Bug#850149: shotwell: Freezes when trying to open an image in fullscreen mode

2017-03-14 Thread Richard B. Kreckel
Looking back at the original description, it might be this upstream bug: .

Bug#857794: reportbug: crash when encountering some non-ASCII characters

2017-03-14 Thread Dima Kogan
Package: reportbug Version: 7.1.5 Severity: grave Dear Maintainer, -- Package-specific info: ** Environment settings: EDITOR="emacs" PAGER="less" DEBEMAIL="dko...@debian.org" ** /home/dima/.reportbugrc: reportbug_version "7.1.1" mode standard ui text Hi. I just tried to send an unblock, and re

Processed: notfound 857765 in 1:3.6.1+deb8, found 857765 in 1:3.6.1

2017-03-14 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > # not a vaild version > notfound 857765 1:3.6.1+deb8 Bug #857765 [flashplugin-nonfree] flashplugin-nonfree has 33 severe security flaws, orphaned? There is no source info for the package 'flashplugin-nonfree' at version '1:3.6.1+deb8' with archi

Bug#857444: [debian-mysql] Bug#857444: mysql-server-5.5: upgrade from jessie to stretch leaves mysql server uninstalled

2017-03-14 Thread Gabriel Filion
Lars Tangvald: > > - gabs...@lelutin.ca wrote: > >> Ugh, I fail at reportbug again :( >> >> real sorry about the initial report. >> >> here's the real description of the problem: >> >> >> when upgrading from jessie to stretch, the upgrade goes through >> without >> an error but the end result

Bug#857651: Multiple security issues

2017-03-14 Thread Salvatore Bonaccorso
On Mon, Mar 13, 2017 at 07:59:34PM +0100, Moritz Muehlenhoff wrote: > Source: audiofile > Severity: grave > Tags: security > > Hi, > please see these security tracker entries for details, which > have all the links to the reports, github issues and patches: > > https://security-tracker.debian.org

Processed: retitle 857560 to mbedtls: CVE-2017-2784: Freeing of memory allocated on stack when validating a public key with a secp224k1 curve ...

2017-03-14 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > retitle 857560 mbedtls: CVE-2017-2784: Freeing of memory allocated on stack > when validating a public key with a secp224k1 curve Bug #857560 {Done: James Cowgill } [libmbedcrypto0] mbedtls: CVE-2017-2748 - Freeing of memory allocated on stack w

Processed: Re: [Pkg-libvirt-maintainers] Bug#854125: libvirt0: could not find capabilities for arch=mips

2017-03-14 Thread Debian Bug Tracking System
Processing control commands: > severity -1 grave Bug #854125 [libvirt0] libvirt0: could not find capabilities for arch=mips Bug #857195 [libvirt0] libvirt-clients Severity set to 'grave' from 'important' Severity set to 'grave' from 'important' -- 854125: http://bugs.debian.org/cgi-bin/bugreport

Processed: waiting for unblock

2017-03-14 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > block 857360 by 854658 Bug #857360 [gitlab] gitlab: Fails to install in Stretch 857360 was not blocked by any bugs. 857360 was not blocking any bugs. Added blocking bug(s) of 857360: 854658 > End of message, stopping processing here. Please conta

Processed: retitle 857699 to ioquake3: CVE-2017-6903: privilege escalation by auto-downloaded files ...

2017-03-14 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > retitle 857699 ioquake3: CVE-2017-6903: privilege escalation by > auto-downloaded files Bug #857699 {Done: Simon McVittie } [ioquake3] ioquake3 has a security vulnerability Changed Bug title to 'ioquake3: CVE-2017-6903: privilege escalation by

Bug#857327: libapache2-authenntlm-perl: does not work with Apache 2.4

2017-03-14 Thread gregor herrmann
On Tue, 14 Mar 2017 10:07:43 +1100, Hamish Moffatt wrote: > > From reading the above URLs, it seems that > > remote_addr -> client_addr > > remote_ip -> client_ip > > should do the trick. > > I tried that, and it's better - no problems on the Apache side at least. Great, thanks for tr

Bug#749991: Wrong kernel in debian-installer package

2017-03-14 Thread Nye Liu
On Tue, Mar 14, 2017 at 08:39:31PM +, Ben Hutchings wrote: > On Tue, 2017-03-14 at 11:36 -0700, Nye Liu wrote: > > The only apparent solution is to have the kernel maintainers coordinate  > > with the d-i maintainers so that whatever kernel is used in d-i is NOT  > > removed from the package re

Bug#854810: marked as done (gnome-control-center: Crash when switching from Network screen back to main screen)

2017-03-14 Thread Debian Bug Tracking System
Your message dated Tue, 14 Mar 2017 21:34:29 + with message-id and subject line Bug#854810: fixed in network-manager 1.6.2-2 has caused the Debian Bug report #854810, regarding gnome-control-center: Crash when switching from Network screen back to main screen to be marked as done. This means

Processed: limit source to gnome-sound-recorder, tagging 852870

2017-03-14 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > limit source gnome-sound-recorder Limiting to bugs with field 'source' containing at least one of 'gnome-sound-recorder' Limit currently set to 'source':'gnome-sound-recorder' > tags 852870 + pending Bug #852870 [gnome-sound-recorder] gnome-soun

Bug#807317: [moodle-packaging] again: future of Moodle in Debian: ship with Debian 10 Buster in 2019?

2017-03-14 Thread Tomasz Muras
Hi Joost, Thank you for your work so far. I'm afraid that realistically it's not possible to maintain quality Moodle 3.0 package in Debian (or Ubuntu 16.04). >From the Moodle site: "Bug fixes for security issues in 3.0.x will end 8 May 2017". This means in less than 2 months upstream will stop al

Processed: limit source to gnome-sound-recorder, tagging 852870

2017-03-14 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > limit source gnome-sound-recorder Limiting to bugs with field 'source' containing at least one of 'gnome-sound-recorder' Limit currently set to 'source':'gnome-sound-recorder' > tags 852870 + pending Bug #852870 [gnome-sound-recorder] gnome-soun

Bug#857699: [scr306054] idTech3 (Quake 3 engine) forks - all prior to 2017-03-14

2017-03-14 Thread cve-request
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 > [Suggested description] > In ioquake3 before 2017-03-14, the auto-downloading feature > has insufficient content restrictions. > This also affects Quake III Arena, OpenArena, OpenJK, iortcw, and > other id Tech 3 (aka Quake 3 engine) forks. > A mal

Bug#857699: ioquake3 has a security vulnerability

2017-03-14 Thread Victor Roemer
FYI, The ioquake3.org blog post was updated to reference me as the reporter. On Tue, Mar 14, 2017 at 4:42 PM, Victor Roemer wrote: > Any way we can amend that? > > On Tue, Mar 14, 2017 at 3:31 PM, Simon McVittie wrote: > >> On Tue, 14 Mar 2017 at 13:38:37 -0400, Victor Roemer wrote: >> > I orig

Bug#853207: bluez: bluetooth.service doesn't start with systemd

2017-03-14 Thread Emilio Pozuelo Monfort
On Sat, 11 Feb 2017 13:08:23 +0900 Nobuhiro Iwamatsu wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > Control: tags 853207 + moreinfo > > Hi, > > > Most likely the bluetooth support for your laptop is broken under linux. > > > > The bluetooth.service file contains > > > > Condi

Bug#857777: redis FTBFS on mipsel/mips64el: Redis 3.2.8 crashed by signal: 10

2017-03-14 Thread Chris Lamb
forwarded 85 https://github.com/antirez/redis/issues/3874 thanks Forwarded upstream. :) Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Processed: Re: redis FTBFS on mipsel/mips64el: Redis 3.2.8 crashed by signal: 10

2017-03-14 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > forwarded 85 https://github.com/antirez/redis/issues/3874 Bug #85 [src:redis] redis FTBFS on mipsel/mips64el: Redis 3.2.8 crashed by signal: 10 Set Bug forwarded-to-address to 'https://github.com/antirez/redis/issues/3874'. > thanks Stopp

Bug#857779: nagvis: broken symlink: /usr/share/nagvis/share/server/core/ext/php-gettext-1.0.9 -> ../../../../../php/php-gettext

2017-03-14 Thread Andreas Beckmann
Package: nagvis Version: 1:1.7.10+dfsg1-3.1 Severity: serious User: debian...@lists.debian.org Usertags: piuparts Hi, during a test with piuparts I noticed your package ships (or creates) a broken symlink. >From the attached log (scroll to the bottom...): 1m55.8s ERROR: FAIL: Broken symlinks:

Bug#857533: marked as done (python-vtk6: broken symlink: /usr/lib//python2.7/site-packages/vtk -> ../../../python2.7/dist/packages/vtk)

2017-03-14 Thread Debian Bug Tracking System
Your message dated Tue, 14 Mar 2017 20:51:28 + with message-id and subject line Bug#857533: fixed in vtk6 6.3.0+dfsg1-4 has caused the Debian Bug report #857533, regarding python-vtk6: broken symlink: /usr/lib//python2.7/site-packages/vtk -> ../../../python2.7/dist/packages/vtk to be marked

Bug#749991: Wrong kernel in debian-installer package

2017-03-14 Thread Ben Hutchings
On Tue, 2017-03-14 at 11:36 -0700, Nye Liu wrote: > The only apparent solution is to have the kernel maintainers coordinate  > with the d-i maintainers so that whatever kernel is used in d-i is NOT  > removed from the package repository and its mirrors. The kernel maintainers already coordinate wi

Bug#857699: ioquake3 has a security vulnerability

2017-03-14 Thread Victor Roemer
Any way we can amend that? On Tue, Mar 14, 2017 at 3:31 PM, Simon McVittie wrote: > On Tue, 14 Mar 2017 at 13:38:37 -0400, Victor Roemer wrote: > > I originally reported the vulnerability to ioquake3. I'd like to help > with the > > CVE however I can. > > I'm not familiar with CVE reports which

Bug#857777: redis FTBFS on mipsel/mips64el: Redis 3.2.8 crashed by signal: 10

2017-03-14 Thread Adrian Bunk
Source: redis Version: 3:3.2.8-2 Severity: serious https://buildd.debian.org/status/package.php?p=redis&suite=sid ... === REDIS BUG REPORT START: Cut & paste starting from here === 27468:M 11 Mar 13:31:03.788 # Redis 3.2.8 crashed by signal: 10 27468:M 11 Mar 13:31:03.788 # Accessing address: (ni

Bug#857772: sushi: FTBFS with bash as /bin/sh

2017-03-14 Thread Chris Lamb
tags 857772 + patch thanks Patch attached. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- diff --git a/debian/rules b/debian/rules index 6540d82..03414a6 100755 --- a/debian/rules +++ b/debian/rules @@ -29,7 +29,7 @@ override_

Processed: Re: sushi: FTBFS with bash as /bin/sh

2017-03-14 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tags 857772 + patch Bug #857772 [src:sushi] sushi: FTBFS with bash as /bin/sh Added tag(s) patch. > thanks Stopping processing here. Please contact me if you need assistance. -- 857772: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=857772 Deb

Processed: Fix the version

2017-03-14 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > found 857653 1:4.0-1 Bug #857653 [liblld-4.0] liblld-4.0: missing liblld-4.0.so.1 Marked as found in versions llvm-toolchain-4.0/1:4.0-1. > thanks Stopping processing here. Please contact me if you need assistance. -- 857653: http://bugs.debian.

Bug#857772: sushi: FTBFS with bash as /bin/sh

2017-03-14 Thread Chris Lamb
Source: sushi Version: 1.4.0+git20160822+dfsg-1 Severity: serious Justification: fails to build from source User: reproducible-bui...@lists.alioth.debian.org Usertags: ftbfs X-Debbugs-Cc: reproducible-b...@lists.alioth.debian.org Dear Maintainer, sushi fails to build from source in unstable/amd64

Bug#854828: get-iplayer: get_iplayer fails to save any content, *_original.partial.mp4.flv files are empty

2017-03-14 Thread dinkypumpkin
> On 14 Mar 2017, at 19:30, Adrian Bunk wrote: > > Versions of packages get-iplayer depends on: > ii ffmpeg 6:0.8.17-1 The other part of the problem was that the obsolete ffmpeg carried the 0.8 libav version number, but it was really a older version of ffmpeg from before the gre

Processed: Re: Bug#853171: segmentation fault when disabling a screen with kscreen without upower installed on the system

2017-03-14 Thread Debian Bug Tracking System
Processing control commands: > reassign -1 kscreen 4:5.8.4-1 Bug #853171 {Done: Maximiliano Curia } [plasma-desktop] plasma-desktop: Should probably add upower to Depends Bug reassigned from package 'plasma-desktop' to 'kscreen'. No longer marked as found in versions plasma-desktop/4:5.8.4-1. No

Processed: Add version information

2017-03-14 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > found 857368 1:4.0.0~rc1-2 Bug #857368 [resource-agents] heartbeat: Heartbeat-Package ist missing package "net-tools" as depency due the need of command "ifconfig". Marked as found in versions resource-agents/1:4.0.0~rc1-2. > thanks Stopping proc

Bug#857699: ioquake3 has a security vulnerability

2017-03-14 Thread Simon McVittie
On Tue, 14 Mar 2017 at 13:38:37 -0400, Victor Roemer wrote: > I originally reported the vulnerability to ioquake3. I'd like to help with the > CVE however I can. > I'm not familiar with CVE reports which is why one hasn't already been > written. MITRE's new process really doesn't help matters the

Processed: Re: Bug#854828: get-iplayer: get_iplayer fails to save any content, *_original.partial.mp4.flv files are empty

2017-03-14 Thread Debian Bug Tracking System
Processing control commands: > severity -1 serious Bug #854828 [get-iplayer] get-iplayer: get_iplayer fails to save any content, *_original.partial.mp4.flv files are empty Severity set to 'serious' from 'important' -- 854828: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=854828 Debian Bug Tr

Bug#857699: CVE Request 306054 for CVE ID Request

2017-03-14 Thread CVE Request
Thank you for your submission. It will be reviewed by a CVE Assignment Team member. Changes, additions, or updates to your request can be sent to the CVE Team by replying directly to this email. Please do not change the subject line, which allows us to effectively track your request. CVE Ass

Bug#856667: marked as done (Make sure that the Stretch .iso are properly detected)

2017-03-14 Thread Debian Bug Tracking System
Your message dated Tue, 14 Mar 2017 19:19:08 + with message-id and subject line Bug#856667: fixed in osinfo-db 0.20170225-1 has caused the Debian Bug report #856667, regarding Make sure that the Stretch .iso are properly detected to be marked as done. This means that you claim that the proble

Bug#857765: flashplugin-nonfree has 33 severe security flaws, orphaned?

2017-03-14 Thread Alf
Package: flashplugin-nonfree Version: 1:3.6.1+deb8 Severity: grave Tags: security Dear Debian Maintainers, since almost 3 months this package no longer works as expected. It fails to download the latest hashes from: https://people.debian.org/~bartm/flashplugin-nonfree/D5C0FC14/ On new installatio

Bug#749991: Wrong kernel in debian-installer package

2017-03-14 Thread Nye Liu
The only apparent solution is to have the kernel maintainers coordinate with the d-i maintainers so that whatever kernel is used in d-i is NOT removed from the package repository and its mirrors.

Processed: "Wrong kernel in debian-installer package" is grave

2017-03-14 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > severity 749991 grave Bug #749991 [debian-installer] debian-installer: Wrong kernel in debian-installer packageHello Severity set to 'grave' from 'important' > End of message, stopping processing here. Please contact me if you need assistance. -

Bug#857444: [debian-mysql] Bug#857444: mysql-server-5.5: upgrade from jessie to stretch leaves mysql server uninstalled

2017-03-14 Thread Lars Tangvald
- gabs...@lelutin.ca wrote: > Ugh, I fail at reportbug again :( > > real sorry about the initial report. > > here's the real description of the problem: > > > when upgrading from jessie to stretch, the upgrade goes through > without > an error but the end result is that mysql-server-5.5 g

Processed: Re: Broken library symlink detected in libptscotch-dev

2017-03-14 Thread Debian Bug Tracking System
Processing control commands: > severity -1 serious Bug #715107 [libptscotch-dev] Broken library symlink detected in libptscotch-dev Severity set to 'serious' from 'normal' > reassign -1 libptscotch-5.1 5.1.12b.dfsg-2 Bug #715107 [libptscotch-dev] Broken library symlink detected in libptscotch-dev

Bug#846560: [Debian-Islamic-maintainers] Bug#846560: Bug#846560: thawab: Build depending on librsvg2-bin fixes the issue.

2017-03-14 Thread Shanavas
Uploaded from https://git.fosscommunity.in/shanavasm/thawab by Praveen. On March 12, 2017 5:33:46 PM GMT+03:00, Shanavas wrote: > > >On March 11, 2017 5:30:45 AM GMT+03:00, "أحمد المحمودي" > wrote: >>Please prepare a NMU. If you can't find a sponsor, upload the binary >>package to a world readabl

Bug#846560: marked as done (thawab: FTBFS with latest imagemagick)

2017-03-14 Thread Debian Bug Tracking System
Your message dated Tue, 14 Mar 2017 18:04:26 + with message-id and subject line Bug#846560: fixed in thawab 3.2.0-1.1 has caused the Debian Bug report #846560, regarding thawab: FTBFS with latest imagemagick to be marked as done. This means that you claim that the problem has been dealt with.

Bug#849720: marked as done (synaptic: settings changes not preserved after exit)

2017-03-14 Thread Debian Bug Tracking System
Your message dated Tue, 14 Mar 2017 17:57:20 + with message-id <20170314175720.4xvpymszn5yxe...@perpetual.pseudorandom.co.uk> and subject line Re: Bug#849720: synaptic: settings changes not preserved after exit has caused the Debian Bug report #849720, regarding synaptic: settings changes not

Bug#857699:

2017-03-14 Thread Victor Roemer
Hi guys, I originally disclosed the bug to ioquake3. I would like to help however I can with the CVE. I am not familiar with the CVE creation process which is why one has been created by myself. Thanks Victor

Bug#857699: ioquake3 has a security vulnerability

2017-03-14 Thread Victor Roemer
Hi guys, I originally reported the vulnerability to ioquake3. I'd like to help with the CVE however I can. I'm not familiar with CVE reports which is why one hasn't already been written. Thanks, Victor

Bug#857699: ioquake3 has a security vulnerability

2017-03-14 Thread Daniel Gibson
Hi, I heard upstream is not gonna create a CVE, so go ahead.. Cheers, Daniel On 14.03.2017 17:44, Salvatore Bonaccorso wrote: Hi Simon, On Tue, Mar 14, 2017 at 08:30:36AM +, Simon McVittie wrote: cc'ing security team for information. No CVE ID yet, I assume ioquake3 upstream will be requ

Processed: Re: gnome-control-center: Crash when switching from Network screen back to main screen

2017-03-14 Thread Debian Bug Tracking System
Processing control commands: > severity -1 serious Bug #854810 [gnome-control-center] gnome-control-center: Crash when switching from Network screen back to main screen Severity set to 'serious' from 'normal' -- 854810: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=854810 Debian Bug Tracking

Processed: reassign 854810 to libnm0, found 854810 in 1.6.0-1

2017-03-14 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > reassign 854810 libnm0 Bug #854810 [gnome-control-center] gnome-control-center: Crash when switching from Network screen back to main screen Bug reassigned from package 'gnome-control-center' to 'libnm0'. No longer marked as found in versions gno

Processed: affects 854810

2017-03-14 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > affects 854810 gnome-control-center Bug #854810 [libnm0] gnome-control-center: Crash when switching from Network screen back to main screen Added indication that 854810 affects gnome-control-center > thanks Stopping processing here. Please conta

Bug#841401: chromium: doesn't update extensions

2017-03-14 Thread Julien Palard
Hi, It does not looks like the bug is fixed in Chromium 57.0.2987.98 built on Debian 9.0, running on Debian 9.0, from stretch. I use --enable-remote-extensions, so the sh wrapper does not put the --disable-background-networking, I can use my extensions, but can't update them. -- Julien Palar

Processed: Re: Bug#801990: gdm3: Keymap is forced to set US

2017-03-14 Thread Debian Bug Tracking System
Processing control commands: > severity -1 important Bug #801990 [gdm3] gdm3: Keymap is forced to set US Severity set to 'important' from 'serious' -- 801990: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=801990 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems

Bug#801990: gdm3: Keymap is forced to set US

2017-03-14 Thread Raphael Hertzog
Control: severity -1 important On Tue, 14 Mar 2017, Raphael Hertzog wrote: > I also see this for any fresh stretch install where I select the French > keyboard layout. On first start, the greeting screen (handled by > gnome-shell AFAIK) uses a default US/qwerty layout and the layout selected > at

Processed: Re: Bug#854335: marked as pending

2017-03-14 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > clone 854335 -1 Bug #854335 {Done: Piotr Ożarowski } [src:python-websockets] python-websockets: Non-determistically FTBFS due to unreliable timing in tests Bug 854335 cloned as bug 857753 > retitle -1 python-websockets: non-determinstic testsuite

Bug#854335: marked as pending

2017-03-14 Thread Chris Lamb
clone 854335 -1 retitle -1 python-websockets: non-determinstic testsuite severity -1 important found -1 3.2-2 thanks Piotr Ożarowski wrote: > > > set WEBSOCKETS_TESTS_TIMEOUT_FACTOR to 100 to avoid > > >FTBFS on slower buildds > > > > Hm. Whilst this might "work" it is still non-dete

Bug#849720: synaptic: settings changes not preserved after exit

2017-03-14 Thread HJ
Hi, sorry I forgot about this report its gone with synaptic 0.84.

Bug#857699: ioquake3 has a security vulnerability

2017-03-14 Thread Salvatore Bonaccorso
Hi Simon, On Tue, Mar 14, 2017 at 08:30:36AM +, Simon McVittie wrote: > cc'ing security team for information. No CVE ID yet, I assume ioquake3 > upstream will be requesting one (or if not I will). heard anything about that yet? If so can you request a CVE via https://cveform.mitre.org/ and lo

Bug#857295: [oss-security] LXC: CVE-2017-5985: lxc-user-nic didn't verify network namespace ownership

2017-03-14 Thread Stiepan
You are welcome. As stated in my reply to Serge H. Hallyn's off-list message, in the meantime I have installed version 2.0.7 from jessie-backports and am unable to reproduce the issue, as I cannot start unprivileged containers anymore (due to a network error). According to Debian's tracker page

Bug#857744: qemu: CVE-2016-9603: cirrus: heap buffer overflow via vnc connection

2017-03-14 Thread Salvatore Bonaccorso
Source: qemu Version: 1:2.8+dfsg-3 Severity: grave Tags: patch security upstream Justification: user security hole Control: found -1 2.1+dfsg-1 Hi, the following vulnerability was published for qemu. CVE-2016-9603[0]: cirrus: heap buffer overflow via vnc connection If you fix the vulnerability

Processed: qemu: CVE-2016-9603: cirrus: heap buffer overflow via vnc connection

2017-03-14 Thread Debian Bug Tracking System
Processing control commands: > found -1 2.1+dfsg-1 Bug #857744 [src:qemu] qemu: CVE-2016-9603: cirrus: heap buffer overflow via vnc connection Marked as found in versions qemu/2.1+dfsg-1. -- 857744: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=857744 Debian Bug Tracking System Contact ow...

Bug#857699: ioquake3 has a security vulnerability

2017-03-14 Thread Daniel Gibson
On 14.03.2017 09:30, Simon McVittie wrote: Thanks for reporting, I'll fix this ASAP. Awesome, thanks for the prompt reaction! Looks like I need to teach ioquake3 upstream about coordinated disclosure, or remind them that their game is in distributions. That might be a good idea, I had th

Bug#855282: debsign: support .buildinfo files

2017-03-14 Thread Ximin Luo
James McCoy: > On Mon, Mar 06, 2017 at 11:45:20PM -0500, James McCoy wrote: >> On Thu, Feb 16, 2017 at 05:23:00PM +, Ximin Luo wrote: >>> I've done an initial implementation here: >>> >>> https://anonscm.debian.org/cgit/collab-maint/devscripts.git/log/?h=pu/debsign-buildinfo >>> >>> Please revi

Bug#850507: marked as done (golang-github-tideland-golib: FTBFS randomly (failing tests))

2017-03-14 Thread Debian Bug Tracking System
Your message dated Tue, 14 Mar 2017 15:06:01 + with message-id and subject line Bug#850507: fixed in golang-github-tideland-golib 4.20.0-3 has caused the Debian Bug report #850507, regarding golang-github-tideland-golib: FTBFS randomly (failing tests) to be marked as done. This means that you

Bug#854335: marked as pending

2017-03-14 Thread Piotr Ożarowski
> > set WEBSOCKETS_TESTS_TIMEOUT_FACTOR to 100 to avoid > >FTBFS on slower buildds > > Hm. Whilst this might "work" it is still non-determinstic, alas... feel free to clone this bug with non-RC severity. All I care about right now is to make it usable for Stretch

Bug#801990: gdm3: Keymap is forced to set US

2017-03-14 Thread Michael Biebl
Am 14.03.2017 um 10:05 schrieb Raphael Hertzog: > Control: severity -1 serious > Control: affects -1 gnome-shell > > I also see this for any fresh stretch install where I select the French > keyboard layout. On first start, the greeting screen (handled by > gnome-shell AFAIK) uses a default US/qwe

Bug#857699: ioquake3 has a security vulnerability

2017-03-14 Thread Moritz Muehlenhoff
On Tue, Mar 14, 2017 at 12:18:27PM +, Simon McVittie wrote: > On Tue, 14 Mar 2017 at 08:30:36 +, Simon McVittie wrote: > > On Tue, 14 Mar 2017 at 04:59:15 +0100, Daniel Gibson wrote: > > > earlier today ioquake3 fixed a vulnerability that, as far as I understand, > > > could let malicious m

Bug#818140: marked as done (cura-engine: FTBFS: mathcalls.h:109:1: error: '__DECL_SIMD__log' does not name a type)

2017-03-14 Thread Debian Bug Tracking System
Your message dated Tue, 14 Mar 2017 13:33:40 + with message-id and subject line Bug#818140: fixed in cura-engine 14.01-2.1 has caused the Debian Bug report #818140, regarding cura-engine: FTBFS: mathcalls.h:109:1: error: '__DECL_SIMD__log' does not name a type to be marked as done. This mean

Bug#856830: [Pkg-javascript-devel] Bug#856830: Bug#856830: Could not reproduce with pbuilder

2017-03-14 Thread Jérémy Lal
2017-03-14 14:10 GMT+01:00 Pirate Praveen : > On ചൊവ്വ 14 മാര്‍ച്ച് 2017 06:24 വൈകു, Shanavas wrote: >> Successfully built using pbuilder. > > Successfully built with sbuild too. autopkgtest also passed. > > Chris, can you check if you can still reproduce the failure? TZ=GMT mocha fails (certainly

Bug#804357: marked as done (beanbag: FTBFS: ImportError: No module named 'requests')

2017-03-14 Thread Debian Bug Tracking System
Your message dated Tue, 14 Mar 2017 13:18:40 + with message-id and subject line Bug#804357: fixed in beanbag 1.9.2-1.1 has caused the Debian Bug report #804357, regarding beanbag: FTBFS: ImportError: No module named 'requests' to be marked as done. This means that you claim that the problem h

Bug#856830: [Pkg-javascript-devel] Bug#856830: Could not reproduce with pbuilder

2017-03-14 Thread Pirate Praveen
On ചൊവ്വ 14 മാര്‍ച്ച് 2017 06:24 വൈകു, Shanavas wrote: > Successfully built using pbuilder. Successfully built with sbuild too. autopkgtest also passed. Chris, can you check if you can still reproduce the failure? signature.asc Description: OpenPGP digital signature

Bug#856830: [Pkg-javascript-devel] Bug#856830: Could not reproduce with pbuilder

2017-03-14 Thread Chris Lamb
Hi, > Successfully built with sbuild too. autopkgtest also passed. > > Chris, can you check if you can still reproduce the failure? Cannot reproduce, so closing in BCC :) Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Bug#856830: marked as done (node-dateformat: FTBFS: dateformat([now], [mask]) should format `longTime` mask)

2017-03-14 Thread Debian Bug Tracking System
Your message dated Tue, 14 Mar 2017 13:13:43 + with message-id <1489497223.2167778.910810872.1ab13...@webmail.messagingengine.com> and subject line Re: [Pkg-javascript-devel] Bug#856830: Could not reproduce with pbuilder has caused the Debian Bug report #856830, regarding node-dateformat: FTB

Bug#856830: Could not reproduce with pbuilder

2017-03-14 Thread Shanavas
Successfully built using pbuilder. -- Sent from my Android device with K-9 Mail. Please excuse my brevity.

Bug#854335: marked as pending

2017-03-14 Thread Chris Lamb
Piotr Ożarowski wrote: > set WEBSOCKETS_TESTS_TIMEOUT_FACTOR to 100 to avoid >FTBFS on slower buildds Hm. Whilst this might "work" it is still non-determinstic, alas... Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk

Bug#854335: marked as done (python-websockets: Non-determistically FTBFS due to unreliable timing in tests)

2017-03-14 Thread Debian Bug Tracking System
Your message dated Tue, 14 Mar 2017 12:50:45 + with message-id and subject line Bug#854335: fixed in python-websockets 3.2-2 has caused the Debian Bug report #854335, regarding python-websockets: Non-determistically FTBFS due to unreliable timing in tests to be marked as done. This means tha

Bug#857473: marked as done (roundcube: CVE-2017-6820: XSS issue in handling of a style tag inside of an svg element)

2017-03-14 Thread Debian Bug Tracking System
Your message dated Tue, 14 Mar 2017 12:36:56 + with message-id and subject line Bug#857473: fixed in roundcube 1.2.3+dfsg.1-3 has caused the Debian Bug report #857473, regarding roundcube: CVE-2017-6820: XSS issue in handling of a style tag inside of an svg element to be marked as done. This

Processed: Bug#854335 marked as pending

2017-03-14 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tag 854335 pending Bug #854335 [src:python-websockets] python-websockets: Non-determistically FTBFS due to unreliable timing in tests Added tag(s) pending. > thanks Stopping processing here. Please contact me if you need assistance. -- 854335:

Bug#854335: marked as pending

2017-03-14 Thread Piotr Ożarowski
tag 854335 pending thanks Hello, Bug #854335 reported by you has been fixed in the Git repository. You can see the changelog below, and you can check the diff of the fix at: http://git.debian.org/?p=python-modules/packages/python-websockets.git;a=commitdiff;h=0ea3518 --- commit 0ea35188326

Bug#857699: ioquake3 has a security vulnerability

2017-03-14 Thread Simon McVittie
On Tue, 14 Mar 2017 at 08:30:36 +, Simon McVittie wrote: > On Tue, 14 Mar 2017 at 04:59:15 +0100, Daniel Gibson wrote: > > earlier today ioquake3 fixed a vulnerability that, as far as I understand, > > could let malicious multiplayer servers execute code on connecting clients. > > It affects al

Bug#856926: marked as done (rekall: package not installable after no-change rebuild)

2017-03-14 Thread Debian Bug Tracking System
Your message dated Tue, 14 Mar 2017 11:50:15 + with message-id and subject line Bug#856926: fixed in rekall 1.6.0+dfsg-2 has caused the Debian Bug report #856926, regarding rekall: package not installable after no-change rebuild to be marked as done. This means that you claim that the problem

Bug#857715: marked as done (ioquake3 has a security vulnerability)

2017-03-14 Thread Debian Bug Tracking System
Your message dated Tue, 14 Mar 2017 11:50:05 + with message-id and subject line Bug#857715: fixed in openjk 0~20170314+dfsg1-1 has caused the Debian Bug report #857715, regarding ioquake3 has a security vulnerability to be marked as done. This means that you claim that the problem has been

Bug#857699: marked as done (ioquake3 has a security vulnerability)

2017-03-14 Thread Debian Bug Tracking System
Your message dated Tue, 14 Mar 2017 11:34:06 + with message-id and subject line Bug#857699: fixed in ioquake3 1.36+u20161101+dfsg1-2 has caused the Debian Bug report #857699, regarding ioquake3 has a security vulnerability to be marked as done. This means that you claim that the problem has b

Bug#857426: [Pkg-gmagick-im-team] Bug#857426: closed by Bastien ROUCARIES (does not affect sid, )

2017-03-14 Thread Salvatore Bonaccorso
Hi Bastien, On Tue, Mar 14, 2017 at 11:24:41AM +0100, Bastien ROUCARIES wrote: > BTW I will open a CVE Thanks. > Moreover could you check if CVE-2016-10068 is fixed ? According to > changelog it is and I could not apply patch (already applied) Yep, it was already fixed with a previous DSA (the

Bug#845241: closing 845241

2017-03-14 Thread Salvatore Bonaccorso
close 845241 8:6.8.9.9-5+deb8u6 thanks

Processed: closing 845241

2017-03-14 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > close 845241 8:6.8.9.9-5+deb8u6 Bug #845241 {Done: Bastien Roucariès } [src:imagemagick] Prevent fault in MSL interpreter Marked as fixed in versions imagemagick/8:6.8.9.9-5+deb8u6. Bug #845241 {Done: Bastien Roucariès } [src:imagemagick] Preven

Bug#857560: marked as done (mbedtls: CVE-2017-2748 - Freeing of memory allocated on stack when validating a public key with a secp224k1 curve)

2017-03-14 Thread Debian Bug Tracking System
Your message dated Tue, 14 Mar 2017 11:19:37 + with message-id and subject line Bug#857560: fixed in mbedtls 2.4.2-1 has caused the Debian Bug report #857560, regarding mbedtls: CVE-2017-2748 - Freeing of memory allocated on stack when validating a public key with a secp224k1 curve to be mark

Processed: Re: Bug#857473: [Pkg-roundcube-maintainers] Bug#857473: roundcube: XSS issue in handling of a style tag inside of an svg element

2017-03-14 Thread Debian Bug Tracking System
Processing control commands: > reopen -1 Bug #857473 {Done: Guilhem Moulin } [src:roundcube] roundcube: CVE-2017-6820: XSS issue in handling of a style tag inside of an svg element 'reopen' may be inappropriate when a bug has been closed with a version; all fixed versions will be cleared, and yo

Bug#857473: [Pkg-roundcube-maintainers] Bug#857473: roundcube: XSS issue in handling of a style tag inside of an svg element

2017-03-14 Thread Guilhem Moulin
Control: reopen -1 Control: tag -1 pending On Tue, 14 Mar 2017 at 07:40:34 +0100, Vincent Bernat wrote: > Both of them uploaded. Crap, I shouldn't work in the middle of the night, I forgot to add the patch to the debian/patches/series… Fixed in the VCS, sorry for the inconvenience. :-( -- Guil

Bug#857714: marked as done (ioquake3 has a security vulnerability)

2017-03-14 Thread Debian Bug Tracking System
Your message dated Tue, 14 Mar 2017 10:48:41 + with message-id and subject line Bug#857714: fixed in iortcw 1.50a+dfsg1-3 has caused the Debian Bug report #857714, regarding ioquake3 has a security vulnerability to be marked as done. This means that you claim that the problem has been dealt w

Bug#856488: marked as done (opendmarc: does not honor Socket config key anymore)

2017-03-14 Thread Debian Bug Tracking System
Your message dated Tue, 14 Mar 2017 10:49:11 + with message-id and subject line Bug#856488: fixed in opendmarc 1.3.2-1 has caused the Debian Bug report #856488, regarding opendmarc: does not honor Socket config key anymore to be marked as done. This means that you claim that the problem has b

Bug#856489: marked as done (opendmarc: defaults file vanished)

2017-03-14 Thread Debian Bug Tracking System
Your message dated Tue, 14 Mar 2017 10:49:11 + with message-id and subject line Bug#856489: fixed in opendmarc 1.3.2-1 has caused the Debian Bug report #856489, regarding opendmarc: defaults file vanished to be marked as done. This means that you claim that the problem has been dealt with. If

Processed: tagging 857715, tagging 857714, tagging 857699

2017-03-14 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tags 857715 + pending fixed-upstream Bug #857715 [openjk] ioquake3 has a security vulnerability Added tag(s) pending and fixed-upstream. > tags 857714 + pending fixed-upstream Bug #857714 [iortcw] ioquake3 has a security vulnerability Added tag(s)

Bug#857426: [Pkg-gmagick-im-team] Bug#857426: closed by Bastien ROUCARIES (does not affect sid, )

2017-03-14 Thread Bastien ROUCARIES
BTW I will open a CVE Moreover could you check if CVE-2016-10068 is fixed ? According to changelog it is and I could not apply patch (already applied) On Tue, Mar 14, 2017 at 7:23 AM, Salvatore Bonaccorso wrote: > Hello Bastien, > > On Sat, Mar 11, 2017 at 03:18:04PM +, Debian Bug Tracking

Processed: Re: Bug#801990: gdm3: Keymap is forced to set US

2017-03-14 Thread Debian Bug Tracking System
Processing control commands: > severity -1 serious Bug #801990 [gdm3] gdm3: Keymap is forced to set US Severity set to 'serious' from 'important' > affects -1 gnome-shell Bug #801990 [gdm3] gdm3: Keymap is forced to set US Added indication that 801990 affects gnome-shell -- 801990: http://bugs.d

Bug#848220: gcc-5 should not ship in stretch

2017-03-14 Thread Matthias Klose
On 14.03.2017 00:53, Mattia Rizzolo wrote: > On Thu, Dec 15, 2016 at 10:35:16AM +0100, Matthias Klose wrote: >> remaining issues: >> https://bugs.debian.org/cgi-bin/pkgreport.cgi?tag=gcc-5-legacy;users=debian-...@lists.debian.org > > All the actionable ones are done (apart from llvm-toolchain-snap

Bug#857699: ioquake3 has a security vulnerability

2017-03-14 Thread Simon McVittie
Control: tags 857699 + security Control: clone 857699 -2 -3 Control: reassign -2 iortcw 1.42b+20150930+dfsg1-1 Control: reassign -3 openjk 0~20150430+dfsg1-1 On Tue, 14 Mar 2017 at 04:59:15 +0100, Daniel Gibson wrote: > earlier today ioquake3 fixed a vulnerability that, as far as I understand, > c

Processed: Re: Bug#857699: ioquake3 has a security vulnerability

2017-03-14 Thread Debian Bug Tracking System
Processing control commands: > tags 857699 + security Bug #857699 [ioquake3] ioquake3 has a security vulnerability Ignoring request to alter tags of bug #857699 to the same tags previously set > clone 857699 -2 -3 Bug #857699 [ioquake3] ioquake3 has a security vulnerability Bug 857699 cloned as bu

Bug#787291: marked as done (needrestart-session: doesn't show the same results as needrestart)

2017-03-14 Thread Debian Bug Tracking System
Your message dated Tue, 14 Mar 2017 07:48:55 + with message-id and subject line Bug#787291: fixed in needrestart-session 0.3-4.1 has caused the Debian Bug report #787291, regarding needrestart-session: doesn't show the same results as needrestart to be marked as done. This means that you clai

Bug#857473: [Pkg-roundcube-maintainers] Bug#857473: roundcube: XSS issue in handling of a style tag inside of an svg element

2017-03-14 Thread Salvatore Bonaccorso
Hi On Tue, Mar 14, 2017 at 04:16:18AM +0100, Guilhem Moulin wrote: > Control: tag -1 pending > > Hi, > > On Sat, 11 Mar 2017 at 20:29:11 +0100, Salvatore Bonaccorso wrote: > > 1.2.4 roundcube release fixed a XSS issue in handling of a style tag > > inside of an svg element. > > Thanks for the p

Processed: notfound 857699 in 1.36, found 857699 in 1.36+svn2287-1, tagging 857699

2017-03-14 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > # there is no such Debian version > notfound 857699 1.36 Bug #857699 [ioquake3] ioquake3 has a security vulnerability There is no source info for the package 'ioquake3' at version '1.36' with architecture '' Unable to make a source version for ve

  1   2   >