Bug#302790: where's the security issue here?

2005-10-30 Thread Florian Weimer
* Joey Hess: > This bug is tagged security. Where's the possible exploit here? A restored directory tree might have less restrictive permissions than the original. -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Bug#329156: exploit via escape sequences?

2005-10-30 Thread Florian Weimer
* Joey Hess: > Well if this allows arbitrary data to be fed into the file and later > be displayed by who or last then that data could be made to contain > escape sequences, and either hide other lines that would normally be > displayed (so you don't know someone has logged into the machine), or >

Bug#264453: Very likely not exploitable

2005-10-30 Thread Florian Weimer
I agree that this is a horrible coding style, but it's unlikely that it's exploitable. As far as I can tell, the situation is follows: * An attacker must change the system's error messages. * This is only possible by setting LC_MESSAGES to a specially crafted locale file. * This in tu

Bug#46709: Bug status

2005-10-30 Thread Florian Weimer
Is this security bug still open, after more than six years? -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Bug#264453: [Pkg-firebird-general] Bug#264453: Very likely not exploitable

2005-10-31 Thread Florian Weimer
* Damyan Ivanov: > So I decided to check whether fb_lock_mgr actually uses this source. It seems > to be linked with jrd statically. (From what I see in the makefile spaghetti) This is only a problem if it also invokes setlocale, to activate the localized message files. > So, what is the code, t

Bug#336582: New round of security issues

2005-10-31 Thread Florian Weimer
Package: phpbb2 Tags: security Severity: grave A new round of security issues in phpBB has been disclosed. | After these weaknesses were found and disclosed to the vendor | nearly 80 days ago, several problems with unitialised variables | were discovered that allow XSS, SQL injection and even r

Bug#264453: [Pkg-firebird-general] Bug#264453: Very likely not exploitable

2005-10-31 Thread Florian Weimer
* Damyan Ivanov: > If you have no objections, I intent to close the bugreport. Ot should it be > tagged "wontfix" and security tag removed? Either way is fine with me. If the underlying problem -- passing around buffer addresses without the corresponding length -- is tracked somewhere else (mayb

Bug#335817: [EMAIL PROTECTED]: Bug#335817: wordpress: SECURITY : Contains an insecure version of class.snoopy]

2005-10-31 Thread Florian Weimer
* Florian Weimer: > * Kai Hendry: > >> On 2005-10-26T00:40-0700 Matt Mullenweg wrote: >>> >I need a Wordpress release with the updated "Snoopy version 1.2.1. ASAP. >>> Could you confirm this affects WP? We use an older version of Snoopy >>> that

Bug#336545: mailman: subscribing does not work

2005-10-31 Thread Florian Weimer
* Kristis Makris: > After checking permissions, settings, manpages, documentation, etc, > I can't find out what the problem is. There should be a tool that > administers mailmain with minimum effort from the operator. Else, > the mailing list tool is useless. Mailman's log files in /var/log/mailm

Bug#336545: mailman: subscribing does not work

2005-10-31 Thread Florian Weimer
* Kristis Makris: >> Mailman's log files in /var/log/mailman typically contain enough >> information to figure out what's going on. Could you share them, >> please? > > Thanks Florian. I've attached the files. subscribe shows that just last > night I t

Bug#336645: PHP 4.4.1 fixes security bugs

2005-10-31 Thread Florian Weimer
Package: php4 Tags: security Severity: grave The Hardened-PHP project has disclosed several security vulnerabilites:

Bug#336654: PHP 5.0.5 fixes security bugs

2005-10-31 Thread Florian Weimer
Package: php5 Tags: security Severity: grave The Hardened-PHP project has disclosed several security vulnerabilites:

Bug#336645: PHP 4.4.1 fixes security bugs

2005-10-31 Thread Florian Weimer
* Florian Weimer: > <http://www.hardened-php.net/advisory_182005.77.html> This appears to be a variant of CVE-2002-1954, although public information is scarce at this stage. See the discussion on full-disclosure and various other places. -- To UNSUBSCRIBE, email to [EMAIL PROTECTE

Bug#304996: [amarok] crash in case of network unavailability

2005-10-31 Thread Florian Lohoff
amarok crash. I have never experienced this kind of crash at work where plenty bandwidth is available. It is easily reproducible for me. Running rsync - on next track change amarok crashes within the first minute. Flo -- Florian Lohoff [EMAIL PROTECTED] +49-171-2280134

Bug#336654: Acknowledgement (PHP 5.0.5 fixes security bugs)

2005-10-31 Thread Florian Weimer
retitle 336654 PHP 5.0.5 contains unfixed security bugs thanks Unfortunately, PHP 5.0.5 is the old version, and a new one hasn't been released today, even though the reported bugs apply to PHP 5. -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EM

Bug#336645: PHP 4.4.1 fixes security bugs

2005-11-01 Thread Florian Weimer
* Steve Langasek: > However, in reading over the description of the vulnerabilities, I don't > really see any grounds for regarding these as grave securty bugs. The most > severe of these problems, 202005.79, only has a significant impact when > register_globals is set in the PHP environment -- a

Bug#336809: xmms-crossfade: build bmp plugin as well

2005-11-01 Thread Florian Ernst
Package: xmms-crossfade Severity: wishlist On Wed, 26 Oct 2005 07:49:04 -0200, Rogério Brito wrote: > On Oct 24 2005, David Moreno Garza wrote: > > On Mon, 2005-10-24 at 08:44 +0200, Martin Waitz wrote: > > > the configure script checks for both XMMS and BEEP. But I haven't > > > tested that yet.

Bug#336838: libnet-ssleay-perl: Net::SSLeay::get_https can't load shared libraries

2005-11-01 Thread Florian Ragwitz
tag 336838 +unreproducable thanks On Tue, Nov 01, 2005 at 11:31:21AM -0500, S. Porth wrote: > Package: libnet-ssleay-perl > Version: 1.25-1.1 I guess that bug was found in -2? > Severity: important > > > Calling Net::SSLeay::get_https produces the following errors: > > CTX_new 3076: 1 - error

Bug#323527: Doesn't FTBFS here...

2005-11-01 Thread Florian Ernst
Hello *, blender_2.37a-1 builds fine in an unstable chroot using pbuilder. Apparently it now uses an internal copy of openal, consequently not showing a Depends on libopenal anymore. Assuming 2.36-1 in stable still builds fine as well and taking into account that 2.36-1 has been removed from test

Bug#330895: blender: Arbitrary code execution when importing a .bvh file

2005-11-01 Thread Florian Ernst
e/scripts/bvh_import.py.diff?r1=1.4&r2=1.5&cvsroot=bf-blender> +in that it doesn't provide the new checks introduced therein; +for reference, this is CVE-2005-3302 - closes: #330895 + + -- Florian Ernst <[EMAIL PROTECTED]> Tue, 1 Nov 2005 17:41:53 +0100 + blender (2.

Bug#336977: ftp.debian.org: Please remove crip

2005-11-01 Thread Florian Ragwitz
Package: ftp.debian.org Severity: normal Please remove the crip package. There are better alternatives, the interface sucks and the code is a bit crappy. TIA, Flo -- System Information: Debian Release: testing/unstable APT prefers unstable APT policy: (500, 'unstable'), (1, 'experimental') A

Bug#336978: ITP: frown -- a parser generator for Haskell 98

2005-11-01 Thread Florian Ragwitz
On Wed, Nov 02, 2005 at 01:17:25AM +0100, Arjan Oosting wrote: > * Package name: frown > Version : 0.6 > Upstream Author : Ralf Hinze <[EMAIL PROTECTED]> > * URL : http://www.informatik.uni-bonn.de/~ralf/frown/index.html > * License : GPL version 2 > Descriptio

Bug#328423: must be moved from recommeds to suggests

2005-11-02 Thread Florian Weimer
* Luca Capello: > I'm in the process of debianize some CL software [1] and I've the same > problem as bug #328423: some extra features of the package needs other > packages to be installed, so I don't know if the package should use > Suggests or Recommends. Use Recommends: if the functionality ad

Bug#337027: libnet-ssleay-perl: TLS dialogue fails with a protocol version error

2005-11-02 Thread Florian Ragwitz
On Fri, Oct 28, 2005 at 01:28:13PM +0200, Alessandro Morelli wrote: > When smbldap-tools (0.9.1-2) is trying to contact a slapd server using TLS, > the operation fails. > > The server (slapd_2.2.26-4.0.1 linked with libssl0.9.8_0.9.8a-2) refuses > to accept the client certificate, signalling: >

Bug#336838: libnet-ssleay-perl: Net::SSLeay::get_https can't load shared libraries

2005-11-02 Thread Florian Ragwitz
On Tue, Nov 01, 2005 at 04:10:09PM -0500, Sean Porth wrote: > I did a bit more troubleshooting and came up with a very strange > thing. > > Using the simple script I attached with version 1.25-1.1, that error > doesn't appear on the 1st attempt to get_https. > > Same script with version 1.25-2, a

Bug#336342: Clarify permitted epoch values

2005-11-03 Thread Florian Weimer
retitle 336342 Clarify permitted epoch values thanks * Florian Weimer: > Package: debian-policy > Version: 3.6.2.1 > Severity: normal > > In section 5.6.12, the permitted epoch values are not specified > precisely. Large epochs tend to cause problems for some tools, for >

Bug#337281: sextractor: Provide: sextractor-doc

2005-11-04 Thread Florian Ernst
On Thu, Nov 03, 2005 at 11:48:47AM -0500, Justin Pryzby wrote: > This is a reminder for myself to edit debian/control for the next > upload. I intend to Provide: sextractor-doc such that users of > previous sextractor packages (by me, with -doc package split by > Florian) will have

Bug#335476: nscd: Caches old IP-address

2005-11-14 Thread Florian Weimer
* Dave Love: > Florian Weimer <[EMAIL PROTECTED]> writes: > >> The current code tries to honor TTLs. It might be sufficient to set a >> zero (or very low) TTL for entries coming from /etc/hosts. > > Does `current' mean in the latest Debian package? Yes. >

Bug#323527: FTBFS: Invalid conversions and undeclared function

2005-11-15 Thread Florian Ernst
retitle 323527 uses internal copy of openal # severity could possibly be lowered even further severity 323527 important tags 323527 - patch found 323527 2.37a-1 notfound 323527 2.36-1 thanks [EMAIL PROTECTED] BCC'd On Tue, 16 Aug 2005 17:06:45 -0700, Matt Kraai wrote: > Package: blender > Version:

Bug#338934: parrot - FTBFS on s390: Segmentation fault

2005-11-15 Thread Florian Ragwitz
On Tue, Nov 15, 2005 at 11:24:32AM +0100, Bastian Blank wrote: > On Tue, Nov 15, 2005 at 01:45:54AM +0100, Florian Ragwitz wrote: > > I'm aware of the unportability of parrot and working on it. > > Unfortunately I don't have a s390 machine where I can log into > > cu

Bug#339311: libnet-ldap-perl: Argument "" isn't numeric in addition

2005-11-15 Thread Florian Ragwitz
Hello Graham, a user of the debian package of Net::LDAP, which I maintain, reported the following bug to me. Please take a look at it and see how it could be fixed. Please also keep Cc'ing [EMAIL PROTECTED] and the submitter of the bug. TIA, Flo, On Tue, Nov 15, 2005 at 01:37:52PM +0100, Yann

Bug#339330: sawfish: amarok messes up sawfish's window handling & decorations

2005-11-15 Thread Florian Laws
per decorations. (I'm using the "arctic" theme) Feel free to reassign this bug if it is in fact a bug of a different package, but I feel at least the fact that the window decorations of other apps get messed up too is a bug of the window manager. Thanks in advance, Florian -- Syst

Bug#339337: db4.2: Please compile with -D__USE_GNU

2005-11-15 Thread Florian Weimer
* Joerg Wendland: > benefit from that. Using DB_ENV->set_flags(DB_DIRECT_DB) for example > yields the following error: > > direct I/O is not supported by this platform > > But it definitely is. If you compile the package with -D__USE_GNU, > O_DIRECT will be defined in {asm,bits}/fcntl.h and db4.

Bug#339360: lintian: typo in package-name-doesnt-match-sonames

2005-11-15 Thread Florian Ernst
Package: lintian Version: 1.23.13 Severity: minor Tags: patch Dear lintian maintainers, some copy and paste error seems to have occurred, please see the attached patch. Cheers, Flo diff -Nru /tmp/lydFnlLX6e/lintian-1.23.13/checks/binaries.desc /tmp/1K7JWy3XIz/lintian-1.23.14/checks/binaries.des

Bug#339361: ITP: libcdg123 -- libcdg123 CD+G data decoder library

2005-11-15 Thread Florian Ernst
Package: wnpp Severity: wishlist Owner: Florian Ernst <[EMAIL PROTECTED]> * Package name: libcdg123 Version : 0.0.3 Upstream Author : Miguel Revilla Rodriguez <[EMAIL PROTECTED]> * URL : http://sourceforge.net/projects/cdg123 * License : GPL

Bug#335881: Bug cause

2005-11-16 Thread Florian Weimer
This bug is caused by a change in GAS which makes it prefer shorter instruction sequences: 80580c1: 8d 14 52lea(%edx,%edx,2),%edx 80580c4: 8d ac 95 17 00 00 00lea0x17(%ebp,%edx,4),%ebp 80580cb: 89 c2 mov%eax,%edx 80580cd:

Bug#335881: Patch

2005-11-16 Thread Florian Weimer
> The first few instruction bundles are not 12 bytes long, as required, > but 11 bytes, with catastrophic consequences. I will see what can be > done about this. Technically, this is not a GAS bug. Below is a first attempt at a patch. It doesn't pass the test suite (but debian/rules doesn't det

Bug#338934: parrot - FTBFS: Segmentation fault

2005-11-16 Thread Florian Ragwitz
tag 338934 + confirmed fixed-upstream thanks I fixed this bug in the SVN tree, as well as the hppa and ia64 build failures. I currently work on mips and mipsel. Regards, Flo -- BOFH excuse #94: Internet outage signature.asc Description: Digital signature

Bug#339126: parrot: manpage versions says "$Revision $"

2005-11-16 Thread Florian Ragwitz
tag 339126 + confirmed fixed-upstream thanks Hello, $Revision$ is not a cvs artifact. It can also be used by svn when svn:keywords is set accordingly. Unfortunately SVN doesn't substitute it because of the space between Revision and $. I fixed that in the SVN tree so this bug will be fixed with t

Bug#301312: uae: Another new upstream version

2005-11-17 Thread Florian Ernst
tags 301312 pending thanks [EMAIL PROTECTED] BCC'd On Fri, 25 Mar 2005 07:39:34 +0100, Georges Seguin wrote: > There's a new upstream version (0.8.27) since 2005-01-07, available at > http://www.rcdrummond.net/uae/ This version is now at 0.8.28. Richard Drummund and me just started working on get

Bug#326383: Bug#339663: bird NMU for RC bugs

2005-11-18 Thread Florian Lohoff
an be quite involved, but that's > probably something you should take a look at next time you upload. Thanks for dealing with this. Newer upstream version will follow later ... Flo -- Florian Lohoff [EMAIL PROTECTED] +49-171-2280134

Bug#339771: mtools: new upstream release available (3.9.10, v20050302)

2005-11-18 Thread Florian Ernst
Package: mtools Severity: wishlist Dear maintainers, a new upstream release 3.9.10 is available as of 2005-03-02, please update the package when you think it is due time. Cheers, Flo signature.asc Description: Digital signature

Bug#339774: docbook: new stable upstream release available (4.4, 2005-01-27), unstable releases as well

2005-11-18 Thread Florian Ernst
Package: docbook Severity: wishlist Dear maintainer, as of 2005-01-27 there is a new upstream release 4.4 available at . The most recent release appears to be 4.5CR1 from 2005-06-29 at . Please update t

Bug#339776: imagemagick: new upstream release available (6.2.5-4, 2005.10.31)

2005-11-18 Thread Florian Ernst
Package: imagemagick Version: 6:6.2.4.5-0.2 Severity: wishlist Dear maintainer, as of 2005.10.31 there is a new upstream release 6.2.5-4 available eg. from . However, beware, once more there seem to be various API and (C-)ABI changes without

Bug#339778: lilo: new upstream release available (22.7.1, 17-Sep-2005)

2005-11-18 Thread Florian Ernst
Package: lilo Severity: wishlist Dear maintainers, as of 17-Sep-2005 there is a new upstream release 22.7.1 available . Please update the package when you think it is due time. Cheers, Flo signature.asc Description: Digital signature

Bug#339771: mtools: new upstream release available (3.9.10, v20050302)

2005-11-18 Thread Florian Ernst
On Fri, Nov 18, 2005 at 07:21:39PM +0100, Florian Ernst wrote: > a new upstream release 3.9.10 is available as of 2005-03-02, please > update the package when you think it is due time. Forgot to add: the following changes seem to make an update worthwhile... | Support for multiple

Bug#339780: linux86: new upstream release available (0.16.17, 2005-01-23)

2005-11-18 Thread Florian Ernst
Package: linux86 Severity: wishlist Dear maintainer, as of 2005-01-23 there is a new upstream release 0.16.17 available at . Please update the package when you think it is due time. Cheers, Flo signature.asc Description: Digital signature

Bug#339781: icon: new upstream release available (9.4.3, 2005.11.14)

2005-11-18 Thread Florian Ernst
Package: icon Severity: wishlist Dear maintainer, as of 2005-11-14 there is a new upstream release 9.4.3 available at . Please update the package when you think it is due time. Cheers, Flo signature.asc Description: Digital signature

Bug#339782: rp-pppoe: new upstream release available (3.7, 2005-11-17)

2005-11-18 Thread Florian Ernst
Package: rp-pppoe Severity: wishlist Dear maintainer, as of 2005-11-17 there is a new upstream release 3.7 available at . Please update the package when you think it is due time. Cheers, Flo signature.asc Description: Digital sig

Bug#339792: dictd: new upstream release available (1.10.2, 2005-09-06)

2005-11-18 Thread Florian Ernst
Package: dictd Severity: wishlist Dear maintainer, as of 2005-09-06 there is a new upstream release 1.10.2 available at . Please update the package when you think it is due time. Cheers, Flo signature.asc Description: Digital signatur

Bug#339800: libjcode-pm-perl: new upstream release available (2.03, 07 Jul 2005)

2005-11-18 Thread Florian Ernst
Package: libjcode-pm-perl Severity: wishlist Dear maintainer, as of 07 Jul 2005 there is a new upstream release 2.03 available at . Please update the package when you think it is due time. Cheers, Flo signature.asc Description: Digital signature

Bug#339805: razor: new upstream release available (2.77, Aug 15 2005)

2005-11-18 Thread Florian Ernst
Package: razor Severity: wishlist Dear maintainer, as of Aug 15 2005 there is a new upstream release 2.77 available at . Please update the package when you think it is due time. Cheers, Flo signature.asc Description: Digital signature

Bug#339807: libgii: new upstream release available (0.9.2)

2005-11-18 Thread Florian Ernst
Package: libgii Severity: wishlist Dear maintainer, a new upstream release 0.9.2 is available at . BTW, the same page reads: """Linux : Debian Packages of the old stable GGI 2.0.x releases are available in all the current debian versions (stable,

Bug#340024: developers-reference: "6.1.1 Helper scripts" is outdated wrt "Debian menu update and /usr/share/menu transition"

2005-11-20 Thread Florian Ernst
Package: developers-reference Version: 3.3.6 Severity: normal Tags: patch With respect to the "Debian menu update and /usr/share/menu transition" as outlined in the chapter "6.1.1 Helper scripts" appears to be outdated. The att

Bug#331108: ITA: xmltv

2005-11-20 Thread Florian Ernst
On Mon, 24 Oct 2005 23:40:11 +0100, Chris Butler wrote: > I would be happy to take xmltv off your hands. I use it all the time for > my mythtv setup. It looks like you forgot the actual retitling as part of the proper procedure. Are you still interested in this? Just wondering... Cheers, Flo s

Bug#340153: sysutils: new upstream releases available; package split?

2005-11-21 Thread Florian Ernst
Package: sysutils Severity: wishlist Dear maintainer, there are new upstream releases available of each of the programs contained in the sysutils package: procinfo-18 at memtester-4.0.5 at bogomips-1.4.1 at

Bug#339108: units: new upstream release available (1.85, 20-May-2005)

2005-11-21 Thread Florian Ernst
Hello again, just wondering, as I noticed the only answer you seem to have given to a bugreport about units within the last year that wasn't sort of an auto-reply was in bug#320221, whether you are still interested in this package... However, the RC bug is only RC for about a week, and the new up

Bug#264672: #264672 already fixed in Sarge and later

2005-11-21 Thread Florian Ernst
Browsing through the code of 0.67-1 and 0.69-2 I see upstream basically covers this issue via a different implementation of sanity checks, so I guess this bug can be closed. Using the version tracking feature of the BTS a mail to <[EMAIL PROTECTED]> with the body starting with | Package: mtr | Ver

Bug#267517: current mtr seems to skip over unresponsive hosts again

2005-11-21 Thread Florian Ernst
On Mon, 23 Aug 2004 14:34:12 +1000, [EMAIL PROTECTED] wrote: > In earlier versions, mtr would skip over unresponsive routers marking them ??? > and still ultimately tracing to the specified destination (where possible) > > In 0.63-1, however, the trace stops at the very first host that fails to >

Bug#259906: #259906 fixed as of 0.68

2005-11-21 Thread Florian Ernst
According to upstream this patch has been included starting with 0.68, and indeed 0.69 still has the patched code, so I guess this bug could simply be closed using the version tracking feature of the BTS via a mail to <[EMAIL PROTECTED]> starting with | Package: mtr | Version: 0.69-1 | and adding a

Bug#257981: rather "FTBFS on amd64" than "broken Build-Depends automaken"

2005-11-21 Thread Florian Ernst
As mtr >= 0.67-1 doesn't show a Build-Depends on automaken (or automake*, FWIW) anymore, this bug rather seems to deal with mtr FTBFS on amd64, so it should possibly be retitled accordingly and will need to be upgraded to RC severity once amd64 hits the archives. Just for the record, upstream link

Bug#197479: mtr: [PATCH] avoid gcc warnings with "-W -Wall -Wstrict-prototypes"

2005-11-21 Thread Florian Ernst
On Sun, 15 Jun 2003 13:09:09 +0200, Roland Illig wrote: > mtr-0.54-gcc-warnings.patch (text/x-c, attachment) FWIW, all parts (or equivalent patches) are applied in 0.69, except for the errno fix to dns.c and the complete patch to getopt.h, so upstream has followed the spirit of this patch and meth

Bug#340171: hdparm: new upstream release available (6.3, October 18 2005)

2005-11-21 Thread Florian Ernst
Package: hdparm Version: 6.1-7 Severity: wishlist Dear maintainer, as of October 18 2005 there is a new upstream release 6.3 available at . Please update the package when you think it is due time. However, apparently you haven't conta

Bug#300807: libhtml-tableextract-perl: version 2.06

2005-11-21 Thread Florian Ernst
On Sat, 22 Oct 2005 00:33:03 +0200, [EMAIL PROTECTED] wrote: > Ross Peachey wrote: > > OK - I'll get onto it ASAP. > > If by ASAP you mean a month, you may want to orphan the package. Or, before orphaning, please let me take over maintenance, as I'm personally interested to see this package updat

Bug#326354: please rebuild with libreadline5-dev as build dependency

2005-11-21 Thread Florian Ernst
On Fri, 2 Sep 2005 22:40:52 +0200, Matthias Klose wrote: > The package depends/recommends libreadline4. This version > will be removed from the archive in the near future. > Please change your build dependencies to > > libreadline5-dev | libreadline-dev > > Please raise the severity of this

Bug#174858: debdiff: make control file comparison work with two .changes files?

2005-11-21 Thread Florian Ernst
FWIW, I "third" Colin's proposal to run wdiff when debdiff-ing *.changes containing multi-binary packages. As you didn't comment on this I wonder whether the patch Robert supplied looks acceptable to you or whether you need a different one... Cheers, Flo signature.asc Description: Digital signa

Bug#340243: selecting a Smart Playlist crashes amarok

2005-11-21 Thread Florian Laws
Package: amarok Version: 1.3.6-1 Severity: normal Selecting one of the "Smart Playlists" in the "Playlists" sidebar causes amarok to crash. The automatically generated backtrace is included below. Thanks, Florian DEBUG INFORMATION === Engine: xine-engin

Bug#340282: [CVE-2005-1790] DoS against Mozilla-based browsers

2005-11-22 Thread Florian Weimer
Package: mozilla-browser Version: 1.7.12-1 Severity: grave Tags: security An exploit for CVE-2005-1790, a bug originally classified as IE-only, causes Mozilla-based browsers to crash. See the proof of concept exploit (for IE) at: The

Bug#340283: [CVE-2005-1790] DoS against Mozilla-based browsers

2005-11-22 Thread Florian Weimer
Package: mozilla-firefox Version: 1.0.7-1 Severity: grave Tags: security An exploit for CVE-2005-1790, a bug originally classified as IE-only, causes Mozilla-based browsers to crash. See the proof of concept exploit (for IE) at: The

Bug#340283: [CVE-2005-1790] DoS against Mozilla-based browsers

2005-11-22 Thread Florian Weimer
severity 340283 grave thanks * Mike Hommey: > severity 340283 important > thanks > > Until it is proven that the crash can lead to an exploit, it's not > critical. A crash which can be triggered just by visiting some web site *is* an exploit. Furthermore, according to the release criteria for e

Bug#340283: [CVE-2005-1790] DoS against Mozilla-based browsers

2005-11-22 Thread Florian Weimer
* Mike Hommey: > If you think a bare crash needs severity grave, then please go ahead > and raise severity of Most of these bugs are not exploitable, i.e. an attacker cannot use them to deliberately cause data loss. > #270822, Not reproducible, non-standard configuration, not exploitable. > #

Bug#340324: lmms hangs on startup

2005-11-22 Thread Florian Ragwitz
On Tue, Nov 22, 2005 at 06:44:24PM +0100, Stijn Declercq wrote: > I installed lmms but it fails to work > The first time i open it, i'm getting a setup screen, > but when it's finished it hangs on the splash screen , when the > message 'creating new song' appears. Do you have any special setup WRT

Bug#340418: wml/developer.wml: generates wrong markup via html_table function

2005-11-23 Thread Florian Ernst
Package: qa.debian.org Severity: minor Tags: patch Hello there, the code currently given generates markup such as | --- developer.wml.orig 2005-11-23 12:36:10.0 +0100 +++ developer.wml 2005-11-23 12:37:22.0 +0100 @@ -360,7 +360,7 @@ */ function html_table($header, $data,

Bug#340536: ftp.debian.org: Please change overrides for libcdg123-dev package to libdevel section

2005-11-23 Thread Florian Ernst
Package: ftp.debian.org Severity: wishlist I think the libdevel section is the natural place for a -dev package to be, yet somehow this was missed previously, sorry about that. Cheers, Flo signature.asc Description: Digital signature

Bug#340566: ITA: php4-pear-log -- Log module for PEAR

2005-11-24 Thread Florian Ernst
On Thu, 24 Nov 2005 03:31:43 -0500, Eddie Tejeda wrote: > I am adopting php4-pear-log. If you want to adopt a package please retitle the corresponding bugreport as explained on . Opening a new report is neither necessary nor recommended. However, please note tha

Bug#328958: RFA: libmusicbrainz-2.1: Second generation incarnation of the CD Index -- optional

2005-11-24 Thread Florian Ernst
On Sun, 18 Sep 2005 14:02:42 +0200, Andreas Rottmann wrote: > I'd like someone adopt libmusicbrainz; [...] > from my side. Maintainance of libmusicbrainz package is not very > time-consuming, you > should be familiar with C++ though. I guess this RFA actually refers to both libmusicbrainz-2.1 an

Bug#281250: Are you out there?

2005-11-25 Thread Florian Ernst
Hello Matt, I'm wondering whether you are still actively working on these packages... The thing is I'm pretty interested in seeing libio-string-perl and libmailtools-perl updated, so if you currently lack the time I can offer to adopt both of them... Cheers, Flo signature.asc Description: Digit

Bug#333478: libsamplerate0-dev: New upstream version available

2005-11-25 Thread Florian Ernst
Hello Anand, On Wed, 12 Oct 2005 14:07:10 +0800, Paul wrote: > Version 0.1.2 is available, and has (among other things) quote (from the > website): > Version 0.1.2 (Sep 12 2004) Callback API reset bug fix. Just wondering, are there any issue that prevent packaging this? Considering this seems to

Bug#300807: Are you out there?

2005-11-25 Thread Florian Ernst
Hello Ross, I'm wondering whether you are still actively working on these packages... The thing is I'm pretty interested in seeing libfinance-quote-perl and libhtml-tableextract-perl updated, so if you currently lack the time I can offer to adopt both of them... Cheers, Flo signature.asc Descri

Bug#329556: Are you out there?

2005-11-25 Thread Florian Ernst
Hello Sander, I'm wondering whether you are still actively working on this package... The thing is I'm pretty interested in seeing libhtml-template-perl updated, so if you currently lack the time I can offer to adopt it... Cheers, Flo signature.asc Description: Digital signature

Bug#288386: libdvdnav: New version available

2005-11-25 Thread Florian Ernst
Hello Philipp, On Mon, 03 Jan 2005 13:33:03 +0100, Dirk Meul wrote: > there is a new version (0.1.10) at http://dvd.sourceforge.net/ > available. Please upgrade. Thank you. Just wondering, are there any issue that prevent packaging this? However, just wondering a bit more: have you maybe lost in

Bug#338211: Are you out there?

2005-11-25 Thread Florian Ernst
Hello Jay, I'm wondering whether you are still actively working on this package... The thing is I'm pretty interested in seeing libcurses-perl updated, so if you currently lack the time I can offer to adopt it... Cheers, Flo signature.asc Description: Digital signature

Bug#275971: Seems to have problems with asymetric routing? Works in 0.48.

2005-11-25 Thread Florian Ernst
On Tue, 12 Oct 2004 10:03:31 +0200, Christian Hammers wrote: > On 2004-10-12 Rogier Wolff wrote: > > WHAT'S NEW? > > v0.65 Dancer Vesperman noted that mtr no longer traces past > > Robert still has to make/upload Debian packages of version 0.65. Umm, he did, sort of, so I guess this bug can be

Bug#65005: #67516 and #65005 are the same bug, should probably be merged

2005-11-25 Thread Florian Ernst
A mail to <[EMAIL PROTECTED]> with | package mtr | forwarded 67516 [EMAIL PROTECTED] | merge 67516 65005 | thanks would suffice. HTH, Flo signature.asc Description: Digital signature

Bug#333478: libsamplerate0-dev: New upstream version available

2005-11-26 Thread Florian Ernst
On Sat, Nov 26, 2005 at 09:38:13AM +1100, Anand Kumria wrote: > On Fri, Nov 25, 2005 at 09:38:17PM +0100, Florian Ernst wrote: > > Just wondering, are there any issue that prevent packaging this? > > No, nothing. In fact it was uploaded previously: [...] > > The upload was

Bug#329556: Are you out there?

2005-11-26 Thread Florian Ernst
On Sat, Nov 26, 2005 at 10:42:05AM +0100, Sander Smeenk wrote: > Quoting Florian Ernst ([EMAIL PROTECTED]): > > > I'm wondering whether you are still actively working on this > > package... The thing is I'm pretty interested in seeing > > libhtml-template-perl

Bug#340863: [EMAIL PROTECTED] acts as a mail amplifier

2005-11-26 Thread Florian Weimer
Package: qa.debian.org I accidentally discovered that [EMAIL PROTECTED] acts as a mail amplifier. A single messagge to [EMAIL PROTECTED], containing lots of commands of the form subscribe ada-mode subscribe apache2 subscribe asterisk ... causes a mail message to be sent for each of these comman

Bug#340536: acknowledged by developer (Bug#340536: fixed)

2005-11-26 Thread Florian Ernst
reopen 340536 thanks [EMAIL PROTECTED] BCC'd On Wed, Nov 23, 2005 at 04:48:06PM -0800, Debian Bug Tracking System wrote: > This is an automatic notification regarding your Bug report > #340536: ftp.debian.org: Please change overrides for libcdg123-dev package to > libdevel section,

Bug#312293: ITP: cl-utilities -- a Common Lisp library of common functions

2005-06-07 Thread Florian Weimer
* Peter Van Eynde: > Package: wnpp > Severity: wishlist > Owner: Peter Van Eynde <[EMAIL PROTECTED]> > > * Package name: cl-utilities > Version : 1.1 > Upstream Author : Peter Scott > * URL : http://common-lisp.net/project/cl-utilities/ > * License : public dom

Bug#312367: gcc-3.3: D support

2005-06-07 Thread Florian Weimer
> GCC support the D language with GDC > (http://home.earthlink.net/~dvdfrdmn/d). Can the debian package be built > with GDC ? Will the D front end be converted to the tree-ssa framework? Otherwise it's going to be obsolete in the forseeable future. -- To UNSUBSCRIBE, email to [EMAIL PROTECTED]

Bug#312458: kernel-patch-suspend2: Latest Sarge kernel 2.6.8-16 unsupported

2005-06-08 Thread Florian Boelstler
/suspend2 failed. Regards, Florian -- Package-specific info: --- debug info: --- partitions: major minor #blocks name 3 0 78150744 hda 3 1 56196 hda1 3 2292 hda2 3 3 16008772 hda3 3 4 1 hda4 3 5 52010406 hda5 3 6

Bug#312670: mtr: debian/copyright doesn't list where the upstream sources were obtained

2005-06-09 Thread Florian Ernst
Package: mtr Version: 0.69-1 Severity: serious Justification: Policy 12.5 Copyright information Hello Robert, your newly created debian/copright violates a "must" directive of the Debian Policy, please see : | In addition, the copyr

Bug#268949: fix for wrong urlencoding of filenames

2005-06-09 Thread Florian Reitmeir
Package: gallery Version: 1.5-1 Followup-For: Bug #268949 Hi, filenames with non-ascii characters break. Problem is a function in classes/Image.php which returns the html img statement non-escaped. Is this a security problem for broken clients? Here a small patch, which looks like to solves

Bug#293667: [sh1tscared@hotmail.com: Woody to sarge failure]

2005-06-09 Thread Florian Ernst
Hello Matthias, it looks like your preinst utilizes db_get before sourcing the debconf library, thus preventing any upgrade from Woody which shipped mailscanner_3.13.2-4. If so, shouldn't the severity of this bug be raised? Find below the message that pointed me to the problem, see

Bug#312756: ftape-util: Typo in debconf-template

2005-06-09 Thread Florian Zumbiehl
Package: ftape-util Version: 1:1.09.2001.08.13-0.3 Severity: normal | If in doubdt say 'yes' should probably read: | If in doubt say 'yes' -- System Information: Debian Release: 3.1 APT prefers testing APT policy: (500, 'testing') Architecture: i386 (i686) Kernel: Linux 2.4.31 Locale: LANG

Bug#312792: ssh-agent removes socket when it finds it in use

2005-06-09 Thread Florian Zumbiehl
Package: ssh Version: 1:3.8.1p1-8.sarge.4 Severity: important When specifying a socket to use on the command line of ssh-agent, if that socket is already in use, that is reported as an error and subsequently, just before quitting, it is changed to not being in use anymore (that is, it's unlinked)

Bug#312955: elinks: doesn't clear window title upon exit

2005-06-10 Thread Florian Zumbiehl
Package: elinks Version: 0.10.4-7 Severity: normal When using elinks in an xterm, it changes the title of the terminal window. When quitting elinks by pressing Q, it doesn't change the window title back, as, for example, vim does. -- System Information: Debian Release: 3.1 APT prefers testing

Bug#312988: ifupdown: [patch] can't configure ipv6 link-local addresses as gateways

2005-06-10 Thread Florian Zumbiehl
Package: ifupdown Version: 0.6.7 Severity: normal The patch probably says it all - the device through which to route should be specified on the route command line so that link-local addresses as gateways aren't ambiguous. --

Bug#127686: [ppp] lcp echo reply / RFC Standard

2005-06-11 Thread Florian Lohoff
y be sent in the LCP Opened state. Echo-Request and Echo-Reply packets received in any state other than the LCP Opened state SHOULD be silently discarded. - Sending LCP Echo Requests is a "Good thing to do&

Bug#277757: Still present in 7.4.8-8

2005-06-14 Thread Florian Weimer
reopen 277757 thanks This bug is still present in 7.4.8-8. The upload apparently only fixed this bug for libpq4. -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

<    1   2   3   4   5   6   7   8   9   10   >