Bug#320757: clamav-freshclam fail because it want a newer version of software

2005-08-01 Thread Salvatore
Subject: clamav-freshclam fail because it want a newer version of softwarePackage: clamavVersion: 0.84-2.sarge.1Severity: graveJustification: renders package unusable   *** Please type your report below this line ***   -- System Information:Debian Release: 3.1Architecture: i386 (i686)Kernel

Bug#75673: getting to know you

2006-07-02 Thread Salvatore
Do not ignore me please, I found your email somewhere and now bdecided to write you. I am coming to your place in few weeks and thought we can meet ebach other. Let me know if you dbo not minda. I am a nice pretty girl. Don't rebply to this email. Email me direclty at [EMAIL PROTECTED] -- To

Bug#317789: my chance

2006-04-30 Thread Salvatore
Do not ignore me please, I founda your email somewhere and now decidebd to write you. I am coming to your place in fewb weeks and thought we can meetb each other. Let me know if you do not mind. I am a nicae pretty girl. Don't reply to this email. Email me direclty at [EMAIL PROTECTED] -- To

Bug#336951: Install tex-common gives warning about chgrp

2005-11-01 Thread Bonaccorso Salvatore
Package: tex-common Version: 0.9 Severity: minor Hi Installing tex-common give some litle warning ( i don't know if it was appropriate to tell this): Setting up tex-common (0.9) ... chgrp: invalid group name `cachegroup' Regards, Salvatore -- System Information: Debian Releas

Bug#339594: visitors: default output is html

2005-11-17 Thread Salvatore Sanfilippo
Fixed, thank you very much for reporting it. Regards, Salvatore On 11/17/05, Rick Pasotto <[EMAIL PROTECTED]> wrote: > Package: visitors > Version: 0.6.1-1 > Severity: normal > > > The man page says the default output is text but it is actually html. > > -- System

Bug#339594: visitors: default output is html

2005-11-17 Thread Salvatore Sanfilippo
On 11/17/05, Romain Francoise <[EMAIL PROTECTED]> wrote: > Salvatore Sanfilippo <[EMAIL PROTECTED]> writes: > > > Fixed, thank you very much for reporting it. > > Fixed upstream, not in Debian... Sure, sorry for not being specific about this. > Salvatore, could

Bug#259268: beep-media-player: bmp stops playing when draging windows with mouse under wmi-10

2005-06-26 Thread Bonaccorso Salvatore
. Moving windows with the shortcuts of wmi-10 (shift + mod1 + {h,l,k,q}) don't provide bmp to stop playing. How can i try to provide more informations, if it could be a bug? Thanks, Salvatore Bonaccorso p.s.: excuse please my very bad english -- System Information: Debian Release: te

Bug#330936: beep-media-player: New release was available

2005-09-30 Thread Bonaccorso Salvatore
packaging it? Thank you very mutch for mantaining this package (excuse please my bad english) Best regards Bonaccorso Salvatore -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Bug#396322: Possible to revert changes in amsthm.sty?

2006-11-04 Thread Salvatore Bonaccorso
Hi On Tue, Oct 31, 2006 at 10:16:34AM +0100, Frank Küster wrote: > [EMAIL PROTECTED] (Salvatore Bonaccorso) wrote: > > > Subject: tetex-extra: Possible to revert changes in amsthm.sty > > Package: tetex-extra > > Version: 3.0.dfsg.3-1 > > Severity: wishlist >

Bug#396322: Possible to revert changes in amsthm.sty?

2006-10-31 Thread Salvatore Bonaccorso
.ps). About this "Problem" or wish, i have found this: http://www.tug.org/pipermail/macostex-archives/2006-July/023683.html Regards, Salvatore Bonaccorso -- Package-specific info: If you report an error when running one of the TeX-related binaries (latex, pdftex, metafont,...), or

Bug#396322: Possible to revert changes in amsthm.sty?

2006-11-17 Thread Salvatore Bonaccorso
Hi On Mon, Nov 06, 2006 at 02:09:04PM +0100, Frank Küster wrote: > [EMAIL PROTECTED] (Salvatore Bonaccorso) wrote: > > > Yes you are absolutely right. The description in amsthdoc.pdf > > explain it how to use \newtheoremstyle. I tried for example now > > > > \ne

Bug#419531: Menus unusables (i.e. without effect) in new gnome-art upload

2007-04-16 Thread Bonaccorso Salvatore
to provide more information, I will try! Best regards, Salvatore -- System Information: Debian Release: lenny/sid APT prefers unstable APT policy: (500, 'unstable') Architecture: i386 (i686) Kernel: Linux 2.6.20-2-ea (PREEMPT) Locale: LANG=C, LC_CTYPE=de_CH (charmap=ISO-8859-1) Shell:

Bug#303940: save dayDress Day Frank

2007-04-03 Thread Salvatore Heilman
Wish Lists RMA Request Location Newsroom http://img444.imageshack.us/img444/4589/quwb6.gif Tone WhatThe Tells Systems -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Bug#390363: lsb-base: On shutdown, while umounting partitions error about /usr/bin/tput

2006-09-30 Thread Bonaccorso Salvatore
closed report there, and the new version of lsb-base (hope it is correct). Regards, Salvatore -- System Information: Debian Release: testing/unstable APT prefers unstable APT policy: (500, 'unstable') Architecture: i386 (i686) Shell: /bin/sh linked to /bin/bash Kernel: Linux 2.6.18-1

Bug#390363: additional information: the error showed in the output

2006-09-30 Thread Salvatore Bonaccorso
Hi The output showed is the following: /lib/lsb/init-functions:250: /usr/bin/tput: No such file or directory /lib/lsb/init-functions:251: /usr/bin/tput: No such file or directory (if i could see it correctly). Regards, Salvatore -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject

Bug#392913: Small typo in a comment in the config-file /etc/console-tools/config

2006-10-13 Thread Bonaccorso Salvatore
Package: console-tools Version: 1:0.2.3dbs-65 Severity: minor Tags: patch Hi There is a small typo in a comment in the /etc/console-tools/config configuration file. It schould be "default" instead of "defalt"? Regards Salvatore -- System Information: Debian Release: te

Bug#190178: Salvatore says Hi

2006-10-20 Thread Driscoll, Salvatore
experience in the field/trade of their choice. Give our recruiting office a call when you have time. Thanks Salvatore Driscoll Office Number: 1-773-509-4920 We hope to be talking to you soon. *We are taking calls at anytime in the day or evening. -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with

Bug#395410: After upgrade to iproute Problems with vpnc

2006-10-26 Thread Bonaccorso Salvatore
nds on iproute but I haven't upgraded vpnc (it is at actual version of unstable: 0.3.3+SVN20051028-3) maybee it's an error caused by iproute? I hope, I filled the bug correctly, if this is a bug. Regards, Salvatore -- System Information: Debian Release: testing/unstable APT prefe

Bug#395410: additional information about the error-message with vpnc and the new iproute package

2006-10-27 Thread Salvatore Bonaccorso
3)... ---snap--- (i cancelled username and IP of the gateway) Where using the my config-File /etc/vpnc/ethz.conf. But, when i downgrade iproute from new version 20061002-1 back again to 20060323-1 all work again fine. Please say, how I can help providing more information, if it is relevant

Bug#395410: update to iproute Version 20061002-2 fix this bug

2006-10-28 Thread Salvatore Bonaccorso
git) (http://bugs.archlinux.org/task/5669) * medium as this bug breaks other packages such as vpnc So this bug can be closed. Regards Salvatore -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Bug#732754: [Pkg-openssl-devel] Bug#732754: openssl: CVE-2013-6449: crash when using TLS 1.2

2013-12-21 Thread Salvatore Bonaccorso
Hi Kurt, On Sat, Dec 21, 2013 at 09:35:38AM +0100, Kurt Roeckx wrote: > On Sat, Dec 21, 2013 at 08:16:42AM +0100, Salvatore Bonaccorso wrote: > > Package: openssl > > Version: 1.0.1e-2 > > Severity: grave > > Tags: security upstream patch > > > > Hi, &

Bug#732807: uscan: Use of uninitialized value in pattern match (m//) at /usr/bin/uscan line 1505.

2013-12-21 Thread Salvatore Bonaccorso
;format'} is actually defined. Regards, Salvatore >From 53cf2ce057faae7ab6a808e1fac8d6fdfdde7f71 Mon Sep 17 00:00:00 2001 From: Salvatore Bonaccorso Date: Sat, 21 Dec 2013 23:25:38 +0100 Subject: [PATCH] Fix unitialized value warning when copyright is not in copyright-format 1.0 If debian

Bug#733209: ruby-will-paginate: CVE-2013-6459: XSS vulnerabilities

2013-12-26 Thread Salvatore Bonaccorso
/tag/v3.0.5 Please adjust the affected versions in the BTS as needed. Regards, Salvatore -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#733212: ITP: librunning-commentary-perl -- Perl module to call system() with tracking messages

2013-12-26 Thread Salvatore Bonaccorso
Package: wnpp Owner: Salvatore Bonaccorso Severity: wishlist X-Debbugs-CC: debian-de...@lists.debian.org,debian-p...@lists.debian.org * Package name: librunning-commentary-perl Version : 0.05 Upstream Author : Damian Conway * URL : https://metacpan.org/release

Bug#733216: ITP: python-rsa -- Pure-Python RSA implementation

2013-12-27 Thread Salvatore Bonaccorso
used as a Python library as well as on the commandline. There seems to be already #673920 for python-rsa, RFP; merging both together. Regards, Salvatore -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#733219: ITP: libkeyword-simple-perl -- Perl module to define new keywords in pure Perl

2013-12-27 Thread Salvatore Bonaccorso
Package: wnpp Owner: Salvatore Bonaccorso Severity: wishlist X-Debbugs-CC: debian-de...@lists.debian.org,debian-p...@lists.debian.org * Package name: libkeyword-simple-perl Version : 0.02 Upstream Author : Lukas Mai * URL : https://metacpan.org/release/Keyword-Simple

Bug#733412: ITP: libtest-effects-perl -- Perl module to test various effects at once

2013-12-28 Thread Salvatore Bonaccorso
Package: wnpp Owner: Salvatore Bonaccorso Severity: wishlist X-Debbugs-CC: debian-de...@lists.debian.org,debian-p...@lists.debian.org * Package name: libtest-effects-perl Version : 0.001003 Upstream Author : Damian Conway * URL : https://metacpan.org/release/Test

Bug#733418: ITP: liblexical-failure-perl -- Perl module for user-selectable lexically-scoped failure signaling

2013-12-28 Thread Salvatore Bonaccorso
Package: wnpp Owner: Salvatore Bonaccorso Severity: wishlist X-Debbugs-CC: debian-de...@lists.debian.org,debian-p...@lists.debian.org * Package name: liblexical-failure-perl Version : 0.04 Upstream Author : Damian Conway * URL : https://metacpan.org/release

Bug#733429: libcatalyst-modules-perl: FTBFS: Tests failed

2013-12-28 Thread Salvatore Bonaccorso
- Only require MultiForm at runtime when needed [1] https://metacpan.org/changes/distribution/Catalyst-Controller-HTML-FormFu Regards, Salvatore -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#706426: memcached: CVE-2011-4971: remote denial of service

2013-12-29 Thread Salvatore Bonaccorso
Control: tags -1 + patch Attached is proposed debdiff with upstream commit. The upload might be also a chance to fix the orig.tar.gz/native package issue. Regards, Salvatore diff -Nru memcached-1.4.13/debian/changelog memcached-1.4.13/debian/changelog --- memcached-1.4.13/debian/changelog 2013

Bug#733588: memcached: Please update to new upstream version (1.4.17)

2013-12-29 Thread Salvatore Bonaccorso
Package: memcached Severity: wishlist Hi On 2013-12-20 there was released a new upstream version of memchaced (1.4.17). See https://code.google.com/p/memcached/wiki/ReleaseNotes1417 https://code.google.com/p/memcached/wiki/ReleaseNotes1416 and earlier for the release notes. Regards, Salvatore

Bug#733643: memcached: CVE-2013-7239: SASL authentication allows wrong credentials to access memcache

2013-12-30 Thread Salvatore Bonaccorso
9cf0910f4ad32 Regards, Salvatore -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#706426: memcached: diff for NMU version 1.4.13-0.3

2013-12-30 Thread Salvatore Bonaccorso
Hi Attached is a preliminary debdiff for fixing both issues. Regards, Salvatore diff -Nru memcached-1.4.13/debian/changelog memcached-1.4.13/debian/changelog --- memcached-1.4.13/debian/changelog 2013-01-23 21:22:12.0 +0100 +++ memcached-1.4.13/debian/changelog 2013-12-30 17:58

Bug#706426: memcached: diff for NMU version 1.4.13-0.3

2014-01-01 Thread Salvatore Bonaccorso
Control: tags 706426 + patch pending Control: tags 733643 + patch pending Dear maintainer, I've prepared an NMU for memcached (versioned as 1.4.13-0.3) and uploaded it to DELAYED/2. Please feel free to tell me if I should delay it longer. Regards, Salvatore diff -Nru memcached-1.4.13/d

Bug#717030: preliminariy (backported) patches for CVE-2013-4130 and CVE-2013-4282

2014-01-03 Thread Salvatore Bonaccorso
Hi Attached is a preliminary (not yet tested) debdiff, with backported patches for CVE-2013-4130 and CVE-2013-4282 to wheezy. Regards, Salvatore diff -Nru spice-0.11.0/debian/changelog spice-0.11.0/debian/changelog --- spice-0.11.0/debian/changelog 2012-06-28 19:09:52.0 +0200

Bug#604483: release-notes: typo in Appendix A.3 Upgrade legacy locales to UTF-8

2010-11-22 Thread Salvatore Bonaccorso
Package: release-notes Severity: normal Tags: patch Hi There is a small typo in section 'A.3 Upgrade legacy locales to UTF-8', it reads 'Upgrade legaly locales ...'. Another one is the spelling of supporetd. Bests Salvatore -- System Information: Debian Release: squee

Bug#605079: Netdot - Network Documentation Tool

2010-11-27 Thread Salvatore Bonaccorso
to 'ITP: netdot -- network documentation tool' to mark it as you would intent to package it. Bests Salvatore signature.asc Description: Digital signature

Bug#581696: libapp-cache-perl and moving Perl packages to Debian Perl Group

2010-11-28 Thread Salvatore Bonaccorso
Hi Jonas Stumbled over this bug. Short note: are you interested moving you Perl modules packages to the Debian Perl Group svn repository? See: http://pkg-perl.alioth.debian.org/ Bests Salvatore signature.asc Description: Digital signature

Bug#605314: libalgorithm-dependency-perl: New upstream version

2010-11-28 Thread Salvatore Bonaccorso
please consider if you agree maintaining your Perl modules related packages to the Debian Perl Group :-) Bests Salvatore -- System Information: Debian Release: 5.0.7 APT prefers stable APT policy: (500, 'stable') Architecture: amd64 (x86_64) Kernel: Linux 2.6.26-2-amd64 (SMP w/8 CPU cor

Bug#601711: WWW::Curl 4.15 uploaded

2010-11-28 Thread Salvatore Bonaccorso
Hi I just uploaded new version of libwww-curl-perl 4.15-1. Could you please try if the problem is solved for you as, when the new package enters the archive? Bests Salvatore signature.asc Description: Digital signature

Bug#600848: This is on the TODO list from upstream

2010-11-29 Thread Salvatore Bonaccorso
to wait for proper implementation from upstream, as the patch seems a bit 'intrusive'. Bests, so far Salvatore signature.asc Description: Digital signature

Bug#738509: python-gnupg: CVE-2013-7323 CVE-2014-1927 CVE-2014-1928

2014-02-12 Thread Salvatore Bonaccorso
t; prepared a package (just submitted to my usual sponsor) And one more CVE was assigned by MITRE: CVE-2014-1929, see [1] for the assignment. [1] http://marc.info/?l=oss-security&m=13912821142&w=2 Regards, Salvatore -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian

Bug#738587: libyaml: diff for NMU version 0.1.4-3.1

2014-02-12 Thread Salvatore Bonaccorso
to go otherwise straight to the new upstream version 0.1.5. (only did the upload in case you are short of time for the 0.1.5 to have #738587 fixed also in unstable soon). Regards, Salvatore diff -Nru libyaml-0.1.4/debian/changelog libyaml-0.1.4/debian/changelog --- libyaml-0.1.4/debian/changelog 2014-

Bug#738924: glance: CVE-2014-1948: Swift store backend password leak

2014-02-13 Thread Salvatore Bonaccorso
tack/glance/commit/?id=108f0e04ad2ed3dc287f1b71b987a7e9d66072ba Regards, Salvatore -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#732022: closed by Thomas Goirand (Bug#732022: fixed in nova 2013.2.1-1)

2014-02-13 Thread Salvatore Bonaccorso
ute-node to be exploited. Regards, Salvatore -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#738832: Segmentation fault in libmagic (src:file) [CVE-2014-1943]

2014-02-14 Thread Salvatore Bonaccorso
one this bugreport, as php5 embedding a modified copy of libmagic would also be affected by CVE-2014-1943. The two relevant commits for file/5.16 were https://github.com/glensc/file/commit/3c081560c23f20b2985c285338b52c7aae9fdb0f and https://github.com/glensc/file/commit/cc9e74dfeca5265ad

Bug#721547: libregexp-grammars-perl: Currently incompatible with Perl 5.18

2014-02-14 Thread Salvatore Bonaccorso
Hi This is only a small update on libregexp-grammars-perl status: the problems were not yet all solved with 5.18.2, see [1] but work is still in progress. [1] https://rt.cpan.org/Public/Bug/Display.html?id=79149#txn-1326842 Regards, Salvatore -- To UNSUBSCRIBE, email to debian-bugs-dist

Bug#739164: arora: Should probably be removed from the archive, like rekonq

2014-02-16 Thread Salvatore Bonaccorso
ot be supported and thus should only be used against trusted websites. Regards, Salvatore signature.asc Description: Digital signature

Bug#738857: mupdf: Stack-based Buffer Overflow in xps_parse_color()

2014-02-18 Thread Salvatore Bonaccorso
Control: retitle -1 mupdf: CVE-2014-2013: Stack-based Buffer Overflow in xps_parse_color() Hi, CVE-2014-2013 was assigned for this issue. Regards, Salvatore -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Conta

Bug#739012: [php-maint] Bug#738832: Segmentation fault in libmagic (src:file) [CVE-2014-1943]

2014-02-18 Thread Salvatore Bonaccorso
ndřej has already prepared packages for squeeze-security and wheezy-security which currently are building. Regards, Salvatore -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#739608: ldirectord: fails to test HTTPS real servers

2014-02-20 Thread Salvatore Bonaccorso
6434e736e32fe395eafe02 In any case I could prepare both packages targetting unstable and wheezy as we need ldirectord. Regards, Salvatore -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#698375: gfs2-utils: fails to upgrade from squeeze: insserv: script gfs2-utils: service gfs2 already provided!

2014-02-20 Thread Salvatore Bonaccorso
an example. Regards, Salvatore -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#739067: jenkins: multiple security vulnerabilities

2014-02-20 Thread Salvatore Bonaccorso
to identify the issues. Please include the CVE identifier in the changelog when fixing the corresponding issues. Regards, Salvatore -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#724116: resource-agents: diff for NMU version 1:3.9.3+git20121009-3.1

2014-02-21 Thread Salvatore Bonaccorso
tags 724116 + pending patch tags 739608 + pending patch thanks Dear maintainer, I've prepared an NMU for resource-agents (versioned as 1:3.9.3+git20121009-3.1) and uploaded it to DELAYED/5. Please feel free to tell me if I should delay it longer. Regards, Salvatore diff -Nru resource-a

Bug#739678: wheezy-pu: package resource-agents/1:3.9.2-5+deb7u2

2014-02-21 Thread Salvatore Bonaccorso
? Regards, Salvatore diff -Nru resource-agents-3.9.2/debian/changelog resource-agents-3.9.2/debian/changelog --- resource-agents-3.9.2/debian/changelog 2013-01-06 23:49:52.0 +0100 +++ resource-agents-3.9.2/debian/changelog 2014-02-21 10:35:08.0 +0100 @@ -1,3 +1,15 @@ +resource-agents

Bug#739782: new upstream version 1.0 released (long term support for bugfixes and security fixes)

2014-02-22 Thread Salvatore Bonaccorso
great to have soon a version which could enter jessie, and later on having jessie released with a package based on that branch. [1] https://lists.linuxcontainers.org/pipermail/lxc-users/2014-February/006260.html Regards, Salvatore -- To UNSUBSCRIBE, email to debian-bugs-dist-requ

Bug#739809: tagging 739809

2014-02-22 Thread Salvatore Bonaccorso
On Sat, Feb 22, 2014 at 06:51:13PM +0100, gregor herrmann wrote: > tags 739809 + confirmed > thanks One further information: The build does not fail (yet) in jessie. Regards, Salvatore -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "

Bug#739873: ldirectord: Upgrade from sid: ldirectord fails to start: Error [8533] reading file /etc/ldirectord.cf at line $number: invalid address for virtual service

2014-02-23 Thread Salvatore Bonaccorso
post-installation script returned error exit status 2 Errors were encountered while processing: ldirectord E: Sub-process /usr/bin/dpkg returned an error code (1) root@sid:~# With the above configuration now ldirectord does not start anymore. Regards, Salvatore -- To UNSUBSCRIBE, email to

Bug#738587: libyaml: diff for NMU version 0.1.4-3.1

2014-02-23 Thread Salvatore Bonaccorso
Hi Anders FTR, apologies, it looks like I dropped the entry in d/p/series, but not the wrong patch completely. Sorry about that. Regards, Salvatore -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Conta

Bug#740083: wheezy-pu: package libpdf-api2-perl/2.019-1+deb7u1

2014-02-25 Thread Salvatore Bonaccorso
be considered for the next point release for wheezy? [1] https://bitbucket.org/ssimms/pdfapi2/commits/2885c70ebf0fc8a7ea3e2f608e398b7de5f53860 Regards, Salvatore diff -Nru libpdf-api2-perl-2.019/debian/changelog libpdf-api2-perl-2.019/debian/changelog --- libpdf-api2-perl-2.019/debian/changelog

Bug#736154: cantata: Information disclosure (no CVE assigned yet)

2014-01-20 Thread Salvatore Bonaccorso
g was reported on oss-security: > https://code.google.com/p/cantata/issues/detail?id=356 Two CVEs were assigned: CVE-2013-7300 and CVE-2013-7301. See [1] for details. [1] http://www.openwall.com/lists/oss-security/2014/01/20/5 Regards, Salvatore -- To UNSUBSCRIBE, email to debian-bugs-dist-requ.

Bug#734747: Jinja 2.7.2 CVE-2014-0012

2014-01-21 Thread Salvatore Bonaccorso
Hi, On Tue, Jan 21, 2014 at 01:22:51PM +0100, Philippe Makowski wrote: > Hi, > > the fix in Jinja 2.7.2 is not correct > http://openwall.com/lists/oss-security/2014/01/11/1 FYI, this is known as #734956. Regards, Salvatore -- To UNSUBSCRIBE, email to debian-bu

Bug#736275: libmarc-xml-perl: XXE vulnerability fixed in 1.0.2

2014-01-21 Thread Salvatore Bonaccorso
rds, Salvatore -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#736465: nova: CVE-2013-7130

2014-01-23 Thread Salvatore Bonaccorso
eded. Regards, Salvatore -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#699647: proftpd-mod-geoip: /usr/lib/proftpd/mod_geoip.so missing after upgrade from sid

2014-01-25 Thread Salvatore Bonaccorso
he maintainer script to be removed. --control-list only shows the control files installed by the package. Regards, Salvatore -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#724227: libnet-mac-vendor-perl: FTBFS: Tests failed

2014-01-27 Thread Salvatore Bonaccorso
Hi Debian Perl Group, > this FTBFS also affects stable. I'm attaching an isolated backport, maybe we > can get this fixed for the upcoming Wheezy point release? Sure, I'm applying the patch for the testuite and will ask the release team for the wheezy point release update. But I'm not sure yet if we should also apply the no-network-tests.patch as we canot guarantee to have network connection. Regards, Salvatore -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#736841: wheezy-pu: package libnet-mac-vendor-perl/1.18-2+deb7u1

2014-01-27 Thread Salvatore Bonaccorso
prefer I can also add the no-network-tests.patch patch. [1] http://patch-tracker.debian.org/patch/series/view/libnet-mac-vendor-perl/1.21-1/no-network-tests.patch Can I upload this (or the variant with also disabling network-tests) for wheezy for the next point release? Regards, Salvatore diff -u

Bug#736841: wheezy-pu: package libnet-mac-vendor-perl/1.18-2+deb7u1

2014-01-27 Thread Salvatore Bonaccorso
Hi Release Team, On Mon, Jan 27, 2014 at 03:09:45PM +0100, Salvatore Bonaccorso wrote: > The FTBFS of libnet-mac-vendor-perl (#724227) also affects stable. The > attached debdiff fixes this (for the case were network access is still > allowed). > > If you prefer I can also add

Bug#736841: wheezy-pu: package libnet-mac-vendor-perl/1.18-2+deb7u1

2014-01-27 Thread Salvatore Bonaccorso
Hi Adam, On Mon, Jan 27, 2014 at 08:39:19PM +, Adam D. Barratt wrote: > Control: tags -1 + confirmed > > On Mon, 2014-01-27 at 15:09 +0100, Salvatore Bonaccorso wrote: > > The FTBFS of libnet-mac-vendor-perl (#724227) also affects stable. The > > attached debdiff fix

Bug#736993: socat: CVE-2014-0019: PROXY-CONNECT address overflow

2014-01-28 Thread Salvatore Bonaccorso
eded. Regards, Salvatore -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#736969: (possible) CVE request: suPHP 0.7.2 release fixed a possible arbitrary code execution

2014-01-28 Thread Salvatore Bonaccorso
] https://lists.marsching.com/pipermail/suphp/2013-May/002554.html Regards, Salvatore -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#737076: libyaml: CVE-2013-6393: heap-based buffer overflow when parsing YAML tags

2014-01-29 Thread Salvatore Bonaccorso
0 [2] https://bugzilla.redhat.com/show_bug.cgi?id=1033990#c15 Note: packages for oldstable and stable are currently beeing prepared. Regards, Salvatore -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#737076: libyaml: CVE-2013-6393: heap-based buffer overflow when parsing YAML tags

2014-01-29 Thread Salvatore Bonaccorso
ff Have you asked your current sponsor? Otherwise I can upload your package. Regards, Salvatore -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#737318: wheezy-pu: package libhtml-formhandler-perl/0.40013-1+deb7u1

2014-02-01 Thread Salvatore Bonaccorso
unstable with 0.40050-2. I would like to fix this FTBFS also for wheezy. Attached is proposed debdiff. The test is adjusted to not depend on 2008 but on the current year when running the test. Can I upload this for this (or the next) wheezy point release? Regards, Salvatore diff -Nru libhtml

Bug#737318: wheezy-pu: package libhtml-formhandler-perl/0.40013-1+deb7u1

2014-02-01 Thread Salvatore Bonaccorso
Hi Adam, On Sat, Feb 01, 2014 at 06:13:33PM +, Adam D. Barratt wrote: > Control: tags -1 + confirmed > > On Sat, 2014-02-01 at 17:48 +0100, Salvatore Bonaccorso wrote: > > libthml-formhandler-perl FTBFS also in stable, due the testsuite > > depending on a 2008 + 5 years

Bug#737406: openswan: CVE-2013-6466

2014-02-02 Thread Salvatore Bonaccorso
.org/tracker/CVE-2013-6466 [1] https://libreswan.org/security/CVE-2013-6467/CVE-2013-6467.txt [2] https://bugzilla.redhat.com/show_bug.cgi?id=1050277 Please adjust the affected versions in the BTS as needed. Regards, Salvatore -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org wi

Bug#737051: python-logilab-common: insecure use of /tmp

2014-02-02 Thread Salvatore Bonaccorso
Control: retitle -1 python-logilab-common: insecure use of /tmp (CVE-2014-1838 CVE-2014-1839) Hi Jakub, FYI, two CVEs were assigned for these issues: CVE-2014-1838 and CVE-2014-1839, see [1] for the assignment. [1] http://marc.info/?l=oss-security&m=139139947905109&w=2 Regards, S

Bug#737495: fwsnort: CVE-2014-0039: configuration file can be loaded from cwd when run as a non-root user

2014-02-02 Thread Salvatore Bonaccorso
mmit/fa977453120cc48e1654f373311f9cac468d3348 [2] https://bugzilla.redhat.com/show_bug.cgi?id=1060602 Please adjust the affected versions in the BTS as needed. Regards, Salvatore -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#737596: mysql-5.5: CVE-2014-0001: command-line tool buffer overflow via long server version string

2014-02-03 Thread Salvatore Bonaccorso
ttps://bugzilla.redhat.com/show_bug.cgi?id=1054592 Please adjust the affected versions in the BTS as needed. Regards, Salvatore -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#737597: mariadb-5.5: CVE-2014-0001: command-line tool buffer overflow via long server version string

2014-02-03 Thread Salvatore Bonaccorso
5.64 [2] https://bugzilla.redhat.com/show_bug.cgi?id=1054592 Regards, Salvatore -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#737644: chrony: CVE-2014-0021: traffic amplification in cmdmon protocol

2014-02-04 Thread Salvatore Bonaccorso
1 [1] http://chrony.tuxfamily.org/News.html Regards, Salvatore -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#737739: mumble: CVE-2014-0044 CVE-2014-0045

2014-02-05 Thread Salvatore Bonaccorso
/850649234d11685145193a59d72d98429e4f9ba7 https://github.com/mumble-voip/mumble/commit/d3be3d7b96a5130e4b20f23e327b040ea4d0b079 Upstream announces at http://mumble.info/security/Mumble-SA-2014-001.txt http://mumble.info/security/Mumble-SA-2014-002.txt Regards, Salvatore -- To UNSUBSCRIBE, email to debian-bugs-dist-requ

Bug#737739: mumble: CVE-2014-0044 CVE-2014-0045

2014-02-05 Thread Salvatore Bonaccorso
Hi Chris, On Wed, Feb 05, 2014 at 11:09:00AM -0500, Chris Knadle wrote: > On Wednesday, February 05, 2014 16:10:36 Salvatore Bonaccorso wrote: > > Source: mumble > > Version: 1.2.3-349-g315b5f5-2.2 > > Severity: grave > > Tags: security upstream fixed-upstream >

Bug#737739: mumble: CVE-2014-0044 CVE-2014-0045

2014-02-05 Thread Salvatore Bonaccorso
Hi Chris, On Wed, Feb 05, 2014 at 04:31:07PM -0500, Chris Knadle wrote: > On Wednesday, February 05, 2014 22:16:32 Salvatore Bonaccorso wrote: > > Hi Chris, > > > > On Wed, Feb 05, 2014 at 11:09:00AM -0500, Chris Knadle wrote: > > > On Wednesday, February 05, 2014

Bug#737815: subversion: CVE-2014-0032: mod_dav_svn crash when handling certain requests with SVNListParentPath on

2014-02-05 Thread Salvatore Bonaccorso
ease adjust the affected versions in the BTS as needed. Salvatore -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#737818: zabbix: CVE-2014-1682: API issue allows users to impersonate other users

2014-02-05 Thread Salvatore Bonaccorso
ions? Regards, Salvatore -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#737835: CVE Request: Capture::Tiny: insecure use of /tmp

2014-02-06 Thread Salvatore Bonaccorso
check is that the file does not already > exist, but there is no guarantee that that condition will continue > to apply.” There is no upstream commit to fix this issue yet. Could a CVE be assigned for this insecure use of /tmp for the Capture::Tiny module? Regards, Salvatore -- To

Bug#727534: security-tracker: Add tabular view listing all CVEs and version table for a source package

2014-02-08 Thread Salvatore Bonaccorso
nce of the security tracker is doing the three steps: make update-packages make all make serve But Luciano is working on adding a section for this to the documentation. Regards, Salvatore -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscrib

Bug#738509: python-gnupg: CVE-2013-7323 CVE-2014-1927 CVE-2014-1928

2014-02-09 Thread Salvatore Bonaccorso
se adjust the affected versions in the BTS as needed. Regards, Salvatore -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#738515: oath-tookit: CVE-2013-7322: certain one-time-passwords not invalidated correctly

2014-02-09 Thread Salvatore Bonaccorso
3-12/txtUm85v7Wqcy.txt Regards, Salvatore -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#738587: libyaml: Patch libyaml-indent-column-overflow-v2.patch applied in update for CVE-2013-6393 introduces regression

2014-02-10 Thread Salvatore Bonaccorso
he commits. Regards, Salvatore diff -u libyaml-0.1.3/debian/changelog libyaml-0.1.3/debian/changelog --- libyaml-0.1.3/debian/changelog +++ libyaml-0.1.3/debian/changelog @@ -1,3 +1,11 @@ +libyaml (0.1.3-1+deb6u3) squeeze-security; urgency=high + + * Non-maintainer upload by the Security Team. + * App

Bug#738607: developers-reference: Change contact preferences to the security-team in 5.8.5.

2014-02-10 Thread Salvatore Bonaccorso
the security-team in the developers-reference in paragraph 5.8.5. The change consist to make the email contact the only point of contact removing the reference to the Request Tracker. Attached patch addresses this, could you apply it for your next update of the dev-ref? Regards, Salvatore Index

Bug#730752: Dublicated CVE, retitling bug with CVE to use

2013-12-03 Thread Salvatore Bonaccorso
Control: -1 retitle horizon: CVE-2013-6858: persistent XSS vulnerability Hi There was a dublication for this CVE, see [1]. [1] http://www.openwall.com/lists/oss-security/2013/12/04/2 Please use CVE-2013-6858 to reference this issue. Regards, Salvatore -- To UNSUBSCRIBE, email to debian

Bug#731305: gimp: CVE-2013-1913 CVE-2013-1978

2013-12-03 Thread Salvatore Bonaccorso
elog entry. For further information see: [0] http://security-tracker.debian.org/tracker/CVE-2013-1913 [1] http://security-tracker.debian.org/tracker/CVE-2013-1978 Please adjust the affected versions in the BTS as needed. Regards, Salvatore -- To UNSUBSCRIBE, email to debian-bugs-dist-

Bug#726478: Debian not affected by this bug

2013-12-04 Thread Salvatore Bonaccorso
Hi Thomas, On Wed, Dec 04, 2013 at 04:04:09PM +0800, Thomas Goirand wrote: [...] > Closing this bug accordingly. Debian security people, please update the > security tracker accordingly. Thanks, updated the entry for this. Regards, Salvatore -- To UNSUBSCRIBE, email to debian-bugs-dis

Bug#728253: pu: package libnet-smtp-tls-butmaintained-perl/0.17-1+deb7u1

2013-12-04 Thread Salvatore Bonaccorso
Hi Adam, On Wed, Dec 04, 2013 at 08:24:46PM +, Adam D. Barratt wrote: > Control: tags -1 + confirmed > > On Tue, 2013-10-29 at 23:50 +0100, Salvatore Bonaccorso wrote: > > The Perl module found int libnet-smtp-tls-butmaintained-perl > > (Net::SMTP::TLS::ButMaintained)

Bug#731439: linux: unable to handle kernel paging request at ffffffffffffffb8 when trying to remove a file in a checkpoint directory of a NFSv4 mount from a EMC VNx Storage

2013-12-05 Thread Salvatore Bonaccorso
unately cannot easily reproduce otherwise and was not able to identify a commit which changed this.] Regards, Salvatore -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#731480: hplip: CVE-2013-6427: insecure (undocumented) auto update feature

2013-12-05 Thread Salvatore Bonaccorso
the affected versions in the BTS as needed (only unstable verified for the source). Regards, Salvatore -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#714388: Missing help_suspend.tt2

2013-12-06 Thread Salvatore Bonaccorso
Hi Would there be a chance to have this bug also fixed in a upcoming point-release? It might be worth of if there are several pending fixes for an update in a point-release (tought it is easy to workaround it). Regards, Salvatore -- To UNSUBSCRIBE, email to debian-bugs-dist-requ

Bug#728232: sup-mail: CVE-2013-4478 and CVE-2013-4479

2013-12-06 Thread Salvatore Bonaccorso
Hi Per, On Mon, Nov 25, 2013 at 01:20:42AM +0100, Per Andersson wrote: > On Sun, Nov 10, 2013 at 8:58 PM, Salvatore Bonaccorso > wrote: > > Hi Per, > > > > Did you had time to prepare the fixes for unstable? > > Still working with the latest upstream release. Hop

  1   2   3   4   5   6   7   8   9   10   >