Bug#988428: [debian-mysql] Bug#988428: mariadb-10.5: CVE-2021-2154 CVE-2021-2166

2021-05-13 Thread Otto Kekäläinen
Hello! Status summary: * MariaDB 10.5 for Debian is pending at https://salsa.debian.org/mariadb-team/mariadb-10.5/ since last weekend but still waiting for contributions on https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=988089, #976147 and #977137. * MariaDB 10.3 for Debian is pending at http

Bug#987279: closing 987279

2021-05-13 Thread Salvatore Bonaccorso
close 987279 1.4.6+really1.4.2-2 thanks

Processed: closing 987279

2021-05-13 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > close 987279 1.4.6+really1.4.2-2 Bug #987279 [src:nim] nim: amd64 binaries built by maintainer; needs source-ony upload Marked as fixed in versions nim/1.4.6+really1.4.2-2. Bug #987279 [src:nim] nim: amd64 binaries built by maintainer; needs sour

Bug#988292: closed by Debian FTP Masters (reply to Andreas Henriksson ) (Bug#988292: fixed in gnome-sound-recorder 3.38.1-1)

2021-05-13 Thread Sophie Herold
If I am not mistaken, this is a release critical bug. Is there a fix for testing on the way as well? On Do, Mai 13, 2021 at 16:51, Debian Bug Tracking System wrote: This is an automatic notification regarding your Bug report which was filed against the gnome-sound-recorder package: #98829

Bug#957233: marked as done (freefem++: ftbfs with GCC-10)

2021-05-13 Thread Debian Bug Tracking System
Your message dated Thu, 13 May 2021 22:04:17 + with message-id and subject line Bug#957233: fixed in freefem++ 3.61.1+dfsg1-6 has caused the Debian Bug report #957233, regarding freefem++: ftbfs with GCC-10 to be marked as done. This means that you claim that the problem has been dealt with.

Bug#987353: CVE-2020-8903 CVE-2020-8907 CVE-2020-8933

2021-05-13 Thread Marcin Kulisz
On 2021-05-10 12:16:09, Noah Meyerhans wrote: > On Mon, May 10, 2021 at 09:00:34PM +0200, Moritz Mühlenhoff wrote: > > > Hi, since this package was brought into Debian in ~2018, there have been > > > several transformations in the GCE guest software stack and thus the > > > current landscape is ver

Bug#988480: pydantic: CVE-2021-29510

2021-05-13 Thread Salvatore Bonaccorso
Source: pydantic Version: 1.7.3-1 Severity: grave Tags: security upstream X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerability was published for pydantic. Note, strictly speaking the severity is slightly choosen inaproritate for the type of security issue. Makin

Bug#988477: xen-hypervisor-4.14-amd64: xen dmesg shows (XEN) AMD-Vi: IO_PAGE_FAULT on sata pci device

2021-05-13 Thread Imre Szőllősi
Package: src:xen Version: 4.14.1+11-gb0b734a8b3-1 Severity: critical Justification: causes serious data loss X-Debbugs-Cc: debian...@virtualzone.hu Dear Maintainer, after a clean install of bullseye/testing the xen dmesg shows the following message: (XEN) AMD-Vi: IO_PAGE_FAULT: :01:00.1 d0 a

Bug#988394: thunar: CVE-2021-32563

2021-05-13 Thread Salvatore Bonaccorso
Hi Yves-Alexis, On Thu, May 13, 2021 at 07:05:37PM +0200, Yves-Alexis Perez wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > On Tue, 2021-05-11 at 21:45 +0200, Salvatore Bonaccorso wrote: > > The following vulnerability was published for thunar. > > > > CVE-2021-32563[0]: > > > An

Bug#988394: marked as done (thunar: CVE-2021-32563)

2021-05-13 Thread Debian Bug Tracking System
Your message dated Thu, 13 May 2021 18:33:31 + with message-id and subject line Bug#988394: fixed in thunar 4.16.8-1 has caused the Debian Bug report #988394, regarding thunar: CVE-2021-32563 to be marked as done. This means that you claim that the problem has been dealt with. If this is not

Processed: [bts-link] source package src:nekobee

2021-05-13 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > # > # bts-link upstream status pull for source package src:nekobee > # see http://lists.debian.org/debian-devel-announce/2006/05/msg1.html > # https://bts-link-team.pages.debian.net/bts-link/ > # > user debian-bts-l...@lists.debian.org Set

Processed: [bts-link] source package solo-python

2021-05-13 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > # > # bts-link upstream status pull for source package solo-python > # see http://lists.debian.org/debian-devel-announce/2006/05/msg1.html > # https://bts-link-team.pages.debian.net/bts-link/ > # > user debian-bts-l...@lists.debian.org Set

Bug#988394: thunar: CVE-2021-32563

2021-05-13 Thread Yves-Alexis Perez
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Tue, 2021-05-11 at 21:45 +0200, Salvatore Bonaccorso wrote: > The following vulnerability was published for thunar. > > CVE-2021-32563[0]: > > An issue was discovered in Thunar before 4.16.7 and 4.17.x before > > 4.17.2. When called with a regula

Bug#988292: marked as done (gnome-sound-recorder: Potential data loss and regression (recordings not saved or unusable))

2021-05-13 Thread Debian Bug Tracking System
Your message dated Thu, 13 May 2021 16:48:30 + with message-id and subject line Bug#988292: fixed in gnome-sound-recorder 3.38.1-1 has caused the Debian Bug report #988292, regarding gnome-sound-recorder: Potential data loss and regression (recordings not saved or unusable) to be marked as do

Bug#984760: grub-pc: upgrade works, boot fails (error: symbol `grub_is_lockdown` not found)

2021-05-13 Thread Sunil Mohan Adapa
On Thu, 15 Apr 2021 23:00:22 -0700 Sunil Mohan Adapa wrote: > Hi, > > The problem is not limited to amd64. I see this problem on arm64. On a > FreedomBox arm64 image, on a Raspberry Pi 3B+ (when booted with UEFI > firmware[1]) when grub efi packages are upgraded, boot fails with the > error 'symb

Bug#984967: GHB build bulls-eye

2021-05-13 Thread andrew glaeser
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 This is the missing part for Debian-11 bulls-eye: > andrew@bulls-eye:~/HandBrake$ ate show libayatana-appindicator-dev > Package: libayatana-appindicator-dev > Version: 0.5.5-2 > State: installed > Automatically installed: no > Priority: optiona

Bug#984956: marked as done (openmpi-bin: with mpirun --host : orte crashes with FORCE-TERMINATE [...] plm_base_launch_support.c)

2021-05-13 Thread Debian Bug Tracking System
Your message dated Thu, 13 May 2021 14:33:30 + with message-id and subject line Bug#984956: fixed in openmpi 4.1.0-9 has caused the Debian Bug report #984956, regarding openmpi-bin: with mpirun --host : orte crashes with FORCE-TERMINATE [...] plm_base_launch_support.c to be marked as done. T

Bug#988463: marked as done (crashes on startup with X11)

2021-05-13 Thread Debian Bug Tracking System
Your message dated Thu, 13 May 2021 16:03:14 +0200 with message-id <8a27d1fe-4437-28ea-3240-8f4aed1f4...@debian.org> and subject line Closing the bug has caused the Debian Bug report #988463, regarding crashes on startup with X11 to be marked as done. This means that you claim that the problem has

Bug#988463: crashes on startup with X11

2021-05-13 Thread Ole Streicher
Package: gnome-control-center Version: 1:3.38.4-1 Severity: serious X-Debbugs-Cc: oleb...@debian.org Dear maintainer, when starting gnome-control-center, I get a crash with the following stacktrace: (gdb) bt #0 0x750d3b79 in _cogl_renderer_handle_native_event (renderer=0x0, event=0x7fff

Bug#988462: trac: not ready for Debian 11

2021-05-13 Thread Martin
Package: trac Version: 1.5.2+dfsg-2 Severity: serious IMHO, the current version of Trac is not suitable for including it in a stable release. I'll try to provide backports of future version 1.6.x for Debian 11.

Processed: Re: [pkg-go] Bug#988328: golang-github-pquerna-cachecontrol: FTBFS in tests constant 9223372036854775807 overflows int

2021-05-13 Thread Debian Bug Tracking System
Processing control commands: > severity -1 important Bug #988328 [src:golang-github-pquerna-cachecontrol] golang-github-pquerna-cachecontrol: FTBFS in tests constant 9223372036854775807 overflows int Severity set to 'important' from 'serious' -- 988328: https://bugs.debian.org/cgi-bin/bugrepor

Bug#988328: [pkg-go] Bug#988328: golang-github-pquerna-cachecontrol: FTBFS in tests constant 9223372036854775807 overflows int

2021-05-13 Thread Ritesh Raj Sarraf
ControL: severity -1 important On Thu, 2021-05-13 at 12:43 +0100, peter green wrote: > The package is arch all. > > While I don't think it's explicitly spelled out anywhere, my > understanding > is that it has never been a requirement for arch all packages to > build > on all architectures. So IM

Bug#988328: [pkg-go] Bug#988328: golang-github-pquerna-cachecontrol: FTBFS in tests constant 9223372036854775807 overflows int

2021-05-13 Thread peter green
During a rebuild of the package, it is seen that the package fails in one of the tests, commonly on 32 bit systems. So far, I can see it fails on armhf and i386. The package is arch all. While I don't think it's explicitly spelled out anywhere, my understanding is that it has never been a r

Bug#987587: libpango1.0-udeb: hangs the installer in various situations

2021-05-13 Thread Simon McVittie
On Tue, 04 May 2021 at 15:47:03 +0200, Cyril Brulebois wrote: > would it seem reasonable to add a hack in whatever would make sense > (pango1.0, harfbuzz, and/or gtk+2.0), but only in the udeb build, so > that we dodge the issue for Bullseye without impacting installed > systems/deb packages? If gi

Bug#988289: htmldoc: CVE-2019-19630

2021-05-13 Thread Utkarsh Gupta
Hi Håvard, On Wed, May 12, 2021 at 9:05 PM Håvard Flaget Aasen wrote: > Thanks for the sponsoring Utkarsh! You're very welcome! :) > I made a package for stretch as well, and uploaded it to mentors. [0] > Though I'm not sure about this lts stuff. So far this package I made > just targets "stret

Bug#987537: RM: scrollz -- RoQA unmaintained, dead upstream, has security issues

2021-05-13 Thread Adrian Bunk
On Mon, May 03, 2021 at 07:58:06AM +0200, Tobias Frost wrote: >... > > I don't actually know the procedures for a security update, in any case. > > so if anyone has advice on next steps, I'd appreciate it. > > https://www.debian.org/doc/manuals/developers-reference/pkgs.html#bug-security > and > h

Processed: Re: Bug#975270: rdiff-backup: Can't talk to the version from buster

2021-05-13 Thread Debian Bug Tracking System
Processing control commands: > severity -1 serious Bug #975270 [rdiff-backup] rdiff-backup: Can't talk to the version from buster Severity set to 'serious' from 'important' -- 975270: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=975270 Debian Bug Tracking System Contact ow...@bugs.debian.or

Bug#988326: libboost-python-dev: Linking against boost_python requires the python version number ex: -lboost_python39

2021-05-13 Thread Dimitri John Ledkov
Hi, On Mon, 10 May 2021 at 16:09, Grégory David wrote: > > Package: libboost-python-dev > Version: 1.74.0.3 > Severity: grave > Justification: renders package unusable > X-Debbugs-Cc: d...@groolot.net > > Dear Maintainer, > >* What led up to the situation? > When I try to compile `mididi

Bug#984956: Pmix issues with openmpi-4.1.0

2021-05-13 Thread Alastair McKinstry
See in part the discussion upstream at : https://github.com/open-mpi/ompi/issues/8596 One workaround might be to use the internal pmix. 4.1.0-4 worked, and using the internal pmix works, BUT reverting to using internal pmix has big testing consequences: We'd move libpmix.so.2 from the extern

Processed: block 988440 with 988444 988445

2021-05-13 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > block 988440 with 988444 988445 Bug #988440 [src:golang-github-seccomp-containers-golang] golang-github-seccomp-containers-golang: Keep out of bookworm 988440 was not blocked by any bugs. 988440 was not blocking any bugs. Added blocking bug(s) of

Processed: retitle 988440 to golang-github-seccomp-containers-golang: Keep out of bookworm

2021-05-13 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > retitle 988440 golang-github-seccomp-containers-golang: Keep out of bookworm Bug #988440 [src:golang-github-seccomp-containers-golang] Keep out of bookwork Changed Bug title to 'golang-github-seccomp-containers-golang: Keep out of bookworm' from

Bug#988440: Keep out of bookwork

2021-05-13 Thread Laurent Bigonville
Source: golang-github-seccomp-containers-golang Version: 0.3.2-1 Severity: serious Tags: bookworm sid Hello, golang-github-seccomp-containers-golang is now deprecated upstream and has been replaced by containers-common This package should be removed of the archive when the rdeps updated to not d

Bug#988439: slurm-wlm: CVE-2021-31215

2021-05-13 Thread Salvatore Bonaccorso
Source: slurm-wlm Version: 20.11.5-1 Severity: grave Tags: security upstream Justification: user security hole X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerability was published for slurm-wlm. CVE-2021-31215[0]: | SchedMD Slurm before 20.02.7 and 20.03.x through