Bug#1035542: libreswan: CVE-2023-30570: Incorrect aggressive mode interaction causes the pluto daemon to crash

2023-06-02 Thread Salvatore Bonaccorso
Hi Daniel, On Fri, Jun 02, 2023 at 06:59:35PM -0400, Daniel Kahn Gillmor wrote: > Hi Salvatore-- > > On Fri 2023-06-02 21:20:50 +0200, Salvatore Bonaccorso wrote: > > Thanks for having a closer look and for your assessment. Then I > > believe we can have a fix scheduled via respective point relea

Bug#1037064: maven-verifier depends on downloading sources at build time

2023-06-02 Thread Steve Langasek
Source: maven-verifier Version: 1.8.0-1 Severity: serious Justification: package in main has dependency on external software User: ubuntu-de...@lists.ubuntu.com Usertags: origin-ubuntu mantic Dear maintainers, maven-verifier 1.8.0-1 has been failing to build in Ubuntu, because its build-time test

Bug#1035542: marked as done (libreswan: CVE-2023-30570: Incorrect aggressive mode interaction causes the pluto daemon to crash)

2023-06-02 Thread Debian Bug Tracking System
Your message dated Fri, 02 Jun 2023 23:04:29 + with message-id and subject line Bug#1035542: fixed in libreswan 4.10-2+deb12u1 has caused the Debian Bug report #1035542, regarding libreswan: CVE-2023-30570: Incorrect aggressive mode interaction causes the pluto daemon to crash to be marked as

Bug#1035542: libreswan: CVE-2023-30570: Incorrect aggressive mode interaction causes the pluto daemon to crash

2023-06-02 Thread Daniel Kahn Gillmor
Hi Salvatore-- On Fri 2023-06-02 21:20:50 +0200, Salvatore Bonaccorso wrote: > Thanks for having a closer look and for your assessment. Then I > believe we can have a fix scheduled via respective point releases, I > do not see an urgency for it requiring a DSA. Initially I was not > completely sur

Bug#1023741: marked as done (raspi-firmware: Please transfer brcmfmac43456-sdio.* files to firmware-brcm80211 package)

2023-06-02 Thread Debian Bug Tracking System
Your message dated Sat, 03 Jun 2023 00:23:08 +0200 with message-id <8225857.T7Z3S40VBb@bagend> and subject line Close bugs I'm no longer interested in has caused the Debian Bug report #1023741, regarding raspi-firmware: Please transfer brcmfmac43456-sdio.* files to firmware-brcm80211 package to be

Bug#1035542: marked as done (libreswan: CVE-2023-30570: Incorrect aggressive mode interaction causes the pluto daemon to crash)

2023-06-02 Thread Debian Bug Tracking System
Your message dated Fri, 02 Jun 2023 22:22:12 + with message-id and subject line Bug#1035542: fixed in libreswan 4.11-1 has caused the Debian Bug report #1035542, regarding libreswan: CVE-2023-30570: Incorrect aggressive mode interaction causes the pluto daemon to crash to be marked as done.

Bug#1036755: linux-image-6.1.0-9-amd64: Android ROM build on Debian breaks with the 6.1.0-9-amd64 kernel

2023-06-02 Thread Infant V Patrick
Package: src:linux Version: 6.1.27-1 Followup-For: Bug #1036755 X-Debbugs-Cc: infant...@yahoo.com Dear Maintainer, *** Reporter, please consider answering these questions, where appropriate *** * What led up to the situation? Doing Android build of a custom ROM using Debian unstable

Bug#1037052: minidlna: CVE-2023-33476

2023-06-02 Thread Salvatore Bonaccorso
Source: minidlna Version: 1.3.2+dfsg-1 Severity: grave Tags: security upstream X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerability was published for minidlna. CVE-2023-33476[0]: | ReadyMedia (MiniDLNA) versions from 1.1.15 up to 1.3.2 is vulnerable | to Buffer

Bug#1036959: marked as done (rasdaemon: invalid Maintainer field)

2023-06-02 Thread Debian Bug Tracking System
Your message dated Fri, 02 Jun 2023 20:33:53 + with message-id and subject line Bug#1036959: fixed in rasdaemon 0.6.8-1.1 has caused the Debian Bug report #1036959, regarding rasdaemon: invalid Maintainer field to be marked as done. This means that you claim that the problem has been dealt wi

Bug#1036071: fixed in gsl 2.7.1+dfsg-4

2023-06-02 Thread Dirk Eddelbuettel
On 2 June 2023 at 20:57, Paul Gevers wrote: | Hi Dirk, | | On 02-06-2023 20:38, Dirk Eddelbuettel wrote: | > | Are you sure? I just diffed the source to see if I should unblock and | > | got this: | > | > I would appear I did NOT add that one line to debian/control !! Doh !! | > | > Shall I p

Bug#1036959: rasdaemon: invalid Maintainer field

2023-06-02 Thread Cyril Brulebois
Control: tag -1 patch pending Mattia Rizzolo (2023-05-30): > v0.6.8-1 of this package has this in d/control: > > Maintainer: Russell Coker , Taihsiang Ho > > > This is against Policy as there should only be one entity in this field. > > > Also, as you noticed, this confused DDPO (actual

Processed: Re: Bug#1036959: rasdaemon: invalid Maintainer field

2023-06-02 Thread Debian Bug Tracking System
Processing control commands: > tag -1 patch pending Bug #1036959 [src:rasdaemon] rasdaemon: invalid Maintainer field Added tag(s) pending and patch. -- 1036959: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1036959 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems

Bug#1000293: marked as done (Problems starting jackd: Method RequestRelease is not implemented on interface org.freedesktop.ReserveDevice1)

2023-06-02 Thread Debian Bug Tracking System
Your message dated Fri, 2 Jun 2023 21:46:29 +0200 with message-id and subject line Re: Bug#1000293: Problems starting jackd: Method RequestRelease is not implemented on interface org.freedesktop.ReserveDevice1 has caused the Debian Bug report #1000293, regarding Problems starting jackd: Method Re

Processed: tagging 1035474, retitle 1035474 to Don't include in trixie?

2023-06-02 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tags 1035474 + trixie - bookworm Bug #1035474 [src:libdmx] Don't include in Bookworm? Added tag(s) trixie. Bug #1035474 [src:libdmx] Don't include in Bookworm? Removed tag(s) bookworm. > retitle 1035474 Don't include in trixie? Bug #1035474 [src:l

Bug#967166: marked as done (lvtk: Unversioned Python removal in sid/bullseye)

2023-06-02 Thread Debian Bug Tracking System
Your message dated Fri, 02 Jun 2023 19:31:36 + with message-id and subject line Bug#107: Removed package(s) from unstable has caused the Debian Bug report #967166, regarding lvtk: Unversioned Python removal in sid/bullseye to be marked as done. This means that you claim that the problem h

Bug#943113: marked as done (lvtk: Python2 removal in sid/bullseye)

2023-06-02 Thread Debian Bug Tracking System
Your message dated Fri, 02 Jun 2023 19:31:36 + with message-id and subject line Bug#107: Removed package(s) from unstable has caused the Debian Bug report #943113, regarding lvtk: Python2 removal in sid/bullseye to be marked as done. This means that you claim that the problem has been dea

Bug#1035574: marked as done (ams.lv2: FTBFS because of 'U' mode)

2023-06-02 Thread Debian Bug Tracking System
Your message dated Fri, 02 Jun 2023 19:31:06 + with message-id and subject line Bug#1035575: Removed package(s) from unstable has caused the Debian Bug report #1035574, regarding ams.lv2: FTBFS because of 'U' mode to be marked as done. This means that you claim that the problem has been dealt

Bug#984008: marked as done (cbmc: ftbfs with GCC-11)

2023-06-02 Thread Debian Bug Tracking System
Your message dated Fri, 02 Jun 2023 19:21:03 + with message-id and subject line Bug#984008: fixed in cbmc 5.84.0-1 has caused the Debian Bug report #984008, regarding cbmc: ftbfs with GCC-11 to be marked as done. This means that you claim that the problem has been dealt with. If this is not t

Bug#1006919: marked as done (src:cbmc FTBFS)

2023-06-02 Thread Debian Bug Tracking System
Your message dated Fri, 02 Jun 2023 19:21:03 + with message-id and subject line Bug#984008: fixed in cbmc 5.84.0-1 has caused the Debian Bug report #984008, regarding src:cbmc FTBFS to be marked as done. This means that you claim that the problem has been dealt with. If this is not the case i

Bug#1035542: libreswan: CVE-2023-30570: Incorrect aggressive mode interaction causes the pluto daemon to crash

2023-06-02 Thread Salvatore Bonaccorso
Hi Daniel, On Thu, Jun 01, 2023 at 05:19:06PM -0400, Daniel Kahn Gillmor wrote: > Control: found 1035542 4.3-1+deb11u3 > Control: tags 1035542 + patch > > Thanks for the documentation of CVE-2023-30570 on > https://bugs.debian.org/1035542, Salvatore. > > fwiw, i don't think this is particularly

Bug#1035871: flare-engine: broken symlink: /usr/share/games/flare/mods/default/fonts/unifont-10.0.06.ttf -> ../../../../../fonts/truetype/unifont/unifont.ttf

2023-06-02 Thread James Addison
Followup-For: Bug #1035871 X-Debbugs-Cc: elb...@debian.org [ not a maintainer, but I have tested the behaviour of this bug ] On Thu, 1 Jun 2023 11:57:46 +0200, Paul wrote: > On Wed, 10 May 2023 13:54:11 +0200 Andreas Beckmann wrote: > > fonts-unifont does no longer ship unifont.ttf or other *.tt

Bug#1036071: fixed in gsl 2.7.1+dfsg-4

2023-06-02 Thread Paul Gevers
Hi Dirk, On 02-06-2023 20:38, Dirk Eddelbuettel wrote: | Are you sure? I just diffed the source to see if I should unblock and | got this: I would appear I did NOT add that one line to debian/control !! Doh !! Shall I prepare a -5 ? If that can happen this evening, then yes. I expect you on

Bug#1036259: moment-timezone.js: FTBFS in testing: make[1]: *** [debian/rules:28: execute_before_dh_auto_configure] Error 1

2023-06-02 Thread Martina Ferrari
Update: I have just uploaded the package, force-pushed my changes to master, and submitted the unblock request: #1037049 On 02/06/2023 19:13, Martina Ferrari wrote: On Sun, 28 May 2023 18:15:14 +0200 gregor herrmann wrote: On Sun, 28 May 2023 20:05:09 +0400, Yadd wrote: > > This looked re

Bug#1036071: fixed in gsl 2.7.1+dfsg-4

2023-06-02 Thread Dirk Eddelbuettel
On 2 June 2023 at 20:19, Paul Gevers wrote: | Hi Dirk, | | On Mon, 15 May 2023 03:04:06 + Debian FTP Masters | wrote: | > gsl (2.7.1+dfsg-4) unstable; urgency=medium | > . | >* debian/control: Add explicit 'Breaks: libgsl25' (with thanks to | > Andreas Beckmann for the suggestio

Bug#1036259: marked as done (moment-timezone.js: FTBFS in testing: make[1]: *** [debian/rules:28: execute_before_dh_auto_configure] Error 1)

2023-06-02 Thread Debian Bug Tracking System
Your message dated Fri, 02 Jun 2023 18:34:05 + with message-id and subject line Bug#1036259: fixed in moment-timezone.js 0.5.40+dfsg-1+2023c has caused the Debian Bug report #1036259, regarding moment-timezone.js: FTBFS in testing: make[1]: *** [debian/rules:28: execute_before_dh_auto_configu

Processed: Bug#1036259 marked as pending in moment-timezone.js

2023-06-02 Thread Debian Bug Tracking System
Processing control commands: > tag -1 pending Bug #1036259 [src:moment-timezone.js] moment-timezone.js: FTBFS in testing: make[1]: *** [debian/rules:28: execute_before_dh_auto_configure] Error 1 Added tag(s) pending. -- 1036259: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1036259 Debian B

Bug#1036259: marked as pending in moment-timezone.js

2023-06-02 Thread Martina Ferrari
Control: tag -1 pending Hello, Bug #1036259 in moment-timezone.js reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/js-team/moment-timezone.js/-/commit/f497c97574

Bug#1036259: moment-timezone.js: FTBFS in testing: make[1]: *** [debian/rules:28: execute_before_dh_auto_configure] Error 1

2023-06-02 Thread Martina Ferrari
On Sun, 28 May 2023 18:15:14 +0200 gregor herrmann wrote: On Sun, 28 May 2023 20:05:09 +0400, Yadd wrote: > > This looked reasonably easy to fix (cf. attached patch), but the > > tests fail as follows: > I fixed it in salsa (needs an update to import 2023 data). I'm waiting for > Martina review

Bug#1036071: fixed in gsl 2.7.1+dfsg-4

2023-06-02 Thread Paul Gevers
Hi Dirk, On Mon, 15 May 2023 03:04:06 + Debian FTP Masters wrote: gsl (2.7.1+dfsg-4) unstable; urgency=medium . * debian/control: Add explicit 'Breaks: libgsl25' (with thanks to Andreas Beckmann for the suggestion) (Closes: #1036071) Are you sure? I just diffed th

Processed: your mail

2023-06-02 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > severity 1037043 important Bug #1037043 [pink-pony] pink-pony crashes on start Severity set to 'important' from 'grave' > thanks Stopping processing here. Please contact me if you need assistance. -- 1037043: https://bugs.debian.org/cgi-bin/bugr

Bug#1037043: (no subject)

2023-06-02 Thread Judit Foglszinger
severity 1037043 important thanks Hi, seems, it only crashes with libsdl1.2-compat-shim installed, so not for everyone and the submitter is ok with downgrading it to important to keep pink ponies in bookworm one week before the release.

Bug#1037043: pink-pony crashes on start

2023-06-02 Thread Jakub Wilk
* Jakub Wilk , 2023-06-02 18:49: ii libsdl1.2-compat-shim [libsdl1.2debian] 1.2.60-1 Looks like it crashes only if libsdl1.2-compat-shim is installed. -- Jakub Wilk

Bug#1037043: pink-pony crashes on start

2023-06-02 Thread Jakub Wilk
Package: pink-pony Version: 1.4.1-3.1 Severity: grave pink-pony crashes on start: $ pink-pony malloc(): corrupted top size Aborted Or sometimes: $ pink-pony Segmentation fault Or: $ pink-pony Fatal glibc error: malloc assertion failure in _int_malloc: (unsigned long) (s

Processed: Re: Bug#1037041: linux-image-6.1.0-9-amd64: Spurious failures from mmap(MAP_32BIT)

2023-06-02 Thread Debian Bug Tracking System
Processing control commands: > forcemerge 1036755 -1 Bug #1036755 {Done: Salvatore Bonaccorso } [src:linux] linux: 6.1.26 <= x < 6.1.30 breaks applications using mmap(MAP_32BIT) Bug #1037041 [src:linux] linux-image-6.1.0-9-amd64: Spurious failures from mmap(MAP_32BIT) Set Bug forwarded-to-addres

Processed: Re: Bug#1035542: libreswan: CVE-2023-30570: Incorrect aggressive mode interaction causes the pluto daemon to crash

2023-06-02 Thread Debian Bug Tracking System
Processing control commands: > found 1035542 4.3-1+deb11u3 Bug #1035542 [src:libreswan] libreswan: CVE-2023-30570: Incorrect aggressive mode interaction causes the pluto daemon to crash Ignoring request to alter found versions of bug #1035542 to the same values previously set > tags 1035542 + pa

Bug#1035542: libreswan: CVE-2023-30570: Incorrect aggressive mode interaction causes the pluto daemon to crash

2023-06-02 Thread Daniel Kahn Gillmor
Control: found 1035542 4.3-1+deb11u3 Control: tags 1035542 + patch Thanks for the documentation of CVE-2023-30570 on https://bugs.debian.org/1035542, Salvatore. fwiw, i don't think this is particularly serious -- the vulnerability only appears to be dangerous if the libreswan endpoint is configur

Bug#1037035: FTBFS due to tests relying on running redis server

2023-06-02 Thread Shengjing Zhu
Source: beaker Version: 1.12.1-1 Severity: serious Tags: ftbfs patch X-Debbugs-Cc: z...@debian.org The tests need a running redis server. I suggests ignore it just like the mongodb one. Please see the patch. diff -Nru beaker-1.12.1/debian/changelog beaker-1.12.1/debian/changelog --- beaker-1.12.

Processed: clang-7-dbgsym: missing /usr/share/doc/clang-7-dbgsym -> clang-7

2023-06-02 Thread Debian Bug Tracking System
Processing control commands: > found -1 7.0.1-8~deb9u2 Bug #1037033 [clang-7-dbgsym] clang-7-dbgsym: missing /usr/share/doc/clang-7-dbgsym -> clang-7 Warning: Unknown package 'clang-7-dbgsym' There is no source info for the package 'clang-7-dbgsym' at version '7.0.1-8~deb9u2' with architecture '

Bug#1037033: clang-7-dbgsym: missing /usr/share/doc/clang-7-dbgsym -> clang-7

2023-06-02 Thread Andreas Beckmann
Package: clang-7-dbgsym Version: 1:7.0.1-8~deb9u3 Severity: serious User: debian...@lists.debian.org Usertags: piuparts Control: found -1 7.0.1-8~deb9u2 Control: fixed -1 7.0.1-8+deb10u1 Control: close -1 7.0.1-9 Hi, during a test with piuparts I noticed your package misses the /usr/share/doc/cla

Bug#1031046: Asterisk packaging

2023-06-02 Thread Olivier
Hello, I lately discovered this thread. I volunteer to help to package Asterisk either in current official Debian repo or in an alternative repository. The perspectives of Asterisk Deb packaging is talked about in [1] (I'm the original author of this thread). One thing that comes to mind readin

Bug#1004805: marked as done (xmms2: FTBFS with ffmpeg 5.0)

2023-06-02 Thread Debian Bug Tracking System
Your message dated Fri, 02 Jun 2023 08:34:15 + with message-id and subject line Bug#1004805: fixed in xmms2 0.8+dfsg-23 has caused the Debian Bug report #1004805, regarding xmms2: FTBFS with ffmpeg 5.0 to be marked as done. This means that you claim that the problem has been dealt with. If th