Bug#733279: scilab: missing changelog entries

2013-12-27 Thread Jonathan Wiltshire
Package: scilab Version: 5.4.0-alpha-1-1~exp1 Severity: normal Hi, Changelog entries for scilab versions 5.3.3-5 through 5.3.3-10 are missing. Apart from the serious loss of change information, this causes misleading information in the BTS and other tools. Please add the missing changelog entrie

Bug#733642: pu: package nut/2.6.4-2.3

2013-12-30 Thread Jonathan Wiltshire
-2.6.4/debian/changelog 2013-12-30 15:37:59.0 + @@ -1,3 +1,10 @@ +nut (2.6.4-2.3+deb7u1) stable; urgency=low + + * Non-maintainer upload. + * Increase USB timeout to 5 seconds (Closes: #720332) + + -- Jonathan Wiltshire Mon, 30 Dec 2013 15:37:11 + + nut (2.6.4-2.3) unstable; urgen

Bug#733646: missing debian/changelog history

2013-12-30 Thread Jonathan Wiltshire
Source: nut Version: 2.6.4-2 Severity: normal debian/changelog history is missing for versions 2.6.4-2.1 through 2.6.4-2.3 in the package in Jessie and sid. Apart from the missing information, this causes other effects like wrong BTS graphs (see #720332). -- System Information: Debian Release: 7

Bug#733642: pu: package nut/2.6.4-2.3

2013-12-31 Thread Jonathan Wiltshire
On 2013-12-31 00:03, Cyril Brulebois wrote: Jonathan Wiltshire (2013-12-30): Please accept this trivial fix for USB timeouts in nut. It's fixed upstream and in sid, and I've reproduced it in Wheezy on some of our client sites. The patch fixed the problem there with no other i

Bug#732842: pu: package libotr/3.2.1-1

2014-01-01 Thread Jonathan Wiltshire
Control: tag -1 pending On 2013-12-22 17:16, intrigeri wrote: Hi, Cyril Brulebois wrote (22 Dec 2013 16:51:49 GMT) : intrigeri (2013-12-22): May I upload libotr 3.2.1-1+deb7u1 to stable? Looks fine to me. Thanks, uploaded. Flagged for acceptance. Thanks, -- Jonathan Wiltshire

Bug#605271: RFP: php-calendar -- PHP PEAR package for building Calendar data structures

2010-11-28 Thread Jonathan Wiltshire
Package: wnpp Severity: wishlist -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 * Package name: php-calendar Version : 0.5.5 Upstream Author : Harry Fuecks, Lorenzo Alberton * URL : http://pear.php.net/package/Calendar/ * License : PHP Programming Lang: PHP

Bug#629003: fabric is prone to file-overwrite security issue(s).

2014-02-23 Thread Jonathan Wiltshire
ker/629003/ 2: <201101232332.11736.th...@debian.org> 3: http://deb.li/prsc Thanks, with his security hat on: -- Jonathan Wiltshire j...@debian.org Debian Developer http://people.debian.org/~jmw 4096R: 0xD3524C51 / 0A55 B7C5 1223

Bug#731956: RFH: logcheck

2014-01-20 Thread Jonathan Wiltshire
.debian.org/BSP/2014/01/gb/Monmouth 1: my time and that of my colleagues, that is; nothing material -- Jonathan Wiltshire Tiger Computing Ltd "Linux for Business" Tel: 01600 483 484 Web: http://www.tiger-computing.co.uk Follow us on Facebook: http://www.facebook.com/TigerComputing Registered

Bug#736245: /usr/sbin/ntp-wait: insufficient dependency on perl

2014-01-21 Thread Jonathan Wiltshire
Package: ntp Version: 1:4.2.6.p5+dfsg-2 Severity: important File: /usr/sbin/ntp-wait Hi, ntp Suggests: perl, but ships /usr/sbin/ntp-wait which requires it. This causes problems in unrelated packages, particularly during upgrades, which quite reasonably call ntp-wait in postinst and Depend on nt

Bug#736851: ppp: Please ship logcheck rules

2014-01-27 Thread Jonathan Wiltshire
Package: ppp Version: 2.4.5+git20130610-3 Severity: normal User: debian-rele...@lists.debian.org Usertags: bsp-2014-01-gb-Monmouth Logcheck is a package to filter system log events for the administrator. Its aim is to remove chatter from the log files, leaving only the events that the administrato

Bug#564063: logcheck-database: heartbeat daily informational stats report

2014-01-27 Thread Jonathan Wiltshire
Control: reassign -1 src:heartbeat Control: retitle -1 incorporate logcheck snippets Control: user debian-rele...@lists.debian.org Control: usertag -1 bsp-2014-01-gb-Monmouth Dear maintainer, Logcheck is a package to filter system log events for the administrator. Its aim is to remove chatter fro

Bug#688339: logcheck-database: dhcp: match IPv6-aware records, too

2014-01-27 Thread Jonathan Wiltshire
Control: reassign -1 src:isc-dhcp Control: retitle -1 incorporate logcheck snippets Control: user debian-rele...@lists.debian.org Control: usertag -1 bsp-2014-01-gb-Monmouth Dear maintainer, Logcheck is a package to filter system log events for the administrator. Its aim is to remove chatter from

Bug#732298: logcheck-database: dhclient diag message changed; updated rule to ignore it

2014-01-27 Thread Jonathan Wiltshire
Control: reassign -1 src:isc-dhcp-client Control: retitle -1 incorporate logcheck snippets Control: user debian-rele...@lists.debian.org Control: usertag -1 bsp-2014-01-gb-Monmouth Dear maintainer, Logcheck is a package to filter system log events for the administrator. Its aim is to remove chatt

Bug#732771: ignore subversion message "DIGEST-MD5 common mech free"

2014-01-27 Thread Jonathan Wiltshire
Control: reassign -1 libsasl2-modules Control: retitle -1 incorporate logcheck snippets Dear maintainer, Logcheck is a package to filter system log events for the administrator. Its aim is to remove chatter from the log files, leaving only the events that the administrator needs to deal with. Fil

Bug#731285: pu: package kexec-tools/1:2.0.3-1

2013-12-04 Thread Jonathan Wiltshire
Hi, On 2013-12-04 00:04, Khalid Aziz wrote: A debdiff of proposed changes is attached. Please go ahead. (For reference, the real bug is #708034.) -- Jonathan Wiltshire j...@debian.org Debian Developer http://people.debian.org

Bug#729747: pu: package apt-listbugs/0.1.8

2013-12-04 Thread Jonathan Wiltshire
ss you say I shouldn't bother... Please do. -- Jonathan Wiltshire j...@debian.org Debian Developer http://people.debian.org/~jmw 4096R: 0xD3524C51 / 0A55 B7C5 1223 3942 86EC 74C3 5394 479D D352 4C51 i have six years of s

Bug#729747: pu: package apt-listbugs/0.1.8

2013-12-06 Thread Jonathan Wiltshire
Control: tag -1 pending On 2013-12-04 21:24, Francesco Poli wrote: On Wed, 04 Dec 2013 14:04:41 + Jonathan Wiltshire wrote: [...] On 2013-11-16 16:43, Francesco Poli (wintermute) wrote: [...] > If you agree, I can ask my usual sponsor to upload the prepared > package to stable, s

Bug#731421: pu: package expat/2.1.0-1+deb7u1

2013-12-06 Thread Jonathan Wiltshire
tance, thanks. -- Jonathan Wiltshire j...@debian.org Debian Developer http://people.debian.org/~jmw 4096R: 0xD3524C51 / 0A55 B7C5 1223 3942 86EC 74C3 5394 479D D352 4C51 i have six years of solaris sysadmin experience, from

Bug#731735: pu: package glance/2012.1.1-5+deb7u1

2013-12-09 Thread Jonathan Wiltshire
n the changelog, then the BTS will find out about your upload. Thanks, -- Jonathan Wiltshire j...@debian.org Debian Developer http://people.debian.org/~jmw 4096R: 0xD3524C51 / 0A55 B7C5 1223 3942 86EC 74C3 5394 479D D352 4C51 i have six

Bug#687530: eglibc: CVE-2012-4412: strcoll integer / buffer overflow

2013-11-10 Thread Jonathan Wiltshire
ker/687530/ 2: <201101232332.11736.th...@debian.org> 3: http://deb.li/prsc Thanks, with his security hat on: -- Jonathan Wiltshire j...@debian.org Debian Developer http://people.debian.org/~jmw 4096R: 0xD3524C51 / 0A55 B7C5 1223

Bug#689423: eglibc: CVE-2012-4424: stack overflow in strcoll()

2013-11-10 Thread Jonathan Wiltshire
ker/689423/ 2: <201101232332.11736.th...@debian.org> 3: http://deb.li/prsc Thanks, with his security hat on: -- Jonathan Wiltshire j...@debian.org Debian Developer http://people.debian.org/~jmw 4096R: 0xD3524C51 / 0A55 B7C5 1223

Bug#729298: mwenext/mwdisext should grok /usr/local as well as /usr/share

2013-11-11 Thread Jonathan Wiltshire
Package: mediawiki-extensions Version: 2.11 Severity: wishlist Hi, The mwenext/mwdisext tools take no account of locally installed (i.e. non-packaged) extensions, so manual creation of symlinks is necessary. These tools should check for a local extension first, and fall back on /usr/share/... if

Bug#729629: mediawiki: CVE-2013-4567, CVE-2013-4568 and CVE-2013-4572

2013-11-15 Thread Jonathan Wiltshire
Thanks. Would you like DSAs prepared for these? -- Jonathan Wiltshire j...@debian.org Debian Developer http://people.debian.org/~jmw 4096R: 0xD3524C51 / 0A55 B7C5 1223 3942 86EC 74C3 5394 479D D352 4C51 i have six years of solaris

Bug#728461: pu: package nagios3/3.4.1-3+deb7u1

2013-11-15 Thread Jonathan Wiltshire
well? Please go ahead to Wheezy. I don't think there is a great need to use wheezy-updates as well. Thanks, -- Jonathan Wiltshire j...@debian.org Debian Developer http://people.debian.org/~jmw 4096R: 0xD3524C51 / 0A55 B7C5 1223

Bug#728763: pu: package starpu/1.0.1+dfsg-1

2013-11-15 Thread Jonathan Wiltshire
Control: tag -1 + confirmed Hi Samuel, Your message never made it to the list, because of the (understandably) large patch. Please go ahead with your proposed upload to Wheezy. Thanks, -- Jonathan Wiltshire j...@debian.org Debian Developer

Bug#729728: pu: package apt/0.9.7.9

2013-11-16 Thread Jonathan Wiltshire
age need to be updated + enum { Suite, Component, Version, Origin, Codename, Label, None } writeTo = None; + if (buffer[0] == ' ') + ; + #define APT_PARSER_WRITETO(X) else if (strncmp(#X, buffer, len) == 0) writeTo = X; + APT_PARSER_WRITETO(Suite) + APT_PARSER_W

Bug#729728: pu: package apt/0.9.7.9

2013-11-16 Thread Jonathan Wiltshire
On 2013-11-16 12:38, Adam D. Barratt wrote: Control: tags -1 + confirmed wheezy On 2013-11-16 12:20, Jonathan Wiltshire wrote: I prepared an update in stable fixing, primarily, #725483. At the suggestion of #debian-apt I include the patch for #723586 as well. Debdiff attached. With the

Bug#730343: dch: default urgency to medium

2013-11-24 Thread Jonathan Wiltshire
entries to medium. The reason for this, rather than changing britney, is that maintainers can artificially delay their package back to ten days for changes they know to be disruptive or in need of longer testing. Thanks, -- Jonathan Wiltshire j...@debian.org

Bug#728461: pu: package nagios3/3.4.1-3+deb7u1

2013-11-24 Thread Jonathan Wiltshire
Control: tag -1 pending On 2013-11-17 14:51, Jonas Meurer wrote: Am 15.11.2013 23:30, schrieb Jonathan Wiltshire: On 2013-11-01 14:45, Jonas Meurer wrote: the nagios3 package in wheezy suffers from at least one minor security bug and a regression. I prepared nagios3/3.4.1+deb7u1 for wheezy

Bug#730251: pu: package shutdown-at-night/0.10+deb7u1

2013-11-24 Thread Jonathan Wiltshire
I do agree your proposed patch is better than the current situation though.) -- Jonathan Wiltshire j...@debian.org Debian Developer http://people.debian.org/~jmw 4096R: 0xD3524C51 / 0A55 B7C5 1223 3942 86EC 74C3 5394 479D D352 4C51 i ha

Bug#752505: smbldap-tools: please backport fix to API in smbldap_tools.pm to stable

2014-06-24 Thread Jonathan Wiltshire
n.gna.org/viewcvs/smbldap-tools/trunk/smbldap_tools.pl?r1=123&r2=124 Please backport this fix to stable. I'm more than happy to handle this on your behalf if you'd rather. Thanks, -- Jonathan Wiltshire Tiger Computing Ltd "Linux for Business" Tel: 01600 483 484 Web: http://ww

Bug#680126: get-iplayer: should support access to ITV, RTÉ, ABC [Australia], CBC, ABC [US], NBC, CBS, DD India,…

2014-04-24 Thread Jonathan Wiltshire
Control: tag -1 wontfix Hi, Since get-iplayer previously had ITV Player support and it was dropped as unsustainable, I think this and the others in your list are unlikely to happen. They are not really in the scope of get-iplayer. Thanks, -- Jonathan Wiltshire

Bug#571120: pisa need python-reportlab >= 2.2

2014-03-25 Thread Jonathan Wiltshire
Package: python-pisa Version: 3.0.32-1 Followup-For: Bug #571120 Control: tag -1 upstream Bumping severity to RC, since with python-reportlab 3 in sid this package is now fatally broken. -- System Information: Debian Release: jessie/sid APT prefers testing APT policy: (990, 'testing'), (500

Bug#688331: boost1.42: CVE-2012-2677

2014-03-31 Thread Jonathan Wiltshire
et/tracker/688331/ 2: <201101232332.11736.th...@debian.org> 3: http://deb.li/prsc Thanks, with his security hat on: -- Jonathan Wiltshire j...@debian.org Debian Developer http://people.debian.org/~jmw 4096R: 0xD3524C51 / 0A55 B7C5 1223

Bug#748266: wheezy-pu: package python2.7/2.7.3-6+deb7u2

2014-05-21 Thread Jonathan Wiltshire
On 2014-05-19 15:45, Luis Alejandro Martínez Faneyth wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, On 18/05/14 16:31, Jonathan Wiltshire wrote: Hi, On 2014-05-15 16:37, Luis Alejandro Martínez Faneyth wrote: There is a serious bug in Wheezy that breaks the upgrade of python2.7

Bug#665720: iptables-persistent: unusable with systemd

2014-05-10 Thread Jonathan Wiltshire
al packages you have installed. Downgrading a little for this reason. Thanks, -- Jonathan Wiltshire j...@debian.org Debian Developer http://people.debian.org/~jmw 4096R: 0xD3524C51 / 0A55 B7C5 1223 3942 86EC 74C3 5394 479D D352 4C51 -- T

Bug#738403: oauth-signpost: diff for NMU version 1.2.1.2-1.2

2014-03-22 Thread Jonathan Wiltshire
tags 738403 + patch tags 738403 + pending thanks Dear maintainer, I've prepared an NMU for oauth-signpost (versioned as 1.2.1.2-1.2) and uploaded it to DELAYED/2. Please feel free to tell me if I should delay it longer. Regards. -- Jonathan Wiltshire

Bug#739139: python-fixtures: diff for NMU version 0.3.14-1.1

2014-03-23 Thread Jonathan Wiltshire
, and does not ignore the result (it was failing unnoticed before now). Regards. -- Jonathan Wiltshire j...@debian.org Debian Developer http://people.debian.org/~jmw 4096R: 0xD3524C51 / 0A55 B7C5 1223 3942 86EC 74C3 5394 479D D352

Bug#737204: zeroc-ice: diff for NMU version 3.5.1-5.2

2014-03-23 Thread Jonathan Wiltshire
tags 737204 + patch tags 737204 + pending thanks Dear maintainer, I've prepared an NMU for zeroc-ice (versioned as 3.5.1-5.2) and uploaded it to DELAYED/5. Please feel free to tell me if I should delay it longer. Regards. -- Jonathan Wiltshire

Bug#742498: RM: davical -- RoQA; RC-buggy, no maintainer activity, not in testing

2014-03-24 Thread Jonathan Wiltshire
Package: ftp.debian.org Severity: normal Please remove davical from sid. It has 5 RC bugs with no maintainer response, including FTBFS. It hasn't been uploaded since before Wheezy was released, and is broken with the version of postgresql in sid. It hasn't been in testing since last October. --

Bug#690151: claws-mail: CVE-2012-4507

2013-01-17 Thread Jonathan Wiltshire
ker/690151/ 2: <201101232332.11736.th...@debian.org> 3: http://deb.li/prsc Thanks, with his security hat on: -- Jonathan Wiltshire j...@debian.org Debian Developer http://people.debian.org/~jmw 4096R: 0xD3524C51 / 0A55 B7C5 1223

Bug#692130: vlc: CVE-2012-5470

2013-01-17 Thread Jonathan Wiltshire
/692130/ 2: <201101232332.11736.th...@debian.org> 3: http://deb.li/prsc Thanks, with his security hat on: -- Jonathan Wiltshire j...@debian.org Debian Developer http://people.debian.org/~jmw 4096R: 0xD3524C51 / 0A55 B7C5 1223 3942 86EC

Bug#637439: qtnx: stores keys world readable

2013-01-17 Thread Jonathan Wiltshire
/637439/ 2: <201101232332.11736.th...@debian.org> 3: http://deb.li/prsc Thanks, with his security hat on: -- Jonathan Wiltshire j...@debian.org Debian Developer http://people.debian.org/~jmw 4096R: 0xD3524C51 / 0A55 B7C5 1223 3942

Bug#654341: [CVE-2012-6076] inkscape reads .eps files from /tmp instead of the current directory

2013-01-17 Thread Jonathan Wiltshire
/654341/ 2: <201101232332.11736.th...@debian.org> 3: http://deb.li/prsc Thanks, with his security hat on: -- Jonathan Wiltshire j...@debian.org Debian Developer http://people.debian.org/~jmw 4096R: 0xD3524C51 / 0A55 B7C5 1223 3942

Bug#689075: CVE-2011-1005: safe level bypass

2013-01-17 Thread Jonathan Wiltshire
ker/689075/ 2: <201101232332.11736.th...@debian.org> 3: http://deb.li/prsc Thanks, with his security hat on: -- Jonathan Wiltshire j...@debian.org Debian Developer http://people.debian.org/~jmw 4096R: 0xD3524C51 / 0A55 B7C5 1223

Bug#659149: CVE-2012-0839: Hash collision DoS

2013-01-17 Thread Jonathan Wiltshire
/659149/ 2: <201101232332.11736.th...@debian.org> 3: http://deb.li/prsc Thanks, with his security hat on: -- Jonathan Wiltshire j...@debian.org Debian Developer http://people.debian.org/~jmw 4096R: 0xD3524C51 / 0A55 B7C5 1223 3942

Bug#669196: libvorbisidec: multiple longstanding unfixed security issues in libvorbis

2013-01-17 Thread Jonathan Wiltshire
et/tracker/669196/ 2: <201101232332.11736.th...@debian.org> 3: http://deb.li/prsc Thanks, with his security hat on: -- Jonathan Wiltshire j...@debian.org Debian Developer http://people.debian.org/~jmw 4096R: 0xD3524C51 / 0A55 B7C5 1223

Bug#687672: xmlrpc-c: Embedded Expat vulnerable to CVE-2012-0876, CVE-2012-1148

2013-01-17 Thread Jonathan Wiltshire
/687672/ 2: <201101232332.11736.th...@debian.org> 3: http://deb.li/prsc Thanks, with his security hat on: -- Jonathan Wiltshire j...@debian.org Debian Developer http://people.debian.org/~jmw 4096R: 0xD3524C51 / 0A55 B7C5 1223 3942

Bug#696184: fail2ban: CVE-2012-5642: input variable quoting flaw on content

2013-01-17 Thread Jonathan Wiltshire
/696184/ 2: <201101232332.11736.th...@debian.org> 3: http://deb.li/prsc Thanks, with his security hat on: -- Jonathan Wiltshire j...@debian.org Debian Developer http://people.debian.org/~jmw 4096R: 0xD3524C51 / 0A55 B7C5 1223 3942

Bug#693112: glusterfs: CVE-2012-4417

2013-01-17 Thread Jonathan Wiltshire
ker/693112/ 2: <201101232332.11736.th...@debian.org> 3: http://deb.li/prsc Thanks, with his security hat on: -- Jonathan Wiltshire j...@debian.org Debian Developer http://people.debian.org/~jmw 4096R: 0xD3524C51 / 0A55 B7C5 1223

Bug#685584: xml-light: CVE-2012-3514

2013-01-17 Thread Jonathan Wiltshire
ker/685584/ 2: <201101232332.11736.th...@debian.org> 3: http://deb.li/prsc Thanks, with his security hat on: -- Jonathan Wiltshire j...@debian.org Debian Developer http://people.debian.org/~jmw 4096R: 0xD3524C51 / 0A55 B7C5 1223

Bug#696707: nusoap: CVE-2012-6071: wrong CURLOPT_SSL_VERIFYHOST: do not check hostname of cert

2013-01-17 Thread Jonathan Wiltshire
et/tracker/696707/ 2: <201101232332.11736.th...@debian.org> 3: http://deb.li/prsc Thanks, with his security hat on: -- Jonathan Wiltshire j...@debian.org Debian Developer http://people.debian.org/~jmw 4096R: 0xD3524C51 / 0A55 B7C5 1223

Bug#672989: Multiple security issues

2013-01-17 Thread Jonathan Wiltshire
/672989/ 2: <201101232332.11736.th...@debian.org> 3: http://deb.li/prsc Thanks, with his security hat on: -- Jonathan Wiltshire j...@debian.org Debian Developer http://people.debian.org/~jmw 4096R: 0xD3524C51 / 0A55 B7C5 1223 3942

Bug#686650: bcron: Possible bcron security breach

2013-01-17 Thread Jonathan Wiltshire
/686650/ 2: <201101232332.11736.th...@debian.org> 3: http://deb.li/prsc Thanks, with his security hat on: -- Jonathan Wiltshire j...@debian.org Debian Developer http://people.debian.org/~jmw 4096R: 0xD3524C51 / 0A55 B7C5 1223 3942

Bug#695614: CVE-2012-6303: buffer overflows

2013-01-17 Thread Jonathan Wiltshire
/695614/ 2: <201101232332.11736.th...@debian.org> 3: http://deb.li/prsc Thanks, with his security hat on: -- Jonathan Wiltshire j...@debian.org Debian Developer http://people.debian.org/~jmw 4096R: 0xD3524C51 / 0A55 B7C5 1223 3942

Bug#674167: CVE-2012-2921

2013-01-17 Thread Jonathan Wiltshire
et/tracker/674167/ 2: <201101232332.11736.th...@debian.org> 3: http://deb.li/prsc Thanks, with his security hat on: -- Jonathan Wiltshire j...@debian.org Debian Developer http://people.debian.org/~jmw 4096R: 0xD3524C51 / 0A55 B7C

Bug#665012: CVE-2012-1570: maradns deleted domain record cache persistance flaw

2013-01-17 Thread Jonathan Wiltshire
/665012/ 2: <201101232332.11736.th...@debian.org> 3: http://deb.li/prsc Thanks, with his security hat on: -- Jonathan Wiltshire j...@debian.org Debian Developer http://people.debian.org/~jmw 4096R: 0xD3524C51 / 0A55 B7C5 1223 3942

Bug#616673: rhythmbox-plugins: CVE-2012-3355 Plugin "context" contains hardcoded path to /tmp/context/

2013-01-18 Thread Jonathan Wiltshire
et/tracker/616673/ 2: <201101232332.11736.th...@debian.org> 3: http://deb.li/prsc Thanks, with his security hat on: -- Jonathan Wiltshire j...@debian.org Debian Developer http://people.debian.org/~jmw 4096R: 0xD3524C51 / 0A55 B7C

Bug#679283: CVE-2012-2825

2013-01-18 Thread Jonathan Wiltshire
/679283/ 2: <201101232332.11736.th...@debian.org> 3: http://deb.li/prsc Thanks, with his security hat on: -- Jonathan Wiltshire j...@debian.org Debian Developer http://people.debian.org/~jmw 4096R: 0xD3524C51 / 0A55 B7C5 1223 3942

Bug#694810: plib: CVE-2012-4552

2013-01-18 Thread Jonathan Wiltshire
/694810/ 2: <201101232332.11736.th...@debian.org> 3: http://deb.li/prsc Thanks, with his security hat on: -- Jonathan Wiltshire j...@debian.org Debian Developer http://people.debian.org/~jmw 4096R: 0xD3524C51 / 0A55 B7C5 1223 3942

Bug#625302: dtach: CVE-2012-3368 random text sent on window close

2013-01-18 Thread Jonathan Wiltshire
/625302/ 2: <201101232332.11736.th...@debian.org> 3: http://deb.li/prsc Thanks, with his security hat on: -- Jonathan Wiltshire j...@debian.org Debian Developer http://people.debian.org/~jmw 4096R: 0xD3524C51 / 0A55 B7C5 1223 3942

Bug#677496: CVE-2012-2693

2013-01-18 Thread Jonathan Wiltshire
/677496/ 2: <201101232332.11736.th...@debian.org> 3: http://deb.li/prsc Thanks, with his security hat on: -- Jonathan Wiltshire j...@debian.org Debian Developer http://people.debian.org/~jmw 4096R: 0xD3524C51 / 0A55 B7C5 1223 3942

Bug#680059: revelation: FPM exporter doesn't encrypt password files [CVE-2012-3818]

2013-01-18 Thread Jonathan Wiltshire
ker/680059/ 2: <201101232332.11736.th...@debian.org> 3: http://deb.li/prsc Thanks, with his security hat on: -- Jonathan Wiltshire j...@debian.org Debian Developer http://people.debian.org/~jmw 4096R: 0xD3524C51 / 0A55 B7C5 1223

Bug#694407: freeradius: CVE-2011-4966

2013-01-18 Thread Jonathan Wiltshire
ker/694407/ 2: <201101232332.11736.th...@debian.org> 3: http://deb.li/prsc Thanks, with his security hat on: -- Jonathan Wiltshire j...@debian.org Debian Developer http://people.debian.org/~jmw 4096R: 0xD3524C51 / 0A55 B7C5 1223

Bug#548633: html2ps: arbitrary file disclosure in ssi directives

2013-01-18 Thread Jonathan Wiltshire
/548633/ 2: <201101232332.11736.th...@debian.org> 3: http://deb.li/prsc Thanks, with his security hat on: -- Jonathan Wiltshire j...@debian.org Debian Developer http://people.debian.org/~jmw 4096R: 0xD3524C51 / 0A55 B7C5 1223 3942

Bug#686764: xen: Multiple security issues

2013-01-18 Thread Jonathan Wiltshire
/686764/ 2: <201101232332.11736.th...@debian.org> 3: http://deb.li/prsc Thanks, with his security hat on: -- Jonathan Wiltshire j...@debian.org Debian Developer http://people.debian.org/~jmw 4096R: 0xD3524C51 / 0A55 B7C5 1223 3942 86EC

Bug#692443: lynx-cur: CVE-2012-5821

2013-01-18 Thread Jonathan Wiltshire
/692443/ 2: <201101232332.11736.th...@debian.org> 3: http://deb.li/prsc Thanks, with his security hat on: -- Jonathan Wiltshire j...@debian.org Debian Developer http://people.debian.org/~jmw 4096R: 0xD3524C51 / 0A55 B7C5 1223 3942

Bug#688956: dracut: CVE-2012-4453: creates non-world readable initramfs images

2013-01-18 Thread Jonathan Wiltshire
/688956/ 2: <201101232332.11736.th...@debian.org> 3: http://deb.li/prsc Thanks, with his security hat on: -- Jonathan Wiltshire j...@debian.org Debian Developer http://people.debian.org/~jmw 4096R: 0xD3524C51 / 0A55 B7C5 1223 3942

Bug#696184: fail2ban: CVE-2012-5642: input variable quoting flaw on content

2013-01-19 Thread Jonathan Wiltshire
On Thu, Jan 17, 2013 at 03:24:05PM -0500, Yaroslav Halchenko wrote: > > On Thu, 17 Jan 2013, Jonathan Wiltshire wrote: > > > Package: fail2ban > > > Dear maintainer, > > > Recently you fixed one or more security problems and as a result you closed > > th

Bug#686764: [Pkg-xen-devel] Bug#686764: xen: Multiple security issues

2013-01-19 Thread Jonathan Wiltshire
On Sat, Jan 19, 2013 at 12:57:58PM +0100, Bastian Blank wrote: > On Fri, Jan 18, 2013 at 12:15:04PM -0000, Jonathan Wiltshire wrote: > > Recently you fixed one or more security problems and as a result you closed > > this bug. These problems were not serious enough for a

Bug#690411: unblock: scim-chewing/0.3.4-1.2

2013-01-19 Thread Jonathan Wiltshire
+- + widget_class->expose_event = scim_color_button_expose; This is not strictly necessary, but harmless (there is another similar instance further down). -- Jonathan Wiltshire j...@debian.org Debian Developer http://peo

Bug#692011: taxbird: version in testing (0.16.x) is completely useless

2013-01-19 Thread Jonathan Wiltshire
On Sat, Dec 22, 2012 at 08:46:50PM +, Steven Chamberlain wrote: > On 21/12/12 12:33, Jonathan Wiltshire wrote: > > On 2012-12-21 12:04, Toni Mueller wrote: > >>> In practice, isn't taxbird dead and therefore unlikely to change at > >>> all in the future?

Bug#698241: CVE-2013-0191: NULL password query result permits login with any password

2013-01-20 Thread Jonathan Wiltshire
et/tracker/698241/ 2: <201101232332.11736.th...@debian.org> 3: http://deb.li/prsc Thanks, with his security hat on: -- Jonathan Wiltshire j...@debian.org Debian Developer http://people.debian.org/~jmw 4096R: 0xD3524C51 / 0A55 B7C5 1223

Bug#698490: git-extras: diff for NMU version 1.7.0-1.2

2013-01-20 Thread Jonathan Wiltshire
. -- Jonathan Wiltshire j...@debian.org Debian Developer http://people.debian.org/~jmw 4096R: 0xD3524C51 / 0A55 B7C5 1223 3942 86EC 74C3 5394 479D D352 4C51 diff -Nru git-extras-1.7.0/debian/changelog git-extras-1.7.0/debian/changelog --- git

Bug#698259: guilt: diff for NMU version 0.35-1.1

2013-01-20 Thread Jonathan Wiltshire
anges. -- Jonathan Wiltshire j...@debian.org Debian Developer http://people.debian.org/~jmw 4096R: 0xD3524C51 / 0A55 B7C5 1223 3942 86EC 74C3 5394 479D D352 4C51 i have six years of solaris sysadmin experience, from 8->10. i

Bug#694376: dovecot: diff for NMU version 1:2.1.7-6.1

2013-01-20 Thread Jonathan Wiltshire
tags 694376 + pending thanks Dear maintainer, I've prepared an NMU for dovecot (versioned as 1:2.1.7-6.1) and uploaded it to DELAYED/5. Please feel free to tell me if I should delay it longer. Regards. -- Jonathan Wiltshire j...@debian.org Debian Deve

Bug#694376: dovecot: diff for NMU version 1:2.1.7-6.1

2013-01-21 Thread Jonathan Wiltshire
On Mon, Jan 21, 2013 at 04:33:47PM -0500, Jaldhar H. Vyas wrote: > On Sun, 20 Jan 2013, Jonathan Wiltshire wrote: > > >tags 694376 + pending > >thanks > > > >Dear maintainer, > > > >I've prepared an NMU for dovecot (versioned as 1:2.1.7-6.1) and &

Bug#690411: unblock: scim-chewing/0.3.4-1.2

2013-01-22 Thread Jonathan Wiltshire
On 2013-01-19 18:11, Jonathan Wiltshire wrote: On Sun, Oct 14, 2012 at 12:43:24AM +0100, Neil Williams wrote: I've prepared an NMU (diff attached) for testing-proposed-updates as 0.3.4-1.2 which simply pulls the gtk patch out of the unstable changes and makes no other changes. Please co

Bug#698467: unblock: taurus/3.0.0-2

2013-01-22 Thread Jonathan Wiltshire
null > 2>/dev/null"%(full_source_fname, full_target_fname) > +ok = not(os.system(cmd)) > else: > pixmap = PyQt4.Qt.QPixmap(full_source_fname) > pix = pixmap.scaledToWidth(24, > PyQt4.Qt.Qt.SmoothTransformatio

Bug#697930: [Pkg-nagios-devel] Bug#697930: nagios3: CVE-2012-6096

2013-01-22 Thread Jonathan Wiltshire
On 2013-01-20 19:54, Alexander Wirt wrote: On Sun, 20 Jan 2013, Moritz Mühlenhoff wrote: On Fri, Jan 11, 2013 at 03:56:25PM +, Jonathan Wiltshire wrote: > Control: found -1 3.2.1-2 > > On 2013-01-11 13:50, Moritz Muehlenhoff wrote: > >Package: nagios3 > >Severity: gr

Bug#698701: tpu: dspam/3.10.1+dfsg-8

2013-01-22 Thread Jonathan Wiltshire
/series/view/dspam/3.10.2+dfsg-4/009_fix_recipient_corruption_when_releasing_message_from_quarantine.diff I'm happy with both these changes provided they have had sufficient testing in unstable first. (I presume the destination in the strcpy() call is large enough not to overflow?)

Bug#698467: RE : Bug#698467: unblock: taurus/3.0.0-2

2013-01-22 Thread Jonathan Wiltshire
; > > Yes in fact I took the patch from the upstream and adapt the rules file to > use the > renamed option. > > If you think that it it better to take only the first and the last chunk, > just tell me. I would prefer that, yes. Otherwise no objections, please ping the

Bug#692506: unblock: chocolate-doom/1.7.0-2 (but please see inside!)

2013-01-23 Thread Jonathan Wiltshire
hich is almost certainly only a documentation fix too, > but for some reason I'd be more hesitant to do that. I would accept the Uploaders fix and the other documentation fixes along with it, but not the standards version. Can you prepare a debdiff before uploading and send it to this bug

Bug#697757: unblock: proftpd-dfsg/1.3.4a-4 (pre-approval)

2013-01-23 Thread Jonathan Wiltshire
-r--r-- root/root 14863 2013-01-23 20:33 ./usr/share/locale/ru/LC_MESSAGES/proftpd.mo Looks like they're a no-op, or at least get corrected further on in the build somewhere. -- Jonathan Wiltshire j...@debian.org Debian Developer

Bug#697757: unblock: proftpd-dfsg/1.3.4a-4 (pre-approval)

2013-01-23 Thread Jonathan Wiltshire
Control: tag -1 - moreinfo On Wed, Jan 23, 2013 at 08:58:51PM +, Jonathan Wiltshire wrote: > Looks like they're a no-op, or at least get corrected further on in the > build somewhere. Oh, no my fault. Sorry. Please go ahead and ping the bug when you have uploaded. Thanks, -

Bug#698245: unblock: moodle/2.2.3.dfsg-2.6~wheezy2

2013-01-23 Thread Jonathan Wiltshire
first if they have not been already. You can go ahead and upload to t-p-u once the fixes reach unstable, and I will accept it after a few days to allow testing to take place. Thanks, -- Jonathan Wiltshire j...@debian.org Debian Developer

Bug#698816: unblock: python-crypto/2.6-3

2013-01-24 Thread Jonathan Wiltshire
; appropriate Breaks stanzas in python-crypto and fixed that in 2.6-3. > So please > > unblock python-crypto/2.6-3 Thanks, unblocked. -- Jonathan Wiltshire j...@debian.org Debian Developer http://people.debian.org/~jmw 4096R

Bug#698915: unblock: php5/5.4.4-12

2013-01-25 Thread Jonathan Wiltshire
good, I was hoping to see a fix for this. Unblocked; thanks. -- Jonathan Wiltshire j...@debian.org Debian Developer http://people.debian.org/~jmw 4096R: 0xD3524C51 / 0A55 B7C5 1223 3942 86EC 74C3 5394 479D D352 4C51 -- To UNSUBSCRIBE

Bug#698976: unblock: libssh/0.5.4-1 (Fix CVE, not uploaded yet)

2013-01-25 Thread Jonathan Wiltshire
n the negative form? -- Jonathan Wiltshire j...@debian.org Debian Developer http://people.debian.org/~jmw 4096R: 0xD3524C51 / 0A55 B7C5 1223 3942 86EC 74C3 5394 479D D352 4C51 i have six years of solaris sysadmin experience, from

Bug#698984: unblock: simpleid - fixes RC issue with OpenID 2.0 support

2013-01-25 Thread Jonathan Wiltshire
intainers > > Build-Depends: debhelper (>= 8), cdbs (>= 0.4.89) > Standards-Version: 3.9.3 No chance. http://www.debian.org/doc/debian-policy/ch-controlfields.html#s-f-Maintainer -- Jonathan Wiltshire j...@debian.org Debian Developer

Bug#699012: unblock: netgen/4.9.13.dfsg-3.2

2013-01-26 Thread Jonathan Wiltshire
8) With the licensing issue aside, what effect does this have on users of the package? -- Jonathan Wiltshire j...@debian.org Debian Developer http://people.debian.org/~jmw 4096R: 0xD3524C51 / 0A55 B7C5 1223 3942 86EC 74C3 5394 479D D352 4

Bug#697976: [j...@hedgerows.org.uk: [PATCH] Generate subtitle files in UTF8, closes debian bug #697976]

2013-01-26 Thread Jonathan Wiltshire
et_iplayer mailing list get_ipla...@lists.infradead.org http://lists.infradead.org/mailman/listinfo/get_iplayer - End forwarded message - -- Jonathan Wiltshire j...@debian.org Debian Developer http://people.debian.org/~jmw 4

Bug#693387: Pre-approval for unblock: sysvinit/2.88dsf-35

2013-01-26 Thread Jonathan Wiltshire
wheezy? -35 has been superceded in unstable with non-RC changes, so a fix will need to go through tpu now. -- Jonathan Wiltshire j...@debian.org Debian Developer http://people.debian.org/~jmw 4096R: 0xD3524C51 / 0A55 B7C5 1223 3942 86E

Bug#699019: Bug#693387: Pre-approval for unblock: sysvinit/2.88dsf-35

2013-01-26 Thread Jonathan Wiltshire
On Sat, Jan 26, 2013 at 01:17:44PM +, Roger Leigh wrote: > (Using the new bug number) > > On Sat, Jan 26, 2013 at 12:14:59PM +, Jonathan Wiltshire wrote: > > Control: tag -1 + moreinfo > > > > On Thu, Nov 15, 2012 at 10:32:19PM +, Roger Leigh wrote: &

Bug#589731: python-scipy: missing source for Cython-generated files

2013-01-26 Thread Jonathan Wiltshire
package and close this bug only? -- Jonathan Wiltshire j...@debian.org Debian Developer http://people.debian.org/~jmw 4096R: 0xD3524C51 / 0A55 B7C5 1223 3942 86EC 74C3 5394 479D D352 4C51 i have six years of solaris sysadmin expe

Bug#690411: unblock: scim-chewing/0.3.4-1.2

2013-01-26 Thread Jonathan Wiltshire
Control: tag -1 + pending On Tue, Jan 22, 2013 at 02:39:15PM +, Jonathan Wiltshire wrote: > On 2013-01-19 18:11, Jonathan Wiltshire wrote: > >On Sun, Oct 14, 2012 at 12:43:24AM +0100, Neil Williams wrote: > >>I've prepared an NMU (diff attached) for testing-proposed-u

Bug#655969: [Pkg-lirc-maint] Bug#655969: lirc: prompting due to modified conffiles which where not modified by the user

2013-01-26 Thread Jonathan Wiltshire
been a year, and with a popcon of over 60,000 a *lot* of people are going to start seeing this prompt very soon... -- Jonathan Wiltshire j...@debian.org Debian Developer http://people.debian.org/~jmw 4096R: 0xD3524C51 / 0A55 B7C5 1223 3

Bug#698635: gosa: diff for NMU version 2.7.4-4.1

2013-01-27 Thread Jonathan Wiltshire
tags 698635 + patch tags 698635 + pending thanks Dear maintainer, I've prepared an NMU for gosa (versioned as 2.7.4-4.1) and uploaded it to DELAYED/2. Please feel free to tell me if I should delay it longer. Regards. -- Jonathan Wiltshire j...@debia

Bug#690394: Bug#690877: unblock: love/0.8.0-3

2013-01-27 Thread Jonathan Wiltshire
uld be 0.8.0-2.1. I'm not all that fussed though. > > Will you upload the package? > > That's OK, but as it is a TPU upload, we first need pre-approval from the > release team. You can upload this fix to tpu. -- Jonathan Wiltshire

Bug#699066: xgks: Contains code preventing commercial distribution

2013-01-27 Thread Jonathan Wiltshire
the freeze, you should be aware that I'll remove xgks and ferret-vis from Wheezy on Wednesday if you are not able to resolve this satisfactorily before then. -- Jonathan Wiltshire j...@debian.org Debian Developer http://people.debi

  1   2   3   4   5   6   7   8   9   10   >