Bug#732841: cicero: TypeError: exceptions must be old-style classes or derived from BaseException, not str

2013-12-22 Thread Raphael Geissert
oss-compat 0.0.4+nmu3 ii python 2.7.2-9 ii sox 14.4.1-3 Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#732963: ssh fails with OpenSSL version mismatch. Built against 1000105f, you have 10001060

2013-12-23 Thread Raphael Geissert
wn bug in openssh. Merging. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#732966: [openssl] Update to openssl 1.0.1e-5 renders X unusable

2013-12-23 Thread Raphael Geissert
match. Built against 1000105f, you have 10001060 That's openssh. If there's anything else that's breaking your DM or something else then it might be another bug in a different package, but not in openssl. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -

Bug#738785: aptitude: (remote) changelogs is broken after packages.d.o move to https

2014-02-12 Thread Raphael Geissert
uding APT's http method from the redirection, but they'd like this issue to be fixed. Hence this email. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "u

Bug#738785: aptitude: (remote) changelogs is broken after packages.d.o move to https

2014-02-13 Thread Raphael Geissert
t the server > reported 77136 338 Yeah, that's possible. I don't think anybody tested that protocol switching worked. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#738785: aptitude: (remote) changelogs is broken after packages.d.o move to https

2014-02-13 Thread Raphael Geissert
On Thursday 13 February 2014 22:07:37 David Kalnischkies wrote: > On Thu, Feb 13, 2014 at 07:52:38PM +0100, Julien Cristau wrote: > > On Thu, Feb 13, 2014 at 10:27:47 +0100, Raphael Geissert wrote: > > > On 13 February 2014 00:26, Julien Cristau > > > wrote: [...]

Bug#731860: libtar: CVE-2013-4420: directory traversal when extracting archives

2014-02-14 Thread Raphael Geissert
a warning message and list the full path, while >> libtar should simply print it as 'empty-file'. > > Yes, an odd number of ".." will yield the desired result, but the even ".."s > will be missed. Ah, yes, indeed. Nice catch. Cheers, -- Raphael Geiss

Bug#739236: libanyevent-http-perl: doesn't separate connection tokens with comma

2014-02-16 Thread Raphael Geissert
anks in advance (and many more thanks if somebody prepares a backport with the fix :)! Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net --- unpacked/usr/share/perl5/AnyEvent/HTTP.pm 2012-11-14 23:22:00.0 +0100 +++ /usr/share/perl5/AnyEvent/HTTP.pm 2013-11-17

Bug#739490: iceweasel: compiled extensions can not be built with version in wheezy-sec

2014-02-19 Thread Raphael Geissert
fails to find the mozilla-nspr pkg-config file, which results in a series of missing files and the build failure. There's also a "cannot find -lmozglue" error from the linker. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email

Bug#739490: iceweasel: compiled extensions can not be built with version in wheezy-sec

2014-02-19 Thread Raphael Geissert
Hi Sylvestre, On 19 February 2014 11:26, Sylvestre Ledru wrote: [...] > I wasn't in cc of the private email. Do you have a build log with the error? Sure, attached is the relevant part of the log. HTH. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net

Bug#729203: Packaging for FFmpeg avoiding conflicts with libav

2014-02-22 Thread Raphael Geissert
libavfilter embedding libavfilter? >Seems like a bug in lintian. It complains because it has detected a copy of libavfilter in a package which is none of the ones it knows that are the "source" of it. So arguably, yes, it's a bug. Cheers, -- Raphael Geissert - De

Bug#736425: poppler-glib: "incorrect password" error bypasses GError

2014-01-23 Thread Raphael Geissert
or. Looking at SecurityHandler.cc I see that there are other cases for which error() is called, and assuming there's no race condition in the "trapping" of error() to GError, it would mean that there are several error conditions which entirely bypass GError. Thanks in advance. Cheers,

Bug#736958: [oss-security] CVE request: temporary file issue in Passenger rubygem

2014-01-29 Thread Raphael Geissert
On 29 January 2014 09:57, Raphael Geissert wrote: [...] > One thing to notice, however, is that there's a race condition between > the stat check introduced in 34b1087870c2. > The following sequence still triggers the bogus behaviour: > > mkdir $dir > lstat() (getF

Bug#737534: vlc: unsafe use of libtar

2014-02-03 Thread Raphael Geissert
about to be extracted that none contains a ../, and something similar for symlinks. Alternatively, vlc could just use tar(1) to unpack the tarballs, or drop support for skins or skins in tarballs. What do you think? This should probably be forwarded to upstream. Cheers, -- Raphael Geissert

Bug#737738: htop: please provide ioprio_get information (aka ionice)

2014-02-05 Thread Raphael Geissert
Package: htop Version: 1.0.1-1 Severity: wishlist Hi, It would be great if htop could also display the I/O priority (and/or the class?) of the processes as another column. This can be obtained via the ioprio_get syscall. Thanks! Cheers, -- Raphael Geissert - Debian Developer www.debian.org

Bug#737738: htop: please provide ioprio_get information (aka ionice)

2014-02-06 Thread Raphael Geissert
t; This is implemented in htop 1.0.2. Ah, indeed! great. It appears to have issues understanding the "idle" class, but it appears to work for "best-effort". Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bu

Bug#738173: security-tracker: detect some "fixed version" inconsistencies

2014-02-08 Thread Raphael Geissert
that either the release-specific tag is incorrect, or the fixed version is incorrect. One sample was fixed with r25293 Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of

Bug#731860: libtar: CVE-2013-4420: directory traversal when extracting archives

2014-02-11 Thread Raphael Geissert
the while loop right after the if. Attached test case contains an entry called ../../../empty-file tar tf should print a warning message and list the full path, while libtar should simply print it as 'empty-file'. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net triple-double-dot.tar Description: Unix tar archive

Bug#718434: ca-certificates: should CAcert.org be included?

2013-12-05 Thread Raphael Geissert
/95_add_spi+cacert_ca_certs.patch That said, I think it is time to start discontinuing the certificate. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe&qu

Bug#718434: Bug#731463: Bug#718434: ca-certificates: should CAcert.org be included?

2013-12-07 Thread Raphael Geissert
y a plan to address that shortcoming? Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#731860: libtar: CVE-2013-4420: directory traversal when extracting archives

2013-12-10 Thread Raphael Geissert
& Exposures) id in your changelog entry. For further information see: [0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4420 http://security-tracker.debian.org/tracker/CVE-2013-4420 Attached is a proposed patch that makes libtar work similarly to tar. Cheers, -- Raphael Geissert - De

Bug#731357: opu: package librsvg/2.26.3-2

2013-12-18 Thread Raphael Geissert
you posted. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#732464: manpages-dev: mcheck(3) typo in compiler flag

2013-12-18 Thread Raphael Geissert
Package: manpages-dev Version: 3.44-1 Severity: minor Hi, mcheck(3) reads: > linking the program with -mcheck inserts an implicit Whereas it should read: > linking the program with -lmcheck inserts an implicit Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debi

Bug#731357: opu: package librsvg/2.26.3-2

2013-12-19 Thread Raphael Geissert
Control: tag 732144 patch Attached patch should correctly handle URIs and non-URIs. I've tested it with a few applications using relative and absolute paths, and URIs. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net Index: librsvg-2.26.3/rsvg-im

Bug#732144: Bug#731357: opu: package librsvg/2.26.3-2

2013-12-20 Thread Raphael Geissert
Hi again, Found another case where it didn't work as expected. Updated, attached, patch should do it. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net Index: librsvg-2.26.3/rsvg-image.c === --- li

Bug#726578: pwgen: Multiple vulnerabilities in passwords generation

2013-10-17 Thread Raphael Geissert
and is command-line and output-compatible with pwgen. Basically changing everything under the hood without letting others know. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subj

Bug#727052: RFP: libanyevent-gearman-perl -- Asynchronous Gearman client/worker module for AnyEvent applications

2013-10-21 Thread Raphael Geissert
ul if the oh so mighty perl group could package this module :-) Would it be possible? Thanks in advance! Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe

Bug#692606: Marking as done in recent versions

2013-10-28 Thread Raphael Geissert
nformation so it's correctly tracked > as fixed in later versions. I'll coordinate with SRM for uploading a fix > to stable. Are you available to test a tentatively fixed package before > upload? The change is trivial, but sure. Cheers, -- Raphael Geissert - Debian Developer www.d

Bug#734238: Fix for CVE-2013-6045 breaks decoding of chroma-subsampled images

2014-01-06 Thread Raphael Geissert
write to memory outside the allocated buffer. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#735292: libstrongswan: configuring strongswan.conf with file snippets (aka strongswan.conf.d)

2014-01-14 Thread Raphael Geissert
configuration management system) to drop a file to modify the configuration without touching the main strongswan.conf LTDR: Please consider git-am'ing the attached mbox. Thanks! Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net From a281d077254db5fd86001896300d3fa356f

Bug#735305: strongswan: should the padlock plugin be disabled?

2014-01-14 Thread Raphael Geissert
Package: strongswan Version: 4.2.4-4 Hi, Given everything that was revealed last year, the openssl package has now disabled support for the VIA Padlock. Given that in strongswan the plugin is compiled and enabled, I wonder what you or upstream think about disabling it. Cheers, -- Raphael

Bug#731111: augeas: CVE-2013-6412

2014-01-15 Thread Raphael Geissert
Control: tag -1 patch Attached are patches fixing the issues for squeeze and wheezy. Also attached is an additional patch needed in squeeze to be able to run the test-save.c test. Could you please coordinate with the release team to fix these issues via O/SPU? Thanks, -- Raphael Geissert

Bug#735292: libstrongswan: configuring strongswan.conf with file snippets (aka strongswan.conf.d)

2014-01-17 Thread Raphael Geissert
hough? Done in attached mbox. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net From a2431a1cdab1a5fa72df9c4ca734d2ea75dcba1d Mon Sep 17 00:00:00 2001 From: Raphael Geissert Date: Tue, 14 Jan 2014 14:51:01 +0100 Subject: [PATCH] Support configuration via /etc/st

Bug#730615: mirrors: Index for wheezy-proposed-updates/contrib contents is out of sync.

2013-11-27 Thread Raphael Geissert
bian/dists/wheezy-proposed-updates/contrib/Contents-i386.diff/ > is: > 2013-09-25-0234.41.gz > 2013-10-12-1445.32.gz > Index Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debia

Bug#730637: gtk+3.0: FTBFS when building with -j8

2013-11-27 Thread Raphael Geissert
sive] Error 1 make[2]: Leaving directory `/tmp/buildd/gtk+3.0-3.4.2/debian/build/shared' make[1]: *** [all] Error 2 make[1]: Leaving directory `/tmp/buildd/gtk+3.0-3.4.2/debian/build/shared' make: *** [debian/stamp-makefile-build/shared] Error 2 dpkg-buildpackage: error: debian/rules bui

Bug#730637: gtk+3.0: FTBFS when building with -j8

2013-11-27 Thread Raphael Geissert
16:31:27 -0400 I'll let you switch the severity back to serious. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#730637: gtk+3.0: FTBFS when building with -j8

2013-11-27 Thread Raphael Geissert
On Wednesday 27 November 2013 22:35:31 Raphael Geissert wrote: > I believe that debhelper does that for you: Sigh, wrong reference, and now that I think about it it's very likely that cdbs is the one using the value of DEB_BUILD_OPTIONS=parallel=8 class/langcore.mk defines DEB_PARALLE

Bug#724741: librsvg: CVE-2013-1881

2013-11-28 Thread Raphael Geissert
weaks; use_data_uris_for_symbolic_icons.patch does the same for the version in wheezy. Could you please prepare packages for O/SPU and coordinate with the release team? TIA. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net Index: librsvg-2.26.3/rsvg-im

Bug#731132: augeas: CVE-2012-0786, CVE-2012-0787

2013-12-02 Thread Raphael Geissert
with the release team? Attached tarballs contain patches for the corresponding release. Note, however, that #73 is introduced by them and should also be fixed :) Thanks in advance. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net squeeze.tar.gz Description

Bug#731237: openjpeg: CVE-2013-1447 CVE-2013-6045 CVE-2013-6052 CVE-2013-6054

2013-12-03 Thread Raphael Geissert
Hi, There are also some other issues that are specific to 1.5.1 (or at least they do not affect 1.3): CVE-2013-6053: information leaks CVE-2013-6887: DoS All the patches will be available as soon as I forward to oss-sec the messages I sent to the distros list. Cheers, -- Raphael Geissert

Bug#751408: linux-3.2: xhci_hcd: "ERR: no room for command on command ring"

2014-06-16 Thread Raphael Geissert
On 12 June 2014 16:59, Raphael Geissert wrote: [...] > So, searching a bit on the git log leads to the following commits: > > "xhci: Reset reserved command ring TRBs on cleanup. " - likely to fix > the no room for command bug > https://github.

Bug#749584: libusb-1.0-0: crashes pcscd, sporadically, on usb plugging on xhci-driven devices

2014-06-16 Thread Raphael Geissert
On 28 May 2014 15:30, Aurelien Jarno wrote: > On Wed, May 28, 2014 at 03:20:24PM +0200, Raphael Geissert wrote: >> On 28 May 2014 15:03, Aurelien Jarno wrote: >> > On Wed, May 28, 2014 at 12:31:00PM +0200, Raphael Geissert wrote: >> [...] >> > With a backtrace, i

Bug#744027: Please remove StartCom Certification Authority root certificate

2014-04-09 Thread Raphael Geissert
, if they > desire. Agreed, so marking it as wontfix. If anything changes upstream, it will be reflected here. For those reading at home don't waste your time, nor ours, sending arguments or "+1"s. If anywhere, do it on mozilla's bugzilla - all the while respecting thei

Bug#744027: data point

2014-04-09 Thread Raphael Geissert
eve that it would be an overreaction. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#744027: Revocation Policy

2014-04-10 Thread Raphael Geissert
library what they want it to check for. From a previous look at the openssl-using applications in Debian, those cases are rare. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a su

Bug#744187: xulrunner-24.0-dbg: dependencies on nss and nspr not needed when LESS_SYSTEM_LIBS

2014-04-11 Thread Raphael Geissert
eeded. Thanks in advance. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#743883: Is it realy fixed?

2014-04-11 Thread Raphael Geissert
and restart applications as soon as possible." [emphasis is mine] We did mention it. -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#744197: ecryptfs-utils: unix_chkpwd should not be used

2014-04-11 Thread Raphael Geissert
Package: ecryptfs-utils Severity: important Version: 103-3 Tags: security Hi, ecryptfs-setup-private calls unix_chkpwd, but according to the latter's manpage it should not be called by anything other than libpam-unix. Cheers, -- Raphael Geissert - Debian Developer www.debia

Bug#745259: ITP: apt-transport-tor -- APT transport for anonymous package downloads via Tor

2014-04-22 Thread Raphael Geissert
Hi, By using curl you are basically allowing the mirror (or anyone who can intercept the clear text) to tell "normal" and tor users apart. Think of targeted attacks. Just saying... Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE

Bug#739490: iceweasel: compiled extensions can not be built with version in wheezy-sec

2014-03-05 Thread Raphael Geissert
On 24 February 2014 09:58, Mike Hommey wrote: > On Wed, Feb 19, 2014 at 10:33:09AM +0100, Raphael Geissert wrote: >> Package: iceweasel >> Version: 24.3.0esr-1~deb7u1 >> Severity: important >> >> Hi, >> >> As mentioned in a private email, binary ex

Bug#588953: file: poor detection of avr32 ELF objects

2014-03-06 Thread Raphael Geissert
Hi, On 1 March 2014 22:08, Christoph Biedl wrote: > Raphael Geissert wrote... >> Running file(1) against an avr32 ELF object prints the following: >> ELF 32-bit MSB shared object, version 1 (SYSV), dynamically linked (uses >> shared libs), for GNU/Linux 2.6.18, stripped &

Bug#741005: iceweasel: using p11-kit to replace nssckbi?

2014-03-07 Thread Raphael Geissert
the two providers is there that I might be missing? Thanks in advance. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#739490: iceweasel: compiled extensions can not be built with version in wheezy-sec

2014-03-07 Thread Raphael Geissert
On 5 March 2014 23:01, Mike Hommey wrote: > What about pkg-config --cflags libxul? Could you also share your built > -dev package? -I/usr/include/xulrunner-24.0 You can find the -dev at https://drive.google.com/file/d/0BxFIoxou14NAU1RPVVU5RjNqbGc/edit?usp=sharing Cheers, -- Raphael Ge

Bug#741199: RFP: libmaxminddb -- library for working with MaxMind DB files

2014-03-09 Thread Raphael Geissert
rsion 2. CC'in the geoip maintainer in case he wants to take this RFP as this is basically the continuation of what he is maintining. [1]https://github.com/maxmind/libmaxminddb Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to d

Bug#741299: freetype: CVE-2014-2240, CVE-2014-2241: stack OOB read/write, DoS

2014-03-10 Thread Raphael Geissert
, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#741346: lintian: check the name of modules config in /etc/pkcs11/modules

2014-03-11 Thread Raphael Geissert
heers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net From 1e197a7baf40d1e7c5874cf02335af4c53f8844d Mon Sep 17 00:00:00 2001 From: Raphael Geissert Date: Tue, 11 Mar 2014 11:39:44 +0100 Subject: [PATCH] Check for the naming convention of etc/pkcs11/modules files --- checks/files

Bug#739490: iceweasel: compiled extensions can not be built with version in wheezy-sec

2014-03-11 Thread Raphael Geissert
On 7 March 2014 11:29, Raphael Geissert wrote: > On 5 March 2014 23:01, Mike Hommey wrote: >> What about pkg-config --cflags libxul? Could you also share your built >> -dev package? > > -I/usr/include/xulrunner-24.0 A quick and dirty workaround is to symlink the nss

Bug#738199: Access to the oval generation script ?

2014-03-11 Thread Raphael Geissert
If so, where ? It's in www team's webwml CVS repository, one of the scripts being: webwml/english/security/oval/parseDsa2Oval.py but there are a few other under oval/ Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to

Bug#718434: fixed in ca-certificates 20140223

2014-03-26 Thread Raphael Geissert
or wants to post) want to say that it is not strictly within the topic of this report, please refrain yourself from writing it here and send it elsewhere. Thanks. -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-

Bug#641469: mobile-broadband-provider-info: Please provide updates for stable distribution, somehow

2014-04-03 Thread Raphael Geissert
Hi, Has any progress been made towards doing old/stable updates? Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#741952: linux: Possible bug in 3.2's cifs/file.c, use of uninitialized variable

2014-04-07 Thread Raphael Geissert
itten; > - } else if (rc < 0) { > - if (!total_written) > - total_written = rc; > - break; > } > > /* get length and number of kvecs of the next write */ > Looks good to me. Thank

Bug#734238: Patch for CVE-2013-6045

2014-04-07 Thread Raphael Geissert
change and upload to security-master.d.o. Can you do that? Thanks. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#741958: [PATCH 3.2 17/18] cifs: ensure that uncached writes handle unmapped areas correctly

2014-04-07 Thread Raphael Geissert
* i + 1 now represents the number of pages we actually used > in > +* the copy phase above. > +*/ > + npages = min(npages, i + 1); I'm having trouble understanding why min() is needed here. It shouldn't harm either,

Bug#745836: wget: certificate revocation is not checked

2014-04-28 Thread Raphael Geissert
t is not a bug, it is a missing feature. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#745837: curl should use a Certificate Revocation List by default

2014-04-28 Thread Raphael Geissert
fy error. OCSP transponder support and/or OCSP stapling support would be nice but they are false solutions. Please bring up the subject on -devel before mass bug filing, it would have avoided it (in its current form at least). Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.

Bug#746245: installation-reports: Jessie daily amd64 netinst from 25/04/2014 won't even load

2014-04-28 Thread Raphael Geissert
hose lines). Under legacy mode it works fine. [1] 2014-04-25 12:24:12.0 +0200 5f7af8ca7220e1ea659869f0f99c6ea8 debian-testing-amd64-netinst.iso Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@list

Bug#694143: php5-ffmpeg: FTBFS because of deprecated functions

2014-04-28 Thread Raphael Geissert
system > libraries get pointed to the _wrong_ time.h. Ah! That explains! The missing declaration of time_t was puzzling me. Thanks, I will take a look at the other bugs to get the package back in shape. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -

Bug#746306: dpkg: CVE-2014-0471 fix introduces the vulnerability into squeeze

2014-04-29 Thread Raphael Geissert
g dependencies, they would need to be added to all versions so that e.g. wheezy's dpkg can't be used with squeeze's patch * if handling both behaviors, it should also apply to both releases. Unless I missed something, of course. Cheers, -- Raphael Geissert - Debian Developer ww

Bug#746306: dpkg: CVE-2014-0471 fix introduces the vulnerability into squeeze

2014-04-30 Thread Raphael Geissert
y've hit the sec archive. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#749584: libusb-1.0-0: crashes pcscd, sporadically, on usb plugging on xhci-driven devices

2014-05-28 Thread Raphael Geissert
or another device during the lifetime of pcscd is enough to reproducibly trigger the bug Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#749584: libusb-1.0-0: crashes pcscd, sporadically, on usb plugging on xhci-driven devices

2014-05-28 Thread Raphael Geissert
On 28 May 2014 15:03, Aurelien Jarno wrote: > On Wed, May 28, 2014 at 12:31:00PM +0200, Raphael Geissert wrote: [...] > I don't really understand the version part. You mean it works on 1.0.8 > and 1.0.11, but crashes with 1.0.17 and 1.0.18? Yes > Did you change only the >

Bug#750550: pm-utils: pm-is-supported should not exit with 0 if hibernation is not setup

2014-06-04 Thread Raphael Geissert
basically an unclean reboot. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#750551: pm-utils: pm-is-supported _is_ used by upower, in spite of the claim from the manpage

2014-06-04 Thread Raphael Geissert
. [1]http://sources.debian.net/src/upower/0.9.23-2/src/linux/up-backend.c?hl=385#L377 Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trou

Bug#750757: wheezy-pu: package mobile-broadband-provider-info/20140317-1~deb7u1

2014-06-06 Thread Raphael Geissert
[1]https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=641469 Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net mobile-broadband-provider-info_20140317-1~deb7u1.debdiff Description: Binary data

Bug#750764: packages.debian.org: please include squeeze-lts suite

2014-06-08 Thread Raphael Geissert
should be lts. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#697963: linux-image-3.2.0-4-amd64: xhci_hcd breaks suspend

2014-06-12 Thread Raphael Geissert
commit. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#751408: linux-3.2: xhci_hcd: "ERR: no room for command on command ring"

2014-06-12 Thread Raphael Geissert
8fe377061a353c120f "xHCI: dynamic ring expansion" - likely to fix other bugs, and maybe help on this one https://github.com/torvalds/linux/commit/8dfec6140fc617b932cf9a09ba46d0ee3f3a7d87 I intend to test those, but sending the report in advance. Cheers, -- Raphael Geissert - Debi

Bug#694143: php5-ffmpeg: FTBFS because of deprecated functions

2014-05-13 Thread Raphael Geissert
ery once and then to sponsor the package. Will be filing the removal request later today. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#747952: RM: ffmpeg-php -- RoM; Unmaintained upstream, incompatible with libav 10

2014-05-13 Thread Raphael Geissert
Package: ftp.debian.org Hi, Please remove ffmpeg-php, it's been dead upstream for a while and it needs somebody with some time to keep up with all the libav transitions. Thanks in advance. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBS

Bug#741346: lintian: check the name of modules config in /etc/pkcs11/modules

2014-03-12 Thread Raphael Geissert
On 11 March 2014 14:36, Raphael Geissert wrote: [...] > An example of a package triggering the warning by p11-kit (from jessie > or wheezy-bpo) is wheezy's gnome-keyring. And now that I take a better look at how things are done in sid, the directory is now usr/share/p11-kit/modu

Bug#741561: No longer ship cacert certificates

2014-03-13 Thread Raphael Geissert
irmation or that doesn't require a special parameter to connect to any server for which it can not verify the validity of the certificate should be fixed. Don't hesitate to file a bug report against those tools. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - ge

Bug#718434: ca-certificates: should CAcert.org be included?

2014-03-13 Thread Raphael Geissert
Hi, On Thursday 13 March 2014 23:09:48 Axel Beckert wrote: > Christoph Anton Mitterer wrote: > > I doubt that the removal of CAcert was a good decision... > > A quite bad decision in my view, too. Thanks for sharing your thoughts. Cheers, -- Raphael Geissert - Debian Developer

Bug#718434: ca-certificates: should CAcert.org be included?

2014-03-14 Thread Raphael Geissert
tes to the ones provided by Gandi. Once the transition is finished we are very likely going to also drop the SPI root certificate. P.S. as a gentle reminder, a decision has been made by the maintainers. The result can be found in the archive. Cheers, -- Raphael Geissert - Debian Developer www.de

Bug#720013: make p11-kit multiarch

2014-03-14 Thread Raphael Geissert
linux-gnu/pkcs11/p11-kit-trust.so lrwxrwxrwx root/root 0 2014-03-14 16:32 ./usr/lib/x86_64-linux-gnu/p11-kit-proxy.so -> libp11-kit.so.0.0.0 Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net From da22bc26e804e4a18b33fef04b7945c307d29fc3 Mon Sep 17 00:00:00 2

Bug#741952: linux: Possible bug in 3.2's cifs/file.c, use of uninitialized variable

2014-03-17 Thread Raphael Geissert
/linux/3.2.54-2/fs/cifs/file.c#L2183 [4]http://sources.debian.net/src/linux/3.2.54-2/fs/cifs/file.c#L2197 Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe&quo

Bug#741955: linux: ssize_t casted to unsigned int in fs/cifs/file.c when CONFIG_CIFS_STATS is set

2014-03-17 Thread Raphael Geissert
}http://sources.debian.net/src/linux/3.2.54-2/fs/cifs/file.c#L2204 [2]http://sources.debian.net/src/linux/3.2.54-2/fs/cifs/file.c#L2219 Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with

Bug#741958: linux: CVE-2014-0069: cifs: incorrect handling of bogus user pointers during uncached writes

2014-03-17 Thread Raphael Geissert
Source: linux Version: 3.2.51-1 Tags: patch security X-debbugs-cc: j...@debian.org Hi, Attached patch is what I believe would be the correct backport for 3.2 of the specific fix for CVE-2014-0069, which is 5d81de8e8667da7135d3a32a964087c0faf5483f. Cheers, -- Raphael Geissert - Debian Developer

Bug#698161: [PTS] RDF descriptions point to broken archive links in some cases

2013-01-14 Thread Raphael Geissert
s the base URL. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#698603: FTBFS against experimental audit, needs new build-dep

2013-01-20 Thread Raphael Geissert
d-fedora will need to > build-dep on libauparse-dev, since the library packages have been split > in the new packaging. Thanks for the report. I've been keeping an eye on the audit 2.x transition, but hadn't noticed the package split. Will fix it when audit 2.x hits sid and this

Bug#698966: initscripts: postinst calls non-existent urandom.sh script

2013-01-25 Thread Raphael Geissert
> then > invoke-rc.d urandom.sh start || true > else > /etc/init.d/urandom.sh start || true > fi > fi P.S. thanks for the report Paul. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSC

Bug#648641: eclipse: missing versioned depends on libjasper-java

2011-11-13 Thread Raphael Geissert
Package: eclipse-platform Version: 3.7.0-1 Severity: important (if not grave) Hi, According that what's been said in other bug reports, eclipse 3.7 looks for jasper-5.5.jar which was added in libjasper-java 5.5.33-1. However, it only depends on >= 5.5.26-1. Regards, -- Raphael

Bug#687334: Please add security queues for armhf and s390x

2013-01-02 Thread Raphael Geissert
On Thursday 13 September 2012 04:17:03 Philipp Kern wrote: > On Tue, Sep 11, 2012 at 03:24:32PM -0500, Raphael Geissert wrote: > > This is just to keep a record of things that need to be done before the > > release: > > * Add security queues for armhf > > * Ad

Bug#681419: Proposed ballot for free/non-free dependencies question

2013-01-12 Thread Raphael Geissert
e I personally disagree with the use of virtual packages in the way proposed by option B of the ballot, I think it should make it clear that the virtual package name must not be the name of a real package. That is, I ask the comittee to explicitely disallow cases such as the example of package

Bug#490605: debian-policy: please discourage the usage of echo -n, and echo in general

2013-01-12 Thread Raphael Geissert
Hi, On 8 July 2012 19:22, Jonathan Nieder wrote: > In July, 2008, Raphael Geissert wrote: >> As demonstrated by the following trivia[1], and also mentioned by SUSv3, the >> echo built-in varies from implementation to implementation and thus should be >> discouraged. [...

Bug#689062: dpkg-dev: Need to add support for Built-Using to dpkg-shlibdeps or new similar tool

2013-01-13 Thread Raphael Geissert
ic > substvars. If the package is not installed then we should at least > warn, or maybe even error out. How about BU (short for Built-Using) or BS (short for Binary's Source)? I find a lone B kind of confusing. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.de

Bug#692003: posh: does a bit too much of tilde expansion

2012-10-31 Thread Raphael Geissert
TIA. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#691389: [checkbashisms] multiple bug fixes and new checks

2012-11-01 Thread Raphael Geissert
On Thursday 25 October 2012 16:44:03 Benjamin Drung wrote: > Am Mittwoch, den 24.10.2012, 21:15 -0500 schrieb Raphael Geissert: > > Attached is an mbox with a bunch of bug fixes and new checks, #687450 > > included. > > Thanks. I have applied your patches 1 up to 14. I grabb

Bug#692086: bash-completion: please make it set -e/E clean

2012-11-01 Thread Raphael Geissert
;exit code: $?"' ERR Now try to autocomplete: cd / A more useful trap for debugging would be trap 'echo "<$BASH_COMMAND> failed"' ERR (add extra $BASH_ vars as needed) Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net --

Bug#695983: mirror submission for mirror.stshosting.co.uk

2012-12-16 Thread Raphael Geissert
t; Comment: Currently Manually Rsyncing 4x Daily, however working to becoming > Push-Triggered and IPv6 Good. Please let us know whenever that happens. How much bandwidth is available to the mirror? Regards, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIB

Bug#695983: mirror submission for mirror.stshosting.co.uk

2012-12-18 Thread Raphael Geissert
; PASV control-socket: Connection reset by peer > initially we have 25TB per month for the mirror but can make more > available should it be required Okay, so that's the monthly transfer limit, but what's the server's link bandwidth? Regards, -- Raphael Geissert - Debia

  1   2   3   4   5   6   7   8   9   10   >