Your message dated Thu, 02 Apr 2015 06:04:05 +
with message-id
and subject line Bug#781024: fixed in quassel 1:0.10.0-2.3
has caused the Debian Bug report #781024,
regarding quassel: Denial of service (CVE-2015-2778 CVE-2015-2779)
to be marked as done.
This means that you claim that the probl
Dear maintainer,
I've been using the patched build locally for 2 working days without
issues, so I think it's time to push it to unstable for wider testing.
This is quite a complex patch for this late in the release cycle, but
I really don't see an option for a less complex one. But I suggest we
Processing commands for cont...@bugs.debian.org:
> tags 755601 fixed-upstream
Bug #755601 [src:django-ldapdb] django-ldapdb: Please ensure it works with
Django 1.7
Added tag(s) fixed-upstream.
>
End of message, stopping processing here.
Please contact me if you need assistance.
--
755601: http:
On Apr 01 2015, Andreas Beckmann wrote:
> Preparing to unpack .../python3-llfuse-dbg_0.40+dfsg-1_amd64.deb ...
> Unpacking python3-llfuse-dbg (0.40+dfsg-1) over (0.40-2+b2) ...
> dpkg: error processing archive
> /var/cache/apt/archives/python3-llfuse-dbg_0.40+dfsg-1_amd64.deb (--unpack):
>
Package: gparted
Version: 0.19.0-2
Severity: serious
Tags: upstream
Forwarded: https://bugzilla.gnome.org/show_bug.cgi?id=745349
Gparted does not lock the disk being partitioned, so it will be automounted
whilst gparted is operating on it, resulting in gparted failing mid-operation.
This has been
On Wed, Apr 01, 2015 at 08:08:50PM +0200, Cyril Brulebois wrote:
>Steve McIntyre (2015-04-01):
>> As it stands, this is only for removable media which people have not
>> already set up as part of their systems. The whole issue here is that
>> this is not useful any more. If anybody is relying on b
> Could you check whether checksums match your environment?
No need to:
% echo $GZIP
--rsyncable
%
Whew. For a while I thought I was compromised. Turns out it's envvar
leaked in build environment.
Time to fix it.
--
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subje
On Thu, 2 Apr 2015, at 00:50, Frédéric Brière wrote:
> > > $ wc -c */usr/share/doc/libssh2-1/changelog.gz
> > >59923 amd64/usr/share/doc/libssh2-1/changelog.gz
> > >60425 i386/usr/share/doc/libssh2-1/changelog.gz
>
> The amd64 version is the "correct" one.
>
> I'm actually unable to re
Processing commands for cont...@bugs.debian.org:
> retitle 781640 Asymmetric keys and x509 certificates should not be used as
> HMAC keys
Bug #781640 [pyjwt] Asymmetric keys and x509 certificates should not be used as
HMAC keys
Ignoring request to change the title of bug#781640 to the same title
retitle 781640 Asymmetric keys and x509 certificates should not be used as HMAC
keys
forwarded 781640 https://github.com/jpadilla/pyjwt/issues/105
thanks
0.2.1 isn't vulnerable to the alg="none" bug, which was added in 0.3.0.
--
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
On Wed, Apr 01, 2015 at 10:41:51PM +0200, Mikhail Gusarov wrote:
> > $ wc -c */usr/share/doc/libssh2-1/changelog.gz
> >59923 amd64/usr/share/doc/libssh2-1/changelog.gz
> >60425 i386/usr/share/doc/libssh2-1/changelog.gz
The amd64 version is the "correct" one.
I'm actually unable to repro
Processing commands for cont...@bugs.debian.org:
> retitle 781640 Asymmetric keys and x509 certificates should not be used as
> HMAC keys
Bug #781640 [pyjwt] Signature bypass via "alg=none" and HMAC/RSA confusion
Changed Bug title to 'Asymmetric keys and x509 certificates should not be used
as H
Package: nodejs
Severity: serious
Version: 0.10.29~dfsg-1.1
nodejs is failing to build with failure of the test "test-crypto-stream.js"
http://buildd.raspbian.org/status/fetch.php?pkg=nodejs&arch=armhf&ver=0.10.29~dfsg-1.1&stamp=1427831511
[02:22|% 13|+ 82|- 0]: release test-crypto-stream
Hi Uwe,
Uwe Hermann wrote:
> > > Due to the Jessie release date being quite close[1] and this being one
> > > of the bug reports listed on [2], I plan to do an NMU with the above
> > > mentioned characteristics either directly to unstable or at most to
> > > DELAYED-1 -- mostly depending on how qu
Hi,
On Wed, Apr 01, 2015 at 10:43:51PM +0200, Axel Beckert wrote:
> Axel Beckert wrote:
> > > * Downgrading the bug to "important" again (which IMHO is now even
> > > more the most appropriate severity) and adding a paragraph to
> > > README.Debian or similar to mention this issue.
> >
> > I'
Your message dated Wed, 01 Apr 2015 21:39:15 +
with message-id
and subject line Bug#774171: fixed in unrar-nonfree 1:5.2.7-0.1
has caused the Debian Bug report #774171,
regarding unrar: symlink directory traversal
to be marked as done.
This means that you claim that the problem has been dealt
Hi,
Axel Beckert wrote:
> > * Downgrading the bug to "important" again (which IMHO is now even
> > more the most appropriate severity) and adding a paragraph to
> > README.Debian or similar to mention this issue.
>
> I've discussed this with Gregor on IRC and we came to the conclusion
> that
Hi.
Indeed it is. Is there a existing solution for such problem?
On Tue, 31 Mar 2015, at 15:59, Frédéric Brière wrote:
> Package: libssh2-1
> Version: 1.5.0-2
> Severity: important
> User: multiarch-de...@lists.alioth.debian.org
> Usertags: multiarch
>
> Apparently, the different-gz-across-archi
Processing control commands:
> found -1 1.7.38-1
Bug #781557 [libwine-development] libwine-development: upgrade failure: file
overwrite
Marked as found in versions wine-development/1.7.38-1.
--
781557: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=781557
Debian Bug Tracking System
Contact ow
Control: found -1 1.7.38-1
Confirmed, I was also preparing to report this. IIRC I didn't have the
problem when I rebuilt the packages 2 weeks ago locally in a cowbuilder
Jessie environment, but unfortunately I can't verify this anymore. The
packages I rebuilt just now are also broken.
At least t
Your message dated Wed, 01 Apr 2015 18:49:23 +
with message-id
and subject line Bug#781194: fixed in qtwebkit-opensource-src 5.3.2+dfsg-4
has caused the Debian Bug report #781194,
regarding libqt5webkit5: Reproducibly crashes with segfault due to missing
checks for `HTMLUnknownElement`
to be
Your message dated Wed, 01 Apr 2015 18:34:33 +
with message-id
and subject line Bug#781649: fixed in ghc 7.6.3-21
has caused the Debian Bug report #781649,
regarding ghc-doc: trigger problem during wheezy->jessie upgrade: haddock:
error while loading shared libraries: libffi.so.6: cannot open
Am 01.04.2015 um 18:23 schrieb Romain Francoise:
> On Thu, Mar 26, 2015 at 09:36:32PM +0100, Michael Biebl wrote:
>> So I decided to ship a /lib/systemd/system/network-manager.service
>> symlink pointing at NetworkManager.service:
>
>> http://anonscm.debian.org/cgit/pkg-utopia/network-manager.git/
Steve McIntyre (2015-04-01):
> As it stands, this is only for removable media which people have not
> already set up as part of their systems. The whole issue here is that
> this is not useful any more. If anybody is relying on being able to
> use such media without any of the existing auto-mounti
On Wed, Apr 01, 2015 at 07:20:02PM +0200, Cyril Brulebois wrote:
>Hi Steve,
>
>Steve McIntyre (2015-03-30):
>> Right, it seems that was too conservative and still left hd-media
>> devices listed. We probably don't want those either. Let's try this:
>> don't add *any* USB devices to /etc/fstab:
>
>
Processing commands for cont...@bugs.debian.org:
> tags 761023 + pending
Bug #761023 [bb] bb: Visual stops when audio starts under pulseaudio
Added tag(s) pending.
> thanks
Stopping processing here.
Please contact me if you need assistance.
--
761023: http://bugs.debian.org/cgi-bin/bugreport.cgi
Hi Steve,
Steve McIntyre (2015-03-30):
> Right, it seems that was too conservative and still left hd-media
> devices listed. We probably don't want those either. Let's try this:
> don't add *any* USB devices to /etc/fstab:
Thanks. I'm slightly worried that some people might depend on this
featur
Processing control commands:
> reassign -1 lvm2
Bug #781661 [initramfs-tools] initramfs-tools: Split /usr on LVM fails when
using LABEL or UUID in fstab
Bug reassigned from package 'initramfs-tools' to 'lvm2'.
No longer marked as found in versions initramfs-tools/0.119.
Ignoring request to alter
Control: reassign -1 lvm2
Control: forcemerge 612402 -1
On Wed, 2015-04-01 at 11:28 +, Marc Ballarin wrote:
> Package: initramfs-tools
> Version: 0.119
> Severity: grave
> Justification: causes non-serious data loss
No it doesn't.
> Dear Maintainer,
>
>* What led up to the situation?
>
On Thu, Mar 26, 2015 at 09:36:32PM +0100, Michael Biebl wrote:
> So I decided to ship a /lib/systemd/system/network-manager.service
> symlink pointing at NetworkManager.service:
> http://anonscm.debian.org/cgit/pkg-utopia/network-manager.git/tree/debian/rules#n64
Why do you have a call to dh_syst
tag 781194 pending
thanks
Dmitry has already pushed the fix to our repos, but neither him nor I can
build the package right now (it requires a lot of disk, ram and time to
build).
I think I won't be able to do it until next week. If anyone feels [s]he could
do it, please coordinate an NMU/team
Processing commands for cont...@bugs.debian.org:
> tag 781194 pending
Bug #781194 [libqt5webkit5] libqt5webkit5: Reproducibly crashes with segfault
due to missing checks for `HTMLUnknownElement`
Added tag(s) pending.
> thanks
Stopping processing here.
Please contact me if you need assistance.
--
Hi again,
As far as I know, this bug is still present in 3.4.0+dfsg-0~exp1 (from
experimental). The fix you applied to unstable (commit
d8603af7f98a6394442818d823a79b680b1f9e8b) can be cherry-picked to
experimental with minor conflicts (d/changelog and d/patches/series). It
seems to work fine here
On Mon, Mar 30, 2015 at 09:48:25AM +0200, Thomas Goirand wrote:
> Package: ruby2.1
> Version: 2.1.5-1
> Severity: grave
> Tags: patch
>
> Hi,
>
> When testing OpenStack Fuel, one of the components is using rethtool, which
> suffer from below ruby 2.1 upstream bug:
>
> https://bugs.ruby-lang.org/
On Wed, Apr 1, 2015 at 8:32 AM, Paul Tagliamonte wrote:
>
> Intersection, not set of both
of course this should read set of both, not intersection :)
--
:wq
--
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists
Comments inline
On Wed, Apr 01, 2015 at 08:43:51AM +0200, Jerome BENOIT wrote:
> I forwarded the bug report to the upstream maintainer:
> please find below his answer.
>
> -
> --8><---
Package: initramfs-tools
Version: 0.119
Severity: grave
Justification: causes non-serious data loss
Dear Maintainer,
* What led up to the situation?
Upgrading a system from Wheezy to Jessie. The system uses a split /usr
on LVM and uses LABEL in fstab to mount this.
* What exactly d
Control: severity -1 wishlist
On Wed, 01 Apr 2015 12:21:57 +0300, David Baron wrote:
> Another alternative could be a /etc/default/qtchooser. This could specify
> even
> more default properties, if desirable. Comment out the build alternative not
> desired
> #QT_SELECT=4
> QT_SELECT=5
You have
Processing control commands:
> severity -1 wishlist
Bug #781516 [qtchooser] [qtchooser] Qtchooser will always find qt5
Severity set to 'wishlist' from 'grave'
--
781516: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=781516
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
Hi,
Axel Beckert wrote:
> gregor herrmann wrote:
> > > - I had the same bug on X. Uninstalling pulseaudio - and rebooting -
> > > fixed the issue.
> >
> > Like Axel and Nirgal I can confirm that bb works fine without
> > pulseaudio.
>
> I can confirm that I don't have pulseaudio installed.
[...]
Your message dated Wed, 01 Apr 2015 09:49:39 +
with message-id
and subject line Bug#780925: fixed in libdbd-firebird-perl 1.18-2
has caused the Debian Bug report #780925,
regarding DBD-Firebird: CVE-2015-2788: Buffer Overflow in dbdimp.c
to be marked as done.
This means that you claim that th
Your message dated Wed, 01 Apr 2015 09:40:14 +
with message-id
and subject line Bug#781524: fixed in fcgiwrap 1.1.0-4
has caused the Debian Bug report #781524,
regarding fcgiwrap: socket is not created and service is not up, but it works
after a reboot
to be marked as done.
This means that y
On 2015-04-01 11:17, Joachim Breitner wrote:
> eek. This is #769554 which I was hoping to have fixed by changing the
> trigger to a trigger-noawait, but it seems that it has not helped.
That is probably the correct solution, just we need to ensure that the
new ghc-doc get installed early enough (o
On Wednesday 01 April 2015 11:46:38 Dmitry Shachnev wrote:
> Control: tags -1 moreinfo
>
> Hi David,
>
> On Mon, 30 Mar 2015 13:51:51 +0300, David Baron wrote:
> > Attempts to use qmake->qtchooser always yields qt5 libraries. Cannot make
> > anything in qt4 unless manually running qmake-qt4 and .
control: tag -1 + help
Hi,
Am Mittwoch, den 01.04.2015, 10:55 +0200 schrieb Andreas Beckmann:
> during a test with piuparts I noticed your package fails to upgrade from
> 'wheezy'.
> It installed fine in 'wheezy', then the upgrade to 'jessie' fails.
>
> >From the attached log (scroll to the bott
Package: python3-llfuse-dbg
Version: 0.40+dfsg-1
Severity: serious
User: debian...@lists.debian.org
Usertags: piuparts
Hi,
during a test with piuparts I noticed your package fails to upgrade from
'testing'.
It installed fine in 'testing', then the upgrade to 'sid' fails
because it tries to overwr
Processing control commands:
> tag -1 + help
Bug #781649 [ghc-doc,dpkg,ghc-haddock] ghc-doc: trigger problem during
wheezy->jessie upgrade: haddock: error while loading shared libraries:
libffi.so.6: cannot open shared object file: No such file or directory
Added tag(s) help.
--
781649: http:/
Package: gazebo5-common
Version: 5.0.1+dfsg-1~exp2
Severity: serious
User: debian...@lists.debian.org
Usertags: piuparts
Control: affects -1 + libgazebo-dev
Hi,
during a test with piuparts I noticed your package fails to upgrade from
'sid' to 'experimental'.
It installed fine in 'sid', then the u
Processing control commands:
> affects -1 + libgazebo-dev
Bug #781651 [gazebo5-common] gazebo5-common: fails to upgrade from 'sid' -
trying to overwrite /usr/share/gazebo-3.0/media/fonts/arial.ttf
Added indication that 781651 affects libgazebo-dev
--
781651: http://bugs.debian.org/cgi-bin/bugre
Processing control commands:
> affects -1 + libomniorb4-dev
Bug #781650 [libomnithread4-dev] libomnithread4-dev: fails to upgrade from
'sid' - trying to overwrite /usr/include/omnithread/posix.h
Added indication that 781650 affects libomniorb4-dev
--
781650: http://bugs.debian.org/cgi-bin/bugre
Package: libomnithread4-dev
Version: 4.2.0-1
Severity: serious
User: debian...@lists.debian.org
Usertags: piuparts
Control: affects -1 + libomniorb4-dev
Hi,
during a test with piuparts I noticed your package fails to upgrade from
'sid' to 'experimental'.
It installed fine in 'sid', then the upgra
Package: ghc-doc,dpkg,ghc-haddock
Severity: serious
Tags: jessie sid
User: debian...@lists.debian.org
Usertags: piuparts
Hi,
during a test with piuparts I noticed your package fails to upgrade from
'wheezy'.
It installed fine in 'wheezy', then the upgrade to 'jessie' fails.
>From the attached lo
Processing control commands:
> tags -1 moreinfo
Bug #781516 [qtchooser] [qtchooser] Qtchooser will always find qt5
Added tag(s) moreinfo.
--
781516: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=781516
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--
To UNSUBSCRIBE,
Control: tags -1 moreinfo
Hi David,
On Mon, 30 Mar 2015 13:51:51 +0300, David Baron wrote:
> Attempts to use qmake->qtchooser always yields qt5 libraries. Cannot make
> anything in qt4 unless manually running qmake-qt4 and ./configure may not set
> up completely correct Makefile.
>
> [snip]
>
>
Your message dated Wed, 01 Apr 2015 09:36:35 +0200
with message-id <551ba003.1000...@debian.org>
and subject line Re: Bug#781225: FTBFS on amd64 and i386: file NVIDIA-Linux is
not a directory
has caused the Debian Bug report #781225,
regarding FTBFS on amd64 and i386: file NVIDIA-Linux is not a di
55 matches
Mail list logo