Bug#742990: News?

2014-05-06 Thread Frank Habermann
Hi, > Frank, are you still active or should someone take over ? I'm asking > because "gitpkg" is much less used than "git-buildpackage" and > it might be easier to use Bastien's solution if we switch to > git-buildpackage. >From my side any help is welcome and somebody could take over. I am very b

Bug#641808: On ckeditor package

2014-01-29 Thread Frank Habermann
Hi, sorry for late reply. Lot of private stuff Feel free to upload an NMU package. I will try to fix the other bugs as soon as possible. regards, Frank -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@list

Bug#706696: dojo: Please upgrade to new upstream version

2013-10-25 Thread Frank Habermann
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hello David, >> there is a new upstream version 1.8.3 of dojotoolkit available > > 1.9.1 is now available, and the version currently in the archive > FTBFSes (#724124). I’d be happy to help maintaining this package > (because the upcoming owncloud pa

Bug#708319: Update to 1.7.1

2013-05-28 Thread Frank Habermann
close 708319 thanks Hi, version 1.7.1 was successfully uploaded. Frank -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#696483: Fix for CVE-2012-5657

2013-01-07 Thread Frank Habermann
Hi, i have prepared a package for squeeze: http://debian.lordlamer.de/zendframework/1.10.6squeeze1/zendframework_1.10.6-1squeeze2.dsc I also tested it and fixes the problem. I will contact security team now. regards, Frank signature.asc Description: This is a digitally signed message part.

Bug#696483: Uploaded to DELAYED/7

2012-12-29 Thread Frank Habermann
Hi, > I've uploaded a NMU with the patch above to DELAYED/7. Thanks for your patch and the work and sorry for delayed answer. Christmas holidays and family ;) Now, i am sitting on a patch for stable/squeeze. regards, Frank -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org w

Bug#688946: zendframework: CVE-2012-4451

2012-10-18 Thread Frank Habermann
close #688946 Hi, > Remember Debian is in freeze, so please only apply the isolated securitx > fix and request an unblock by filing a bug against release.debian.org I contacted upstream to clarify this. Zendframework Version 1 is not affected by this. So no fix is needed here! regards, Frank

Bug#686616: unblock: zendframework 1.11.13-1

2012-09-03 Thread Frank Habermann
Package: release.debian.org Severity: high User: release.debian@packages.debian.org Usertags: freeze-exception Hi, please unblock zendframework 1.11.13-1. Zendframework 1.11.13-1 fixes XML eXternal Entity (XXE) and XML Entity Expansion (XEE) vulnerabilities in Zend_Dom, Zend_Feed, Zend_Soap

Bug#683418: [Debian RT] CVE-2012-4000: XSS vulnerability in fckeditor

2012-08-03 Thread Frank Habermann
Hi, > > I will create fixed packages tomorrow. > > Please try to isolate fixes from the other upstream changes (if any), > since we are in freeze. For Squeeze, please build in a clean chroot and > with -sa. I uploaded a fixed version to unstable. A fixed version for squeeze can be found here: h

Bug#683418: [Debian RT] CVE-2012-4000: XSS vulnerability in fckeditor

2012-08-02 Thread Frank Habermann
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, upstream has released a fixed version. The spellchecker versions in perl and cfm contains also this vulnerability. I will create fixed packages tomorrow. >> I will try to contact upstream to find a solution. > > And can you check if ckeditor is

Bug#683418: [Debian RT] CVE-2012-4000: XSS vulnerability in fckeditor

2012-08-01 Thread Frank Habermann
Hi, > > I will try to contact upstream to find a solution. upstream is working on a solution and will give me feedback tomorrow. > And can you check if ckeditor is affected too? I checked it and it was not affected. regards, Frank signature.asc Description: This is a digitally signed message

Bug#683418: [Debian RT] CVE-2012-4000: XSS vulnerability in fckeditor

2012-07-31 Thread Frank Habermann
Hi, > an XSS vulnerability was found in fckeditor before 2.6.7. Please try to > fix the problem using an isolated fix since we are in freeze. > > More info can be found at > http://disse.cting.org/2012/06/22/fckeditor-reflected-xss-vulnerability/ Thanks for the advice. I found no official solutio

Bug#669168: debian-maintainers: Please add Frank Habermann as a Debian Maintainer

2012-04-17 Thread Frank Habermann
Package: debian-maintainers Severity: normal thanks Hi, Please add my key 01ED3AC7 to the DM keyring. Jetring changeset is attached. regards, Frank Habermann Comment: Add Frank Habermann as a Debian Maintainer Date: Tue, 17 Apr 2012 23:34:18 +0200 Action: import Data: -BEGIN PGP PUBLIC

Bug#638792: libjs-scriptaculous 1.9.0 breaks libjs-protaculous

2012-04-17 Thread Frank Habermann
tags 638792 confirmed thanks Hi, i will add this in the next version. But i think for package libjs-protoaculous the best would be if the files would be created at build time not at install time. So you did not have problems at installation time. Frank signature.asc Description: This is a d

Bug#664082: fckeditor shoud not depends on an httpd server

2012-04-17 Thread Frank Habermann
tags 664082 confirmed thanks Hi, i will fix this in the next version. Frank signature.asc Description: This is a digitally signed message part.

Bug#641808: ckeditor: Includes a copy of YUI which is packaged in debian

2012-04-17 Thread Frank Habermann
tags 641808 confirmed thanks Hi, i will fix this as soon as possible. Hopefully in the next version. Frank signature.asc Description: This is a digitally signed message part.

Bug#666167: ckeditor: missing adapters/jquery.js file

2012-04-17 Thread Frank Habermann
tags 666167 confirmed thanks Hi, i will add this as soon as possible. Frank signature.asc Description: This is a digitally signed message part.

Bug#413066: packaging tinymce locales?

2012-04-17 Thread Frank Habermann
tags 413066 confirmed thanks Bug is confirmed and will be done as soon as possible. signature.asc Description: This is a digitally signed message part.

Bug#413062: tinymce: please bundle the compressor(s)

2012-04-17 Thread Frank Habermann
tags 413062 confirmed thanks Hi, i will add this as soon as possible. Frank signature.asc Description: This is a digitally signed message part.

Bug#591206: License updated (flvplayer)

2010-12-02 Thread Frank Habermann
Hi, sorry for late replay. Lot of private work ;) >From my side it was all ok. Thanks for the work! regards, Frank Am 30.11.2010 16:25, schrieb Didier 'OdyX' Raboud: > Le Tuesday 23 November 2010 13:15:50 Frank Habermann, vous avez écrit : >> I have contacted moxieco

Bug#591206: License updated (flvplayer)

2010-11-23 Thread Frank Habermann
Hi, >> $ find . -name "*swf*" >> ./jscripts/tiny_mce/plugins/media/img/flv_player.swf >> ./examples/media/sample.swf >> >> How important are those files? Could those be replaced or removed without >> affecting application functionality? > I found nothing about using the flv_player.swf in sources.

Bug#591206: License updated (flvplayer)

2010-11-22 Thread Frank Habermann
Hi, > $ find . -name "*swf*" > ./jscripts/tiny_mce/plugins/media/img/flv_player.swf > ./examples/media/sample.swf > > How important are those files? Could those be replaced or removed without > affecting application functionality? I found nothing about using the flv_player.swf in sources. Seems t

Bug#592385: zendframework: Unable to translate error messages because resources files are not shipped

2010-08-09 Thread Frank Habermann
Hi, > Could you please provide resources files in the Debian package? I will add the stuff as soon as possible! regards, Frank signature.asc Description: This is a digitally signed message part.

Bug#413066: Packaging TinyMCE locales

2010-07-28 Thread Frank Habermann
Hi, sounds good for me. If you could help and post a patch it would be fine. Thanks and regards Frank signature.asc Description: This is a digitally signed message part.

Bug#538722: CVE-2009-2265: fckeditor is embedded in etch version

2010-03-25 Thread Frank Habermann
close #538722 thanks fixed in lenny, and testing/unstable; etch is unsupported, closing. Frank -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#511767: tinymce: please consider defining web server config in this package

2010-03-25 Thread Frank Habermann
close #511767 thanks Bug could be closed because version 3.3.2 will come to unstable next. Frank -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#480676: tinymce: please consider defining web server config in this package

2010-03-25 Thread Frank Habermann
close #480676 thanks Bug could be closed because the user should place the config in the vhost part and not in a global part of apache. Frank -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#566871: libjs-prototype: Using /javascript/ as the default alias easily breaks web

2010-03-25 Thread Frank Habermann
close #566871 thanks Could be closed because the bug is not in prototype package. Frank -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#538722: knowledgeroot: embeds prototype.js

2009-11-28 Thread Frank Habermann
reopen 538722 thanks The previous close is wrong. The version is still affected. regards, Frank -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#555229: knowledgeroot: CVE-2007-2383 and CVE-2008-7720 prototypejs vulnerabilities

2009-11-28 Thread Frank Habermann
reopen 555229 thanks The previous close is wrong. The version is still affected. regards, Frank -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#555230: knowledgeroot: embeds prototype.js

2009-11-28 Thread Frank Habermann
reopen 555230 thanks The previous close is wrong. The version is still affected. regards, Frank -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#544793: Acknowledgement (zf.sh and zf.php unavailable)

2009-09-06 Thread Frank Habermann
> For Debian i think we could be even smarter. :-) Yes. The package in Ubuntu does not look so good i think. > We could have "zendframework" (as it is now) or "libphp-zendframework" > (for coherence with other php library), then "zendframework-doc" or > "libphp-zendframework-doc" for the documen

Bug#536051: CVE-2009-2265, CVE-2009-2324: input sanitization errors

2009-07-07 Thread Frank Habermann
Hi, i contacted the security team ~6 hours ago with that. Frank -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#489806: tinymce: new upstream version

2008-07-07 Thread Frank Habermann
Package: tinymce Version: 3.0.8-1 Severity: normal A new upstream version 3.1.0.1 is available. Thanks Frank Habermann -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Bug#471641: Needs to use fckeditor

2008-03-19 Thread Frank Habermann
Package: egroupware-core Severity: serious Your package includes a copy of FCKEditor, which also is packaged as fckeditor in the archive. You need to fix your package to use the system-wide editor. Otherwise it requires too much overhead whenever a vulnerability in FCKEditor is found. Frank

Bug#469570: please update to new upstream version

2008-03-05 Thread Frank Habermann
Package: tinymce Please update this package to the new upstream version (3.0.3 at the moment). Frank Habermann -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Bug#467363: Needs to use fckeditor

2008-02-24 Thread Frank Habermann
Package: moinmoin-common Severity: serious Your package includes a copy of FCKEditor, which also is packaged as fckeditor in the archive. You need to fix your package to use the system-wide editor. Otherwise it requires too much overhead whenever a vulnerability in FCKEditor is found. Frank

Bug#467362: Needs to use fckeditor

2008-02-24 Thread Frank Habermann
Package: karrigell-doc Severity: serious Your package includes a copy of FCKEditor, which also is packaged as fckeditor in the archive. You need to fix your package to use the system-wide editor. Otherwise it requires too much overhead whenever a vulnerability in FCKEditor is found. Frank

Bug#431025: Bug#431026: Bug#433141: Bug#431025: Bug#431026: [PEAR-DEV] Quality assurancepropositionfor HTMLSax3

2007-11-13 Thread Frank Habermann
Hi, > A debian package php-xml-htmlsafe3 has just entered debian Where can i find the package? I did not found it. Frank -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Bug#431026: Bug#433141: Bug#431025: Bug#431026: [PEAR-DEV] Quality assurancepropositionfor HTMLSax3

2007-11-02 Thread Frank Habermann
Hi, FYI: Harry is adding LGPL to HTMLSax and HTMLSax3. So it will be ok for debian or not? regards, Frank -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Bug#431025: Bug#431026: [PEAR-DEV] Quality assurance proposition for HTMLSax3

2007-10-30 Thread Frank Habermann
Hi all, good news from Harry, he has fixed the licence problem with HtmlSax and HTMLSax3 in CVS of pear. You can see it here: http://cvs.php.net/viewvc.cgi/pear/XML_HTMLSax/ regards, Frank -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL

Bug#447592: fckeditor

2007-10-24 Thread Frank Habermann
Hello, FYI: i am working on a package. I hope to upload it to unstable these days. regards, Frank -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Bug#444928: CVE-2007-5156 remote php file inclusion vulnerability in fckeditor

2007-10-08 Thread Frank Habermann
Hi, thanks for the link! Sorry for my mistake. I have tested it again and it works now. I dont know why my first test does not work. But that does not matter now. I hope to fix this tomorrow for stable and for unstable. Thanks. Frank pgpUoF7bZhps0.pgp Description: PGP signature

Bug#444928: CVE-2007-5156 remote php file inclusion vulnerability in fckeditor

2007-10-07 Thread Frank Habermann
apache configuration problem. So also here is not a problem in Knowledgeroot. Thanks for the report. Frank Habermann pgpnSY4dxLTy4.pgp Description: PGP signature

Bug#431026: Quality assurance proposition for HTMLSax3

2007-10-03 Thread Frank Habermann
Hi, i have talked with Lukas on the pear-dev list about that problem and he want to talk with Harry next week as you see here [0]. I hope he can clear this problem that we have a solution as fast as possible. Frank Habermann [0]: http://news.php.net/php.pear.dev/48218 -- To UNSUBSCRIBE

Bug#431026: Bug#433141: Clarifications on issues for this bug

2007-09-01 Thread Frank Habermann
Hi, Am Mittwoch, 18. Juli 2007 15:22 schrieb Michael Schultheiss: > I spoke with the upstream Gallery developers and they're working on > getting this module relicensed under BSD or some other GPL compatible > license. Have you any feedback from the developers for this problem?

Bug#415784: recommends also postgresql-7.4 if you have postgresql-8.1

2007-03-21 Thread Frank Habermann
Package: phppgadmin Version: 4.0.1-3.1 When you install phppgadmin in etch/testing it need postgresql-7.4. This is a bad solution if you have installed postgresql-8.1. So you should change that you have recommends to postgresq 7.4 and 8.1 and not only to 7.4. Frank Habermann -- To

Bug#398200: knowledgeroot: Upgrade overwrites config.inc.php without warning

2006-11-15 Thread Frank Habermann
Hi, i have fixed this in version 0.9.7.3-2. The config is now placed in /etc/knowledgeroot/ I will wait for your feedback and will close the bugreport if all is fine. regards, Frank -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECT

Bug#398200: knowledgeroot: Upgrade overwrites config.inc.php without warning

2006-11-12 Thread Frank Habermann
Hi, thanks for the information. I will fix this! regards, Frank Habermann pgpWrwpJddmHA.pgp Description: PGP signature

Bug#381912: knowledgeroot: embedded FCKeditor and TinyMCE may have unfixed security

2006-08-09 Thread Frank Habermann
Hello, we have checked that bugs. All bugs are fixed in our fckeditor and in tinymce! Thanks for inform us! regards, Frank Habermann -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]