you claim that the

Processed: tagging 780447

2015-03-14 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tags 780447 + pending Bug #780447 [libtcnative-1] tomcat-native: SSLv23_* calls shouldn't be disabled Added tag(s) pending. > thanks Stopping processing here. Please contact me if you need assistance. -- 780447: http://bugs.debian.org/cgi-bin/bu

Processed: your mail

2015-03-14 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > severity 765514 serious Bug #765514 {Done: Michael Stone } [coreutils] coreutils: regression in chroot semantics Severity set to 'serious' from 'normal' > End of message, stopping processing here. Please contact me if you need assistance. -- 76

Bug#778634: marked as done (libphp-snoopy: CVE-2008-7313 / CVE-2014-5008)

2015-03-14 Thread Debian Bug Tracking System
Your message dated Sat, 14 Mar 2015 17:48:46 + with message-id and subject line Bug#778634: fixed in libphp-snoopy 2.0.0-1 has caused the Debian Bug report #778634, regarding libphp-snoopy: CVE-2008-7313 / CVE-2014-5008 to be marked as done. This means that you claim that the problem has been

Bug#779621: jakarta-taglibs-standard: CVE-2015-0254

2015-03-14 Thread Miguel Landaeta
On Sat, Mar 14, 2015 at 06:21:37PM +0100, Emmanuel Bourg wrote: > Thank you for taking care of this Miguel. Upstream told me that the > commits r1642442 [1] and r1642613 [2] contained the relevant fixes for > this issue. I haven't checked if they can be easily backported though. > > Emmanuel Bourg

Bug#779621: jakarta-taglibs-standard: CVE-2015-0254

2015-03-14 Thread Emmanuel Bourg
Thank you for taking care of this Miguel. Upstream told me that the commits r1642442 [1] and r1642613 [2] contained the relevant fixes for this issue. I haven't checked if they can be easily backported though. Emmanuel Bourg [1] http://svn.apache.org/r1642442 [2] http://svn.apache.org/r1642613

Bug#779621: jakarta-taglibs-standard: CVE-2015-0254

2015-03-14 Thread Miguel Landaeta
On Sat, Mar 14, 2015 at 02:03:52PM -0300, Miguel Landaeta wrote: > > the release cycle. I mean, the full diff between 2.1.1 and 2.1.3 has almost Sorry, I got it wrong. The new upstream releases are 1.2.1 and 1.2.3. -- Miguel Landaeta, nomadium at debian.org secure email with PGP 0x6E608B637D896

Processed: Re: jakarta-taglibs-standard: CVE-2015-0254

2015-03-14 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > owner 779621 ! Bug #779621 [jakarta-taglibs-standard] jakarta-taglibs-standard: CVE-2015-0254 Owner recorded as Miguel Landaeta . > thanks Stopping processing here. Please contact me if you need assistance. -- 779621: http://bugs.debian.org/cgi-

Bug#779621: jakarta-taglibs-standard: CVE-2015-0254

2015-03-14 Thread Miguel Landaeta
owner 779621 ! thanks On Tue, Mar 03, 2015 at 07:57:36AM +0100, Moritz Muehlenhoff wrote: > Package: jakarta-taglibs-standard > Severity: important > Tags: security > > Please see > http://www.securityfocus.com/archive/1/534772 > > Cheers, > Moritz > > Hi, I can try to backport the f

Bug#780143:

2015-03-14 Thread Chris Bainbridge
Axel's patch from upstream git fixes the issue (tested with fixedsc font in terminator).

Bug#778634: CVE-2008-7313 / CVE-2014-5008

2015-03-14 Thread Marcelo Jorge Vieira
Hi Moritz, On Thu, 2015-03-05 at 19:13 +0100, Moritz Mühlenhoff wrote: > Did you test the reverse deps in wheezy and jessie to check whether > they are compatible? > > wordpress (wheezy) > libphp-magpierss (jessie/wheezy) > ampache (jessie) No, I didn't. But I will do it today and I will upload

Bug#780473: Architecture attribute must be a single line, not multiple lines

2015-03-14 Thread Matthias Klose
Package: src:kissplice Version: 2.2.1-2 Severity: serious Tags: sid wheezy this is not allowed by policy, and the builds break then, see https://buildd.debian.org/status/package.php?p=kissplice Package: kissplice Architecture: any-amd64 any-arm64 any-mips64 any-mips64el any-ia64 any

Bug#745454: marked as done ([libgcrypt11] Non free RFC)

2015-03-14 Thread Debian Bug Tracking System
Your message dated Sat, 14 Mar 2015 15:39:56 + with message-id and subject line Bug#767611: Removed package(s) from unstable has caused the Debian Bug report #745454, regarding [libgcrypt11] Non free RFC to be marked as done. This means that you claim that the problem has been dealt with. If

Bug#368297: marked as done (sudo-ldap failes when you change uri to ldaps)

2015-03-14 Thread Debian Bug Tracking System
Your message dated Sat, 14 Mar 2015 15:39:56 + with message-id and subject line Bug#767611: Removed package(s) from unstable has caused the Debian Bug report #368297, regarding sudo-ldap failes when you change uri to ldaps to be marked as done. This means that you claim that the problem has b

Bug#545414: marked as done (sudo-ldap: sudo fails with "sudo: setreuid(ROOT_UID, user_uid): Operation not permitted" for ldap users)

2015-03-14 Thread Debian Bug Tracking System
Your message dated Sat, 14 Mar 2015 15:39:56 + with message-id and subject line Bug#767611: Removed package(s) from unstable has caused the Debian Bug report #368297, regarding sudo-ldap: sudo fails with "sudo: setreuid(ROOT_UID, user_uid): Operation not permitted" for ldap users to be marked

Bug#658739: marked as done (gnutls26: LDAP+SSL account cannot use setuid binaries until gnutls26 is rebuilt with nettle not libgcrypt11)

2015-03-14 Thread Debian Bug Tracking System
Your message dated Sat, 14 Mar 2015 15:39:56 + with message-id and subject line Bug#767611: Removed package(s) from unstable has caused the Debian Bug report #368297, regarding gnutls26: LDAP+SSL account cannot use setuid binaries until gnutls26 is rebuilt with nettle not libgcrypt11 to be ma

Processed: Re: Bug#780401: Sounds like it might be related to bug 726530

2015-03-14 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > reassign 780401 fvwm Bug #780401 [gimp] gimp: crashes window manager (fvwm) on closing Bug reassigned from package 'gimp' to 'fvwm'. No longer marked as found in versions gimp/2.8.14-1. Ignoring request to alter fixed versions of bug #780401 to th

Bug#566351: marked as done (libgcrypt11: should not change user id as a side effect)

2015-03-14 Thread Debian Bug Tracking System
Your message dated Sat, 14 Mar 2015 15:39:56 + with message-id and subject line Bug#767611: Removed package(s) from unstable has caused the Debian Bug report #368297, regarding libgcrypt11: should not change user id as a side effect to be marked as done. This means that you claim that the pro

Bug#628671: marked as done (passwd: Ordinary users can't change their passwords.)

2015-03-14 Thread Debian Bug Tracking System
Your message dated Sat, 14 Mar 2015 15:39:56 + with message-id and subject line Bug#767611: Removed package(s) from unstable has caused the Debian Bug report #368297, regarding passwd: Ordinary users can't change their passwords. to be marked as done. This means that you claim that the proble

Bug#601667: marked as done (libpam-smbpass migrate breaks su (squeeze))

2015-03-14 Thread Debian Bug Tracking System
Your message dated Sat, 14 Mar 2015 15:39:56 + with message-id and subject line Bug#767611: Removed package(s) from unstable has caused the Debian Bug report #368297, regarding libpam-smbpass migrate breaks su (squeeze) to be marked as done. This means that you claim that the problem has been

Bug#658896: marked as done (sudo: setresuid(ROOT_UID, ROOT_UID, ROOT_UID): Operation not permitted)

2015-03-14 Thread Debian Bug Tracking System
Your message dated Sat, 14 Mar 2015 15:39:56 + with message-id and subject line Bug#767611: Removed package(s) from unstable has caused the Debian Bug report #368297, regarding sudo: setresuid(ROOT_UID, ROOT_UID, ROOT_UID): Operation not permitted to be marked as done. This means that you cla

Bug#579647: marked as done (nss-ldap changing uid due to using gcrypt somewhere...)

2015-03-14 Thread Debian Bug Tracking System
Your message dated Sat, 14 Mar 2015 15:39:56 + with message-id and subject line Bug#767611: Removed package(s) from unstable has caused the Debian Bug report #368297, regarding nss-ldap changing uid due to using gcrypt somewhere... to be marked as done. This means that you claim that the prob

Bug#779048: no point in migrating

2015-03-14 Thread Adam Borowski
Why won't you just rename the package back to "libjpeg-progs"? Without this nonsense migration, there won't be any issues. The reason for libjpeg-turbo-progs, those "waaah hijack" complaints don't hold any water anymore as libjpeg9 is gone, and I don't think the Release Team is going to ever allow

Bug#780424: Emedded ZendDb component affected by several security issues

2015-03-14 Thread David Prévot
Hi François-Régis, [ I Shouldn’t reply to mail too late: I misunderstood your proposal… ] >> Do you think, in between, it's worth to make a package which remove the >> upstream embedded ZendDB and embed a proper (let says 2.3.6) version of >> it. That would be fine: you may just copy a recent Ze

Processed: fixed in new upstream

2015-03-14 Thread Debian Bug Tracking System
Processing control commands: > tags -1 + patch Bug #747958 [gimp-help] FTBFS: parser error : Start tag expected, '<' not found Added tag(s) patch. -- 747958: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=747958 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems -- To UNS

Bug#747958: fixed in new upstream

2015-03-14 Thread Matthias Klose
Control: tags -1 + patch this is fixed upstream in 2.6.2, but this drops Korean. 2.8.2 builds Korean, and a few other languages. see https://launchpad.net/ubuntu/+source/gimp-help/2.8.2-0ubuntu1 -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of "unsubscribe".

Bug#780240: [Pkg-phototools-devel] Bug#780240: libgphoto2-port10: Wrong transition package for ABI changing library

2015-03-14 Thread hpfn
On Fri, 13 Mar 2015 22:24:13 +0100 Andreas Beckmann wrote: > On 2015-03-13 22:00, Herbert Parentes Fortes Neto (hpfn) wrote: > > Thanks for checking the package. > > Looks good now! Do you need a sponsor to upload this? > It would be nice if you do the upload. I belive it would be faster to clo

Processed: package is in NEW

2015-03-14 Thread Debian Bug Tracking System
Processing control commands: > tags -1 +pending Bug #776483 [python-imaging] python-imaging: no smooth upgrade path from wheezy due to python-imaging-tk becoming a virtual package Added tag(s) pending. -- 776483: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=776483 Debian Bug Tracking System

Processed: severity of 777191 is important

2015-03-14 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > severity 777191 important Bug #777191 [grub-efi-amd64] grub-efi-amd64 on Debian Jessie cannot boot zfs native root filesystem running the latest git code soon to be 0.6.4 tagged - official release Severity set to 'important' from 'critical' > th

Bug#776483: package is in NEW

2015-03-14 Thread Tobias Hansen
Control: tags -1 +pending A fix for this is currently in the NEW queue. -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#779634: marked as done (pymad: FTBFS - No 'Setup' file. Perhaps you need to run the configure script.)

2015-03-14 Thread Debian Bug Tracking System
Your message dated Sat, 14 Mar 2015 11:34:05 + with message-id and subject line Bug#779634: fixed in pymad 0.8-2 has caused the Debian Bug report #779634, regarding pymad: FTBFS - No 'Setup' file. Perhaps you need to run the configure script. to be marked as done. This means that you claim t

Bug#778810: grub-efi-amd64-bin: boot/bootx86.efi problems

2015-03-14 Thread Ian Campbell
Control: severity -1 important Control: tags -1 +unreproducible +moreinfo On Wed, 2015-02-25 at 12:19 +, Ian Campbell wrote: > On Sat, 2015-02-21 at 23:27 +0900, Mark Brown wrote: > > On Sat, Feb 21, 2015 at 10:31:19AM +, Ian Campbell wrote: > > > On Sat, 2015-02-21 at 11:39 +0900, Mark Br

Processed: Re: Bug#778810: grub-efi-amd64-bin: boot/bootx86.efi problems

2015-03-14 Thread Debian Bug Tracking System
Processing control commands: > severity -1 important Bug #778810 [grub-efi-amd64-bin] grub-efi-amd64-bin: boot/bootx86.efi problems Severity set to 'important' from 'critical' > tags -1 +unreproducible +moreinfo Bug #778810 [grub-efi-amd64-bin] grub-efi-amd64-bin: boot/bootx86.efi problems Added t

Processed: user release.debian....@packages.debian.org, usertagging 778810, tagging 778810

2015-03-14 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > user release.debian@packages.debian.org Setting user to release.debian@packages.debian.org (was ni...@thykier.net). > usertags 778810 jessie-can-defer There were no usertags set. Usertags are now: jessie-can-defer. > tags 778810 + jessie-i

Bug#777191: grub-efi-amd64 on Debian Jessie cannot boot zfs native root filesystem running the latest git code soon to be 0.6.4 tagged - official release

2015-03-14 Thread Ian Campbell
On Thu, 2015-02-05 at 20:04 -0800, Azeem Esmail wrote: > Works with 0.6.3 (v0.6.3-766_gfde0d6d) > Does not work with 0.6.3 latest code (dailies version). What are these the versions of? > At first reboot, the screen freezes with the following message: > > mount: mounting /sys on /root/sys faile

Bug#767040: Superblock time check causes problems for fsck in initramfs

2015-03-14 Thread Beck, Andre
Hi, isn't that a bug in e2fsck anyway? There is accept_time_fudge which defaults to true and should take care of this situation. Even when it wouldn't default to true, my e2fsck.conf already had its alias buggy_init_scripts set to 1. Nevertheless, I'm briefly seeing an fsck running now on every bo

Bug#778895: Bug#780388: RM: trafficserver/5.0.1-1

2015-03-14 Thread Niels Thykier
On 2015-03-13 09:29, Arnaud Fontaine wrote: > Package: release.debian.org > Severity: normal > User: release.debian@packages.debian.org > Usertags: rm > > Hello, > > Considering that trafficserver is currently affected by 3 security bugs > (CVE-2014-3624, CVE-2014-10022 (#778895) and #74984

Bug#780452: libwebkitgtk-3.0-0: Segfault in `VectorBufferBase` at `../Source/WTF/wtf/Vector.h:330`

2015-03-14 Thread Paul Menzel
Dear Debian folks, Am Samstag, den 14.03.2015, 10:00 +0100 schrieb Paul Menzel: […] > I reported this to the WebKitGTK+ bug tracker as ticket #127474 [1]. I meant ticket #142692 [2] as denoted in the meta data. Thanks, Paul [2] https://bugs.webkit.org/show_bug.cgi?id=142692 Segfault i

Bug#780452: libwebkitgtk-3.0-0: Segfault in `VectorBufferBase` at `../Source/WTF/wtf/Vector.h:330`

2015-03-14 Thread Paul Menzel
Package: libwebkitgtk-3.0-0 Version: 2.4.8-1 Severity: grave Tags: upstream Control: forwarded -1 https://bugs.webkit.org/show_bug.cgi?id=142692 Control: affects -1 evolution Dear Debian folks, Evolution sometimes crashes due to a segmentation fault in libwebkitgtk-3.0.so.0.22.14. evolu

Processed: libwebkitgtk-3.0-0: Segfault in `VectorBufferBase` at `../Source/WTF/wtf/Vector.h:330`

2015-03-14 Thread Debian Bug Tracking System
Processing control commands: > forwarded -1 https://bugs.webkit.org/show_bug.cgi?id=142692 Bug #780452 [libwebkitgtk-3.0-0] libwebkitgtk-3.0-0: Segfault in `VectorBufferBase` at `../Source/WTF/wtf/Vector.h:330` Set Bug forwarded-to-address to 'https://bugs.webkit.org/show_bug.cgi?id=142692'. > a

Bug#779797: gdisk: Returns exit code 1 after successful operations

2015-03-14 Thread intrigeri
Hi Guillaume, Guillaume Delacour wrote (12 Mar 2015 23:05:35 GMT) : > Splitted in two patches. Thanks! Is it on purpose that the newly-introduced test_exit_condition.diff isn't listed in debian/patches/series? Reading debian/changelog, I guess not => I can trivially fix that in the Vcs-Git befor

Bug#780444: Update my email address

2015-03-14 Thread Paul Menzel
Control: submitter -1 ! Dear Debian folks, Unfortunately I submitted that report from the wrong email address. So update it. Thanks, Paul signature.asc Description: This is a digitally signed message part

Processed: Re: Bug#780444: Update my email address

2015-03-14 Thread Debian Bug Tracking System
Processing control commands: > submitter -1 ! Bug #780444 [libwebkitgtk-3.0-0] libwebkitgtk-3.0-0: use after free: GLib-GObject-CRITICAL **: g_closure_unref: assertion 'closure->ref_count > 0' failed Changed Bug submitter to 'Paul Menzel ' from 'Paul Menzel ' -- 780444: http://bugs.debian.org

Bug#776094: dovecot-imapd: corrupts mailbox after trying to retrieve it (fwd)

2015-03-14 Thread Andrew Worsley
On Thu, 19 Feb 2015 22:34:07 +0100 (CET) Santiago Vila wrote: One more follow up suggestion based on my debugging locally. (You may already be aware of these options - so forgive me if you already are). You can install strace and strace the dovecot process e.g. Run ps axf and look for : ... 4