Bug#699503: libnotify0.4-cil: can lead to application crash

2013-01-31 Thread Mirco Bauer
Package: libnotify0.4-cil Version: 0.4.0~r3032-5 Severity: serious The notfiy-sharp library can crash the application when the notification-daemon refuses the notification for whatever reason like this: Exception Message: org.freedesktop.Notifications.MaxNotificationsExceeded: Exceeded maximum nu

Processed: severity of 699495 is normal

2013-01-31 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > severity 699495 normal Bug #699495 [ocamldsort] ocamldsort breaks with recent versions of ocamldep Severity set to 'normal' from 'grave' > thanks Stopping processing here. Please contact me if you need assistance. -- 699495: http://bugs.debian.o

Bug#699470: [PATCH] crystalhd git.linuxtv.org kernel driver: FIX MORE null pointer BUGs triggered by multithreaded or faulty apps

2013-01-31 Thread thomas schorpp
This patch should pass the 2nd test case of this bug. The Broadcom driver can only handle strict open->close sequences, not in parallel or subsequent open() before HANDLE close(), so using the usual multithreaded or faulty apps will crash the kernel due to missing !ctx->hw_ctx exception catcher

Bug#699495: ocamldsort breaks with recent versions of ocamldep

2013-01-31 Thread Roberto Di Cosmo
Package: ocamldsort Version: 0.15.0-2 Severity: grave Justification: renders package unusable the 4.00 release of OCaml comes with a version of ocamldep that outputs dependency lines of the form foo : bar baz instead of the old foo: bar baz Since the parser in ocamldsort is not expecting

Bug#677054: marked as done (nut-client: prompting due to modified conffiles which were not modified by the user)

2013-01-31 Thread Debian Bug Tracking System
Your message dated Thu, 31 Jan 2013 21:17:58 + with message-id and subject line Bug#677054: fixed in nut 2.6.5-2 has caused the Debian Bug report #677054, regarding nut-client: prompting due to modified conffiles which were not modified by the user to be marked as done. This means that you c

Bug#699441: [Secure-testing-team] Bug#699441: owncloud: Multiple security issues in owncloud

2013-01-31 Thread Salvatore Bonaccorso
Hey John On Thu, Jan 31, 2013 at 08:39:42AM -0600, John Goerzen wrote: > Ah, sorry for the noise. 698737 did not show up on > bugs.debian.org/owncloud and I didn't think to check the src:. No problem. I'm unsure if I should have reported this against owncloude instead src:owncloud. But security-

Bug#696942: marked as done ([1.83->1.84 regression]: GRUB won't install to a dummy device)

2013-01-31 Thread Debian Bug Tracking System
Your message dated Thu, 31 Jan 2013 19:02:26 + with message-id and subject line Bug#696942: fixed in grub-installer 1.85 has caused the Debian Bug report #696942, regarding [1.83->1.84 regression]: GRUB won't install to a dummy device to be marked as done. This means that you claim that the p

Bug#696903: marked as done ([1.83->1.84 regression]: GRUB won't install to a character device)

2013-01-31 Thread Debian Bug Tracking System
Your message dated Thu, 31 Jan 2013 19:02:26 + with message-id and subject line Bug#696903: fixed in grub-installer 1.85 has caused the Debian Bug report #696903, regarding [1.83->1.84 regression]: GRUB won't install to a character device to be marked as done. This means that you claim that t

Bug#699470: crystalhd-dkms: Kernel null pointer BUG in crystalhd_dioq_fetch_wait()

2013-01-31 Thread tom schorpp
Package: crystalhd-dkms Version: 1:0.0~git20110715.fdd2f19-7 Severity: critical Tags: patch Justification: breaks the whole system Reproducible NULL pointer BUG at crystalhd-0.0~git20110715.fdd2f19/driver/linux/crystalhd_misc.c:515, triggered by adobe flash plugin from dmo repo, ffmpeg, mplayer,

Bug#698527: [oce-dev] Incompatibility of OpenCASCADE libraries license with GPL

2013-01-31 Thread Boris Pek
2013-01-31 17:39, "Thomas Paviot" wrote: >  Dear Boris, > >  There already had been a lot of discussions related to OCCT Public License > and incompatibilities with OSI approved free licenses. The OpenCascade > Company is already aware of this complaint from the community users, I'm not > sure y

Processed: expected type-specifier before 'intptr_t'

2013-01-31 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > fixed 675315 vtk/5.10.1-1 Bug #675315 [src:vtk] vtk: FTBFS in experimental: expected type-specifier before 'intptr_t' Marked as fixed in versions vtk/5.10.1-1. > thanks Stopping processing here. Please contact me if you need assistance. -- 6753

Bug#699396: CVE-2013-0241 - qxl: synchronous io guest DoS

2013-01-31 Thread Liang Guo
Hi, On Thu, Jan 31, 2013 at 12:10:16AM +0100, Luciano Bello wrote: > Package: xserver-xorg-video-qxl > Severity: grave > Tags: security patch > Justification: user security hole > > Hi there, >Take a look to http://seclists.org/oss-sec/2013/q1/204 >Please, use CVE-2013-0241 to refer this

Bug#696386: makedumpfile fails with elf_readall error : more information

2013-01-31 Thread Bouchard Louis
Hello John, Well this is what happen when juggling with too many distros. I might have tested with a .deb package built on Ubuntu instead of my normal Debian/Sid build VM. After rebuilding the package on Sid, the makedumpfile command works as expected. You can mark this bug as invalid. Thanks fo

Bug#698527: Incompatibility of OpenCASCADE libraries license with GPL

2013-01-31 Thread Anton Gladky
Hi, just to let you know. There is a thread on opencascade forum about relicensing [1]. The decision is postponed. Anton [1] http://dev.opencascade.org/index.php?q=node/31#comment-63 2013/1/31 Boris Pek : > Hi all, > > I am writing a message to Open CASCADE S.A.S. about incompatibility of > Ope

Bug#699351: linux-gd obsolete and lubupnp4

2013-01-31 Thread Scott Howard
On Thu, Jan 31, 2013 at 3:32 AM, VALETTE Eric OLNC/OLPS wrote: > Look at the CVE that have been filled regarding libupnp6 and the associated > bugs. Thanks, I'll put something on libupnp4's debian BTS so it's on their radar. >> Are there security problems with linux-igd independent of libupnp4?

Bug#699459: libupnp4: Multiple stack buffer overflow vulnerabilities

2013-01-31 Thread Scott Howard
Package: libupnp4 Severity: grave Tags: security More information is available at bug #699316 (including a patch). According to bug #699351, these security problems are also found in libupnp4. Here's the original posting by Salvatore Bonaccorso Hi, the following vulnerabilities were publishe

Bug#699455: libiulib0d fails to install (dependencies problem)

2013-01-31 Thread Florent Lévigne
Package: libiulib0d Version: 0.4.4+ds-2 Severity: grave Justification: renders package unusable libiulib0d depend of libpng15-15, but there is no package named libpng15-15. -- System Information: Debian Release: 7.0 APT prefers testing APT policy: (500, 'testing'), (1, 'experimental') Ar

Bug#537051: Bug#692911: Bug#537051: ca-certificates: Unneeded and confusing usage of interest-noawait

2013-01-31 Thread Niels Thykier
On 2013-01-19 18:44, Michael Shuler wrote: > On 01/19/2013 10:41 AM, Guillem Jover wrote: >> As discussed in 537051 the NMU introduced an unneeded and confusing >> usage of interest-noawait, and the accompanying Pre-Depends on dpkg. >> The attached patch removes these. > > Thanks for the patch. I

Bug#698527: Incompatibility of OpenCASCADE libraries license with GPL

2013-01-31 Thread Boris Pek
Hi all, I am writing a message to Open CASCADE S.A.S. about incompatibility of Open CASCADE Technology Public License with GPL (see [1] for example). This message will be send using contact form on their web site. But I want to keep all discussion publicly. So may I use your mailing list for this

Bug#699441: [Secure-testing-team] Bug#699441: owncloud: Multiple security issues in owncloud

2013-01-31 Thread John Goerzen
Ah, sorry for the noise. 698737 did not show up on bugs.debian.org/owncloud and I didn't think to check the src:. -- John On 01/31/2013 08:37 AM, Salvatore Bonaccorso wrote: Control: merge 698737 699441 Hi John On Thu, Jan 31, 2013 at 07:25:38AM -0600, John Goerzen wrote: Package: owncloud

Processed: found 698737 in 4.0.8debian-1.3, found 698737 in 4.0.4debian2-3.2

2013-01-31 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > found 698737 4.0.8debian-1.3 Bug #698737 [src:owncloud] owncloud: Multiple XSS vulnerabilities (oC-SA-2013-001) Bug #699441 [src:owncloud] owncloud: Multiple security issues in owncloud Marked as found in versions owncloud/4.0.8debian-1.3. Marked

Processed: reassign 699441 to src:owncloud, merging 698737 699441

2013-01-31 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > reassign 699441 src:owncloud Bug #699441 [owncloud] owncloud: Multiple security issues in owncloud Bug reassigned from package 'owncloud' to 'src:owncloud'. No longer marked as found in versions owncloud/4.0.8debian-1.3 and owncloud/4.0.4debian2-

Bug#699441: [Secure-testing-team] Bug#699441: owncloud: Multiple security issues in owncloud

2013-01-31 Thread Salvatore Bonaccorso
Control: merge 698737 699441 Hi John On Thu, Jan 31, 2013 at 07:25:38AM -0600, John Goerzen wrote: > Package: owncloud > Version: 4.0.4debian2-3.2 > Severity: grave > Tags: security > Justification: user security hole > > The version of owncloud in both testing and unstable contains security > h

Processed (with 1 errors): Re: [Secure-testing-team] Bug#699441: owncloud: Multiple security issues in owncloud

2013-01-31 Thread Debian Bug Tracking System
Processing control commands: > merge 698737 699441 Bug #698737 [src:owncloud] owncloud: Multiple XSS vulnerabilities (oC-SA-2013-001) Unable to merge bugs because: package of #699441 is 'owncloud' not 'src:owncloud' Failed to merge 698737: Did not alter merged bugs Debbugs::Control::set_m

Processed: found 699441 in 4.0.8debian-1.3

2013-01-31 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > found 699441 4.0.8debian-1.3 Bug #699441 [owncloud] owncloud: Multiple security issues in owncloud Marked as found in versions owncloud/4.0.8debian-1.3. > thanks Stopping processing here. Please contact me if you need assistance. -- 699441: http

Bug#699316: libupnp4: Multiple stack buffer overflow vulnerabilities

2013-01-31 Thread Scott Howard
clone 699316 -1 reassign -1 libupnp4 retitle -1 libupnp4: Multiple stack buffer overflow vulnerabilities thanks >From [1], libupnp4 has the same vulnerabilities as described in Bug #688316. Cloning so it's on someone's radar. [1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=699351 -- To UN

Processed (with 3 errors): libupnp4: Multiple stack buffer overflow vulnerabilities

2013-01-31 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > clone 699316 -1 Bug #699316 [libupnp] libupnp: Multiple stack buffer overflow vulnerabilities Bug #699342 [libupnp] libupnp6: Security problem in SSDP code widely publicized today Failed to clone 699316: Bug is marked as being merged with others.

Bug#699441: owncloud: Multiple security issues in owncloud

2013-01-31 Thread John Goerzen
Package: owncloud Version: 4.0.4debian2-3.2 Severity: grave Tags: security Justification: user security hole The version of owncloud in both testing and unstable contains security holes. http://owncloud.org/changelog/ has details. Upstream versions 4.0.11 and 4.5.6 fixed: * Security: Fix multi

Bug#698527: elmer: executable ElmerGUI.real links with both GPL-licensed and GPL-incompatible libraries

2013-01-31 Thread Boris Pek
Hi, I see you contacted with Open CASCADE S.A.S. using their contact form on web site. Have they replied? Did you try to send your messages directly to email or another? Have they replied in this case? I believe that discussion with Open CASCADE S.A.S. should be public but not personal. Is there

Bug#693666: marked as done (Contains non-free FPGA bitfiles)

2013-01-31 Thread Debian Bug Tracking System
Your message dated Thu, 31 Jan 2013 10:47:32 + with message-id and subject line Bug#693666: fixed in dahdi-linux 1:2.6.1+dfsg2-1 has caused the Debian Bug report #693666, regarding Contains non-free FPGA bitfiles to be marked as done. This means that you claim that the problem has been dealt

Bug#685812: ABI change in 1.6.1 version

2013-01-31 Thread Sébastien Villemot
Update: all reverse dependencies are now fixed, except pygtk which FTBFS on ia64. Once this is sorted out, I plan to NMU python-numpy with the patch previously sent, and then finally close this bug. -- .''`.Sébastien Villemot : :' :Debian Developer `. `' http://www.dynare.org/sebasti

Bug#673185: marked as done (gnome-shell: segfault in libaccountsservice.so.0.0.0)

2013-01-31 Thread Debian Bug Tracking System
Your message dated Thu, 31 Jan 2013 09:55:51 + with message-id and subject line Closing #674419 has caused the Debian Bug report #674419, regarding gnome-shell: segfault in libaccountsservice.so.0.0.0 to be marked as done. This means that you claim that the problem has been dealt with. If th

Bug#673211: marked as done (gnome-shell: segfault in libaccountsservice.so.0.0.0)

2013-01-31 Thread Debian Bug Tracking System
Your message dated Thu, 31 Jan 2013 09:55:51 + with message-id and subject line Closing #674419 has caused the Debian Bug report #674419, regarding gnome-shell: segfault in libaccountsservice.so.0.0.0 to be marked as done. This means that you claim that the problem has been dealt with. If th

Bug#674419: marked as done (gnome-shell: segfaults in libaccountservice)

2013-01-31 Thread Debian Bug Tracking System
Your message dated Thu, 31 Jan 2013 09:55:51 + with message-id and subject line Closing #674419 has caused the Debian Bug report #674419, regarding gnome-shell: segfaults in libaccountservice to be marked as done. This means that you claim that the problem has been dealt with. If this is not

Bug#674419: marked as done (gnome-shell: segfaults in libaccountservice)

2013-01-31 Thread Debian Bug Tracking System
Your message dated Thu, 31 Jan 2013 09:55:02 + with message-id and subject line Closes: #673211 has caused the Debian Bug report #673211, regarding gnome-shell: segfaults in libaccountservice to be marked as done. This means that you claim that the problem has been dealt with. If this is not

Bug#673185: marked as done (gnome-shell: segfault in libaccountsservice.so.0.0.0)

2013-01-31 Thread Debian Bug Tracking System
Your message dated Thu, 31 Jan 2013 09:55:02 + with message-id and subject line Closes: #673211 has caused the Debian Bug report #673211, regarding gnome-shell: segfault in libaccountsservice.so.0.0.0 to be marked as done. This means that you claim that the problem has been dealt with. If th

Bug#673211: marked as done (gnome-shell: segfault in libaccountsservice.so.0.0.0)

2013-01-31 Thread Debian Bug Tracking System
Your message dated Thu, 31 Jan 2013 09:55:02 + with message-id and subject line Closes: #673211 has caused the Debian Bug report #673211, regarding gnome-shell: segfault in libaccountsservice.so.0.0.0 to be marked as done. This means that you claim that the problem has been dealt with. If th

Bug#696625: marked as done (EXDEV not catched properly)

2013-01-31 Thread Debian Bug Tracking System
Your message dated Thu, 31 Jan 2013 09:47:30 + with message-id and subject line Bug#696625: fixed in autopkgtest 2.2.3+nmu1 has caused the Debian Bug report #696625, regarding EXDEV not catched properly to be marked as done. This means that you claim that the problem has been dealt with. If t

Bug#699419: snappy: FTBFS because it insists on doing benchmarks despite nocheck/nobench DEB_BUILD_OTPS

2013-01-31 Thread Thorsten Glaser
Source: snappy Version: 1.0.5-2 Severity: serious Justification: fails to build from source (but built successfully in the past) Hi, despite “export DEB_BUILD_OPTIONS='nobench nocheck'” your package insists on running benchmarks during the package build and then fails due to a bug in the benchmar

Processed: calligrastage: fails to upgrade from 'squeeze' - trying to overwrite /usr/share/templates/Presentation.desktop

2013-01-31 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tag 699200 pending Bug #699200 [calligrastage] calligrastage: fails to upgrade from 'squeeze' - trying to overwrite /usr/share/templates/Presentation.desktop Added tag(s) pending. > thanks Stopping processing here. Please contact me if you need

Bug#699351: linux-gd obsolete and lubupnp4

2013-01-31 Thread VALETTE Eric OLNC/OLPS
On 01/30/2013 10:26 PM, Scott Howard wrote: Hello Eric, You wrote: "Linux-igd is dead code, use very old libpunp version that contains numerous security holes. Besides this version is not compatible with IPV6 as required by UPnP IGD V2 specification." I believe yo

Bug#699413: [nagios-snmp-plugins] not compatible with recent libnet-snmp-perl package

2013-01-31 Thread Jan Wagner
Am 31.01.2013 09:10, schrieb Jan Wagner: > Tags: patch now the correct patch against latest package in testing/unstable. diff -u nagios-snmp-plugins-1.1.1/debian/changelog nagios-snmp-plugins-1.1.1/debian/changelog --- nagios-snmp-plugins-1.1.1/debian/changelog +++ nagios-snmp-plugins-1.1.1/debian

Processed: [pkg-nagios] r2081 - in nagios-snmp-plugins/trunk/debian: . patches

2013-01-31 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tags 699413 pending Bug #699413 [nagios-snmp-plugins] [nagios-snmp-plugins] not compatible with recent libnet-snmp-perl package Added tag(s) pending. > thanks Stopping processing here. Please contact me if you need assistance. -- 699413: http:/

Bug#699413: [Pkg-nagios-devel] Bug#699413: [nagios-snmp-plugins] not compatible with recent libnet-snmp-perl package

2013-01-31 Thread Michael Friedrich
On 31.01.2013 09:10, Jan Wagner wrote: Package: nagios-snmp-plugins Version: 1.1.1-7 Severity: serious Tags: patch All scripts are failing with: Argument "v6.0.1" isn't numeric in numeric lt (<) at /usr/lib/nagios/plugins/check_snmp_(.*).pl line [0-9]*. This is due a incompatibility of version