Bug#711590: nginx-naxsi-ui: fails to install: preinst called with unknown argument `install'

2013-06-08 Thread Cyril Lavier
On 06/08/2013 10:25 AM, Andreas Beckmann wrote: > Package: nginx-naxsi-ui > Version: 1.4.1-2 > Severity: serious > User: debian...@lists.debian.org > Usertags: piuparts > > Hi, > > during a test with piuparts I noticed your package failed to install. As > per definition of the release team this mak

Bug#708164: nginx proxy_pass buffer overflow (CVE-2013-2070)

2013-06-05 Thread Cyril Lavier
On 05/13/2013 09:15 PM, Florian Weimer wrote: > * Thijs Kinkhorst: > >> A buffer overflow in the proxy_pass module has been reported by >> Nginx upstream, and a patch made available. Please see: >> http://www.openwall.com/lists/oss-security/2013/05/13/3 >> >> The issue is already fixed in the versi

Bug#707291: nginx-common: prompting due to modified conffiles which were not modified by the user

2013-05-13 Thread Cyril Lavier
Hello Andreas. Thanks for this report. I completely messed up the last update on the naxsi-ui part. I'm deeply sorry for this and I'm currently working on an update. If it goes well, it should arrive on wednesday. Thanks. -- Cyril "Davromaniak" Lavier KeyID 59E9A881 http://www.davromaniak.eu

Bug#700426: vulnerable to CRIME SSL attack (CVE-2012-4929)

2013-02-13 Thread Cyril LAVIER
Le 2013-02-13 15:36, Thijs Kinkhorst a écrit : Hi Cyril, On Wed, February 13, 2013 14:55, Cyril LAVIER wrote: Thanks for this report. I think we have to include this patch in the nginx packages (stable and unstable). I don't actually know if you already prepared an upload, so I did i

Bug#700426: vulnerable to CRIME SSL attack (CVE-2012-4929)

2013-02-13 Thread Cyril LAVIER
Le 2013-02-12 16:27, Thijs Kinkhorst a écrit : Package: nginx Version: 0.7.67-3 Severity: grave Tags: security patch Hi, nginx in squeeze and wheezy is vulnerable to the SSL attack CVE-2012-4929 dubbed 'CRIME'. The attack is related to SSL compression. The popular solution to the attack is t

Bug#678060: Configuration should be purged in nginx-common

2012-06-19 Thread Cyril Lavier
On 06/18/2012 10:35 PM, Jeroen Dekkers wrote: > Package: nginx > Version: 1.2.0-1 > Severity: serious > Tags: patch > > The nginx-light, nginx-full and nginx-naxsi packages delete the > /etc/nginx and /var/log directory when they are purged, but the > configuration files are owned by nginx-common.

Bug#666115: ruby-passenger: FTBFS with NGINX on hurd-i386

2012-03-28 Thread Cyril Lavier
Package: ruby-passenger Version: 3.0.11 Severity: serious Justification: fails to build from source Dear Maintainer, I tested the nginx 1.1.18 build under hurd-i386, and here is the error log for nginx-passenger : (in /root/compile/nginx-1.1.18/debian/modules/ruby-passenger) mkdir -p ext/common

Bug#662697: nginx-extras: Package removes nginx.conf and other config files on upgrade.

2012-03-17 Thread Cyril Lavier
On 03/10/2012 06:59 PM, Kartik Mistry wrote: On Sat, Mar 10, 2012 at 6:29 PM, Cyril Lavier wrote: I just tried to upgrade nginx-extras to 1.1.16-1 on my debian Sid machine, and I didn't had this issue. Could you explain us clearly what you did to upgrade nginx-extras ? To the

Bug#664212: nginx: debian/rules file is using dpkg-buildflags without defining build-dependency on dpkg-dev (>= 1.15.7)

2012-03-16 Thread Cyril Lavier
On 03/16/2012 07:09 PM, Laurent Bigonville wrote: Package: nginx Version: 1.1.14-1 Severity: serious Hi, debian/rules file is using dpkg-buildflags. This tool has been introduced in dpkg 1.15.7, but the package is not defining any build-dependency on this version of dpkg. The build is not fail

Bug#664137: [CVE-2012-1180] nginx fix for malformed HTTP responses from upstream servers

2012-03-15 Thread Cyril Lavier
On 03/15/2012 09:34 PM, Cyril Lavier wrote: On 03/15/2012 09:28 PM, Luciano Bello wrote: On Thursday 15 March 2012, Cyril Lavier wrote: The 1.1.17 will be uploaded tomorrow, we already done the needed test for the upload (build and functionality). Great! Can you check if stable is affected

Bug#664137: [CVE-2012-1180] nginx fix for malformed HTTP responses from upstream servers

2012-03-15 Thread Cyril Lavier
On 03/15/2012 09:28 PM, Luciano Bello wrote: On Thursday 15 March 2012, Cyril Lavier wrote: The 1.1.17 will be uploaded tomorrow, we already done the needed test for the upload (build and functionality). Great! Can you check if stable is affected? The bug looks quite important. Do you think

Bug#664137: [CVE-2012-1180] nginx fix for malformed HTTP responses from upstream servers

2012-03-15 Thread Cyril Lavier
On 03/15/2012 08:54 PM, Luciano Bello wrote: Package: nginx Severity: grave Tags: security patch The following vulnerability had been reported against nginx: http://seclists.org/oss-sec/2012/q1/644 The patch can be found in the report. Please use CVE-2012-1180 for this issue. Can you check if

Bug#662697: nginx-extras: Package removes nginx.conf and other config files on upgrade.

2012-03-10 Thread Cyril Lavier
On 03/05/2012 09:43 PM, Gasper Zejn wrote: Package: nginx-extras Version: 1.1.16-1 Severity: grave Justification: renders package unusable Dear Maintainer, while upgrading (via apt-get upgrade), the package removes its configuration files. -- System Information: Debian Release: wheezy/sid

Bug#659820: audacious FTBFS on sparc with ICE

2012-02-17 Thread Cyril LAVIER
Le 13.02.2012 23:07, peter green a écrit : Source: audacious Version: 3.2-1 Severity: serious Tags: patch Justification: fails to build from source (but built successfully in the past) audacious FTBFS on sparc with an internal compiler error. This has been reported to the gcc maintainers at http

Bug#657592: A patch seems to be available.

2012-01-27 Thread Cyril LAVIER
Hi. After some research a patch seems to be available for having XMP working with audacious 3.2. It's available here : http://pkgs.fedoraproject.org/gitweb/?p=xmp.git;a=blob_plain;f=xmp-3.4.0-audacious-3.1.patch;h=250ae80a04c53e0aeedc9a5483a637039754b7f5;hb=HEAD This patch was made for the

Bug#657596: wmauda: FTBFS with audacious 3.2

2012-01-27 Thread Cyril Lavier
Package: wmauda Version: 0.7-5 Severity: serious Justification: fails to build from source (but built successfully in the past) Dear Maintainer, Audacious was recently updated with the 3.2 release, and now wmauda doesn't build anymore. Here is the build log : CFLAGS="-Wall -g -O2" /usr/bin/mak

Bug#657592: xmp: FTBFS with audacious 3.2

2012-01-27 Thread Cyril Lavier
Source: xmp Version: 3.4.0-1 Severity: serious Justification: fails to build from source (but built successfully in the past) Dear Maintainer, Audacious was recently updated with the 3.2 release, and now, XMP doesn't build anymore. I also tried with the 3.4.1 upstream version, and the build als