Bug#929781: rkt: CVE-2019-10144 CVE-2019-10145 CVE-2019-10147

2019-06-18 Thread Dmitry Smirnov
On Wednesday, 19 June 2019 1:10:03 AM AEST Moritz Muehlenhoff wrote: > On Tue, Jun 18, 2019 at 05:35:55PM +1000, Dmitry Smirnov wrote: > > I would reclassify those vulnerabilities with lesser severity to avoid > > removal from Buster. > > That's certainly possible, but there's still the bigger iss

Bug#929283: marked as done (zookeeper: CVE-2019-0201: information disclosure vulnerability)

2019-06-18 Thread Debian Bug Tracking System
Your message dated Tue, 18 Jun 2019 21:51:05 + with message-id and subject line Bug#929283: fixed in zookeeper 3.4.9-3+deb9u2 has caused the Debian Bug report #929283, regarding zookeeper: CVE-2019-0201: information disclosure vulnerability to be marked as done. This means that you claim that

Bug#930276: marked as done (vlc: multiple vulnerabilities fixed in 3.0.7 release)

2019-06-18 Thread Debian Bug Tracking System
Your message dated Tue, 18 Jun 2019 21:50:15 + with message-id and subject line Bug#930276: fixed in vlc 3.0.7-0+deb9u1 has caused the Debian Bug report #930276, regarding vlc: multiple vulnerabilities fixed in 3.0.7 release to be marked as done. This means that you claim that the problem has

Bug#930693: ksh: previous versions have the info

2019-06-18 Thread Greg Wooledge
Having ksh removed from buster is definitely not my preferred outcome. Getting one line added to the copyright file would be ideal, but if that's not allowed, then I can live with "fixed after buster".

Bug#929877: installation-reports: Buster installer hangs at hard disk step with arabic language

2019-06-18 Thread Holger Wansing
Hi, Samuel Thibault wrote: > Hello, > > Holger Wansing, le mar. 04 juin 2019 20:59:12 +, a ecrit: > > Am Sonntag, 2. Juni 2019 schrieb Holger Wansing: > > > Am Sonntag, 2. Juni 2019 schrieb Samuel Thibault: > > > > ButterflyOfFire, le dim. 02 juin 2019 15:43:41 +, a ecrit: > > > > > >> "

Bug#929781: rkt: CVE-2019-10144 CVE-2019-10145 CVE-2019-10147

2019-06-18 Thread Paul Gevers
Hi On Tue, 18 Jun 2019 17:10:03 +0200 Moritz Muehlenhoff wrote: > On Tue, Jun 18, 2019 at 05:35:55PM +1000, Dmitry Smirnov wrote: > > I would reclassify those vulnerabilities with lesser severity to avoid > > removal from Buster. > > That's certainly possible, but there's still the bigger issue

Bug#930321: php-horde-form: diff for NMU version 2.0.18-3.1

2019-06-18 Thread Salvatore Bonaccorso
Hi Mathieu, On Tue, Jun 18, 2019 at 10:03:21PM +0200, Mathieu Parent wrote: > Le dim. 16 juin 2019 à 17:48, Salvatore Bonaccorso a > écrit : > > > > Control: tags 930321 + pending > > > > Hi Mathieu, > > > > I've prepared an NMU for php-horde-form (versioned as 2.0.18-3.1) and > > uploaded it to

Bug#930321: php-horde-form: diff for NMU version 2.0.18-3.1

2019-06-18 Thread Mathieu Parent
Le dim. 16 juin 2019 à 17:48, Salvatore Bonaccorso a écrit : > > Control: tags 930321 + pending > > Hi Mathieu, > > I've prepared an NMU for php-horde-form (versioned as 2.0.18-3.1) and > uploaded it to DELAYED/2. Please feel free to tell me if I > should cancel it or feel free to override it with

Bug#929588: usat: source tarballs are missing the source of the configure script

2019-06-18 Thread baddlci
Hello, I am the author of the lsat tool, version 0.9.8.6 I have a new release out today. it is on the github site, also on the main homepage which is http://www.dimlight.org/lsat and it is also on the old sourceforge, but I try not to use that. The autoconfig should be fixed and includes the conf

Bug#930693: ksh: previous versions have the info

2019-06-18 Thread Neil Williams
I'm not sure this warrants being RC. It's a result of a reformatting of debian/copyright when previous versions had the information available: https://tracker.debian.org/media/packages/k/ksh/copyright-93u%2B20120801-1 "It was downloaded from http://www.research.att.com/sw/download"; It's not as

Bug#930321: marked as done (php-horde-form: CVE-2019-9858)

2019-06-18 Thread Debian Bug Tracking System
Your message dated Tue, 18 Jun 2019 19:14:05 + with message-id and subject line Bug#930321: fixed in php-horde-form 2.0.18-3.1 has caused the Debian Bug report #930321, regarding php-horde-form: CVE-2019-9858 to be marked as done. This means that you claim that the problem has been dealt with

Bug#930693: ksh: no Source field in copyright file

2019-06-18 Thread Greg Wooledge
Package: ksh Version: 93u+20120801-3.4 Severity: serious Justification: Policy 12.5 There is no Source field, nor any other information saying where the upstream sources were obtained, in the copyright file. -- System Information: Debian Release: 10.0 APT prefers testing APT policy: (500, 'te

Bug#929781: rkt: CVE-2019-10144 CVE-2019-10145 CVE-2019-10147

2019-06-18 Thread Moritz Muehlenhoff
On Tue, Jun 18, 2019 at 05:35:55PM +1000, Dmitry Smirnov wrote: > I would reclassify those vulnerabilities with lesser severity to avoid > removal from Buster. That's certainly possible, but there's still the bigger issue that the projects seems unmaintained. None of the developers even acknowled

Processed (with 1 error): forcibly merging 805711 929834

2019-06-18 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > forcemerge 805711 929834 Bug #805711 [light-locker] light-locker, lightdm: screen stays off after resume Bug #846278 [light-locker] light-locker, lightdm: screen stays off after resume Bug #870641 [light-locker] light-locker, lightdm: screen stays

Bug#902959: pluginhook: diff for NMU version 0~20150216.0~a320158-2.1

2019-06-18 Thread Ondrej Novy
Hi, uploaded to DELAYED/10-day Thanks. -- Best regards Ondřej Nový

Processed: enhancing the severity of bug #930672

2019-06-18 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > severity #930672 grave Bug #930672 {Done: Georges Khaznadar } [geophar] geophar: Please fix the bug with the obsoleted class FigureCanvasQTAggBase Severity set to 'grave' from 'important' > thanks Stopping processing here. Please contact me if y

Processed: found 930676 in 0.9.1+nmu1, tagging 930676

2019-06-18 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > found 930676 0.9.1+nmu1 Bug #930676 [goplay] goplay: Should this package be removed? Marked as found in versions goplay/0.9.1+nmu1. > tags 930676 + sid buster Bug #930676 [goplay] goplay: Should this package be removed? Added tag(s) sid and buster

Bug#930682: debian-xcontrol: Remove from archive?

2019-06-18 Thread Julian Andres Klode
Package: debian-xcontrol Version: 0.0.4-1.1 Severity: serious There do not seem to be any users of debian-xcontrol left, and the last update was 9 years ago, so time to let it go? Also FTBFS with latest apt (in binary-NEW/experimental). -- System Information: Debian Release: buster/sid APT pre

Bug#929187: marked as done (libbpf soversion does not match the package name)

2019-06-18 Thread Debian Bug Tracking System
Your message dated Tue, 18 Jun 2019 10:52:03 + with message-id and subject line Bug#929187: fixed in linux 4.19.37-4 has caused the Debian Bug report #929187, regarding libbpf soversion does not match the package name to be marked as done. This means that you claim that the problem has been d

Bug#930676: goplay: Should this package be removed?

2019-06-18 Thread Julian Andres Klode
Package: goplay Severity: serious Hi folks, goplay has not received any updates since 2015, it uses libept, which we'd like to get rid of eventually I think, as it's also unmaintained, so I think it would be best to remove it. -- System Information: Debian Release: buster/sid APT prefers eoan

Bug#864320: [RFC] Changing the default cursor on the Linux console?

2019-06-18 Thread Robert Schindler
Hello, I've got low vision as well and don't like the blinking cursor either. I'm using gnome-terminal most of the time and find the big, blinking cursor quite nice. Maybe a non-blinking cursor might catch less attention, especially when you're in some kind of ncurses UI, maybe even one with a cha

Bug#929781: rkt: CVE-2019-10144 CVE-2019-10145 CVE-2019-10147

2019-06-18 Thread Dmitry Smirnov
On Monday, 17 June 2019 6:02:50 AM AEST Shengjing Zhu wrote: > On Sun, Jun 16, 2019 at 11:47 PM Shengjing Zhu wrote: > > So I would suggest we remove rkt from buster. Personally I wouldn't do that but rules are rules so whatever... It is reasonable to assume that application containers are not p

Bug#928214: marked as done (mingw-w64 GCC is built without linker plugin support making LTO unusable)

2019-06-18 Thread Debian Bug Tracking System
Your message dated Tue, 18 Jun 2019 07:18:34 + with message-id and subject line Bug#928214: fixed in gcc-mingw-w64 21.3 has caused the Debian Bug report #928214, regarding mingw-w64 GCC is built without linker plugin support making LTO unusable to be marked as done. This means that you claim

Processed: severity of 928214 is serious

2019-06-18 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > severity 928214 serious Bug #928214 [gcc-mingw-w64] mingw-w64 GCC is built without linker plugin support making LTO unusable Severity set to 'serious' from 'normal' > thanks Stopping processing here. Please contact me if you need assistance. --