Processed: user debian-secur...@lists.debian.org, usertagging 780565, usertagging 780566, usertagging 780567 ...

2015-03-16 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > user debian-secur...@lists.debian.org Setting user to debian-secur...@lists.debian.org (was car...@debian.org). > usertags 780565 + tracked Usertags were: tracked. Usertags are now: tracked. > usertags 780566 + tracked Usertags were: tracked. User

Bug#755202: network-manager: keeps creating and using new connection "eth0" that does not work

2015-03-16 Thread Fitzcarraldo
I started experiencing this problem in Gentoo Linux (~amd64 installation using OpenRC) around 5 months ago. Keivan Moradi's fix (Message #79) did not cure the problem for me, and, in any case, my wired NIC uses a different driver (atl1c) which appears to be stable in my installation. I think an inv

Bug#780629: libibverbs1: please add Breaks: libopenmpi1.3

2015-03-16 Thread Andreas Beckmann
Package: libibverbs1 Version: 1.1.8-1 Severity: serious Tags: patch User: debian...@lists.debian.org Usertags: piuparts Control: affects -1 + libopenmpi1.6 src:openmpi Hi, while analyzing some piuparts upgrade tests I noticed some cases where the openmpi 1.3 -> 1.6 transition does not work out as

Processed: libibverbs1: please add Breaks: libopenmpi1.3

2015-03-16 Thread Debian Bug Tracking System
Processing control commands: > affects -1 + libopenmpi1.6 src:openmpi Bug #780629 [libibverbs1] libibverbs1: please add Breaks: libopenmpi1.3 Added indication that 780629 affects libopenmpi1.6 and src:openmpi -- 780629: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=780629 Debian Bug Tracking

Processed: block 780424 with 780422

2015-03-16 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > block 780424 with 780422 Bug #780424 [galette] Emedded ZendDb component affected by several security issues 780424 was not blocked by any bugs. 780424 was not blocking any bugs. Added blocking bug(s) of 780424: 780422 > thanks Stopping processing

Bug#775235: gnome-shell not starting with gdm3/mesa/llvm-3.4 but does start from startx & lightdm regardless

2015-03-16 Thread Philip Hands
Hi Simon, Thanks for the detailed response. Simon McVittie writes: ... >> Hints about where gdm3 might be logging what happened would be useful. > > You seem to be running systemd as pid 1, so the catch-all answer is > "in the journal" (available via either journalctl or the traditional > syslo

Bug#780424: Emedded ZendDb component affected by several security issues

2015-03-16 Thread François-Régis
tag -1 pending thanks This bug affects only unstable and will be fixed with #780422 fix. Cheers signature.asc Description: OpenPGP digital signature

Bug#775733: xemacs21-gnome-*: hangs during upgrade from squeeze -> wheezy -> jessie

2015-03-16 Thread Andreas Beckmann
Package: src:xemacs21,xemacs21-gnome-mule,xemacs21-gnome-nomule,xemacs21-gnome-mule-canna-wnn Followup-For: Bug #775733 Attached are two new piuparts logs: * failure due to deadlock and timeout * success after patching xemacs The logfiles contain the piuparts command lines used. Andreas xema

Processed: reassign 766608 to src:qpidd, reassign 743177 to src:vtk6, reassign 749921 to src:vtk6 ...

2015-03-16 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > # housekeeping on bugs reported for not (any longer) existing packages > reassign 766608 src:qpidd 0.28-9 Bug #766608 [qpidd-store] qpidd-store: The Qpid store package installs a stub and not the store module Warning: Unknown package 'qpidd-store

Bug#780506: marked as done (requests: CVE-2015-2296: session fixation and cookie stealing issue)

2015-03-16 Thread Debian Bug Tracking System
Your message dated Mon, 16 Mar 2015 23:03:50 + with message-id and subject line Bug#780506: fixed in requests 2.4.3-6 has caused the Debian Bug report #780506, regarding requests: CVE-2015-2296: session fixation and cookie stealing issue to be marked as done. This means that you claim that th

Bug#780624: libmpeg2-4: introduces new symbols

2015-03-16 Thread Raphael Geissert
Package: libmpeg2-4 Version: 0.5.1-6 Severity: serious Hi, Between wheezy and jessie libmpeg2-4 introduced at least one new symbol, mpeg2_guess_aspect, without even including a shlibs or symbols files. The result being that some applications using libmpeg2-4 that use the new symbols, perhaps di

Bug#760366: marked as done (gdm3: Stopped showing any users, no way to log in)

2015-03-16 Thread Debian Bug Tracking System
Your message dated Mon, 16 Mar 2015 21:33:50 + with message-id and subject line Bug#757348: fixed in cgmanager 0.33-2+deb8u2 has caused the Debian Bug report #757348, regarding gdm3: Stopped showing any users, no way to log in to be marked as done. This means that you claim that the problem h

Bug#757348: marked as done (systemd: with SysV init, can no longer suspend and shutdown from lightdm)

2015-03-16 Thread Debian Bug Tracking System
Your message dated Mon, 16 Mar 2015 21:33:50 + with message-id and subject line Bug#757348: fixed in cgmanager 0.33-2+deb8u2 has caused the Debian Bug report #757348, regarding systemd: with SysV init, can no longer suspend and shutdown from lightdm to be marked as done. This means that you

Bug#754850: marked as done (regression: no suspend/hibernate on non-systemd systems)

2015-03-16 Thread Debian Bug Tracking System
Your message dated Mon, 16 Mar 2015 21:33:50 + with message-id and subject line Bug#757348: fixed in cgmanager 0.33-2+deb8u2 has caused the Debian Bug report #757348, regarding regression: no suspend/hibernate on non-systemd systems to be marked as done. This means that you claim that the pro

Bug#759745: marked as done (gdm3: Unable to login post-upgrade without systemd-sysv installed)

2015-03-16 Thread Debian Bug Tracking System
Your message dated Mon, 16 Mar 2015 21:33:50 + with message-id and subject line Bug#757348: fixed in cgmanager 0.33-2+deb8u2 has caused the Debian Bug report #757348, regarding gdm3: Unable to login post-upgrade without systemd-sysv installed to be marked as done. This means that you claim th

Bug#758746: marked as done (kde-workspace-bin: Energy saving schemes have no effect)

2015-03-16 Thread Debian Bug Tracking System
Your message dated Mon, 16 Mar 2015 21:33:50 + with message-id and subject line Bug#757348: fixed in cgmanager 0.33-2+deb8u2 has caused the Debian Bug report #757348, regarding kde-workspace-bin: Energy saving schemes have no effect to be marked as done. This means that you claim that the pro

Bug#760281: marked as done (xfce4: cannot mount usb drive: "Not authorized to perform operation")

2015-03-16 Thread Debian Bug Tracking System
Your message dated Mon, 16 Mar 2015 21:33:50 + with message-id and subject line Bug#757348: fixed in cgmanager 0.33-2+deb8u2 has caused the Debian Bug report #757348, regarding xfce4: cannot mount usb drive: "Not authorized to perform operation" to be marked as done. This means that you claim

Bug#757698: marked as done ([network-manager] network-manager: Not authorized to control networking)

2015-03-16 Thread Debian Bug Tracking System
Your message dated Mon, 16 Mar 2015 21:33:50 + with message-id and subject line Bug#757348: fixed in cgmanager 0.33-2+deb8u2 has caused the Debian Bug report #757348, regarding [network-manager] network-manager: Not authorized to control networking to be marked as done. This means that you c

Bug#780620: control file not policy compliant and build failures almost everywhere

2015-03-16 Thread Matthias Klose
Package: src:kcov Version: 25+dfsg-1 Severity: serious Tags: sid stretch patch Architecture attributes in the control file are not multi-line fields. see the buildd logs, that the architectures on the second line are not picked up for the build. Then the package fails everywhere except on i386. Y

Processed (with 1 errors): Re: Bug#780489: dpkg-dev: dpkg-gensymbols does not demangle C++ symbols on some archs

2015-03-16 Thread Debian Bug Tracking System
Processing control commands: > reassign -1 verbiste Bug #780489 [dpkg-dev] dpkg-dev: dpkg-gensymbols does not demangle C++ symbols on some archs Bug reassigned from package 'dpkg-dev' to 'verbiste'. No longer marked as found in versions dpkg/1.17.24. Ignoring request to alter fixed versions of bu

Processed: reassign 706743 to debian-installer, reassign 708167 to installation-reports ..., closing 691501 ...

2015-03-16 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > reassign 706743 debian-installer Bug #706743 [installer] Fwd: Efi in Legacy mode Warning: Unknown package 'installer' Bug reassigned from package 'installer' to 'debian-installer'. No longer marked as found in versions CR1. Ignoring request to alt

Bug#780613: diakonos: completely broken in jessie

2015-03-16 Thread Antonio Terceiro
Package: diakonos Version: 0.9.0-2 Severity: grave Justification: renders package unusable $ diakonos /usr/lib/ruby/2.1.0/rubygems/core_ext/kernel_require.rb:55:in `require': cannot load such file -- curses (LoadError) from /usr/lib/ruby/2.1.0/rubygems/core_ext/kernel_require.rb:55:in `r

Bug#780424: Emedded ZendDb component affected by several security issues

2015-03-16 Thread François-Régis
Hi, Le 16/03/2015 13:59, Raphael Hertzog a écrit : > On Mon, 16 Mar 2015, François-Régis wrote: >> As I've no experience on that sort of thing, would you mind to have a >> look at attached patch and tell me if : > No, the package build should not rely on the network to download stuff to > embed in

Processed: [bts-link] source package freetype

2015-03-16 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > # > # bts-link upstream status pull for source package freetype > # see http://lists.debian.org/debian-devel-announce/2006/05/msg1.html > # > user bts-link-upstr...@lists.alioth.debian.org Setting user to bts-link-upstr...@lists.alioth.debian.

Bug#779040: marked as done (fake-hwclock: does not run at shutdown)

2015-03-16 Thread Debian Bug Tracking System
Your message dated Mon, 16 Mar 2015 17:18:34 + with message-id and subject line Bug#779040: fixed in fake-hwclock 0.9 has caused the Debian Bug report #779040, regarding fake-hwclock: does not run at shutdown to be marked as done. This means that you claim that the problem has been dealt with

Processed: severity of 779040 is serious

2015-03-16 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > severity 779040 serious Bug #779040 [fake-hwclock] fake-hwclock: does not run at shutdown Severity set to 'serious' from 'important' > thanks Stopping processing here. Please contact me if you need assistance. -- 779040: http://bugs.debian.org/c

Bug#777164: systemd: libvirt cgroups start to disappear from machine.slice after systemctl daemon-reload

2015-03-16 Thread Mateusz Nalewajski
I have just checked your patch Christian and it resolves my issue. After I applied it to systemd-215-12, I'm not able to reproduce the issue mentioned in the bug report. Thank you for help! 2015-03-16 14:57 GMT+01:00 Christian Seiler : > Am 2015-03-16 13:51, schrieb Michael Biebl: > >> It would

Bug#775733: Processed: reassign 775733 to src:xemacs21,xemacs21-gnome-mule,xemacs21-gnome-nomule,xemacs21-gnome-mule-canna-wnn ...

2015-03-16 Thread Mark Brown
On Mon, Mar 16, 2015 at 04:27:48PM +0100, Andreas Beckmann wrote: > I can deterministically reproduce this bug in piuparts, haven't tried > other means to get it reproduced. > Please check the bug log for details and a patch. > https://bugs.debian.org/775733 I can't see instructions for reproduci

Processed: severity of 776908 is serious

2015-03-16 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > severity 776908 serious Bug #776908 {Done: Steve McIntyre <93...@debian.org>} [abcde] Tagging MP3-files fails Severity set to 'serious' from 'important' > thanks Stopping processing here. Please contact me if you need assistance. -- 776908: htt

Bug#718110: marked as done (rhmessaging: FTBFS: jrnl/rmgr.cpp:75:44: error: argument to 'sizeof' in 'void* memset(void*, int, size_t)' call is the same pointer type 'mrg::journal::aio_cb* {aka iocb*}'

2015-03-16 Thread Debian Bug Tracking System
Your message dated Mon, 16 Mar 2015 16:51:56 +0100 with message-id <5506fc1c.7010...@debian.org> and subject line rhmessaging was removed from Debian has caused the Debian Bug report #718110, regarding rhmessaging: FTBFS: jrnl/rmgr.cpp:75:44: error: argument to 'sizeof' in 'void* memset(void*, int

Bug#780599: verbiste: FTBFS on various architectures due to outdated symbols file

2015-03-16 Thread John Paul Adrian Glaubitz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 03/16/2015 04:42 PM, Tomasz Buchert wrote: >> Indeed, you could be right. I just checked the build log for >> verbiste_0.1.41-2 on sh4, for example, and the buildd was, >> indeed, using dpkg_1.17.23 that time while it was using 1.17.24 >> for the

Bug#754671: marked as done (rhmessaging: FTBFS on powerpc: configure: error: Couldn't find required library in range db_cxx-4.2 through db_cxx-5.1)

2015-03-16 Thread Debian Bug Tracking System
Your message dated Mon, 16 Mar 2015 16:51:56 +0100 with message-id <5506fc1c.7010...@debian.org> and subject line rhmessaging was removed from Debian has caused the Debian Bug report #754671, regarding rhmessaging: FTBFS on powerpc: configure: error: Couldn't find required library in range db_cxx-

Processed: Re: Bug#780599: verbiste: FTBFS on various architectures due to outdated symbols file

2015-03-16 Thread Debian Bug Tracking System
Processing control commands: > block -1 by 780489 Bug #780599 [src:verbiste] verbiste: FTBFS on various architectures due to outdated symbols file 780599 was not blocked by any bugs. 780599 was not blocking any bugs. Added blocking bug(s) of 780599: 780489 -- 780599: http://bugs.debian.org/cgi-

Bug#780599: verbiste: FTBFS on various architectures due to outdated symbols file

2015-03-16 Thread Tomasz Buchert
Control: block -1 by 780489 On 16/03/15 16:24, John Paul Adrian Glaubitz wrote: > Hi Tomasz! > > On 03/16/2015 04:14 PM, Tomasz Buchert wrote: > > I don't think it is the case. It seems to me (although I may be > > wrong) that dpkg-gensymbols does not demangle C++ symbols properly. > > I reported

Bug#775733: Processed: reassign 775733 to src:xemacs21,xemacs21-gnome-mule,xemacs21-gnome-nomule,xemacs21-gnome-mule-canna-wnn ...

2015-03-16 Thread Andreas Beckmann
Control: tag -1 - unreproducible On 2015-03-16 16:00, Mark Brown wrote: > Please don't only send mail to the control interface, send mail to the > maintainer explaining why you're doing whatever you're doing. I've not > been able to reproduce this so unless I hear something soon I'm likely > to j

Processed: Re: Processed: reassign 775733 to src:xemacs21,xemacs21-gnome-mule,xemacs21-gnome-nomule,xemacs21-gnome-mule-canna-wnn ...

2015-03-16 Thread Debian Bug Tracking System
Processing control commands: > tag -1 - unreproducible Bug #775733 [src:xemacs21,xemacs21-gnome-mule,xemacs21-gnome-nomule,xemacs21-gnome-mule-canna-wnn] xemacs21-gnome-*: hangs during upgrade from squeeze -> wheezy -> jessie Removed tag(s) unreproducible. -- 775733: http://bugs.debian.org/cgi

Bug#780601: asterisk: CVE-2015-1558: File descriptor leak when incompatible codecs are offered

2015-03-16 Thread Salvatore Bonaccorso
Source: asterisk Version: 1:13.1.0~dfsg-1 Severity: grave Tags: security upstream patch fixed-upstream Hi, the following vulnerability was published for asterisk. CVE-2015-1558[0]: | Asterisk Open Source 12.x before 12.8.1 and 13.x before 13.1.1, when | using the PJSIP channel driver, does not p

Bug#780599: verbiste: FTBFS on various architectures due to outdated symbols file

2015-03-16 Thread Tomasz Buchert
On 16/03/15 15:49, John Paul Adrian Glaubitz wrote: > Source: verbiste > Version: 0.1.41-3 > Severity: serious > Justification: FTBFS on release architecture leaves package out-of-date > > Hello! > > Your package currently fails to build on various (release) architectures since > the symbols file

Processed: Re: Processed: reassign 775733 to src:xemacs21,xemacs21-gnome-mule,xemacs21-gnome-nomule,xemacs21-gnome-mule-canna-wnn ...

2015-03-16 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tag 775733 + unreproducible Bug #775733 [src:xemacs21,xemacs21-gnome-mule,xemacs21-gnome-nomule,xemacs21-gnome-mule-canna-wnn] xemacs21-gnome-*: hangs during upgrade from squeeze -> wheezy -> jessie Warning: Unknown package 'xemacs21-gnome-mule'

Bug#780599: verbiste: FTBFS on various architectures due to outdated symbols file

2015-03-16 Thread John Paul Adrian Glaubitz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi Tomasz! On 03/16/2015 04:14 PM, Tomasz Buchert wrote: > I don't think it is the case. It seems to me (although I may be > wrong) that dpkg-gensymbols does not demangle C++ symbols properly. > I reported a bug yesterday: > http://bugs.debian.org/

Bug#780506: Reproduction script

2015-03-16 Thread Daniele Tricoli
Hello Daniel, On Monday 16 March 2015 11:18:42 Daniel Watkins wrote: > I've written a simple reproduction script for the CVE, which validates > whether or not the issue is fixed. I patched requests yesterday and I made a pre unblock request: RT agrees for unblocking requests 2.4.3-6 with the fix

Bug#780240: marked as done (libgphoto2-port10: Wrong transition package for ABI changing library)

2015-03-16 Thread Debian Bug Tracking System
Your message dated Mon, 16 Mar 2015 15:19:53 + with message-id and subject line Bug#780240: fixed in libgphoto2 2.5.7-2 has caused the Debian Bug report #780240, regarding libgphoto2-port10: Wrong transition package for ABI changing library to be marked as done. This means that you claim that

Bug#768988: marked as done (lintian4python: uninstallable in jessie and sid)

2015-03-16 Thread Debian Bug Tracking System
Your message dated Mon, 16 Mar 2015 15:55:40 +0100 with message-id <5506eeec.6080...@debian.org> and subject line lintian4python was removed from Debian has caused the Debian Bug report #768988, regarding lintian4python: uninstallable in jessie and sid to be marked as done. This means that you cla

Bug#780599: verbiste: FTBFS on various architectures due to outdated symbols file

2015-03-16 Thread John Paul Adrian Glaubitz
Source: verbiste Version: 0.1.41-3 Severity: serious Justification: FTBFS on release architecture leaves package out-of-date Hello! Your package currently fails to build on various (release) architectures since the symbols file is outdated and needs to be updated using the diff output generated d

Processed: reassign 775733 to src:xemacs21,xemacs21-gnome-mule,xemacs21-gnome-nomule,xemacs21-gnome-mule-canna-wnn ...

2015-03-16 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > reassign 775733 > src:xemacs21,xemacs21-gnome-mule,xemacs21-gnome-nomule,xemacs21-gnome-mule-canna-wnn Bug #775733 [xemacs21-gnome-mule,xemacs21-gnome-nomule,xemacs21-gnome-mule-canna-wnn] xemacs21-gnome-*: hangs during upgrade from squeeze ->

Processed: wireshark: Ctrl+C/Ctrl+V does not work in filter textbox

2015-03-16 Thread Debian Bug Tracking System
Processing control commands: > forwarded -1 https://code.wireshark.org/review/7276 Bug #780596 [wireshark] wireshark: Ctrl+C/Ctrl+V does not work in filter textbox Set Bug forwarded-to-address to 'https://code.wireshark.org/review/7276'. -- 780596: http://bugs.debian.org/cgi-bin/bugreport.cgi?bu

Bug#780596: wireshark: Ctrl+C/Ctrl+V does not work in filter textbox

2015-03-16 Thread Bálint Réczey
Package: wireshark Severity: serious Control: forwarded -1 https://code.wireshark.org/review/7276 Tags: pending A back-ported change fixing a crash when using Broadway interface caused this problem. IMO this regression should be fixed for Jessie by either dropping the back-ported change and lettin

Bug#780240: libgphoto2-port10: Wrong transition package for ABI changing library

2015-03-16 Thread Andreas Beckmann
On 2015-03-14 13:27, Herbert Parentes Fortes Neto (hpfn) wrote: > It would be nice if you do the upload. I belive it would be > faster to close the bug. OK, uploaded to experimental. Andreas -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of "unsubscribe". T

Bug#771341: segfaults in sqlite3_value_type while using from Python

2015-03-16 Thread Marc F. Clemente
> On Mar 16, 2015, at 8:43 AM, László Böszörményi (GCS) wrote: > > On Mon, Mar 16, 2015 at 1:11 PM, Marc F. Clemente wrote: >> For what it's worth, I am still getting segfaults in version 3.8.7.4-1. >> Multiple different computers, all amd64. > What kind of CPU do you have? Intel or AMD? One i

Bug#777164: systemd: libvirt cgroups start to disappear from machine.slice after systemctl daemon-reload

2015-03-16 Thread Christian Seiler
Am 2015-03-16 13:51, schrieb Michael Biebl: It would be great, if Mateusz can confirm that this patch [1] does indeed fix his issue. Mateusz, if you are not versed in compiling packages yourself and you would prefer if we provided you with a test package, please let us know. I can also provide

Bug#780592: marked as done (cdbs: broken compiler flag passing for perl-makemaker-vars.mk (wrong quoting))

2015-03-16 Thread Debian Bug Tracking System
Your message dated Mon, 16 Mar 2015 13:48:34 + with message-id and subject line Bug#780592: fixed in cdbs 0.4.129 has caused the Debian Bug report #780592, regarding cdbs: broken compiler flag passing for perl-makemaker-vars.mk (wrong quoting) to be marked as done. This means that you claim

Bug#771341: segfaults in sqlite3_value_type while using from Python

2015-03-16 Thread GCS
On Mon, Mar 16, 2015 at 1:11 PM, Marc F. Clemente wrote: > For what it's worth, I am still getting segfaults in version 3.8.7.4-1. > Multiple different computers, all amd64. What kind of CPU do you have? Intel or AMD? Laszlo/GCS -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.

Bug#780592: cdbs: broken compiler flag passing for perl-makemaker-vars.mk (wrong quoting)

2015-03-16 Thread Jonas Smedegaard
Package: cdbs Version: 0.4.128 Severity: serious -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Recent fix for bug#770767 contained a typo: Ending quote was applied too early in perl-makemaker-vars.mk, leading to broken compiler flags. This affects _all_ packages using perl-makemaker.mk snippet,

Bug#780424: Emedded ZendDb component affected by several security issues

2015-03-16 Thread Raphael Hertzog
On Mon, 16 Mar 2015, François-Régis wrote: > Version of galette in jessie is 0.7.8+dfsg-1 and rely on zendframework > (>= 1.11) as provided by debian. It should not be concerned by #780424. > > Do I miss something or do I need to do something to avoid its removal > from jessie ? Oh, I missed that

Bug#777164: systemd: libvirt cgroups start to disappear from machine.slice after systemctl daemon-reload

2015-03-16 Thread Michael Biebl
Am 15.03.2015 um 12:33 schrieb Christian Seiler: > Control: severity -1 serious > Control: tags -1 + patch > > Dear Maintainers, > > this doesn't only affect libvirt/KVM somewhat, but it also breaks LXC, > which also uses its own cgropus. lxc-attach will stop working once > systemctl daemon-reloa

Bug#771341: segfaults in sqlite3_value_type while using from Python

2015-03-16 Thread Marc F. Clemente
For what it's worth, I am still getting segfaults in version 3.8.7.4-1. Multiple different computers, all amd64. kernel: [413524.044820] fail2ban-server[10402]: segfault at 8 ip 7fbdb22b2350 sp 7fbdb1a5d808 error 4 in libsqlite3.so.0.8.6[7fbdb22a1000+c3000] and kernel: [663408.9252

Bug#780424: Emedded ZendDb component affected by several security issues

2015-03-16 Thread François-Régis
Hi David, Hi Raphaël, Le 14/03/2015 14:23, David Prévot a écrit : >>> Do you think, in between, it's worth to make a package which remove the >>> upstream embedded ZendDB and embed a proper (let says 2.3.6) version of >>> it. > > That would be fine: you may just copy a recent ZendDB in place of

Bug#780424: Emedded ZendDb component affected by several security issues

2015-03-16 Thread François-Régis
Hi Raphaël, Le 16/03/2015 10:13, Raphael Hertzog a écrit : > On Sat, 14 Mar 2015, François-Régis wrote: > But you need to act quickly as we are in deep freeze and galette is a leaf > package that can quickly go away... Version of galette in jessie is 0.7.8+dfsg-1 and rely on zendframework (>= 1.1

Bug#780506: Reproduction script

2015-03-16 Thread Daniel Watkins
Hello, I've written a simple reproduction script for the CVE, which validates whether or not the issue is fixed. You can find it at https://gist.github.com/OddBloke/211ff98b63a8cfb3f6d4; all you need installed is python-bottle (for HTTP serving). Dan signature.asc Description: OpenPGP digita

Bug#770130: Bug#775235: gnome-shell not starting with gdm3/mesa/llvm-3.4 but does start from startx & lightdm regardless

2015-03-16 Thread Simon McVittie
On Sun, 15 Mar 2015 at 19:48:07 +, Philip Hands wrote: > I only posted to the bug because I saw no mention of the fact that one > can get things working by avoiding gdm3 in any of these bugs, which > seemed like it might be relevant. The fact that llvm-3.4 didn't help me > is just an extra det

Bug#780139: squeeze update of checkpw?

2015-03-16 Thread Raphael Hertzog
Hello Gerrit, the Debian LTS team would like to fix the security issues which are currently open in the Squeeze version of checkpw: https://security-tracker.debian.org/tracker/CVE-2015-0885 Would you like to take care of this yourself? We are still understaffed so any help is always highly apprec

Bug#779048: libjpeg-turbo: Migration of jpeg-progs from Wheezy to Jessie

2015-03-16 Thread Ondřej Surý
I have prepared t-p-u upload based on reverted patch we already had in libjpeg-turbo: http://anonscm.debian.org/cgit/collab-maint/libjpeg-turbo.git/commit/?h=master-jessie&id=a024ab84ab6181270713e2e3f181cbe887582124 I don't care whether we solve this in t-p-u or unstable as long as I don't caught

Bug#775235: gnome-shell not starting with gdm3/mesa/llvm-3.4 but does start from startx & lightdm regardless

2015-03-16 Thread Julien Cristau
On Sun, Mar 15, 2015 at 19:03:41 +0100, Bernhard Übelacker wrote: > Hello Philip, > probably your case is more an example for the problem described in bugs > #770130 and #776911. > https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=770130 > https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=

Processed: Re: libfreetype6_2.5.2-3 makes some fonts unusable

2015-03-16 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tags 780143 patch Bug #780143 [libfreetype6] libfreetype6_2.5.2-3 makes some fonts unusable Added tag(s) patch. > End of message, stopping processing here. Please contact me if you need assistance. -- 780143: http://bugs.debian.org/cgi-bin/bugre

Bug#766988: The package: gstreamer0.10-ffmpeg isn't installable

2015-03-16 Thread Jürgen Göricke
Dear maintainer, fix the depensies from package: gstreamer0.10-ffmpeg please. I need the package to play mpeg4 media files in parole the default media player from Xfce project. Error message: apt-get install gstreamer0.10-ffmpeg Reading package lists... Done Building dependency tree Readi

Bug#780424: Emedded ZendDb component affected by several security issues

2015-03-16 Thread Raphael Hertzog
Hi François, On Sat, 14 Mar 2015, François-Régis wrote: > Do you think, in between, it's worth to make a package which remove the > upstream embedded ZendDB and embed a proper (let says 2.3.6) version of it. Yes, or alternatively apply only the security relevant patches that David mentioned. But

Bug#780575: marked as done (exim4-config: information disclosure issue)

2015-03-16 Thread Debian Bug Tracking System
Your message dated Mon, 16 Mar 2015 09:39:10 +0100 with message-id <20150316083909.gw7...@torres.zugschlus.de> and subject line Re: Bug#780575: exim4-config: information disclosure issue has caused the Debian Bug report #780575, regarding exim4-config: information disclosure issue to be marked as d

Bug#780575: exim4-config: information disclosure issue

2015-03-16 Thread Daniel Reichelt
Package: exim4-config Version: 4.80-7+deb7u1 Severity: grave Tags: security Justification: user security hole Hi folks, suppose you have set up an exim4 which provides virtual mailing, managing domains/accounts in a DB, say mysql. Just adding mysql queries and DB-*authentication data* to the ex

Bug#773593: marked as done (missing source for qprint.c)

2015-03-16 Thread Debian Bug Tracking System
Your message dated Mon, 16 Mar 2015 07:48:41 + with message-id and subject line Bug#773593: fixed in qprint 1.1.dfsg.2-1 has caused the Debian Bug report #773593, regarding missing source for qprint.c to be marked as done. This means that you claim that the problem has been dealt with. If thi

Bug#779634: closed by Jamie Wilkinson (Bug#779634: fixed in pymad 0.8-2)

2015-03-16 Thread Jérémy Bobbio
Control: reopen -1 Hi! > Changes: > pymad (0.8-2) unstable; urgency=medium > . >* Fix the pre-configure command to build Setup correctly. (Closes: > #779634) Sorry, but this does not seem to be fixed. dh_auto_clean -O--buildsystem=pybuild I: pybuild base:170: python2.7 setup.py clean

Processed: Re: Bug#779634 closed by Jamie Wilkinson (Bug#779634: fixed in pymad 0.8-2)

2015-03-16 Thread Debian Bug Tracking System
Processing control commands: > reopen -1 Bug #779634 {Done: Jamie Wilkinson } [src:pymad] pymad: FTBFS - No 'Setup' file. Perhaps you need to run the configure script. 'reopen' may be inappropriate when a bug has been closed with a version; all fixed versions will be cleared, and you may need to