Processed: severity of 819555 is grave

2017-06-01 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > severity 819555 grave Bug #819555 {Done: Adrian Bunk } [libifd-cyberjack6] pcscd: cyberJack pp_a2 init failed with pcscd_1.8.16-1 Bug #819659 {Done: Adrian Bunk } [libifd-cyberjack6] pcscd: readerfactory.c:372:RFAddReader(e-com) REINER SCT cyber

Processed: tagging 851545

2017-06-01 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tags 851545 - stretch-ignore Bug #851545 {Done: Adrian Bunk } [libpam-modules] libpam-modules: multiarch packages with differing files Removed tag(s) stretch-ignore. > thanks Stopping processing here. Please contact me if you need assistance. --

Bug#861840: google sign in error in thunderbird

2017-06-01 Thread Carsten Schoenert
Hello Frederico, Am 02.06.2017 um 02:12 schrieb Frederico Rodrigues Abraham: > Hi all. Thanks for maintaining the thunderbird package in debian, much > appreciated. > > I'd like to know if you've seen this issue: when I add a google mail > account, I get this google sign in window and it doesn'

Processed: retitle 863906 to asterisk: CVE-2017-9358: AST-2017-004: Memory exhaustion on short SCCP packets

2017-06-01 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > retitle 863906 asterisk: CVE-2017-9358: AST-2017-004: Memory exhaustion on > short SCCP packets Bug #863906 [src:asterisk] AST-2017-004: Memory exhaustion on short SCCP packets Changed Bug title to 'asterisk: CVE-2017-9358: AST-2017-004: Memory e

Processed: retitle 863902 to pjproject: AST-2017-003: Crash in PJSIP multi-part body parser

2017-06-01 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > retitle 863902 pjproject: AST-2017-003: Crash in PJSIP multi-part body parser Bug #863902 [src:pjproject] AST-2017-003: Crash in PJSIP multi-part body parser Changed Bug title to 'pjproject: AST-2017-003: Crash in PJSIP multi-part body parser' fr

Processed: fixed 863811 in 3.4.5+dfsg-2+deb8u2, fixed 862958 in 2:3.26-1+debu8u2 ...

2017-06-01 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > fixed 863811 3.4.5+dfsg-2+deb8u2 Bug #863811 {Done: tony mancill } [src:zookeeper] CVE-2017-5637 Marked as fixed in versions zookeeper/3.4.5+dfsg-2+deb8u2. > fixed 862958 2:3.26-1+debu8u2 Bug #862958 [src:nss] nss: CVE-2017-5461 CVE-2017-5462 Mar

Bug#863935: dlang-libevent: FTBFS: build-dependency not installable: ldc

2017-06-01 Thread Lucas Nussbaum
Source: dlang-libevent Version: 2.0.16-1 Severity: serious Tags: stretch sid User: debian...@lists.debian.org Usertags: qa-ftbfs-20170601-i386 qa-ftbfs Justification: FTBFS in stretch on i386 Hi, During a rebuild of all packages in stretch (in a stretch chroot, not a sid chroot), your package

Bug#863937: faustworks: FTBFS: RCC: Error in 'Resources/i18n.qrc': Cannot find file 'translations/i18n_ru.qm'

2017-06-01 Thread Lucas Nussbaum
Source: faustworks Version: 0.5~repack0-2 Severity: serious Tags: stretch sid User: debian...@lists.debian.org Usertags: qa-ftbfs-20170601 qa-ftbfs Justification: FTBFS in stretch on amd64 Hi, During a rebuild of all packages in stretch (in a stretch chroot, not a sid chroot), your package

Bug#863927: qtwebengine-opensource-src: FTBFS: memory exhausted

2017-06-01 Thread Lucas Nussbaum
Source: qtwebengine-opensource-src Version: 5.7.1+dfsg-6 Severity: serious Tags: stretch sid User: debian...@lists.debian.org Usertags: qa-ftbfs-20170601-i386 qa-ftbfs Justification: FTBFS in stretch on i386 Hi, During a rebuild of all packages in stretch (in a stretch chroot, not a sid chroot

Bug#863928: postgresql-9.6: FTBFS: test failures

2017-06-01 Thread Lucas Nussbaum
Source: postgresql-9.6 Version: 9.6.3-3 Severity: serious Tags: stretch sid User: debian...@lists.debian.org Usertags: qa-ftbfs-20170601-i386 qa-ftbfs Justification: FTBFS in stretch on i386 Hi, During a rebuild of all packages in stretch (in a stretch chroot, not a sid chroot), your package

Bug#863931: dlang-openssl: FTBFS: build-dependency not installable: ldc

2017-06-01 Thread Lucas Nussbaum
Source: dlang-openssl Version: 1.1.5+1.0.1g-1 Severity: serious Tags: stretch sid User: debian...@lists.debian.org Usertags: qa-ftbfs-20170601-i386 qa-ftbfs Justification: FTBFS in stretch on i386 Hi, During a rebuild of all packages in stretch (in a stretch chroot, not a sid chroot), your

Bug#863934: node-dateformat: FTBFS: Test failures

2017-06-01 Thread Lucas Nussbaum
Source: node-dateformat Version: 1.0.11-3 Severity: serious Tags: stretch sid User: debian...@lists.debian.org Usertags: qa-ftbfs-20170601-i386 qa-ftbfs Justification: FTBFS in stretch on i386 Hi, During a rebuild of all packages in stretch (in a stretch chroot, not a sid chroot), your package

Bug#863930: ycmd: FTBFS: dh_link: parameters list a link without a destination.

2017-06-01 Thread Lucas Nussbaum
Source: ycmd Version: 0+20161219+git486b809-1 Severity: serious Tags: stretch sid User: debian...@lists.debian.org Usertags: qa-ftbfs-20170601-i386 qa-ftbfs Justification: FTBFS in stretch on i386 Hi, During a rebuild of all packages in stretch (in a stretch chroot, not a sid chroot), your

Bug#863929: falcon: FTBFS: Test failures

2017-06-01 Thread Lucas Nussbaum
Source: falcon Version: 1.8.6-1 Severity: serious Tags: stretch sid User: debian...@lists.debian.org Usertags: qa-ftbfs-20170601-i386 qa-ftbfs Justification: FTBFS in stretch on i386 Hi, During a rebuild of all packages in stretch (in a stretch chroot, not a sid chroot), your package failed to

Bug#863936: gecode: FTBFS: mv: cannot stat 'gecode/flatzinc/parser.tab.hpp': No such file or directory

2017-06-01 Thread Lucas Nussbaum
Source: gecode Version: 4.4.0-4 Severity: serious Tags: stretch sid User: debian...@lists.debian.org Usertags: qa-ftbfs-20170601 qa-ftbfs Justification: FTBFS in stretch on amd64 Hi, During a rebuild of all packages in stretch (in a stretch chroot, not a sid chroot), your package failed to build

Bug#863926: fxt: FTBFS: Test failures

2017-06-01 Thread Lucas Nussbaum
Source: fxt Version: 0.3.2-2 Severity: serious Tags: stretch sid User: debian...@lists.debian.org Usertags: qa-ftbfs-20170601-i386 qa-ftbfs Justification: FTBFS in stretch on i386 Hi, During a rebuild of all packages in stretch (in a stretch chroot, not a sid chroot), your package failed to

Bug#801564: marked as done (squid: prompting due to modified conffiles which were not modified by the user: /etc/squid/squid.conf)

2017-06-01 Thread Debian Bug Tracking System
Your message dated Fri, 02 Jun 2017 01:04:16 + with message-id and subject line Bug#801564: fixed in squid3 3.5.23-4 has caused the Debian Bug report #801564, regarding squid: prompting due to modified conffiles which were not modified by the user: /etc/squid/squid.conf to be marked as done.

Bug#861536: runit-init: Cannot reboot or shutdown after installing (or removing) the package.

2017-06-01 Thread Michael Biebl
On Wed, 31 May 2017 13:26:36 -0400 Daniel Kahn Gillmor wrote: > I apologize for the oversight, and want to know if it'd be ok for me to > upload 2.1.2-9.2 using the attached debdiff. I've pushed a queue of > these changes into the "unstable" branch at > https://anonscm.debian.org/git/collab-main

Bug#823796: marked as done (phatch: impossible to use phatch there is just the logo that is displayed)

2017-06-01 Thread Debian Bug Tracking System
Your message dated Fri, 02 Jun 2017 00:20:21 + with message-id and subject line Bug#823796: fixed in phatch 0.2.7.1-5 has caused the Debian Bug report #823796, regarding phatch: impossible to use phatch there is just the logo that is displayed to be marked as done. This means that you claim

Bug#823796: [Python-apps-team] Bug#823796: phatch: impossible to use phatch there is just the logo that is displayed

2017-06-01 Thread Sandro Tosi
> This patch works well here. I think it is simple enough to be accepted > by the release team. I've just uploaded the fixed package. PAPT: i couldnt commit it to the svn repo because the version in there is out of sync with the reality (ie the archive): it misses -3 and -4 while it contains the

Bug#781535: unarchiving 781535, found 781535 in 3.22.3-2

2017-06-01 Thread Michael Biebl
On Fri, 02 Jun 2017 01:49:49 +0200 Andreas Beckmann wrote: > unarchive 781535 > found 781535 3.22.3-2 > thanks Andreas, can you explain why you reopened this bug report? -- Why is it that all of the instruments seeking intelligent life in the universe are pointed away from Earth? signature.

Bug#863811: marked as done (CVE-2017-5637)

2017-06-01 Thread Debian Bug Tracking System
Your message dated Fri, 02 Jun 2017 00:04:32 + with message-id and subject line Bug#863811: fixed in zookeeper 3.4.9-3 has caused the Debian Bug report #863811, regarding CVE-2017-5637 to be marked as done. This means that you claim that the problem has been dealt with. If this is not the cas

Processed: unarchiving 781535, found 781535 in 3.22.3-2

2017-06-01 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > unarchive 781535 Bug #781535 {Done: Josselin Mouette } [libgdm1] libgdm1: missing Breaks+Replaces: gdm Unarchived Bug 781535 > found 781535 3.22.3-2 Bug #781535 {Done: Josselin Mouette } [libgdm1] libgdm1: missing Breaks+Replaces: gdm Marked as

Processed: Re: gobby: fails to upgrade squeeze -> wheezy -> jessie -> stretch

2017-06-01 Thread Debian Bug Tracking System
Processing control commands: > tag -1 patch pending Bug #863680 [gobby] gobby: fails to upgrade squeeze -> wheezy -> jessie -> stretch Added tag(s) pending and patch. -- 863680: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=863680 Debian Bug Tracking System Contact ow...@bugs.debian.org with

Bug#863680: gobby: fails to upgrade squeeze -> wheezy -> jessie -> stretch

2017-06-01 Thread Andreas Beckmann
Followup-For: Bug #863680 Control: tag -1 patch pending Hi, I just uploaded the attached fix to DELAYED/2. I verified that this fixes the problematic upgrade path in piuparts. Andreas diff -Nru gobby-0.5.0/debian/changelog gobby-0.5.0/debian/changelog --- gobby-0.5.0/debian/changelog 2016-05-29

Bug#863679: could you say more about that system?

2017-06-01 Thread Vagrant Cascadian
On 2017-06-01, Adam Borowski wrote: >> In the last few days, pm-powersave is being called roughly once per >> second, which is logging to /var/log/pm-powersave.log until there's no >> disk space left. I don't think I have any custom configuration of >> pm-utils or related software. > > I'm trying t

Bug#863495: marked as done (Broken on (at least) amd64, looks in wrong path for libporg-log.so)

2017-06-01 Thread Debian Bug Tracking System
Your message dated Thu, 01 Jun 2017 22:49:09 + with message-id and subject line Bug#863495: fixed in porg 2:0.10-1.1 has caused the Debian Bug report #863495, regarding Broken on (at least) amd64, looks in wrong path for libporg-log.so to be marked as done. This means that you claim that the

Bug#863870: perl: File-Path rmtree/remove_tree race condition [CVE-2017-6512]

2017-06-01 Thread Dominic Hargreaves
On Thu, Jun 01, 2017 at 10:41:56AM +0100, Dominic Hargreaves wrote: > Similar to #286905, a new race condition has been reported in File-Path: > > https://rt.cpan.org/Public/Bug/Display.html?id=121951 > > In the rmtree() and remove_tree() functions, the chmod()logic to make > directories traversa

Bug#744753: marked as done (anacron: Anacron not triggered when system resumes under systemd)

2017-06-01 Thread Debian Bug Tracking System
Your message dated Thu, 01 Jun 2017 22:33:37 + with message-id and subject line Bug#744753: fixed in anacron 2.3-24 has caused the Debian Bug report #744753, regarding anacron: Anacron not triggered when system resumes under systemd to be marked as done. This means that you claim that the pro

Bug#767092: marked as done (anacron fails to run when laptop goes out of sleep)

2017-06-01 Thread Debian Bug Tracking System
Your message dated Thu, 01 Jun 2017 22:33:37 + with message-id and subject line Bug#744753: fixed in anacron 2.3-24 has caused the Debian Bug report #744753, regarding anacron fails to run when laptop goes out of sleep to be marked as done. This means that you claim that the problem has been

Bug#863679: could you say more about that system?

2017-06-01 Thread Adam Borowski
Control: tags -1 +moreinfo unreproducible > In the last few days, pm-powersave is being called roughly once per > second, which is logging to /var/log/pm-powersave.log until there's no > disk space left. I don't think I have any custom configuration of > pm-utils or related software. I'm trying t

Processed: could you say more about that system?

2017-06-01 Thread Debian Bug Tracking System
Processing control commands: > tags -1 +moreinfo unreproducible Bug #863679 [pm-utils] /usr/sbin/pm-powersave: repeatedly runs until /var/log/pm-powersave.log fills up disk Added tag(s) moreinfo and unreproducible. -- 863679: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=863679 Debian Bug Tr

Bug#863584: CVE-2017-2824

2017-06-01 Thread Dmitry Smirnov
On Wednesday, 31 May 2017 10:57:01 PM AEST Moritz Mühlenhoff wrote: > Dmitry, can you please upload a fix in time for the stretch release? I'm planning to work on it this weekend... I'll let you know how it goes. -- Best wishes, Dmitry Smirnov. --- The more false we destroy the more room ther

Bug#863673: [Pkg-freeradius-maintainers] Bug#863673: CVE-2017-9148: FreeRADIUS TLS resumption authentication bypass

2017-06-01 Thread Michael Stapelberg
Thanks, I agree that updating the FAQ would be good. The original question of how to proceed still stands. I sent the patch in my previous message; do you want me to upload it, or do you want to upload it? If I should do it, let me state for the record that I have no idea what I’m doing (I never u

Bug#863492: marked as done (pavuk: segmentation fault when opening graphical "Limitations" window)

2017-06-01 Thread Debian Bug Tracking System
Your message dated Thu, 01 Jun 2017 21:04:20 + with message-id and subject line Bug#863492: fixed in pavuk 0.9.35-6.1 has caused the Debian Bug report #863492, regarding pavuk: segmentation fault when opening graphical "Limitations" window to be marked as done. This means that you claim that

Bug#863906: AST-2017-004: Memory exhaustion on short SCCP packets

2017-06-01 Thread Bernhard Schmidt
Package: src:asterisk Version: 1:13.0.0~dfsg-1 Severity: critical Tags: security Asterisk Project Security Advisory - AST-2017-004 Product Asterisk Summary Memory exhaustion on short SCCP packets

Bug#863420: marked as done (timemachine: segfaults on startup)

2017-06-01 Thread Debian Bug Tracking System
Your message dated Thu, 01 Jun 2017 19:34:06 + with message-id and subject line Bug#863420: fixed in timemachine 0.3.3-2.1 has caused the Debian Bug report #863420, regarding timemachine: segfaults on startup to be marked as done. This means that you claim that the problem has been dealt with

Bug#862437: marked as done (pcsc-cyberjack: REINER SCT cyberJack pp_a2 Failed adding USB device)

2017-06-01 Thread Debian Bug Tracking System
Your message dated Thu, 01 Jun 2017 19:18:32 + with message-id and subject line Bug#819555: fixed in pcsc-cyberjack 3.99.5final.sp09-1.1 has caused the Debian Bug report #819555, regarding pcsc-cyberjack: REINER SCT cyberJack pp_a2 Failed adding USB device to be marked as done. This means tha

Bug#819555: marked as done (pcscd: cyberJack pp_a2 init failed with pcscd_1.8.16-1)

2017-06-01 Thread Debian Bug Tracking System
Your message dated Thu, 01 Jun 2017 19:18:32 + with message-id and subject line Bug#819555: fixed in pcsc-cyberjack 3.99.5final.sp09-1.1 has caused the Debian Bug report #819555, regarding pcscd: cyberJack pp_a2 init failed with pcscd_1.8.16-1 to be marked as done. This means that you claim t

Bug#819659: marked as done (pcscd: readerfactory.c:372:RFAddReader(e-com) REINER SCT cyberJack pp_a2 init failed)

2017-06-01 Thread Debian Bug Tracking System
Your message dated Thu, 01 Jun 2017 19:18:32 + with message-id and subject line Bug#819555: fixed in pcsc-cyberjack 3.99.5final.sp09-1.1 has caused the Debian Bug report #819555, regarding pcscd: readerfactory.c:372:RFAddReader(e-com) REINER SCT cyberJack pp_a2 init failed to be marked as don

Bug#862400: several bios updates exist since 2007

2017-06-01 Thread Sigun Negun
We have same problem with same hardware - HP DL380 G5. Server can't boot with 4.9 kernel from testing. It boots and is stable with 4.8 and older kernels. I think we have updated to the newest possible bios, firmware for raid card, hdd's etc. Sigunas On Fri, 19 May 2017 13:58:31 +0200 Arturo Borr

Bug#863902: AST-2017-003: Crash in PJSIP multi-part body parser

2017-06-01 Thread Bernhard Schmidt
Package: src:pjproject Version: 2.5.5~dfsg-5 Severity: critical Tags: security patch The following security advisory was published by the Asterisk project for the pjproject third party library. A patch is available. Asterisk Project Security Advisory - AST-2017-003 Prod

Bug#863901: AST-2017-002: Buffer Overrun in PJSIP transaction layer

2017-06-01 Thread Bernhard Schmidt
Package: src:pjproject Version: 2.5.5~dfsg-5 Severity: critical Tags: security patch The following security advisory has been announced by the Asterisk project for the third party pjproject library. A patch is available. Asterisk Project Security Advisory - AST-2017-002

Bug#863887: [debhelper-devel] Bug#863887: debhelper: not running autoreconf anymore with compat level 9

2017-06-01 Thread Niels Thykier
Iain Lane: > On Thu, Jun 01, 2017 at 03:23:19PM +, Gianfranco Costamagna wrote: >> Source: debhelper >> >> Version: 10.4 >> Severity: serious >> Justification: breaks compat level 9 autoreconf feature >> >> >> Hello, >> as said, using debhelper 10.4 breaks my boinc builds, >> because dh_autore

Bug#863447: [debhelper-devel] Bug#863447: dh_install -X is ignored for --list/fail-missing

2017-06-01 Thread Niels Thykier
Iain Lane: > On Sat, May 27, 2017 at 12:51:38AM +0200, Michael Biebl wrote: >> Package: debhelper >> Version: 10.4 >> Severity: normal >> >> Hi, >> >> I just tried debhelper 10.4 from experimental which implements >> dh_install --list/fail-missing via the new dh_missing tool. >> >> I don't use dh_m

Bug#863447: [debhelper-devel] Bug#863447: dh_install -X is ignored for --list/fail-missing

2017-06-01 Thread Niels Thykier
Michael Biebl: > Am 31.05.2017 um 22:23 schrieb Iain Lane: >> On Sat, May 27, 2017 at 12:51:38AM +0200, Michael Biebl wrote: >>> I also note, that usr/share/doc/NetworkManager/examples/server.conf is >>> actually installed via debian/network-manager.examples, which contains: >>> debian/tmp/usr/shar

Processed: retitle 863887 to debhelper: Broken handling of -indep/-arch override target in 10.3+ ...

2017-06-01 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > retitle 863887 debhelper: Broken handling of -indep/-arch override target in > 10.3+ Bug #863887 [src:debhelper] debhelper: not running autoreconf anymore with compat level 9 Changed Bug title to 'debhelper: Broken handling of -indep/-arch overr

Bug#801564: squid: prompting due to modified conffiles which were not modified by the user: /etc/squid/squid.conf

2017-06-01 Thread Andreas Beckmann
On 2017-05-30 09:25, Andreas Beckmann wrote: > Please upload even if you cannot fix the other RC bug properly right now ... I've filed pre-approval/unblock request #863895 and plan to NMU squid3 to DELAYED/1 if this is approved. Andreas

Processed: tagging 863886, found 863886 in 0.13-1

2017-06-01 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tags 863886 + upstream Bug #863886 [jbig2dec] jbig2dec: CVE-2016-8729 Added tag(s) upstream. > found 863886 0.13-1 Bug #863886 [jbig2dec] jbig2dec: CVE-2016-8729 Marked as found in versions jbig2dec/0.13-1. > thanks Stopping processing here. Plea

Processed: [bts-link] source package fontconfig

2017-06-01 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > # > # bts-link upstream status pull for source package fontconfig > # see http://lists.debian.org/debian-devel-announce/2006/05/msg1.html > # > user bts-link-upstr...@lists.alioth.debian.org Setting user to bts-link-upstr...@lists.alioth.debia

Processed: tagging 863884, found 863884 in 4.11.0-1

2017-06-01 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tags 863884 + upstream fixed-upstream Bug #863884 [chicken] CVE-2017-9334 Added tag(s) fixed-upstream and upstream. > found 863884 4.11.0-1 Bug #863884 [chicken] CVE-2017-9334 There is no source info for the package 'chicken' at version '4.11.0-1'

Processed: found 863884 in 4.9.0.1-1

2017-06-01 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > found 863884 4.9.0.1-1 Bug #863884 [chicken] CVE-2017-9334 There is no source info for the package 'chicken' at version '4.9.0.1-1' with architecture '' Unable to make a source version for version '4.9.0.1-1' Marked as found in versions 4.9.0.1-1

Processed: This time with correct syntax

2017-06-01 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > retitle 863892 zziplib: unsuitable for future stable releases? Bug #863892 [src:zziplib] Multiple vulnerabilities / unsuitable for stretch? Changed Bug title to 'zziplib: unsuitable for future stable releases?' from 'Multiple vulnerabilities / un

Processed (with 1 error): Splitting the zziplib vulnerabilities bug into two

2017-06-01 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > clone 854727 -1 Bug #854727 [src:zziplib] Multiple vulnerabilities / unsuitable for stretch? Bug 854727 cloned as bug 863892 > retitile -1 zziplib: unsuitable for future stable releases? Unknown command or malformed arguments to command. > tags -1

Bug#854727: Splitting the zziplib vulnerabilities bug into two

2017-06-01 Thread Adrian Bunk
clone 854727 -1 retitile -1 zziplib: unsuitable for future stable releases? tags -1 - security retitle 854727 zziplib: Multiple vulnerabilities tags 854727 - jessie-ignore stretch-ignore thanks Considering the way the discussion developed, I am splitting this bug to track two separate issues: - t

Bug#863717: marked as done (libgrpc++1: incorrect SONAME link: /usr/lib/libgrpc++_error_details.so.3)

2017-06-01 Thread Debian Bug Tracking System
Your message dated Thu, 01 Jun 2017 16:33:55 + with message-id and subject line Bug#863717: fixed in grpc 1.3.2-0.2 has caused the Debian Bug report #863717, regarding libgrpc++1: incorrect SONAME link: /usr/lib/libgrpc++_error_details.so.3 to be marked as done. This means that you claim tha

Bug#863811: CVE-2017-5637

2017-06-01 Thread Moritz Mühlenhoff
On Thu, Jun 01, 2017 at 08:17:21AM -0700, tony mancill wrote: > On Wed, May 31, 2017 at 02:45:18PM +0200, Moritz Muehlenhoff wrote: > > Source: zookeeper > > Severity: grave > > Tags: security > > > > Please see https://issues.apache.org/jira/browse/ZOOKEEPER-2693 > > > > Fix is referenced here:

Bug#863870: marked as done (perl: File-Path rmtree/remove_tree race condition [CVE-2017-6512])

2017-06-01 Thread Debian Bug Tracking System
Your message dated Thu, 01 Jun 2017 16:19:14 + with message-id and subject line Bug#863870: fixed in perl 5.24.1-3 has caused the Debian Bug report #863870, regarding perl: File-Path rmtree/remove_tree race condition [CVE-2017-6512] to be marked as done. This means that you claim that the pro

Bug#863890: postrm fails on jessie to stretch upgrade

2017-06-01 Thread Steinar H. Gunderson
Package: dblatex Version: 0.3.5-2 Severity: serious Hi, When dist-upgrading from jessie to stretch, I've seen this happen on a number of systems: Removing dblatex (0.3.5-2) ... /var/lib/dpkg/info/dblatex.postrm: 44: /var/lib/dpkg/info/dblatex.postrm: mktexlsr: not found dpkg: error processing p

Bug#863887: debhelper: not running autoreconf anymore with compat level 9

2017-06-01 Thread Iain Lane
On Thu, Jun 01, 2017 at 03:23:19PM +, Gianfranco Costamagna wrote: > Source: debhelper > > Version: 10.4 > Severity: serious > Justification: breaks compat level 9 autoreconf feature > > > Hello, > as said, using debhelper 10.4 breaks my boinc builds, > because dh_autoreconf is not run auto

Bug#863888: openjdk-8-jdk: cannot install package

2017-06-01 Thread Michael P. Soulier
Package: openjdk-8-jdk Version: 8u131-b11-1~bpo8+1 Severity: grave Justification: renders package unusable I was looking for a jdk to install, so I picked the latest jdk. msoulier@cappuccino:~$ sudo apt-get install openjdk-8-jdk Reading package lists... Done Building dependency tree Reading state

Bug#851066: flashplugin-nonfree: Mismatch between detected and available versions (Download file not available at people.debian.org)

2017-06-01 Thread Philipp Huebner
Hi, > This patch adds a new option to update-flashplugin-nonfree: > > > --using > Specifies the name of a local tar file instead of attempting to > discover and download the latest version. This file is presumed to be a tar > file downloaded by hand from Adobe.com, containing t

Processed: your mail

2017-06-01 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > found 863887 10.4 Bug #863887 [src:debhelper] debhelper: not running autoreconf anymore with compat level 9 Marked as found in versions debhelper/10.4. > severity 863887 serious Bug #863887 [src:debhelper] debhelper: not running autoreconf anymor

Bug#863811: CVE-2017-5637

2017-06-01 Thread tony mancill
On Wed, May 31, 2017 at 02:45:18PM +0200, Moritz Muehlenhoff wrote: > Source: zookeeper > Severity: grave > Tags: security > > Please see https://issues.apache.org/jira/browse/ZOOKEEPER-2693 > > Fix is referenced here: https://github.com/apache/zookeeper/pull/183 > > I'm also attaching the debdi

Bug#863886: jbig2dec: CVE-2016-8729

2017-06-01 Thread Guido Günther
Package: jbig2dec X-Debbugs-CC: t...@security.debian.org secure-testing-t...@lists.alioth.debian.org Severity: grave Tags: security Hi, the following vulnerability was published for jbig2dec. CVE-2016-8729[0]: JBIG2 Parser Code Execution Vulnerability If you fix the vulnerability please also m

Bug#863885: libterralib: superfluous Conflicts/Replaces on libterralib3 cause problems on upgrades to stretch

2017-06-01 Thread Andreas Beckmann
Package: libterralib Version: 4.3.0+dfsg.1-2 Severity: serious Tags: jessie User: debian...@lists.debian.org Usertags: piuparts Hi, during a test with piuparts I noticed upgrade problems from jessie to stretch that can be attributed to libterralib in jessie. libterralib/jessie has (unversioned)

Bug#863884: CVE-2017-9334

2017-06-01 Thread Guido Günther
Package: chicken X-Debbugs-CC: t...@security.debian.org secure-testing-t...@lists.alioth.debian.org Severity: grave Tags: security Hi, the following vulnerability was published for chicken. CVE-2017-9334[0]: | An incorrect "pair?" check in the Scheme "length" procedure results in | an unsafe po

Processed: found 863870 in perl/5.14.2-21+deb7u3

2017-06-01 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > found 863870 perl/5.14.2-21+deb7u3 Bug #863870 [perl] perl: File-Path rmtree/remove_tree race condition [CVE-2017-6512] Marked as found in versions perl/5.14.2-21+deb7u3. > thanks Stopping processing here. Please contact me if you need assistanc

Processed: tagging 805203, tagging 863567, tagging 860780

2017-06-01 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tags 805203 + patch Bug #805203 [src:granule] granule: FTBFS: DeckManager.h: fatal error: sigc++/object.h: No such file or directory Added tag(s) patch. > tags 863567 + pending Bug #863567 [rmail] rmail: unable to install because of unmet depende

Bug#854884: baloo: is this obsoleted by src:baloo-kf5?

2017-06-01 Thread Andreas Beckmann
On Thu, 01 Jun 2017 09:01:34 +0200 Pino Toscano wrote: > src:kdepim4, which provides ktimetracker and knode, requires the old > baloo libraries. Patching that source honestly requires more work than > what is worth spending. If only the libraries are still needed, could the binary package baloo4

Bug#863541: marked as done (vblade-persist: depends on runit, which is about to be removed)

2017-06-01 Thread Debian Bug Tracking System
Your message dated Thu, 1 Jun 2017 12:07:36 +0200 with message-id <20170601100736.vcllt2hhsl7iu...@angband.pl> and subject line Re: Bug#863542: depends on runit not runit-init has caused the Debian Bug report #863541, regarding vblade-persist: depends on runit, which is about to be removed to be ma

Bug#863539: marked as done (cereal: depends on runit, which is about to be removed)

2017-06-01 Thread Debian Bug Tracking System
Your message dated Thu, 1 Jun 2017 12:07:36 +0200 with message-id <20170601100736.vcllt2hhsl7iu...@angband.pl> and subject line Re: Bug#863542: depends on runit not runit-init has caused the Debian Bug report #863539, regarding cereal: depends on runit, which is about to be removed to be marked as

Bug#863543: marked as done (git-daemon-run: depends on runit, which is about to be removed)

2017-06-01 Thread Debian Bug Tracking System
Your message dated Thu, 1 Jun 2017 12:07:36 +0200 with message-id <20170601100736.vcllt2hhsl7iu...@angband.pl> and subject line Re: Bug#863542: depends on runit not runit-init has caused the Debian Bug report #863543, regarding git-daemon-run: depends on runit, which is about to be removed to be ma

Processed: bug 863870 is forwarded to https://rt.cpan.org/Public/Bug/Display.html?id=121951

2017-06-01 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > forwarded 863870 https://rt.cpan.org/Public/Bug/Display.html?id=121951 Bug #863870 [perl] perl: File-Path rmtree/remove_tree race condition [CVE-2017-6512] Set Bug forwarded-to-address to 'https://rt.cpan.org/Public/Bug/Display.html?id=121951'.

Processed: set versions/tags

2017-06-01 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tags 863870 + security Bug #863870 [perl] perl: File-Path rmtree/remove_tree race condition [CVE-2017-6512] Added tag(s) security. > found 863870 5.24.1-2 Bug #863870 [perl] perl: File-Path rmtree/remove_tree race condition [CVE-2017-6512] Marke

Bug#863416: marked as done (jackeq: segmentation fault)

2017-06-01 Thread Debian Bug Tracking System
Your message dated Thu, 01 Jun 2017 09:49:59 + with message-id and subject line Bug#863416: fixed in jackeq 0.5.9-2.1 has caused the Debian Bug report #863416, regarding jackeq: segmentation fault to be marked as done. This means that you claim that the problem has been dealt with. If this is

Bug#863421: marked as done (kluppe: segfaults when pressing 'new looper')

2017-06-01 Thread Debian Bug Tracking System
Your message dated Thu, 01 Jun 2017 09:50:09 + with message-id and subject line Bug#863421: fixed in kluppe 0.6.20-1.1 has caused the Debian Bug report #863421, regarding kluppe: segfaults when pressing 'new looper' to be marked as done. This means that you claim that the problem has been dea

Processed: tagging 863870

2017-06-01 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tags 863870 + fixed-upstream Bug #863870 [perl] perl: File-Path rmtree/remove_tree race condition [CVE-2017-6512] Added tag(s) fixed-upstream. > thanks Stopping processing here. Please contact me if you need assistance. -- 863870: http://bugs.d

Bug#863870: perl: File-Path rmtree/remove_tree race condition [CVE-2017-6512]

2017-06-01 Thread Dominic Hargreaves
Package: perl Version: 5.26.0~rc1-1 Severity: critical Justification: privilege escalation in library code Similar to #286905, a new race condition has been reported in File-Path: https://rt.cpan.org/Public/Bug/Display.html?id=121951 In the rmtree() and remove_tree() functions, the chmod()logic

Bug#863676: marked as done (libcaf-mpi1: missing Breaks+Replaces: libcoarrays0d (<< 1.8.10))

2017-06-01 Thread Debian Bug Tracking System
Your message dated Thu, 01 Jun 2017 09:33:57 + with message-id and subject line Bug#863676: fixed in open-coarrays 1.9.0-1 has caused the Debian Bug report #863676, regarding libcaf-mpi1: missing Breaks+Replaces: libcoarrays0d (<< 1.8.10) to be marked as done. This means that you claim that t

Bug#827122: marked as done (liboasis3-0d: libpsmile.so is a broken symbolic link to libpsmile.MPI1.so.0d)

2017-06-01 Thread Debian Bug Tracking System
Your message dated Thu, 01 Jun 2017 09:04:34 + with message-id and subject line Bug#827122: fixed in oasis3 3.mct+dfsg.121022-9 has caused the Debian Bug report #827122, regarding liboasis3-0d: libpsmile.so is a broken symbolic link to libpsmile.MPI1.so.0d to be marked as done. This means th

Processed: This should clearly be RC

2017-06-01 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > severity 842882 serious Bug #842882 [jp2a] jp2a: Version 1.0.7 improper to be released Severity set to 'serious' from 'important' > thanks Stopping processing here. Please contact me if you need assistance. -- 842882: http://bugs.debian.org/cgi-

Processed: tagging 863447

2017-06-01 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tags 863447 + patch Bug #863447 [debhelper] dh_install -X is ignored for --list/fail-missing Added tag(s) patch. > thanks Stopping processing here. Please contact me if you need assistance. -- 863447: http://bugs.debian.org/cgi-bin/bugreport.cgi

Bug#863829: python2: dolfin 'module' object has no attribute 'cpp'

2017-06-01 Thread Johannes Ring
On Wed, May 31, 2017 at 6:37 PM, Drew Parsons wrote: > Weird, the new python3 module seems to have broken the python2 dolfin > module. That's not good. > > Importing dolfin gives the error: > AttributeError: 'module' object has no attribute 'cpp' The problem is that the Python 2 modules for dolf

Bug#863707: simple-tpm-pk11: FTBFS: ./m4/test-driver: line 107: 4695 Aborted (core dumped)

2017-06-01 Thread Michael Stapelberg
Thomas, here are the steps to reproduce using docker. They should be easily transferrable to a VM: % docker run -t -i debian:sid /bin/bash root# echo deb-src http://deb.debian.org/debian sid main >> /etc/apt/sources.list root# apt update root# apt build-dep simple-tpm-pk11 root# apt source simple-

Bug#863673: [Pkg-freeradius-maintainers] Bug#863673: CVE-2017-9148: FreeRADIUS TLS resumption authentication bypass

2017-06-01 Thread Salvatore Bonaccorso
Hi On Thu, Jun 01, 2017 at 08:54:57AM +0200, Michael Stapelberg wrote: > I got the idea from https://www.debian.org/security/faq#upload. Is the FAQ > outdated, or did I read it wrong? If the latter, please elaborate so that > we can update the docs to be more clear. The idea behind that FAQ entry

Bug#854884: #854884: baloo: is this obsoleted by src:baloo-kf5?

2017-06-01 Thread Pino Toscano
In data giovedì 1 giugno 2017 14:28:58 CEST, Boyuan Yang ha scritto: > In my understanding, perhaps baloo4 is completely useless in Debian Stretch > with Plasma 5. Why don't we remove it from unstable/testing *now*? src:kdepim4, which provides ktimetracker and knode, requires the old baloo librar