Bug#860287: libosip2: CVE-2016-10324 CVE-2016-10325 CVE-2016-10326 CVE-2017-7853

2017-04-14 Thread Salvatore Bonaccorso
Hi Antonie, On Fri, Apr 14, 2017 at 04:44:49PM -0400, anarcat wrote: [...] > I forgot to mention the bug # in the NMU, unfortunately... Since it is in the delayed queue, can you cancel, and reupload with the changelog fixing the bugnumber? Otherwise you will need to do that anyway manually (or so

Bug#859805: Patch proposal

2017-04-14 Thread JC
Hi Scott, Le ven. 14 avr. 2017 à 19:59, Scott Kitterman a écrit : > Thanks for the patch. > I still need to review the underlying issue. I suspect it is user error. > Scott K > Well, I was not sure myself, so I did install postfix into new jessie and stretch VMs and I've seen myself the same d

Bug#859805: Patch proposal

2017-04-14 Thread Scott Kitterman
Thanks for the patch. I still need to review the underlying issue. I suspect it is user error. Scott K

Bug#860347: xserver-xorg-core: can't produce script.log for running X server

2017-04-14 Thread G. Branden Robinson
At 2017-04-14T14:41:59-0700, Mark wrote: > Package: xserver-xorg-core > Version: 2:1.16.4-1 > Severity: serious > Justification: unknow > > Dear Maintainer, > > For the ability to file other bug reports, this bug is in fact responsible for > affecting. > > I cannot, via the command > "sudo /usr/

Bug#860347: xserver-xorg-core: can't produce script.log for running X server

2017-04-14 Thread Mark
Package: xserver-xorg-core Version: 2:1.16.4-1 Severity: serious Justification: unknow Dear Maintainer, For the ability to file other bug reports, this bug is in fact responsible for affecting. I cannot, via the command "sudo /usr/share/bug/xorg/script 3>/tmp/script.log" produce a script.log, s

Bug#781155: openbsd-inetd: openbsd-inetd.service should be the main service file

2017-04-14 Thread Marco d'Itri
On Apr 13, Raphael Hertzog wrote: > Consistency between package name and init script and service file > has no reason to be classified as "historical accident", it seems > to be nice bonus point to me... I think that consistenct between daemon name and systemd unit name is a much better goal. -

Bug#857794: reportbug: crash when encountering some non-ASCII characters

2017-04-14 Thread Louis-Philippe Véronneau
Control: tag -1 patch Hi! I tested your patch (0001-Stop-using-subprocess.getoutput.patch) and it works fine for me using C locales and packages where the maintainer's name has non-ascii chars. It's not pretty thought (but does not crash, so \0/): "Maintainer for stressant is 'Antoine Beaupr\xe

Processed: Re: Bug#857794: reportbug: crash when encountering some non-ASCII characters

2017-04-14 Thread Debian Bug Tracking System
Processing control commands: > tag -1 patch Bug #857794 [reportbug] reportbug: crash when encountering some non-ASCII characters Added tag(s) patch. -- 857794: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=857794 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems

Bug#859539: filezilla: Filezilla crashes at startup

2017-04-14 Thread Kienan Stewart
Hi, I was unable to reproduce this bug on a clean install (QEMU VM), or on my laptop which had been upgraded from Jessie to Stretch some time ago. I followed the test proposed by John earlier. Perhaps there are some details in the config file or the bookmark path that may be pertinent to provo

Bug#860287: libosip2: CVE-2016-10324 CVE-2016-10325 CVE-2016-10326 CVE-2017-7853

2017-04-14 Thread anarcat
Control: fixed -1 4.1.0-2.1 Control: tags -1 +pending I have made a NMU (diff in #860345) to fix this in sid/stretch, the patches apply fairly cleanly, and since it's the same version in jessie, it should be trivial to backport there... I forgot to mention the bug # in the NMU, unfortunately...

Processed: Re: Bug#860287: libosip2: CVE-2016-10324 CVE-2016-10325 CVE-2016-10326 CVE-2017-7853

2017-04-14 Thread Debian Bug Tracking System
Processing control commands: > fixed -1 4.1.0-2.1 Bug #860287 [src:libosip2] libosip2: CVE-2016-10324 CVE-2016-10325 CVE-2016-10326 CVE-2017-7853 The source 'libosip2' and version '4.1.0-2.1' do not appear to match any binary packages Marked as fixed in versions libosip2/4.1.0-2.1. > tags -1 +pe

Bug#856874: Confirm patch for bug #856874 is good

2017-04-14 Thread Long Vu
user debian-rele...@lists.debian.org usertags 856874 bsp-2017-04-ca-montreal thanks Reproducing the bug: dget -x http://httpredir.debian.org/debian/pool/main/r/resiprocate/resiprocate_1.11.0~beta1-1.dsc cowbuilder build resiprocate_1.11.0~beta1-1.dsc cd /var/cache/pbuild

Bug#859927: Works, uploaded to DELAYED-3

2017-04-14 Thread micah anderson
That fix works, I've done a NMU fixed package and uploaded it to DELAYED-3. Micah

Bug#857992: openjdk-8-jre-headless: please add Breaks: tzdata-java

2017-04-14 Thread anarcat
user debian-rele...@lists.debian.org usertags 857992 bsp-2017-04-ca-montreal thanks On Mon, Apr 10, 2017 at 12:28:07PM +0200, Andreas Beckmann wrote: > Control: severity -1 serious > > On 2017-03-17 00:33, Andreas Beckmann wrote: > > I haven't rebuilt openjdk-8 to test whether this actually works

Bug#859805: Patch proposal

2017-04-14 Thread JC
Control: user debian-rele...@lists.debian.org Control: usertags -1 bsp-2017-04-ca-montreal Here is a patch to manage the upgrade of postfix maps from postinst. I know modifying a user config file is controversial, but here we only do it for postfix libraries in standard Debian installation path,

Bug#860343: unittest++: Incomplete debian/copyright?

2017-04-14 Thread Chris Lamb
Source: unittest++ Version: 2.0.0-1~exp1 Severity: serious Justication: Policy 12.5 X-Debbugs-CC: Gianfranco Costamagna Hi, I just ACCEPTed unittest++ from NEW but noticed it was missing attribution in debian/copyright for at least m4/ax_cxx_compile_stdcxx.m4 and m4/ax_cxx_compile_stdcxx_11.m4.

Bug#860342: python3-taglib: Newer upstream releases available since Jan 21, 2014

2017-04-14 Thread Robbie Harwood
Package: python3-taglib Severity: grave Justification: renders package unusable Dear Maintainer, Please update to a newer version of the package. This looks unmaintained and I would have filed an RM request save that there are packages that depend on this in the archive. Thanks. -- System Info

Processed: [cacti/debian-sid] Add enable_faster_polling_than_cron.patch

2017-04-14 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tag 860271 pending Bug #860271 {Done: Paul Gevers } [cacti] cacti: polling at a higher frequency than cron doesn't work due to php 7 deprecation of split() Added tag(s) pending. > thanks Stopping processing here. Please contact me if you need as

Bug#860271: [cacti/debian-sid] Add enable_faster_polling_than_cron.patch

2017-04-14 Thread Paul Gevers
tag 860271 pending thanks Date: Thu Apr 13 21:43:46 2017 +0200 Author: Paul Gevers Commit ID: 934091e6738b1f2939b63119141776f683afa156 Commit URL: http://git.debian.org/?p=pkg-cacti/cacti.git;a=commitdiff;h=934091e6738b1f2939b63119141776f683afa156 Patch URL: http://git.debian.org/?p=pkg-cacti/c

Bug#860341: libmtp-common: libmtp does not work w/ recent Android phones

2017-04-14 Thread Julien AUBIN
Package: libmtp-common Version: 1.1.12-1 Severity: grave Justification: renders package unusable Hi, libmtp should be upgraded to version 1.1.13 as it renders many recent smartphone unable to mount. Issue is reported there : https://sourceforge.net/p/libmtp/bugs/1625/ Many Android 6+ smartphone

Bug#859655: golang-go.crypto: CVE-2017-3204

2017-04-14 Thread anarcat
Control: user -1 debian-rele...@lists.debian.org Control: usertags -1 bsp-2017-04-ca-montreal Control: tags -1 +patch I looked into this during the Montreal BSP, and it's unclear what we should do here, considering there has been multiple new uploads since the stretch freeze. The patch is pretty

Bug#857444: [debian-mysql] Bug#857444: Bug#857444: mysql-server-5.5: upgrade from jessie to stretch leaves mysql server uninstalled

2017-04-14 Thread Gabriel Filion
Hi there, I've traced inter-package links (depends, conflicts et al) and I think I found the reason why the server gets removed. stretch still has a mysql-common package that has a "Replaces:" for mysql-server-5.5. during a dist-upgrade mysql-common will get upgraded to the stretch version, whic

Processed (with 2 errors): Re: Bug#859655: golang-go.crypto: CVE-2017-3204

2017-04-14 Thread Debian Bug Tracking System
Processing control commands: > user -1 debian-rele...@lists.debian.org Unknown command or malformed arguments to command. > usertags -1 bsp-2017-04-ca-montreal Unknown command or malformed arguments to command. > tags -1 +patch Bug #859655 [src:golang-go.crypto] golang-go.crypto: CVE-2017-3204 I

Bug#859927: Confirmed

2017-04-14 Thread micah anderson
I've confirmed this bug, as reported: I installed lighttpd: The following NEW packages will be installed: lighttpd spawn-fcgi 0 upgraded, 2 newly installed, 0 to remove and 326 not upgraded. Need to get 299 kB of archives. After this operation, 1,019 kB of additional disk space will be used. D

Bug#860258: marked as done (i too got the same error when i m compiling ptxdist source, can i get help about this?)

2017-04-14 Thread Debian Bug Tracking System
Your message dated Fri, 14 Apr 2017 20:39:55 +0300 with message-id <20170414173955.u6mjgmlnivtwbuep@localhost> and subject line This bug tracker is for bugs in packages in Debian has caused the Debian Bug report #860258, regarding i too got the same error when i m compiling ptxdist source, can i ge

Bug#831007: fix requires upgrading to newer upstream

2017-04-14 Thread Peter Silva
Control: severity -1 wishlist It is painful that the behaviour changed, but if upstream decided that is the way it is, we cannot break upstream. There is a later upstream version (in the thread already) that reports, rather than being silent, but patch doesn't apply to what is in stretch, need th

Processed: fix requires upgrading to newer upstream

2017-04-14 Thread Debian Bug Tracking System
Processing control commands: > severity -1 wishlist Bug #831007 [tar] tar 1.29 silently ignores previously-supported --exclude options Severity set to 'wishlist' from 'serious' -- 831007: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=831007 Debian Bug Tracking System Contact ow...@bugs.debia

Bug#859963: marked as done (mimetic FTBFS on architectures where char is unsigned)

2017-04-14 Thread Debian Bug Tracking System
Your message dated Fri, 14 Apr 2017 16:03:58 + with message-id and subject line Bug#859963: fixed in mimetic 0.9.8-5 has caused the Debian Bug report #859963, regarding mimetic FTBFS on architectures where char is unsigned to be marked as done. This means that you claim that the problem has b

Processed: Re: Bug#860142: libgeo-ip-perl: incompatible with geoip-database - cannot load

2017-04-14 Thread Debian Bug Tracking System
Processing control commands: > retitle -1 libgeo-ip-perl: should recommend geoip-database and > geoip-database-extra Bug #860142 [libgeo-ip-perl] libgeo-ip-perl: incompatible with geoip-database - cannot load Changed Bug title to 'libgeo-ip-perl: should recommend geoip-database and geoip-databa

Bug#860142: Pending fixes for bugs in the libgeo-ip-perl package

2017-04-14 Thread pkg-perl-maintainers
tag 860142 + pending thanks Some bugs in the libgeo-ip-perl package are closed in revision aed87202233265db1b3f136bb02e9615a9dde290 in branch 'master' by gregor herrmann The full diff can be seen at https://anonscm.debian.org/cgit/pkg-perl/packages/libgeo-ip-perl.git/commit/?id=aed8720 Commit me

Bug#860142: libgeo-ip-perl: incompatible with geoip-database - cannot load

2017-04-14 Thread gregor herrmann
Control: retitle -1 libgeo-ip-perl: should recommend geoip-database and geoip-database-extra Control: severity -1 normal Control: tag -1 + pending On Wed, 12 Apr 2017 23:18:36 +0200, gregor herrmann wrote: > On Wed, 12 Apr 2017 22:31:52 +0200, Jonas Smedegaard wrote: > > > > This means that all

Bug#860026: marked as done (debian-parl: please update dependencies)

2017-04-14 Thread Debian Bug Tracking System
Your message dated Fri, 14 Apr 2017 15:33:48 + with message-id and subject line Bug#860026: fixed in debian-parl 1.9.10 has caused the Debian Bug report #860026, regarding debian-parl: please update dependencies to be marked as done. This means that you claim that the problem has been dealt w

Processed: fixed 854592 in 0.0.20160626.a-2

2017-04-14 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > fixed 854592 0.0.20160626.a-2 Bug #854592 {Done: Tanguy Ortolo } [dokuwiki] dokuwiki: Unable to login, missing usr/share/php/Crypt/AES.php Marked as fixed in versions dokuwiki/0.0.20160626.a-2. > thanks Stopping processing here. Please contact m

Bug#854592: marked as done (dokuwiki: Unable to login, missing usr/share/php/Crypt/AES.php)

2017-04-14 Thread Debian Bug Tracking System
Your message dated Fri, 14 Apr 2017 16:06:43 +0200 with message-id <20170414140643.ga18...@ortolo.eu> and subject line Re: Bug#854592: [pkg-php-pear] Bug#854592: dokuwiki: Unable to login, missing usr/share/php/Crypt/AES.php has caused the Debian Bug report #854592, regarding dokuwiki: Unable to l

Processed: retitle 860316 to grpc: CVE-2017-7860 CVE-2017-7861

2017-04-14 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > retitle 860316 grpc: CVE-2017-7860 CVE-2017-7861 Bug #860316 [src:grpc] CVE-2017-7861 Changed Bug title to 'grpc: CVE-2017-7860 CVE-2017-7861' from 'CVE-2017-7861'. > thanks Stopping processing here. Please contact me if you need assistance. --

Bug#854592: [pkg-php-pear] Bug#854592: dokuwiki: Unable to login, missing usr/share/php/Crypt/AES.php

2017-04-14 Thread Tanguy Ortolo
Hello, David Prévot, 2017-02-13 08:45-0900: Then it sounds like this bug was incorrectly reassigned to php-phpseclib: either dokuwiki should depend on version 1 of phpseclib via the php-seclib package and have the files where expected, or it is able to use version 2 via the php-phpseclib package

Bug#860316: CVE-2017-7861

2017-04-14 Thread Moritz Mühlenhoff
Moritz Muehlenhoff wrote: > Source: grpc > Severity: grave > Tags: security > > Please see > http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7861 for details. Also http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7860 Cheers, Moritz

Bug#860316: CVE-2017-7861

2017-04-14 Thread Moritz Muehlenhoff
Source: grpc Severity: grave Tags: security Please see http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7861 for details. Cheers, Moritz

Processed: Re: Bug#860314: icu: CVE-2017-7867 CVE-2017-7868: Heap-buffer-overflow in utf8TextAccess

2017-04-14 Thread Debian Bug Tracking System
Processing control commands: > retitle -1 icu: CVE-2017-7867 CVE-2017-7868: Heap-buffer-overflow in > utf8TextAccess Bug #860314 [src:icu] icu: CVE-2017-7867: Heap-buffer-overflow in utf8TextAccess Changed Bug title to 'icu: CVE-2017-7867 CVE-2017-7868: Heap-buffer-overflow in utf8TextAccess' fr

Bug#860314: icu: CVE-2017-7867 CVE-2017-7868: Heap-buffer-overflow in utf8TextAccess

2017-04-14 Thread Salvatore Bonaccorso
Control: retitle -1 icu: CVE-2017-7867 CVE-2017-7868: Heap-buffer-overflow in utf8TextAccess Adding as well CVE-2017-7868: | International Components for Unicode (ICU) for C/C++ before 2017-02-13 | has an out-of-bounds write caused by a heap-based buffer overflow | related to the utf8TextAccess

Bug#860314: icu: CVE-2017-7867: Heap-buffer-overflow in utf8TextAccess

2017-04-14 Thread Salvatore Bonaccorso
Source: icu Version: 52.1-8 Severity: grave Tags: patch security upstream Justification: user security hole Forwarded: https://ssl.icu-project.org/trac/ticket/12888 *** /tmp/icu.reportbug Package: icu X-Debbugs-CC: t...@security.debian.org secure-testing-t...@lists.alioth.debian.org Severity: g

Bug#859462: Fix from upstream

2017-04-14 Thread Frederic Bonnard
Hi, here is attached part of the patch applied upstream ( https://github.com/TelepathyIM/telepathy-qt/commit/15374115fa910ffa41ac2acce71b7f4fc0937674 ) That fixed the problem here. F. --- a/tests/dbus/contacts-capabilities.cpp +++ b/tests/dbus/contacts-capabilities.cpp @@ -111,7 +111,7 @@ QSt

Bug#860280: marked as done (imagemagick-doc upgrade failure: dpkg-maintscript-helper: error: missing arguments after --)

2017-04-14 Thread Debian Bug Tracking System
Your message dated Fri, 14 Apr 2017 11:19:09 + with message-id and subject line Bug#860280: fixed in imagemagick 8:6.9.7.4+dfsg-5 has caused the Debian Bug report #860280, regarding imagemagick-doc upgrade failure: dpkg-maintscript-helper: error: missing arguments after -- to be marked as don

Bug#860026: [Parl-devel] Bug#860026: debian-parl: please update dependencies

2017-04-14 Thread Jonas Smedegaard
Quoting Andreas Beckmann (2017-04-10 14:46:41) > The following packages have unmet dependencies: > parl-desktop-world : Depends: myspell-cs but it is not going to be installed > E: Unable to correct problems, you have held broken packages. > > > The relevant bits of the dependency chain seem to

Bug#860307: freetype: CVE-2017-7857 CVE-2017-7858

2017-04-14 Thread Salvatore Bonaccorso
Source: freetype Version: 2.7.1-0.1 Severity: grave Tags: security upstream experimental Hi, the following vulnerabilities were published for freetype. AFAICS these affect only the version in experimental, so before it will migrate at some point to unstable, fixes for those two CVEs should be inc

Bug#858626: marked as done (libllvm-3.8-ocaml-dev: Package is empty)

2017-04-14 Thread Debian Bug Tracking System
Your message dated Fri, 14 Apr 2017 09:36:15 + with message-id and subject line Bug#858626: fixed in llvm-toolchain-3.9 1:3.9.1-6 has caused the Debian Bug report #858626, regarding libllvm-3.8-ocaml-dev: Package is empty to be marked as done. This means that you claim that the problem has be

Bug#860146: marked as done (python-formencode: Ships /usr/lib/py2.7/dist-p/docs/index.txt)

2017-04-14 Thread Debian Bug Tracking System
Your message dated Fri, 14 Apr 2017 08:52:43 + with message-id and subject line Bug#860146: fixed in python-formencode 1.3.0-2 has caused the Debian Bug report #860146, regarding python-formencode: Ships /usr/lib/py2.7/dist-p/docs/index.txt to be marked as done. This means that you claim that

Bug#858626: marked as done (libllvm-3.8-ocaml-dev: Package is empty)

2017-04-14 Thread Debian Bug Tracking System
Your message dated Fri, 14 Apr 2017 08:50:44 + with message-id and subject line Bug#858626: fixed in llvm-toolchain-3.8 1:3.8.1-19 has caused the Debian Bug report #858626, regarding libllvm-3.8-ocaml-dev: Package is empty to be marked as done. This means that you claim that the problem has b

Processed: Bug#860146 marked as pending

2017-04-14 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tag 860146 pending Bug #860146 [python-formencode] python-formencode: Ships /usr/lib/py2.7/dist-p/docs/index.txt Added tag(s) pending. > thanks Stopping processing here. Please contact me if you need assistance. -- 860146: http://bugs.debian.or

Bug#860146: marked as pending

2017-04-14 Thread Chris Lamb
tag 860146 pending thanks Hello, Bug #860146 reported by you has been fixed in the Git repository. You can see the changelog below, and you can check the diff of the fix at: https://anonscm.debian.org/cgit/python-modules/packages/python-formencode.git/commit/?id=984eb01 --- commit 984eb01b

Processed: Re: python-formencode: Ships /usr/lib/py2.7/dist-p/docs/index.txt

2017-04-14 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tags 860146 + pending Bug #860146 [python-formencode] python-formencode: Ships /usr/lib/py2.7/dist-p/docs/index.txt Ignoring request to alter tags of bug #860146 to the same tags previously set > thanks Stopping processing here. Please contact m

Bug#860146: python-formencode: Ships /usr/lib/py2.7/dist-p/docs/index.txt

2017-04-14 Thread Chris Lamb
tags 860146 + patch thanks Patch attached. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- diff --git a/debian/python-formencode.docs b/debian/python-formencode.docs new file mode 100644 index 000..bf4cbd5 --- /dev/null +++

Processed: Re: python-formencode: Ships /usr/lib/py2.7/dist-p/docs/index.txt

2017-04-14 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tags 860146 + patch Bug #860146 [python-formencode] python-formencode: Ships /usr/lib/py2.7/dist-p/docs/index.txt Added tag(s) patch. > thanks Stopping processing here. Please contact me if you need assistance. -- 860146: http://bugs.debian.org