Bug#999659: perdition: failed to install, failed to uninstall (error in initscript)

2021-11-14 Thread Sergey Spiridonov
Package: perdition Version: 2.2-3.1+b1 Severity: grave Justification: renders package unusable X-Debbugs-Cc: s...@s73.work Dear Maintainer, The error happens only on first install of the perdition, see instructions below on how to reproduce it. First I get an error during # apt install perdit

Bug#927775: monit: CVE-2019-11454 CVE-2019-11455

2019-06-17 Thread Sergey B Kirpichev
On Wed, 12 Jun 2019 17:07:11 +0200 Ivo De Decker wrote: > As the security team considers this an issue that needs to be fixed for > buster, I'm increasing the severity. Please do not downgrade it again. Thanks for "help", security team. > Note that the revert Paul mentioned in #930313 I don't u

Bug#927775: monit: CVE-2019-11454 CVE-2019-11455

2019-06-09 Thread Sergey B Kirpichev
severity 927775 important thanks No reasons, so revert back severity. On Tue, 4 Jun 2019 08:00:43 +0300 Sergey B Kirpichev wrote: > On Tue, 23 Apr 2019 06:53:03 +0200 Salvatore Bonaccorso > wrote: > > CVE-2019-11454[0]: > > | Persistent cross-site scripting (XSS) in

Bug#927775: monit: CVE-2019-11454 CVE-2019-11455

2019-06-03 Thread Sergey B Kirpichev
On Tue, 23 Apr 2019 06:53:03 +0200 Salvatore Bonaccorso wrote: > CVE-2019-11454[0]: > | Persistent cross-site scripting (XSS) in http/cervlet.c in Tildeslash > | Monit before 5.25.3 allows a remote unauthenticated attacker to > | introduce arbitrary JavaScript via manipulation of an unsanitized u

Bug#923609: Binary incompatibility in libgdbm6

2019-03-10 Thread Sergey Poznyakoff
Hi Dmitry, > Thank you, Sergey. Does incompatibility goes other way too, that version > without LFS support is incapable of reading file, created with LFS > version? Yes, as the accompanying NOTE-WARNING file says: Gdbm files have never been `portable' between different oper

Bug#923609: Binary incompatibility in libgdbm6

2019-03-05 Thread Sergey Poznyakoff
--disable-largefile flag and it will be able to read the file. Regards, Sergey

Bug#906499: parser-mysql: FTBFS in buster/sid (aclocal-1.15: command not found)

2018-09-12 Thread Sergey B Kirpichev
-10.7/ && env PATH="/usr/sbin:/usr/bin:/sbin:/bin" HOME="/nonexistent" dpkg-buildpackage -us -uc -rfakeroot dpkg-buildpackage: warning: using a gain-root-command while being root dpkg-buildpackage: info: source package parser-mysql dpkg-buildpackage: info: source v

Bug#904366: mailutils-config and the mailutils tool are unusable in 1:3.4-1

2018-07-23 Thread Sergey Poznyakoff
per: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=541458. Perhaps it's worth reporting to cdbs hackers. Anyway, adding DEB_CONFIGURE_LIBEXECDIR = \$${prefix}/lib to the debian/rules will fix this as well (obviously the paths in the attached file should be changed accordingly).

Bug#900399: memtest86+: very probably kills system controller on Lenovo Thinkpad T500 laptop

2018-05-30 Thread Sergey Kogan
Package: memtest86+ Version: 5.01-3 Severity: critical Justification: breaks the whole system Hi! There is a situation I belive should be reported ASAP. We have two Lenovo T500 laptops completely dead after an overnight testing with memtest86+. Notebooks do not power on, and even do not show up th

Bug#873539: monit 1:5.23.0-3 won't install - "epoch in version is empty"

2017-08-28 Thread Sergey B Kirpichev
On Tue, Aug 29, 2017 at 01:24:27AM +0200, Vincent Lefevre wrote: > > dpkg-maintscript-helper: error: dpkg: error: version '"1:5.15-1~"' has bad > > syntax: epoch in version is empty Looks like regression in dpkg-maintscript-helper: quotation marks were passed to dpkg --validate-version. C.f. #

Bug#867032: jabberd2 allowing anyone to authenticate using SASL ANONYMOUS, even when the option is not enabled

2017-07-03 Thread Sergey Korobitsin
Package: jabberd2 Version: 2.4.0-3 Severity: grave Tags: security Justification: user security hole During investigation of some issue on my local jabber server I've found plenty of records like these in my c2s.log: Mon Jul 3 20:06:21 2017 [notice] [150] ANONYMOUS authentication succeeded: bf71

Bug#864705: [plasma-desktop] "KDE Menu"/"Alt+F2" runner don't work if "Focus stealing prevention" set "High" or "Extream" and any window focused

2017-06-12 Thread Sergey Nikitin
Package: plasma-desktop Version: 4:5.8.6-1 Severity: critical --- Please enter the report below this line. --- If you set System settings->Window Management->Window Behavior: "Click To Focus" and "Focus stealing prevention" to "High"/"Extream" You can't open KDE Menu by menu-key or mouse click,

Bug#850829: monit overwrites its log file

2017-01-10 Thread Sergey B Kirpichev
tags 850829 -unreproducible +pending thanks On Tue, Jan 10, 2017 at 08:20:14PM +0100, Vincent Lefevre wrote: > No, I don't think I have anything that should affect --reinstall. > Correct me if I'm wrong, but it seems normal that with --reinstall, > the package gets configured (ditto with an upgrad

Bug#850829: monit overwrites its log file

2017-01-10 Thread Sergey B Kirpichev
On Tue, Jan 10, 2017 at 08:03:31PM +0100, Vincent Lefevre wrote: > On 2017-01-10 21:49:26 +0300, Sergey B Kirpichev wrote: > > Hmm, I can't reproduce this as suggested by you. > > On my side, I've tried two other times, and each time it was > reproducible. App

Bug#850829: monit overwrites its log file

2017-01-10 Thread Sergey B Kirpichev
tags 850829 -pending +unreproducible thanks > On Tue, Jan 10, 2017 at 05:28:27PM +0100, Vincent Lefevre wrote: > > However... > > > > # apt install --reinstall monit > > Oh, I see, this happens on reinstallation. Hmm, I can't reproduce this as suggested by you. # apt install monit Reading pack

Bug#850829: monit overwrites its log file

2017-01-10 Thread Sergey B Kirpichev
tags 850829 +pending thanks On Tue, Jan 10, 2017 at 05:28:27PM +0100, Vincent Lefevre wrote: > However... > > # apt install --reinstall monit Oh, I see, this happens on reinstallation. > Something wrong in the postinst script? > Could this be: > install -o root -g adm -m 0640 /dev/null /var

Bug#850829: monit overwrites its log file

2017-01-10 Thread Sergey B Kirpichev
On Tue, Jan 10, 2017 at 04:08:03PM +0100, Vincent Lefevre wrote: > I've noticed that the latest version of monit has overwritten > its log file (/var/log/monit.log). /var/log/monit.log.1 ends > on January 2 with: How logging system configured? journald? > [...] > [CET Jan 2 07:32:58] error:

Bug#847196: monit segfault on stop and start

2016-12-12 Thread Sergey B Kirpichev
On Mon, Dec 12, 2016 at 04:23:57PM +0100, Arthur Hoffmann wrote: > It looks like this bug is fixed, > I did "dpkg -i monit_5.4-2+deb7u3_amd64.deb", monit restarted and is > running > now. > Thank you. > >Source package was uploaded to > >https://mentors.debian.net/package/monit > >amd64 deb attache

Bug#847196: monit segfault on stop and start

2016-12-12 Thread Sergey B Kirpichev
On Mon, Dec 12, 2016 at 02:06:41PM +0100, Martin Pala wrote: > The securitytoken in collector is not needed at all - the CSRF > protection is related to Monit's own HTTP API (the securitytoken > cookie is not present in upstream). Ok, I see. Thank you, Martin. > To fix the problem, just drop the

Bug#847196: monit segfault on stop and start

2016-12-12 Thread Sergey B Kirpichev
On Mon, Dec 12, 2016 at 01:11:38PM +0100, Arthur Hoffmann wrote: > Ok, now I have checked my config files and found out that it > works with the latest package if I remove the following line: > > set mmonit https://USER:PASSWORD@URL:PORT/collector Ok, I see. I don't use closed-source software, s

Bug#847196: monit segfault on stop and start

2016-12-12 Thread Sergey B Kirpichev
On Mon, Dec 12, 2016 at 12:24:31PM +0100, Arthur Hoffmann wrote: > I just want to confirm that Monit is running again on all 5 Debian Wheezy > (i386 and amd64) machines if I downgrade the package with "sudo apt-get > install monit=1:5.4-2". Unfortunately, I can't reproduce this on several testing

Bug#847196: monit segfault on stop and start

2016-12-12 Thread Sergey B Kirpichev
reopen 847196 thanks Please don't reply personally (unless you want to share some private info)! Either to bugtracker, or add CC to bugtracker. Meanwhile, bug reopened. Perhaps, backport is still broken. (Also, co-mantainers, please use git!) BTW, I can't reproduce this yet. Perhaps, this rel

Bug#847196: monit segfault on stop and start

2016-12-07 Thread Sergey B Kirpichev
On Wed, Dec 07, 2016 at 09:41:11AM +0100, Arthur Hoffmann wrote: > I'm not sure whether this bug is the same that I have got, > but it began with 1:5.4-2+deb7u1 and it is NOT fixed with 1:5.4-2+deb7u2. Very likely. > The service/process is starting and writes some INFO log lines without > errors

Bug#847196: monit segfault on stop and start

2016-12-06 Thread Sergey B Kirpichev
On Tue, Dec 06, 2016 at 01:52:04PM +0100, Victor Seva wrote: > Yes, I just notice the security update is broken. > > I have prepared the fix for this and I was planing to contact the > security team about this. > > Thanks for reporting, > Victor Seva Victor, you are in uploaders for the package.

Bug#844801: libapache2-mod-qos: FTBFS: build-dependency not installable: libssl-dev (>= 0.9.8g)

2016-11-19 Thread Sergey B Kirpichev
On Sat, Nov 19, 2016 at 08:37:20PM +0100, Lucas Nussbaum wrote: > There's an ongoing transition to OpenSSL 1.1. Yes, I'm aware of. > See https://lists.debian.org/debian-devel-announce/2016/11/msg1.html > https://bugs.debian.org/cgi-bin/pkgreport.cgi?tag=openssl-1.1-trans;users=pkg-openssl-dev

Bug#844801: libapache2-mod-qos: FTBFS: build-dependency not installable: libssl-dev (>= 0.9.8g)

2016-11-19 Thread Sergey B Kirpichev
On Sat, Nov 19, 2016 at 07:25:15AM +0100, Lucas Nussbaum wrote: > During a rebuild of all packages in sid, your package failed to build on > amd64. > > > The following packages have unmet dependencies: > > sbuild-build-depends-libapache2-mod-qos-dummy : Depends: libssl-dev (>= > > 0.9.8g) but it

Bug#828439: monit: FTBFS with openssl 1.1.0

2016-11-14 Thread Sergey B Kirpichev
On Sun, Nov 13, 2016 at 06:41:31PM +0100, Kurt Roeckx wrote: > On Sun, Nov 13, 2016 at 08:26:48PM +0300, Sergey B Kirpichev wrote: > > On Sun, Nov 13, 2016 at 05:29:10PM +0100, Kurt Roeckx wrote: > > > That's because the configure script tries to look for a function > >

Bug#828439: monit: FTBFS with openssl 1.1.0

2016-11-13 Thread Sergey B Kirpichev
On Sun, Nov 13, 2016 at 05:29:10PM +0100, Kurt Roeckx wrote: > That's because the configure script tries to look for a function > that's been turned into a define. For some reason it's only trying > to look for SSL_library_init() on i386. Could you suggest a more portable solution? > It doesn't s

Bug#828439: monit: FTBFS with openssl 1.1.0

2016-11-13 Thread Sergey B Kirpichev
On Sun, Nov 13, 2016 at 03:43:29PM +0100, Kurt Roeckx wrote: > This seems to have been fixed upstream. Yes, this bug was closed by upstream. Thank you for tagging. BTW, it still FTBFS on i386. > It also seems like for some reason ssl support is disabled on > other arches than amd64 and i386. O

Bug#843425: Fwd: Bug#843425: blender doesn't optimize for amd64 defaults

2016-11-07 Thread Sergey Sharybin
nks to Matteo i guess :) Is there anything else here to be solved? [1] https://buildd.debian.org/status/package.php?p=blender On Mon, Nov 7, 2016 at 10:52 AM, Sergey Sharybin wrote: > Ah, it's Pemtium 4 where SSE2 first arrived, for a moment thought it's > Pentium Pro. My bad.

Bug#843425: Fwd: Bug#843425: blender doesn't optimize for amd64 defaults

2016-11-07 Thread Sergey Sharybin
ld already have global SSE2 optimization disabled. If CPU on the builder machine supports SSE2 we can still force SSE/SSE2 optimization to be off by passing `-DSUPPORT_SSE_BUILD=OFF -DSUPPORT_SSE2_BUILD=OFF` to CMake. On Mon, Nov 7, 2016 at 10:40 AM, Matthias Klose wrote: > On 07.11.2016 10:3

Bug#843425: blender doesn't optimize for amd64 defaults

2016-11-07 Thread Sergey Sharybin
ould be all fine as far as i know (amd64 always have SSE2, 32bit builds will disable SSE2 automatically if current CPU does not support it). -- With best regards, Sergey Sharybin

Bug#832622: clang-3.9: Uninstallable in unstable

2016-07-29 Thread Sergey Zinov
I have encountered this bug too. I found following workaround so far: First removing llvm-3.9-dev package: apt remove llvm-3.9-dev Then installing them together: apt install llvm-3.9-dev clang-3.9

Bug#816265: [Pkg-php-pecl] Bug#816265: Bug#816265: Bug#816265: Bug#816265: php-geoip: FTBFS: libtool: No such file or directory

2016-02-29 Thread Sergey B Kirpichev
On Mon, Feb 29, 2016 at 03:56:57PM +0100, Ondřej Surý wrote: > I simply cannot fix I'm not about requesting a fix from you. Just about accepting that there is a problem ("We won't hide problems", remember?). But it seems you know better how to do the work and I'm just in a wrong place as a co-ma

Bug#816265: [Pkg-php-pecl] Bug#816265: Bug#816265: Bug#816265: php-geoip: FTBFS: libtool: No such file or directory

2016-02-29 Thread Sergey B Kirpichev
On Mon, Feb 29, 2016 at 02:28:08PM +0100, Ondřej Surý wrote: > It's not how important they seem to *me*, but to the release team. > The FTBFS on non-release archs are not "serious" I don't see that here: https://www.debian.org/Bugs/Developer#severities btw, will kfreebsd release arch or not - up

Bug#816265: [Pkg-php-pecl] Bug#816265: Bug#816265: php-geoip: FTBFS: libtool: No such file or directory

2016-02-29 Thread Sergey B Kirpichev
> So a FTBFS on non-release arch with outdated PHP version. I did some work to keep my packages in installable status for all arch's, no matter how important they seems to you. Why you break this so easily? (btw, how such archs could get release status if you refuse to assist them?). > And with s

Bug#816265: [Pkg-php-pecl] Bug#816265: php-geoip: FTBFS: libtool: No such file or directory

2016-02-29 Thread Sergey B Kirpichev
On Mon, Feb 29, 2016 at 12:44:54PM +0100, Ondřej Surý wrote: > What versions of php-all-dev and php7.0-dev are installed at your > machine? Since the libtool 2.4.6-0.1 compatibility was fixed couple > releases back. https://buildd.debian.org/status/package.php?p=php-geoip

Bug#816265: php-geoip: FTBFS: libtool: No such file or directory

2016-02-29 Thread Sergey B Kirpichev
Package: php-geoip Version: 1.1.0-3 Severity: serious Justification: fails to build from source Tags: sid stretch Usertags: ftbfs Tail of build log: dh_auto_build --builddirectory=/«PKGBUILDDIR»/build-$v --sourcedirectory=geoip-1.1.0; \ done make -j1 make[2]: Entering directory '/«PKGBUILDD

Bug#796989: monit: Monit 5.9 has a serious umask bug.

2015-09-11 Thread Sergey Kirpichev
On Sep 10, 2015 2:04 PM, "Nikos Timiopulos" wrote: > so I think I’ve applied that patch and it doesn’t fix the bug. Most likely, patch wasn't applied. > Because I’m noob in the package modifications I’ve made these steps for > your review: > > $ apt-get source monit > $ cd monit-5.9 > I’ve put

Bug#796989: monit: Monit 5.9 has a serious umask bug.

2015-09-10 Thread Sergey B Kirpichev
On Thu, Sep 10, 2015 at 11:17:57AM +0200, Nikos Timiopulos wrote: > this bug bothers me a few days and I would like to help, can you please tell > me how to test that patch? You could add this patch to the stable package patches dir (man quilt) and then build the package as usual.

Bug#763451: mpmath files should be installed in /usr/share/pyshared

2014-09-30 Thread Sergey B Kirpichev
Package: mpmath Severity: serious Mpmath's source files are identical across all python's versions. You should share them in /usr/share/pyshared, see the policy [1]. .. [1] https://www.debian.org/doc/packaging-manuals/python-policy/ch-python.html#s-paths -- To UNSUBSCRIBE, email to debian-bu

Bug#763042: linux-image-3.16-2: davfs2 broken with 3.16

2014-09-27 Thread Sergey Dorofeev
Package: src:linux Version: 3.16.3-2 Severity: grave File: linux-image-3.16-2 Justification: causes non-serious data loss Dear Maintainer, since upgrade to 3.16-1, I cannot save files on davfs2 mounted resources. The problem affects only some editors: mcedit, libreoffice writer Does not affect vi

Bug#759840: parser: FTBFS: string3.h:51: undefined reference to `_pcre_default_tables'

2014-08-30 Thread Sergey Kirpichev
Closed as a duplicate of #755346 On Sat, Aug 30, 2014 at 11:02 PM, Lucas Nussbaum wrote: > Source: parser > Version: 3.4.3-3 > Severity: serious > Tags: jessie sid > User: debian...@lists.debian.org > Usertags: qa-ftbfs-20140830 qa-ftbfs > Justification: FTBFS on amd64 > > Hi, > > During a rebui

Bug#752532: Sources licensed under PHP License and not being PHP are not distributable

2014-06-26 Thread Sergey B Kirpichev
On Thu, Jun 26, 2014 at 01:00:12PM +0200, Ondřej Surý wrote: > 3. We remove the source packages from Debian. Can you kindly explain why? Is the PHP license is non-free? If so, why? If not - let's lower the bugs severity. I see only *one* reply from debian-legal here: https://lists.debian.org/d

Bug#752673: does not work

2014-06-25 Thread Sergey B Kirpichev
tag 752673 +patch thanks Try to apply provided patch. --- /usr/share/festival/voices/russian/msu_ru_nsh_clunits/festvox/msu_ru_nsh_clunits.scm.orig 2014-06-25 21:05:53.097309896 +0400 +++ /usr/share/festival/voices/russian/msu_ru_nsh_clunits/festvox/msu_ru_nsh_clunits.scm 2014-06-25 21:05:58.64131

Bug#752673: does not work

2014-06-25 Thread Sergey B Kirpichev
severity 752673 wishlist thanks On Wed, Jun 25, 2014 at 06:14:47PM +0400, Dmitry Eremin-Solenikov wrote: > After installing festvox-ru I see the following error message Please read the documentation of the package. -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subj

Bug#745956: snmpd: new version of startup script fails on VPS which obviously do not have /proc/bus/pci

2014-04-26 Thread Sergey Dorofeev
Package: snmpd Version: latest jessie Severity: grave Justification: renders package unusable Dear Maintainer, After upgrading system got error installing snmpd. Trying to uninstall report weird problem deleting /run/snmpd.pid. Touch'ed it and only then got it uninstalled, weird. Trying to inst

Bug#692628: non-free files in upstream tarball ("The Software shall be used for Good, not Evil")

2013-10-06 Thread Sergey Kirpichev
tags 692628 +upstream +pending thanks On Thu, Nov 8, 2012 at 2:16 AM, Ansgar Burchardt wrote: > The upstream tarball contains files under the non-free JSON license: > > % rgrep -l 'The Software shall be used for Good, not Evil.' . > ./src/lib/json/JSON_parser.C Fix is available in the upstream c

Bug#718054: nlopt: FTBFS: dh_auto_test: error: unable to chdir to debian/build

2013-07-28 Thread Sergey B Kirpichev
tags 718054 +pending thanks Updated package was uploaded to m.d.n: https://mentors.debian.net/package/nlopt RFS bug: http://bugs.debian.org/717822 -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#717306: nvidia-kernel-legacy-173xx-dkms

2013-07-19 Thread Sergey Oskorbin
I have this problem too. -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#522747: xserver-xorg-video-s3: X failed after upgrading stable to testing

2013-03-21 Thread Sergey Dorofeev
Yes, this version works fine Пользователь Julien Cristau писал: >On Sun, Mar 17, 2013 at 22:06:59 +0400, Sergey Dorofeev wrote: > >> Package: xserver-xorg-video-s3 >> Version: 1:0.6.3-4+b3 >> Followup-For: Bug #522747 >> >> Dear Maintainer, >> >

Bug#617613: freecad in fact does not link to incompatible libraries

2013-02-02 Thread Sergey Kurdakov
cense. Regards Sergey On Sat, Feb 2, 2013 at 10:10 PM, Adam D. Barratt wrote: > On Sat, 2013-02-02 at 21:48 +0400, Sergey Kurdakov wrote: >> > Do you have a pointer to a statement that earlier versions are covered >> > by the relicensing? >> >> the code cover whi

Bug#617613: freecad in fact does not link to incompatible libraries

2013-02-02 Thread Sergey Kurdakov
Hi > Do you have a pointer to a statement that earlier versions are covered > by the relicensing? the code cover which is put under BSD is since ver 3.1.2 https://bitbucket.org/Coin3D/coin/overview so the code is re licensed back since version 3.1.2 Regards Sergey On Sat, Feb 2, 2013 a

Bug#617613: freecad in fact does not link to incompatible libraries

2013-02-02 Thread Sergey Kurdakov
Hi, it is quite a long time that coin3D was re-licensed to BSD, so no problems to link with opencascade http://mailman.coin3d.org/pipermail/coin-discuss/2011-November/018377.html https://bitbucket.org/Coin3D/coin/wiki/Home Regards Sergey

Bug#692013: php5-memcache: fails to install and uninstall

2012-11-02 Thread Sergey B Kirpichev
tag 692013 -unreproducible -moreinfo reassign 692013 php5 retitle 692013 php5-* modules: fails to install and uninstall if the config file was removed by user thanks On Fri, Nov 02, 2012 at 05:09:00PM +0100, Tobias Frost wrote: > > Anyway, this bug should belong to php5enmod/php5dismod (package p

Bug#692013: php5-memcache: fails to install and uninstall

2012-11-02 Thread Sergey Kirpichev
tag 692013 +unreproducible moreinfo thanks On Thu, Nov 1, 2012 at 2:19 PM, Tobias Frost wrote: > the package fails to update from version? > and trying to recover by uninstalling fails too Right now looks as nothing wrong. Probably, you should fix your system first (touch /etc/php5/mods-avail

Bug#677801: [Python-modules-team] Bug#677801: (no subject)

2012-08-25 Thread Sergey Kravchuk
Thanks answer! I found the problem, it virtualenv 1.7.2 If you use the package python-virtualenv_1.7.1.2-2, then it works. i installed virtualenv from pip. Best regads, Sergey V. Kravchuk sergey.kravc...@vuaro.ru tel: +7 906 278 3751 25.08.2012, в 23:16, Stefano Rivera написал(а): >

Bug#677801: (no subject)

2012-08-15 Thread Sergey Kravchuk
Package: python-pip Version: 1.1-3 Followup-For: Bug #677801 Hello, The problem appeared again in the version of python 2.7.3-2. Cleaning up... Running virtualenv with interpreter /usr/bin/python2.7 The --no-site-packages flag is deprecated; it is now the default behavior. New python executable

Bug#684949: php5-memcached: Fails PHP to start (unresolved symbol memcached_server_micro_version

2012-08-15 Thread Sergey B Kirpichev
forwarded 684949 https://github.com/php-memcached-dev/php-memcached/issues/25 tag 684949 +pending +patch +upstream thanks On Wed, Aug 15, 2012 at 01:33:35AM +0300, Gleb Golubitsky wrote: > php5-memcached extension fails to load with the following message: > PHP Warning: PHP Startup: Unable to loa

Bug#683984: libapache2-mod-rpaf: potential Denial of Service

2012-08-09 Thread Sergey Kirpichev
On Mon, Aug 6, 2012 at 4:23 AM, Luciano Bello wrote: > Sébastien Bocahu reported to the security team: >> patch that was applied by Debian exposes Apache to segfaults under specific >> crafted requests. >> >> The magick request is the following: >> curl -H "x-forwarded-for: 1'\"5000" -H "Host: a

Bug#683984: libapache2-mod-rpaf: potential Denial of Service

2012-08-08 Thread Sergey B Kirpichev
On Tue, Aug 07, 2012 at 03:11:46PM +0200, Sébastien Bocahu wrote: > I don't want to. It was "allowed" until now, as X-Forwarded-For headers were > not > deleted by the reverse proxy. By *some* reverse proxies. It depends on configuration. > I still think that many people are using Debian and mo

Bug#683984: libapache2-mod-rpaf: potential Denial of Service

2012-08-07 Thread Sergey B Kirpichev
tag 683984 +upstream thanks On Tue, Aug 07, 2012 at 12:58:40PM +0200, Sébastien Bocahu wrote: > This is definitely _not_ a misconfiguration issue. > > mod_rpaf is supposed to use the *last* X-Forwarded-For header. > There's a bug which adds some garbage to the remote_ip field, when a > specific r

Bug#683984: libapache2-mod-rpaf: potential Denial of Service

2012-08-07 Thread Sergey B Kirpichev
Ok, now it makes sense. As a workaround, you should avoid using x-forwarded-for header from untrusted sources. Usually, it is the case - you can trust your frontend servers ;) That means - real impact of this issue is very minor and mostly due to misconfiguration. 07.08.2012 14:15 пользователь "

Bug#683984: libapache2-mod-rpaf: potential Denial of Service

2012-08-07 Thread Sergey Kirpichev
tag 683984 +pending thanks 06.08.2012 4:27 пользователь "Luciano Bello" написал: > Sébastien Bocahu reported to the security team: > > (...) > > A single request makes Apache segfault. On some of the environments I > tested, > > it even kills all Apache processes (they become zombies). Thank yo

Bug#679619: not working guile bindings

2012-06-30 Thread Sergey B Kirpichev
Package: libnlopt-guile0 Version: 2.2.4+dfsg-1 Severity: grave This issue was reported in closed ITP #610623. $ guile ./tutorial.scm ERROR: In procedure dynamic-link: ERROR: file: "libnlopt_guile.so", message: "file not found" Test suite (tutorial examples from upstream wiki, nlopt-test.tgz) was

Bug#679617: not working octave bindings

2012-06-30 Thread Sergey B Kirpichev
Package: octave-nlopt Version: 2.2.4+dfsg-1 Severity: grave This issue was reported in closed ITP bugreport #610623. But after accepting buggy package in Debian --- test script (tutorial example from upstream wiki) fails as before: $ octave -q ./tutorial.m error: invalid use of script /usr/share/

Bug#677728: ProvisioningError: Your filesystem or build does not support posix ACLs, s3fs is unworkable in this mode

2012-06-16 Thread Sergey Sidlyarenko
Package: samba4 Version: 4.0.0~beta1+dfsg1-1 Severity: serious Justification: normal Dear Maintainer, root@dc:~# uname -r 3.2.0-2-amd64 root@dc:~# cat /boot/config-3.2.0-2-amd64 |egrep "EXT4|EXT3"|egrep "ACL|ATTR|SECURITY" CONFIG_EXT3_FS_XATTR=y CONFIG_EXT3_FS_POSIX_ACL=y CONFIG_EXT3_FS_SECURIT

Bug#654428: blender: FTBFS: uses i386/amd64 specific register definitions on all architectures

2012-01-26 Thread Sergey Sharybin
logs after all this my changes. -- With best regards, Sergey Sharybin -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#654428: blender: FTBFS: uses i386/amd64 specific register definitions on all architectures

2012-01-26 Thread Sergey Sharybin
ow the buildd-situation evolves. > > Cheers. > > -- > Matteo F. Vescovi > Debian Sponsored Maintainer > e-mail: mfv.deb...@gmail.com > GnuPG KeyID: 83B2CF7A -- With best regards, Sergey Sharybin -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#654428: blender: FTBFS: uses i386/amd64 specific register definitions on all architectures

2012-01-25 Thread Sergey Sharybin
On Wed, Jan 25, 2012 at 11:40 PM, Kevin Roy wrote: > I think the patch 0011-fix_FTBFS_with_libmv [1] in git will cover > configs other than i386/amd64 but in doubt, could you look at it and > tell me if yours is need to be added? -- With best regards, Sergey Sharybin -- To UNSUBSC

Bug#654428: blender: FTBFS: uses i386/amd64 specific register definitions on all architectures

2012-01-25 Thread Sergey Sharybin
work fine, it can be commited to trunk. -- With best regards, Sergey Sharybin Index: extern/libmv/third_party/glog/src/config_linux.h === --- extern/libmv/third_party/glog/src/config_linux.h (revision 43691) +++ extern/libmv/third_party

Bug#629896: segfault while simply get()ing a value from squeeze memcached

2011-12-28 Thread Sergey Kirpichev
tag 629896 +confirmed severity 629896 important thanks I'll lower down the severity of this bugreport. Clearly, this issue does not makes the package "unusable or mostly so". Even for heavy-loaded websites (mass virtual hosting, actually) there exists an alternative: using fcgi. Please, explain

Bug#652070: awstats: virtualname / SiteDomain accepts nearly everything

2011-12-14 Thread Sergey B Kirpichev
tag 652070 +moreinfo thanks > - AWstats runs fine for months. > - Yesterday apt updated Perl. > - Now AWSTats directives %virtualname and SiteDomain accepts nearly all > records of the logfile, even with an arbirtray string as SiteDomain, for > example SiteDomain="fhawefruzasdfh" Please, test t

Bug#643019: monit: FTBFS: configure: error: Architecture not supported: `uname`.

2011-09-29 Thread Sergey B Kirpichev
On Mon, Sep 26, 2011 at 8:06 PM, Christoph Egger wrote: > Justification: fails to build from source (but built successfully in the past) > > Your package failed to build on the kfreebsd-* buildds: > > checking for sys/filio.h... yes > configure: error: Architecture not supported: `uname`. > > If y

Bug#614261: Maybe a local install

2011-09-18 Thread sergey
On Fri, 16 Sep 2011 16:54:44 +0200 "Thomas Preud'homme" wrote: > Greetings Sergey, > > I looked at the version 1.3.3.13.dfsg~svn20081228-2+b2 of scribus you seem to > be using and it is correctly linked against libtiff.so.4. Maybe you are using > a > local i

Bug#615104: Bug can be closed

2011-07-14 Thread sergey
Please see #615476. This is not bug of Scribus, IMHO this is system architecture or documentation problem. Bug report can be closed now. Regards, Sergey. -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Conta

Bug#615104: bug can be closed

2011-07-14 Thread sergey
Please see #615476. This is not bug of Scribus, IMHO this is system architecture or documentation problem. Bug report can be closed now. Regards, Sergey. -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Conta

Bug#630254: pidgin: Version in stable cannot login anymore

2011-06-27 Thread Sergey Spiridonov
Hi Disabling SSL in settings does not help with both AIM and ICQ. Log file looks like if SSL is enabled, but it is disabled in account settings. So, it looks like there are 2 bugs, one more is that disabling SSL does not work... I can not use ICQ and AIM at all... :( (23:52:21) account: Connect

Bug#622658: (no subject)

2011-04-26 Thread Sergey Svishchev
Install php5-cgi too, this will satisfy 'php' dependency and apache won't be required. -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#615289: gnuplot compiled with libtiff.so.3 that is not exist in Squeeze

2011-02-27 Thread sergey
RY_PATH=/lib:/usr/lib Then gnuplot runs normally in this terminal session. Is it normal that Debian's gnuplot in my system gets dependencies from non-Debian libraries? - Regards, Sergey -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of

Bug#615476: general: many binaries are linked with non-existent libtiff.so.3 library

2011-02-26 Thread sergey
-perm /a+x -exec ./q {} \; ----- Regards, Sergey -- System Information: Debian Release: 6.0 APT prefers stable APT policy: (500, 'stable') Architecture: i386 (i686) Kernel: Linux 2.6.30-2-686 (SMP w/1 CPU core) Locale: LANG=ru_RU.UTF-8, LC_CTYPE=ru_RU.UTF-8 (charmap=UTF-8

Bug#615289: gnuplot compiled with libtiff.so.3 that is not exist in Squeeze

2011-02-26 Thread sergey
Package: gnuplot Version: 4.4.0-1.1 Severity: grave Justification: renders package unusable This is the error: $ gnuplot gnuplot: error while loading shared libraries: libtiff.so.3: cannot open shared object file: No such file or directory -- System Information: Debian Release: 6.0 APT prefer

Bug#615104: multiget can't run because of missing libtiff.so.3 library

2011-02-25 Thread sergey
Package: multiget Version: 1.2.0-3 Severity: grave Justification: renders package unusable This is the error: $ multiget multiget: error while loading shared libraries: libtiff.so.3: cannot open shared object file: No such file or directory -- System Information: Debian Release: 6.0 APT pre

Bug#614261: scribus: compiled with libtiff.so.3 that does not exists in Debian 6

2011-02-20 Thread sergey
Package: scribus Version: 1.3.3.13.dfsg~svn20081228-2+b2 Severity: grave Justification: renders package unusable The error is: $ scribus scribus: error while loading shared libraries: libtiff.so.3: cannot open shared object file: No such file or directory -- System Information: Debian Release

Bug#593429: 08-adjtimex.patch

2011-01-24 Thread Sergey B Kirpichev
tag 593429 +patch thanks Attached patch adopted for 3.9p1+debian-6 package (it builds and seems to be working). Please review/comment. -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#606263: [Pkg-awstats-devel] Bug#606263: Multiple security issues

2010-12-14 Thread Sergey B Kirpichev
tag 606263 pending thanks > http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4369 Fixed in repo: http://git.debian.org/?p=collab-maint/awstats.git;a=commit;h=aaf089d10ce4e12e6d499089407d93c62511e9c0 > http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4368 > http://cve.mitre.org/cgi-bi

Bug#596803: hdfview exception can't load xawt/libmawt.so

2010-09-14 Thread Sergey Spiridonov
Package: hdfview Version: 2.6.1-1+b1 Severity: grave Tags: sid Justification: renders package unusable Startign hdfview failes with following exception: $ /usr/bin/hdfview Exception in thread "main" java.lang.UnsatisfiedLinkError: Can't load library: /usr/lib/jvm/java-6-openjdk/jre/lib/i386/xawt/

Bug#588330: Fwd: Bug#588330: Critical bug

2010-07-08 Thread Sergey B Kirpichev
Please, test v0.91 package from mentors.debian.net, to see if this one fixes the problem for you. On Wed, Jul 7, 2010 at 6:08 PM, Bastien ROUCARIES wrote: > I was hitting the  "invisible" memory leak  downloading huge video > file on my site, and it really lok like the invisible bugs... > > > >

Bug#588330: Critical bug

2010-07-07 Thread Sergey B Kirpichev
tag 588330 +moreinfo On Wed, Jul 7, 2010 at 4:24 PM, Bastien ROUCARIES wrote: > The current package has a leak that could lead to crashing current > apache process. Please correct and upgrade a new one. Do you mean the fix - an "invisible" memory leak (v0.9) or - stupid bug that caused crash wh

Bug#587320: slim needs xauth , but not depends on it

2010-06-27 Thread Sergey
Package: slim Version: 1.3.0-1+lenny2 Severity: grave Justification: renders package unusable Without xauth installed, i have "Cant execute login command" message after login -- System Information: Debian Release: 5.0.5 APT prefers stable APT policy: (500, 'stable') Architecture: i386 (i686)

Bug#587000: virt-manager: Missing dependency on python-pycurl

2010-06-24 Thread Sergey Korobitsin
Package: virt-manager Version: 0.8.4-4 Severity: grave Tags: sid Justification: renders package unusable I use Debian system installed without recommended packages, and after installing the virt-manager and trying to launch it it get these: Traceback (most recent call last): [...] ImportError:

Bug#582671: [Bug-dico] Bug#582671: dicoweb: configuration provided as data (fwd)

2010-05-23 Thread Sergey Poznyakoff
Commit 96770e6e7026ccb54c53c904bb9a3e37102098db renames settings.py to settings-sample.py. Will it help? Regards, Sergey -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#576457: pulseaudio: fails to start

2010-04-07 Thread Sergey Fionov
version 0.9.21-1.2 fixes problem in local build with dpkg-buildpackage, but don't fix problem on buildd. Buildd log at https://buildd.debian.org/fetch.cgi?pkg=pulseaudio;ver=0.9.21-1.2;arch=amd64 have warnings about unused variables in core-util.c:199, it means that HAVE_FSTAT and HAVE_FCHMOD are

Bug#576457:

2010-04-07 Thread Sergey Fionov
Sorry for incorrect link in my previous comment, link to buildd log should be: https://buildd.debian.org/build.cgi?pkg=pulseaudio;ver=0.9.21-1.2;arch=amd64 -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debi

Bug#576637: [Bug-cpio] Re: Bug#576637: cpio: FTBFS: multiple definition of `fatal_exit'

2010-04-06 Thread Sergey Poznyakoff
Clint Adams ha escrit: > The mt man page suggests that a fatal error should exit with a 2; > mt's fatal_exit exits with a 1 (MT_EXIT_INVOP). > > What is truly intended here? The former: it shoud exit with code 2. Thanks for reporting. Regards, Sergey -- To UNSUBSCRIBE

Bug#573119: libmenu-cache1: dpkg --unpack failed: package tries to overwrite files of libmenu-cache0

2010-03-08 Thread Sergey Korobitsin
Package: libmenu-cache1 Severity: grave Justification: renders package unusable I've tried to install libmenu-cache1, and the install fails: Unpacking libmenu-cache1 (from .../libmenu-cache1_0.3.2-1_i386.deb) ... dpkg: error processing /var/cache/apt/archives/libmenu-cache1_0.3.2-1_i386.deb (--un

Bug#475279: Fwd: Bug#475279: mediatomb-common: Don't embedd prototype.js

2010-02-03 Thread Sergey 'Jin' Bostandzhyan
Hi, On Wed, Feb 03, 2010 at 10:12:08PM +0100, Mehdi wrote: > > I'm not sure if Leo already told you this, but here's a bug asking for > > mediatomb not to use an embedded prototype.js. > > > > I've already tried using the prototype.js delivered in Debian (version > > 1.6.0.2). It's giving me pr

Bug#567569: Unable to bind some core keys to pad buttons

2010-01-29 Thread Sergey I. Sharybin
com suggests: ii xinput1.5.0-2Runtime configuration and test of -- no debconf information -- With best regards, Sergey I. Sharybin # /etc/X11/xorg.conf (xorg X Window System server configuration file) # # This file was generated by dexconf, the Debian X Configuration t

Bug#560608: parser: FTBFS: config.status: error: invalid argument: src/lib/ltdl/Makefile

2009-12-23 Thread Sergey B Kirpichev
Hello, Git version introduce fix for improperly formed patch 199 (use automake-1.9 instead of automake-1.10): WARNING: `automake-1.10' is missing on your system. You should only need it if you modified `Makefile.am', `acinclude.m4' or `configure.in'. You might want to install th

Bug#559837: Bug#559824: CVE-2009-3736 local privilege escalation

2009-12-08 Thread Sergey B Kirpichev
severity 559824 minor severity 559837 minor tags 559824 + fixed pending tags 559837 + fixed pending thanks It's very unlikely to exploit either parser3 or it's mysql-extension this way. If you have write access to the parser3 working directory - just edit auto.p (@conf method) to include addition

  1   2   >