Bug#931255: Update in stable?

2019-08-29 Thread Christoph Haas
I would like to see this simple fix in Buster. Without it the package is nearly unusable in my opinion. Do you think the release team would agree? …Christoph

Bug#651225: Security vulnerabilities (CVE-2011-2904, CVE-2011-3263, CVE-2011-3265, CVE-2011-4674)

2012-03-18 Thread Christoph Haas
I have received a very simple patch from the upstream developers (perhaps) fixing just a minor issue regarding one of the several reported security issues. I'm giving up here trying to get a security patch. There are way too many changes across the versions and upstream doesn't have resources to f

Bug#652664: Upstream is on it

2012-01-05 Thread Christoph Haas
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 I have talked to my contact at the upstream company. He is bugging the developers to help backport the security fix. No reply yet. …Christoph -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.11 (GNU/Linux) Comment: Using GnuPG with Mozilla - http://e

Bug#651225: Concerning hobbits…

2012-01-01 Thread Christoph Haas
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 I have talked to the upstream developers and they are still evaluating (within their means) whether a decent backported patch for 1.8.2 can be provided. They have pointed me to using the newer version instead that has the security flaws fixed. And I ha

Bug#652664: Status on security issues

2011-12-19 Thread Christoph Haas
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 http://security-tracker.debian.org/tracker/CVE-2011-2904 I have extracted a patch using svn diff -r r20742:r20789 frontends/php/acknow.php from the upstream sources. http://security-tracker.debian.org/tracker/CVE-2011-3263 I have extracted a patch usi

Bug#652664: CVE-2011-4615

2011-12-19 Thread Christoph Haas
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Sorry for the missing reaction. I'm still alive and currently figuring out a minimal patch for the reported security issues. Expect a fresh upload to unstable and a patch for the Squeeze version. Whether a patch for Lenny can be created is currently be

Bug#637451: Duplicate

2011-08-28 Thread Christoph Haas
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 You did not quite give a lot of information regarding the problem. I can just guess but will probably guess wrong. Please explain what you did exactly, what happened and what you expected to happen instead. Thanks. -BEGIN PGP SIGNATURE- Version

Bug#577661: Status of DSPAM in Debian

2011-03-27 Thread Christoph Haas
time now, which makes me >>> confident for the future. >>> >> >> Experimental is experimental after all :-) > > ;) > >> Also, most of the DSPAM uploaders are MIA. Well, I think all are MIA except >> Christoph Haas. Could you please update the list in your upload? Sam

Bug#610015: zabbix-frontend-php: Renaming screens removes all graphs within

2011-01-14 Thread Christoph Haas
Package: zabbix-frontend-php Version: 1.8.2 Severity: grave Tags: squeeze Justification: causes non-serious data loss The current 1.8.2 package to be shipped with Squeeze is suffering from this issue: https://support.zabbix.com/browse/ZBX-2329 Renaming a screen causes all graphs defined in that s

Bug#609726: zabbix: Insufficient information for Lenny->Squeeze database upgrade

2011-01-11 Thread Christoph Haas
Package: zabbix Version: 1.8 Severity: grave Tags: squeeze Justification: renders package unusable The 1.8 package just contains information to upgrade the database schema used by the 1.6 package. Lenny however used the 1.4 version and there was accidentally no database upgrade path from 1.4->1.8.

Bug#597375: bsc: canceling move-operation removes source folder

2010-10-19 Thread Christoph Haas
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Am 19.10.2010 13:15, schrieb Julien Cristau: > On Mon, Sep 20, 2010 at 23:07:26 +0200, Christoph Haas wrote: > >> I understand that this behavior was not what you expected. And I'm on >> your side that the "Break" bu

Bug#597375: bsc: canceling move-operation removes source folder

2010-09-20 Thread Christoph Haas
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 I understand that this behavior was not what you expected. And I'm on your side that the "Break" button should actually do something instead of just waiting for the operation to finish halfway and lose everything that should have been moved after press

Bug#594304: CVE-2010-2790: Multiple cross-site scripting (XSS) vulnerabilities

2010-08-25 Thread Christoph Haas
Thanks for the bug report. I'm currently preparing a 1.8.3 package and will contact the release team. Maybe we can get 1.8.3 into Squeeze then. Cheers Christoph -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lis

Bug#532392: Downgrading works

2009-06-09 Thread Christoph Haas
Just dropping a note that a downgrade of the "ghostscript" package from 8.64~dfsg-6 to 8.64~dfsg-1.1 solved this problem here. Christoph -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#528164: FTBFS: reference to 'exception' is ambiguous

2009-05-11 Thread Christoph Haas
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Martin Michlmayr schrieb: > * Christoph Haas [2009-05-11 22:34]: >> Upstream proposed a fix to what seems to have to do with the recent >> 'boost' upgrade. I have prepared a package that should fix it. But I >> do

Bug#528164: FTBFS: reference to 'exception' is ambiguous

2009-05-11 Thread Christoph Haas
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Martin Michlmayr schrieb: > Package: pdns-recursor > Version: 3.1.7-3 > Severity: serious > > This package fails to build in unstable: > >> Automatic build of pdns-recursor_3.1.7-3 on em64t by sbuild/amd64 0.53 > ... >> g++ -Wall -g -Wall -DBOOST_SP_

Bug#493742: Bug#461087: python-babel: package name conflict?

2008-09-23 Thread Christoph Haas
On Dienstag, 23. September 2008, Raphael Hertzog wrote: > On Thu, 07 Aug 2008, Christoph Haas wrote: > > > For now and the lenny release, it seems we need to make the packages > > > conflict. > > > > In favor. > > Why has this not yet been done ? > >

Bug#493742: Bug#461087: python-babel: package name conflict?

2008-08-06 Thread Christoph Haas
gt; is nothing now, at least no Debian packages)? IMHO you would have to alter the setup.py. The setuptools are creating the EGG-INFO directory automatically. Might be better to have the upstream do this. setuptools can be beasty. > On Thu, 2008-08-07 at 00:05 +0200, Christoph Haas wrote:

Bug#493742: Bug#461087: python-babel: package name conflict?

2008-08-06 Thread Christoph Haas
On Mittwoch, 6. August 2008, Adam C Powell IV wrote: > On Sun, 2008-08-03 at 15:30 +0200, Christoph Haas wrote: > > We talked about the python-babel name clash recently. Although I > > renamed my package to "python-pybabel" we seem to have a problem here. > > As lo

Bug#493576: pdns-server: CVE-2008-3217 ( PowerDNS Recursor before 3.1.6 does not always use the strongest random number generator... )

2008-08-03 Thread Christoph Haas
On Sonntag, 3. August 2008, Thomas Bläsing wrote: > the following CVE (Common Vulnerabilities & Exposures) id was > published for pdns-server. Not exactly - the CVE was assigned to the pdns-recursor package. pdns-server and pdns-recursor are seperate packages. I have added the CVE to pdns-recurs

Bug#491830: trac-mercurial: Can't synchronize with the repository / Repository checkins event provider (ChangesetModule) failed

2008-07-22 Thread Christoph Haas
Package: trac-mercurial Version: 0.11.0.5dev~svnr7354-1 Severity: grave Justification: renders package unusable It appears like the 0.11.05dev version of the the trac-mercurial package isn't working at all here. I get this warning on every page: Warning: Can't synchronize with the repository

Bug#459799: driftnet: doesn't build anymore

2008-02-15 Thread Christoph Haas
Hi, Steev... On Fri, Feb 15, 2008 at 12:06:17PM -0600, Steev Klimaszewski wrote: > I wrote you a while back, since I am the maintainer of driftnet in > Gentoo. We also have a bug open about this - specifically, > Gentoo bug #192627. > > http://bugs.gentoo.org/show_bug.cgi?id=192627 > > There

Bug#459799: driftnet: doesn't build any more

2008-01-08 Thread Christoph Haas
Package: driftnet Version: 0.1.6-7 Severity: grave Justification: renders package unusable Unfortunately the package doesn't build anymore. First it went in circles looking for stdarg.h. So I added this to the Makefile: # DEBIAN: dirty hack to make the Makefile find the stdarg.h GCC_VERSION = `/u

Bug#422221: nscd fails to install (incorrectly indented comments in nscd.conf)

2007-05-04 Thread Christoph Haas
Package: nscd Version: 2.5-5 Severity: grave Justification: renders package unusable The package does not install here: Unpacking nscd (from .../archives/nscd_2.5-5_i386.deb) ... Setting up nscd (2.5-5) ... Starting Name Service Cache Daemon: nscd/usr/sbin/nscd: Parse error: /usr/sbin/nscd: Unkn

Bug#420067: python-pudge: Installation failed (SyntaxError)

2007-04-19 Thread Christoph Haas
Package: python-pudge Version: 0.1.3~svn134-1 Severity: grave Justification: renders package unusable Installing python-pudge fails if python2.3 is still installed: Unpacking python-pudge (from .../python-pudge_0.1.3~svn134-1_all.deb) ... Setting up python-pudge (0.1.3~svn134-1) ... INFO: using o

Bug#418098: Seconded - it works

2007-04-16 Thread Christoph Haas
Just wanted to stop by and say that the patch fixed the trouble here, too. However the problem appeared only on systems with NVidia graphic cards when using the Xinerama extension. The problem did not appear on single-monitor setups. I hope the fixed version will make it into Etch. Christoph s

Bug#419042: zabbix-frontend-php: cannot create hosts in web interface with pgsql backend

2007-04-13 Thread Christoph Haas
Package: zabbix-frontend-php Version: 1:1.1.4-10 Severity: grave Justification: renders package unusable I logged into the web interface, created a host and submitted the form. Then I got this output: Warning: pg_exec() [function.pg-exec]: Query failed

Bug#406465: [bind backend] TXT record parsing overflow with special characters

2007-02-16 Thread Christoph Haas
Update: upstream says it's not a serious security issue in his opinion. He intends to release a fix this weekend anyway. Christoph -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Bug#406465: [bind backend] TXT record parsing overflow with special characters

2007-02-16 Thread Christoph Haas
On Friday 16 February 2007 13:57, Jeroen van Wolffelaar wrote: > On Sat, Feb 10, 2007 at 11:13:11AM +0100, Jeroen van Wolffelaar wrote: > > An option, therefore, is to have a pdns uploaded without the bind > > backend, and a NEWS.Debian stating that "sorry, no bind backend > > available, because it

Bug#325522: libweather-com-perl: package should live in contrib

2005-08-29 Thread Christoph Haas
On Mon, Aug 29, 2005 at 10:01:38AM +0200, Gerfried Fuchs wrote: > From reading your package description I wonder: > > ,---> quote <--- > | Notice: To use the weather.com's service you have to register at > | weather.com first. > `---

Bug#322352: Fixed the debian/rules to properly remove upstream's debian/ files

2005-08-28 Thread Christoph Haas
As said before the upstream distributes his own debian/ directory. We tried to remove it in the "clean:" target. However that wasn't run always before building the package. So we now moved it to the "build:" target. The fixed package will be uploaded to stable-proposed-updates. -- To UNSUBSCRIBE

Bug#322352: pdns and pdns-doc both contain /usr/share/doc-base/pdns (sarge security update version)

2005-08-22 Thread Christoph Haas
On Mon, Aug 22, 2005 at 12:01:48PM +0200, Martin Schulze wrote: > Christoph Haas wrote: > > process. We aren't happy that the upstream was shipping a debian/ > > directory along with the tarball and this might well be the cause that > > the build broke. > > I

Bug#322352: pdns and pdns-doc both contain /usr/share/doc-base/pdns (sarge security update version)

2005-08-21 Thread Christoph Haas
On Tue, Aug 16, 2005 at 12:06:48PM +0200, Jeremie Koenig wrote: > I've not tested anything but I may have found the cause for this > problem. Freshly extracted, the source package contains some cruft which > gets removed upon running debian/rules clean. Specifically, > [...] > pdns-2.9.17/deb

Bug#322352: pdns and pdns-doc both contain /usr/share/doc-base/pdns (sarge security update version)

2005-08-16 Thread Christoph Haas
On Tue, Aug 16, 2005 at 10:23:41AM +0200, Martin Schulze wrote: > That is very strange. I've just rebuilt it on gluck > (see /tmp/joey for log and packages) and it does still contain > the doc-base directory. I was too slow for /tmp/joey. :( Matthijs suspected that it might have to do with gluck

Bug#322352: pdns and pdns-doc both contain /usr/share/doc-base/pdns (sarge security update version)

2005-08-15 Thread Christoph Haas
Hi, Martin... On Sat, Aug 13, 2005 at 07:09:02AM +0200, Martin Schulze wrote: > Please retry in the sarge chroot on gluck or escher. I've just > rebuilt it in both environments and both times the pdns_*.deb > contained both /usr/share/doc/pdns and /usr/share/doc-base/pdns, > while the package in

Bug#308967: pdns-recursor: syntax error in init.d script

2005-05-13 Thread Christoph Haas
On Fri, May 13, 2005 at 07:42:51PM +0200, root wrote: > Previously Christoph Haas wrote: > > This has been fixed in the revision 2.9.17-12 already. Please upgrade. > > Thanks for your report though. > > Since sarge is frozen and you uploaded only to unstable I fear that >

Bug#308967: pdns-recursor: syntax error in init.d script

2005-05-13 Thread Christoph Haas
close 308967 thanks > Package: pdns-recursor > Version: 2.9.17-11 > Severity: serious > > The restart target in the init.d script has a nasty typo. It currently > says: > > if [ "$START" |= "yes" ]; then > > that probably should be "!=". This has been fixed in the revision 2.9.17-12 alre