Bug#860225: bind9: CVE-2017-3137: A response packet can cause a resolver to terminate when processing an answer containing a CNAME or DNAME

2017-05-10 Thread Salvatore Bonaccorso
On Thu, May 11, 2017 at 08:27:57AM +0200, Salvatore Bonaccorso wrote: > On Thu, May 11, 2017 at 08:19:15AM +0200, Salvatore Bonaccorso wrote: > > Hi > > > > Packages for testing can be found at: > > > > https://people.debian.org/~carnil/tmp/bind9/ > > > > (amd64 build only), and attached the deb

Bug#860225: bind9: CVE-2017-3137: A response packet can cause a resolver to terminate when processing an answer containing a CNAME or DNAME

2017-05-10 Thread Salvatore Bonaccorso
On Thu, May 11, 2017 at 08:19:15AM +0200, Salvatore Bonaccorso wrote: > Hi > > Packages for testing can be found at: > > https://people.debian.org/~carnil/tmp/bind9/ > > (amd64 build only), and attached the debdiff. There was an error in those packages and I have removed them again. Salvatore

Bug#712612: gcr: diff for NMU version 3.20.0-5.1

2017-05-10 Thread Christoph Biedl
Michael Biebl wrote... > Well, Ansgar mentioned this: > > > there are two files under a BSD license in build/valgrind/*. In addition the > > documentation has its own license in docs/reference/COPYING. > > He was referring to that file afaics: > https://git.gnome.org/browse/gcr/tree/docs/referen

Bug#860225: bind9: CVE-2017-3137: A response packet can cause a resolver to terminate when processing an answer containing a CNAME or DNAME

2017-05-10 Thread Salvatore Bonaccorso
Hi Packages for testing can be found at: https://people.debian.org/~carnil/tmp/bind9/ (amd64 build only), and attached the debdiff. I would appreciate any testing feedback from people mentioning in this bug that they are affected by the issue. Thanks already in advance, Regards, Salvatore dif

Bug#862306: marked as done (mariadb-server hangs indefinitely during install)

2017-05-10 Thread Debian Bug Tracking System
Your message dated Thu, 11 May 2017 12:47:19 +0900 with message-id and subject line Re: mariadb-server hangs indefinitely during install has caused the Debian Bug report #862306, regarding mariadb-server hangs indefinitely during install to be marked as done. This means that you claim that the pr

Bug#859912: Bug#862178: problem with packages build-depending on locales in experimental

2017-05-10 Thread Mike Hommey
On Thu, May 11, 2017 at 06:13:13AM +0300, Adrian Bunk wrote: > On Thu, May 11, 2017 at 08:08:06AM +0900, Mike Hommey wrote: > > On Wed, May 10, 2017 at 04:44:07PM +0300, Adrian Bunk wrote: > > > On Tue, May 09, 2017 at 04:08:04PM +0200, Daniel Baumann wrote: > >... > > > > For the rational why o-i-

Bug#859912: Bug#862178: problem with packages build-depending on locales in experimental

2017-05-10 Thread Adrian Bunk
On Thu, May 11, 2017 at 08:08:06AM +0900, Mike Hommey wrote: > On Wed, May 10, 2017 at 04:44:07PM +0300, Adrian Bunk wrote: > > On Tue, May 09, 2017 at 04:08:04PM +0200, Daniel Baumann wrote: >... > > > For the rational why o-i-locales-c.utf-8 is usefull, see its manpage: > > > > > > https://manpa

Bug#862306: mariadb-server hangs indefinitely during install

2017-05-10 Thread Matthew Mummert
Dear Package Maintainer: This bug report was a false alarm. Please disregard. My sincerest apologies.

Bug#858250: Bug#861953: unblock: runc/0.1.1+dfsg1-3

2017-05-10 Thread Roger Shimizu
control: tag 861953 -moreinfo On Mon, 8 May 2017 08:40:52 +0900 Roger Shimizu wrote: > What's your opinion? I proposed two plans. Either is fine to me. Please kindly help to decide, so as to avoid a few packages get removed in stretch. Thank you! Cheers, -- Roger Shimizu, GMT +9 Tokyo PGP/GP

Bug#859912: Bug#862178: Bug#859912: Bug#862178: problem with packages build-depending on locales in experimental

2017-05-10 Thread Aurelien Jarno
On 2017-05-11 08:08, Mike Hommey wrote: > On Wed, May 10, 2017 at 04:44:07PM +0300, Adrian Bunk wrote: > > On Tue, May 09, 2017 at 04:08:04PM +0200, Daniel Baumann wrote: > > >... > > > Can anybody have a look at this why it's failing? Bug with references is > > > #859912 > > >... > > > > Your pac

Bug#862306: mariadb-server hangs indefinitely during install

2017-05-10 Thread Matthew Mummert
Package: mariadb-server Version: 10.0.30-0+deb8u2 Severity: grave Justification: renders package unusable -- System Information: Debian Release: 8.2 APT prefers stable-updates APT policy: (500, 'stable-updates'), (500, 'stable') Architecture: armhf (armv7l) Kernel: Linux 4.1.12-ti-r29 (SMP

Bug#859912: Bug#862178: problem with packages build-depending on locales in experimental

2017-05-10 Thread Mike Hommey
On Wed, May 10, 2017 at 04:44:07PM +0300, Adrian Bunk wrote: > On Tue, May 09, 2017 at 04:08:04PM +0200, Daniel Baumann wrote: > >... > > Can anybody have a look at this why it's failing? Bug with references is > > #859912 > >... > > Your package shouldn't exist, this is the main problem here. I

Bug#861591: Bug#862071: password-store: FTBFS when built in a path with >= 74 characters

2017-05-10 Thread Dominic Hargreaves
On Mon, May 08, 2017 at 10:43:21PM +0100, Chris Lamb wrote: > gregor herrmann wrote: > > > > This is due to GNUPGHOME needing to fit within sockaddr_un.sun_path. > > > > Also #861591, where the same happens. > > > > I'm not sure how RC-ish this should be, as build paths by our usual > > tools (s

Processed: Does not apply to jessie

2017-05-10 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tags 861744 stretch sid Bug #861744 [torbrowser-launcher] torbrowser-launcher: Should not be part of Stretch Added tag(s) sid and stretch. > thanks Stopping processing here. Please contact me if you need assistance. -- 861744: http://bugs.debia

Bug#862301: isoquery: FTBFS: test_integration_add_test_from_files: stdout of child process failed to match

2017-05-10 Thread Chris Lamb
Source: isoquery Version: 3.2.1-1 Severity: serious Justification: fails to build from source User: reproducible-bui...@lists.alioth.debian.org Usertags: ftbfs X-Debbugs-Cc: reproducible-b...@lists.alioth.debian.org Dear Maintainer, isoquery fails to build from source in unstable/amd64: […]

Bug#862300: Crashes during the login process

2017-05-10 Thread John Goerzen
Package: citadel-server Version: 902-3 Severity: grave Hello, I have confirmed this issue in both stretch and sid with version 902-3. jessie with version 8.24-1+b3 is fine. Essentially, I can neither log in with the admin account nor create a new user. This also occurs if I make the attempt vi

Bug#862297: Install fails if SMTP server is running on port 25, rendering console unuseable

2017-05-10 Thread John Goerzen
Package: citadel-server Version: 902-3 Severity: grave Hi, I installed citadel-server (but not citadel-mta). I will note that citadel-server does not conflict with mail-transport-agent (citadel-mta does, but not citadel server). I attempted to install citadel-server on a system that already h

Bug#857296: closed by Camm Maguire (Re: hol-library empty on arm64)

2017-05-10 Thread Adrian Bunk
Control: reopen -1 On Tue, May 02, 2017 at 08:21:08PM +, Debian Bug Tracking System wrote: >... > Greetings! This was due to a transient failure in the build > architecture on the affected platforms. Package builds fine now in a > fresh up to date chroot. BinNMU uploaded. >... This is clear

Processed: Re: Bug#857296 closed by Camm Maguire (Re: hol-library empty on arm64)

2017-05-10 Thread Debian Bug Tracking System
Processing control commands: > reopen -1 Bug #857296 {Done: Camm Maguire } [hol88-library] hol88-library is an empty package on arm64, hppa, and m68k Bug reopened Ignoring request to alter fixed versions of bug #857296 to the same values previously set -- 857296: http://bugs.debian.org/cgi-bin

Bug#862296: Install hangs in postinst with error about c_Default_cal_zone

2017-05-10 Thread John Goerzen
Package: citadel-server Version: 902-3 Severity: grave Hi, On initial install, this package hangs in postinst, and spews several of these messages across the console: Broadcast message from systemd-journald@sid (Wed 2017-05-10 14:45:52 CDT): citserver[12599]: configuration setting c_default_ca

Processed: python-jenkins bug 861656 severity important

2017-05-10 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > severity 861656 important Bug #861656 [src:python-jenkins] 0.4.11 lacks support for get_info and URLs with a prefix path Severity set to 'important' from 'grave' > End of message, stopping processing here. Please contact me if you need assistanc

Bug#861612: pixbros: level designs appear to be non-free

2017-05-10 Thread Adrian Bunk
On Mon, May 01, 2017 at 03:50:21PM +0200, Steve Cotton wrote: >... > Oh well at least this will resolve the Fenix-is-not-64-bit bugs. Is pixfrogger also affected? > Steve cu Adrian -- "Is there not promise of rain?" Ling Tan asked suddenly out of the darkness. There had been ne

Bug#861958: lintian: insecure YAML validation [CVE-2017-8829]

2017-05-10 Thread Niels Thykier
Dominique Dumont: > Ive logged a bug to upstream YAML parser library: > > https://github.com/ingydotnet/yaml-pm/issues/176 > > HTH > Thanks. :) ~Niels

Bug#862075: ceph-detect-init: Platform is not supported.: debian 9.0

2017-05-10 Thread Simon McVittie
On Mon, 08 May 2017 at 11:16:48 +0200, Pim van den Berg wrote: > As you can see ceph assumes our init system is sysvinit in stretch, while it > is systemd. No, our init system is "either sysvinit or systemd, or maybe even Upstart". get_init_system() in reportbug's reportbug.utils demonstrates how

Bug#861958: lintian: insecure YAML validation [CVE-2017-8829]

2017-05-10 Thread Dominique Dumont
Ive logged a bug to upstream YAML parser library: https://github.com/ingydotnet/yaml-pm/issues/176 HTH

Bug#861683: Install xserver-xorg-legacy by default for stretch

2017-05-10 Thread Moritz Muehlenhoff
On Wed, May 10, 2017 at 01:40:42PM +0200, Michael Biebl wrote: > Am 10.05.2017 um 07:32 schrieb Moritz Muehlenhoff: > > On Tue, May 02, 2017 at 07:39:37PM +0200, Michael Biebl wrote: > >> Same is true for users of startx. They need the suid wrapper provided by > >> xserver-xorg-legacy in such a cas

Processed: severity of 862075 is serious

2017-05-10 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > severity 862075 serious Bug #862075 [ceph-base] ceph-detect-init: Platform is not supported.: debian 9.0 Severity set to 'serious' from 'normal' > thanks Stopping processing here. Please contact me if you need assistance. -- 862075: http://bug

Processed: severity of 862244 is normal

2017-05-10 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > severity 862244 normal Bug #862244 [postfix] Fwd: bug 850430 still here in postfix version 3.1.4-4 ? Severity set to 'normal' from 'grave' > thanks Stopping processing here. Please contact me if you need assistance. -- 862244: http://bugs.debian

Bug#862249: Mounting an SFTP share with path may lead to data being deleted

2017-05-10 Thread Jason Crain
On Wed, May 10, 2017 at 10:42:51AM +0200, Jonas Meurer wrote: > I just discovered a severe bug in the sftp protocol support of nautilus: > > I tried to mount a remote folder via SFTP/SSH by using a syntax similar > to the following: > > 'sftp:///path/to/directory'. Instead of displaying > '/path/

Processed: Re: Bug#860548

2017-05-10 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > severity 860548 normal Bug #860548 [r10k] r10k - rugged provider does neither HTTPS, nor SSH Severity set to 'normal' from 'grave' > stop Stopping processing here. Please contact me if you need assistance. -- 860548: http://bugs.debian.org/cgi-b

Bug#862273: miniupnpc: CVE-2017-8798: miniupnp integer signedness error

2017-05-10 Thread Salvatore Bonaccorso
Source: miniupnpc Version: 1.9.20140610-2 Severity: grave Tags: patch upstream security Justification: user security hole Hi, the following vulnerability was published for miniupnpc. CVE-2017-8798[0]: miniupnp integer signedness error If you fix the vulnerability please also make sure to includ

Processed: Re: Bug#862233: libpomegranate-clojure: Package does not work with available version of maven

2017-05-10 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > found 862233 0.2.0-1 Bug #862233 [libpomegranate-clojure] libpomegranate-clojure: Package does not work with available version of maven Marked as found in versions pomegranate-clojure/0.2.0-1. > tags 862233 stretch sid Bug #862233 [libpomegranat

Bug#862272: libpomegranate-clojure lost all dependencies

2017-05-10 Thread Adrian Bunk
Package: libpomegranate-clojure Version: 0.3.1-1 Severity: serious libpomegranate-clojure 0.2.0-1 has: Depends: libaether-java, libdynapath-clojure, libwagon-java, libwagon2-java, maven libpomegranate-clojure 0.3.1-1 has no dependencies at all.

Bug#860548: r10k - rugged provider does neither HTTPS, nor SSH

2017-05-10 Thread Sebastien Badia
On Tue, Apr 18, 2017 at 02:01:04PM (+0200), Bastian Blank wrote: > Package: r10k > Version: 2.5.0-1 > Severity: grave > > The rugged provider, as provided by ruby-rugged in Debian, does neither > support HTTPS, nor SSH. As this is a hard dependency, I think it is > safe to assume it should work.

Bug#859912: Bug#862178: problem with packages build-depending on locales in experimental

2017-05-10 Thread Adrian Bunk
On Tue, May 09, 2017 at 04:08:04PM +0200, Daniel Baumann wrote: >... > Can anybody have a look at this why it's failing? Bug with references is > #859912 >... Your package shouldn't exist, this is the main problem here. And the potential breakage is not limited to buildds. Package: open-infrastr

Bug#862252: dns-root-data: FTBFS if /bin/sh is bash

2017-05-10 Thread Chris Lamb
tags 862252 + patch thanks Patch attached. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- diff --git a/parse-root-anchors.sh b/parse-root-anchors.sh index 91e99f9..2f5f779 100755 --- a/parse-root-anchors.sh +++ b/parse-root-an

Processed: Re: dns-root-data: FTBFS if /bin/sh is bash

2017-05-10 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tags 862252 + patch Bug #862252 [src:dns-root-data] dns-root-data: FTBFS if /bin/sh is bash Added tag(s) patch. > thanks Stopping processing here. Please contact me if you need assistance. -- 862252: http://bugs.debian.org/cgi-bin/bugreport.cgi?

Bug#862244: Fwd: bug 850430 still here in postfix version 3.1.4-4 ?

2017-05-10 Thread Scott Kitterman
What's the output of: ls -al /usr/lib/postfix/sbin/lmtp Scott K

Bug#861683: Install xserver-xorg-legacy by default for stretch

2017-05-10 Thread Michael Biebl
Am 10.05.2017 um 07:32 schrieb Moritz Muehlenhoff: > On Tue, May 02, 2017 at 07:39:37PM +0200, Michael Biebl wrote: >> Same is true for users of startx. They need the suid wrapper provided by >> xserver-xorg-legacy in such a case. such a case == a non-KMS driver being in use. > That's not true. I

Bug#861656: BROKEN: 0.4.11 lacks support for get_info and URLs with a prefix path

2017-05-10 Thread intrigeri
Hi, Antoine Musso: > python-jenkins 0.4.11 is partly broken. At least the jenkins-job-builder use case works fine for me on current Stretch, and the bug report says "partly", so I'm not sure this bug should really be RC. Cheers, -- intrigeri

Bug#809669: RC Bug NMU diff

2017-05-10 Thread Louis Bouchard
Hello, Le 06/05/2017 à 20:09, Gaudenz Steinlin a écrit : > > Hi > > I uplaoded an NMU to unstable to fix this bug. I mostly used the debdiff > prepared by Louis Bouchard but fixed the version number to be > 0.93.1+nmu1 instead of 0.93.2 and actually fixed the systemd unit in the > way proposed i

Bug#862252: dns-root-data: FTBFS if /bin/sh is bash

2017-05-10 Thread Chris West
Source: dns-root-data Version: 2017020200 User: reproducible-bui...@lists.alioth.debian.org Usertags: ftbfs X-Debbugs-Cc: reproducible-b...@lists.alioth.debian.org Severity: serious dns-root-data's parse-root-anchors.sh script contains a dashism: it does not produce the right output when /bin/sh i

Bug#862250: Proposed diff fixing prefetch logic of 9.10

2017-05-10 Thread Thomas Leuxner
Package: bind9 Version: 9.10.3.dfsg.P4-12.3 Severity: serious Please cherry-pick this upstream patch to fix the broken prefetching logic, which is enabled by default: https://kb.isc.org/article/AA-01315/0/prefetch-performance-in-BIND-9.10.html --- bind9-9.10.3.dfsg.P4.orig/bin/named/query.c +++

Bug#862249: Mounting an SFTP share with path may lead to data being deleted

2017-05-10 Thread Jonas Meurer
Package: nautilus Version: 3.22.3-1 Severity: critical Hello, I just discovered a severe bug in the sftp protocol support of nautilus: I tried to mount a remote folder via SFTP/SSH by using a syntax similar to the following: 'sftp:///path/to/directory'. Instead of displaying '/path/to/directory

Bug#862244: Fwd: bug 850430 still here in postfix version 3.1.4-4 ?

2017-05-10 Thread Bastien Steimer
Package: postfix Version: 3.1.4-4 Severity: grave Hello, I'm rather a baby sysadmin, and I am currently installing my new web and mail server on debian stretch. I got stuck on this bug (?), and the hints given on the linked page (https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=850430) help

Bug#859912: FTBFS on khal

2017-05-10 Thread Filip Pytloun
On Tue, 9 May 2017 15:40:18 +0200 Daniel Baumann wrote: > Hi, > > thanks for your report. I'm currently trying to reproduce a sbuild setup > where this happens. > > With a "normal" setup (i.e. debootstrap and then add experimental, this > does not happen and apt does the right thing). > > I've

Bug#860952: fixed in rar 2:5.4.0+dfsg.1-0.1

2017-05-10 Thread Martin Meredith
Someone decided a long time ago that it wasn't "free enough" to be autobuilt, so took it off the list. I hadnt even thought to remove the tags! On 7 May 2017 16:36, "Ivo De Decker" wrote: > Hi Ben, > > On Sun, May 07, 2017 at 03:44:14PM +0100, Ben Hutchings wrote: > > > On Thu, May 04, 2017 at 0