Processed: reassign 773575 to src:ntp, forcibly merging 773576 773575

2014-12-21 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > reassign 773575 src:ntp Bug #773575 [ntp] ntp: CERT VU#852879 Bug reassigned from package 'ntp' to 'src:ntp'. No longer marked as found in versions ntp/1:4.2.6.p5+dfsg-2. Ignoring request to alter fixed versions of bug #773575 to the same values

Bug#747141: [debhelper-devel] Bug#747141: dh_installdocs --link-doc forces source-version dependencies (Was: Re: [debhelper-devel] Bug#747141: closed by Niels Thykier (Bug#747141:

2014-12-21 Thread Niels Thykier
On 2014-12-22 07:47, Stephen Kitt wrote: > Control: reopen -1 > Control: found -1 debhelper/9.20141222 > > Hi Niels, > Hi Stephen, > On Mon, 22 Dec 2014 00:36:05 +, ow...@bugs.debian.org (Debian Bug > Tracking System) wrote: >> #747141: debhelper: dh_installdocs --link-doc forces source-ver

Bug#771871: marked as done (netscript: fails to install due to insserv rejecting the script header: There is a loop between service networking and netscript if started)

2014-12-21 Thread Debian Bug Tracking System
Your message dated Mon, 22 Dec 2014 07:18:55 + with message-id and subject line Bug#771871: fixed in netscript-2.4 5.4.6 has caused the Debian Bug report #771871, regarding netscript: fails to install due to insserv rejecting the script header: There is a loop between service networking and n

Bug#747141: closed by Niels Thykier (Bug#747141: fixed in debhelper 9.20141222)

2014-12-21 Thread Stephen Kitt
Control: reopen -1 Control: found -1 debhelper/9.20141222 Hi Niels, On Mon, 22 Dec 2014 00:36:05 +, ow...@bugs.debian.org (Debian Bug Tracking System) wrote: > #747141: debhelper: dh_installdocs --link-doc forces source-version > dependencies Unfortunately the bug I reported isn't fixed (see

Processed: Re: Bug#747141 closed by Niels Thykier (Bug#747141: fixed in debhelper 9.20141222)

2014-12-21 Thread Debian Bug Tracking System
Processing control commands: > reopen -1 Bug #747141 {Done: Niels Thykier } [debhelper] debhelper: dh_installdocs --link-doc forces source-version dependencies Bug #766711 {Done: Niels Thykier } [debhelper] debhelper: Dependency added by dh_installdocs --link-doc breaks binary-only NMUs Bug #766

Processed (with 1 errors): forcibly merging 773576 773575

2014-12-21 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > forcemerge 773576 773575 Bug #773576 {Done: } [src:ntp] ntp: CVE-2014-9293 CVE-2014-9294 CVE-2014-9295 CVE-2014-9296 Unable to merge bugs because: package of #773575 is 'ntp' not 'src:ntp' Failed to forcibly merge 773576: Did not alter merged bug

Bug#748728: Bug#772679: unblock: libuser/1:0.60~dfsg-1.1

2014-12-21 Thread Brad Bosch
I've not chimed in on this yet because I haven't had much time to research the history or use of libuser (and I still haven't, really). But I'd like to point out... The id-utils package has been part of Debian for almost as long as Debian existed. It is a rather old official GNU package (for wha

Bug#773041: Bug#773318: clamav dies/hangs

2014-12-21 Thread duck
Coin, On 2014-12-21 22:16, Sebastian Andrzej Siewior wrote: On 2014-12-20 12:12:13 [+0100], Andreas Cadhalpun wrote: As it shows that clamd hangs in libmspack, I think this is bug #773041 [1]. A possible fix is mentioned in [2]. I can upload this simple fix quickly, nevertheless i did not ha

Bug#766711: marked as done (debhelper: Dependency added by dh_installdocs --link-doc breaks binary-only NMUs)

2014-12-21 Thread Debian Bug Tracking System
Your message dated Mon, 22 Dec 2014 00:33:55 + with message-id and subject line Bug#747141: fixed in debhelper 9.20141222 has caused the Debian Bug report #747141, regarding debhelper: Dependency added by dh_installdocs --link-doc breaks binary-only NMUs to be marked as done. This means that

Bug#766795: marked as done (afterstep not binnmu safe and not installable in sid)

2014-12-21 Thread Debian Bug Tracking System
Your message dated Mon, 22 Dec 2014 00:33:55 + with message-id and subject line Bug#747141: fixed in debhelper 9.20141222 has caused the Debian Bug report #747141, regarding afterstep not binnmu safe and not installable in sid to be marked as done. This means that you claim that the problem h

Bug#747141: marked as done (debhelper: dh_installdocs --link-doc forces source-version dependencies)

2014-12-21 Thread Debian Bug Tracking System
Your message dated Mon, 22 Dec 2014 00:33:55 + with message-id and subject line Bug#747141: fixed in debhelper 9.20141222 has caused the Debian Bug report #747141, regarding debhelper: dh_installdocs --link-doc forces source-version dependencies to be marked as done. This means that you clai

Bug#773579: fontypython should be ported to wx 3.0 (yes, again)

2014-12-21 Thread Olly Betts
On Mon, Dec 22, 2014 at 12:17:12AM +0100, Pietro Battiston wrote: > Yes, stock buttons are indeed localized (i.e. the wx.ID_CANCEL in the > settings dialog). > > The only localization initialization I see is in > fontypythonmodules/i18n.py ... maybe wx is getting the locale from > gettext?! I rea

Bug#773579: fontypython should be ported to wx 3.0 (yes, again)

2014-12-21 Thread Pietro Battiston
Il giorno dom, 21/12/2014 alle 22.58 +, Olly Betts ha scritto: > On Sun, Dec 21, 2014 at 11:16:16PM +0100, Pietro Battiston wrote: > > Il giorno dom, 21/12/2014 alle 20.07 +, Olly Betts ha scritto: > > > On Sun, Dec 21, 2014 at 12:41:19AM +0100, Pietro Battiston wrote: > > > > Il giorno sab

Processed: Re: Bug#773343: request-tracker4: fails to upgrade from 'wheezy' if rt4-extension-assettracker is installed

2014-12-21 Thread Debian Bug Tracking System
Processing control commands: > tag -1 + confirmed Bug #773343 [request-tracker4] request-tracker4: fails to upgrade from 'wheezy' if rt4-extension-assettracker is installed Added tag(s) confirmed. -- 773343: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=773343 Debian Bug Tracking System Cont

Bug#773343: request-tracker4: fails to upgrade from 'wheezy' if rt4-extension-assettracker is installed

2014-12-21 Thread gregor herrmann
Control: tag -1 + confirmed On Wed, 17 Dec 2014 10:36:49 +0100, Andreas Beckmann wrote: > Package: request-tracker4 > Version: 4.2.8-1 > Severity: serious > User: debian...@lists.debian.org > Usertags: piuparts > > Hi, > > during a test with piuparts I noticed your package fails to upgrade from

Bug#773579: fontypython should be ported to wx 3.0 (yes, again)

2014-12-21 Thread Olly Betts
On Sun, Dec 21, 2014 at 11:16:16PM +0100, Pietro Battiston wrote: > Il giorno dom, 21/12/2014 alle 20.07 +, Olly Betts ha scritto: > > On Sun, Dec 21, 2014 at 12:41:19AM +0100, Pietro Battiston wrote: > > > Il giorno sab, 20/12/2014 alle 10.37 +, Olly Betts ha scritto: > > > > On Sat, Dec 2

Bug#772793: cpio: CVE-2014-9112

2014-12-21 Thread Michael Gilbert
On Sun, Dec 21, 2014 at 12:15 AM, Michael Gilbert wrote: > Those are included in the LTS update, and I think they really need to > be included in exp/unstable also. Hi, I uploaded an nmu with the mentioned changes to unstable. Please see attached patch. Best wishes, Mike diff -Nru cpio-2.11+dfs

Bug#772864: marked as done (mcollective: Trigger cycle causes dpkg to fail processing)

2014-12-21 Thread Debian Bug Tracking System
Your message dated Sun, 21 Dec 2014 22:49:44 + with message-id and subject line Bug#772864: fixed in mcollective 2.6.0+dfsg-2.1 has caused the Debian Bug report #772864, regarding mcollective: Trigger cycle causes dpkg to fail processing to be marked as done. This means that you claim that th

Bug#772793: marked as done (cpio: CVE-2014-9112)

2014-12-21 Thread Debian Bug Tracking System
Your message dated Sun, 21 Dec 2014 22:33:57 + with message-id and subject line Bug#772793: fixed in cpio 2.11+dfsg-2.1 has caused the Debian Bug report #772793, regarding cpio: CVE-2014-9112 to be marked as done. This means that you claim that the problem has been dealt with. If this is not

Bug#773579: fontypython should be ported to wx 3.0 (yes, again)

2014-12-21 Thread Pietro Battiston
Il giorno dom, 21/12/2014 alle 20.07 +, Olly Betts ha scritto: > On Sun, Dec 21, 2014 at 12:41:19AM +0100, Pietro Battiston wrote: > > Il giorno sab, 20/12/2014 alle 10.37 +, Olly Betts ha scritto: > > > On Sat, Dec 20, 2014 at 10:10:53AM +0100, Pietro Battiston wrote: > > > > [...] > > 1)

Processed: your mail

2014-12-21 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > severity 773623 grave Bug #773623 [libv8-3.14] nodejs: CVE-2014-7192 Severity set to 'grave' from 'important' > thanks Stopping processing here. Please contact me if you need assistance. -- 773623: http://bugs.debian.org/cgi-bin/bugreport.cgi?bu

Bug#773576: marked as done (ntp: CVE-2014-9293 CVE-2014-9294 CVE-2014-9295 CVE-2014-9296)

2014-12-21 Thread Debian Bug Tracking System
Your message dated Sun, 21 Dec 2014 22:05:29 + with message-id and subject line Bug#773576: fixed in ntp 1:4.2.6.p5+dfsg-3.2 has caused the Debian Bug report #773576, regarding ntp: CVE-2014-9293 CVE-2014-9294 CVE-2014-9295 CVE-2014-9296 to be marked as done. This means that you claim that th

Bug#773323: marked as done (perl: Wheezy->Jessie upgrade breaks wheezy pdl)

2014-12-21 Thread Debian Bug Tracking System
Your message dated Sun, 21 Dec 2014 22:06:04 + with message-id and subject line Bug#773323: fixed in perl 5.20.1-4 has caused the Debian Bug report #773323, regarding perl: Wheezy->Jessie upgrade breaks wheezy pdl to be marked as done. This means that you claim that the problem has been dealt

Bug#772956: marked as done (tlsdate: FTBFS on recent MIPS kernels)

2014-12-21 Thread Debian Bug Tracking System
Your message dated Sun, 21 Dec 2014 21:53:27 + with message-id and subject line Bug#772956: fixed in tlsdate 0.0.12-2 has caused the Debian Bug report #772956, regarding tlsdate: FTBFS on recent MIPS kernels to be marked as done. This means that you claim that the problem has been dealt with.

Bug#711502: marked as done (Bug in quotatool, need to update package)

2014-12-21 Thread Debian Bug Tracking System
Your message dated Sun, 21 Dec 2014 21:53:07 + with message-id and subject line Bug#711502: fixed in quotatool 1:1.4.12-2 has caused the Debian Bug report #711502, regarding Bug in quotatool, need to update package to be marked as done. This means that you claim that the problem has been deal

Bug#773263: marked as done (subversion: CVE-2014-3580)

2014-12-21 Thread Debian Bug Tracking System
Your message dated Sun, 21 Dec 2014 21:53:21 + with message-id and subject line Bug#773263: fixed in subversion 1.6.12dfsg-7+deb6u1 has caused the Debian Bug report #773263, regarding subversion: CVE-2014-3580 to be marked as done. This means that you claim that the problem has been dealt wit

Bug#772811: unrtf: CVE-2014-9274 CVE-2014-9275

2014-12-21 Thread Salvatore Bonaccorso
Hi Willi, On Sun, Dec 21, 2014 at 10:02:08PM +0100, Willi Mann wrote: > Hi Salvatore, > > we were working in parallel unfortunately, as I prepared the same > patches in the morning. However, I also added 2 patches by > Fabian Keil. I'll upload tomorrow in the evening, you can have a look at Don

Bug#772325: marked as done (libmbim-utils: bashism in /bin/sh script)

2014-12-21 Thread Debian Bug Tracking System
Your message dated Sun, 21 Dec 2014 21:19:41 + with message-id and subject line Bug#772325: fixed in libmbim 1.10.0-2.1 has caused the Debian Bug report #772325, regarding libmbim-utils: bashism in /bin/sh script to be marked as done. This means that you claim that the problem has been dealt

Bug#773041: Bug#773318: clamav dies/hangs

2014-12-21 Thread Sebastian Andrzej Siewior
On 2014-12-20 12:12:13 [+0100], Andreas Cadhalpun wrote: > As it shows that clamd hangs in libmspack, I think this is bug #773041 [1]. > A possible fix is mentioned in [2]. We'll have to include it in the > libmspack copy embedded in clamav, which is used in wheezy. Oh great. So for clamav we have

Bug#771132: marked as done (morse-simulator is not usable with the current version of blender)

2014-12-21 Thread Debian Bug Tracking System
Your message dated Sun, 21 Dec 2014 21:20:24 + with message-id and subject line Bug#771132: fixed in morse-simulator 1.2.1-2 has caused the Debian Bug report #771132, regarding morse-simulator is not usable with the current version of blender to be marked as done. This means that you claim th

Bug#772811: unrtf: CVE-2014-9274 CVE-2014-9275

2014-12-21 Thread Willi Mann
Hi Salvatore, we were working in parallel unfortunately, as I prepared the same patches in the morning. However, I also added 2 patches by Fabian Keil. I'll upload tomorrow in the evening, you can have a look at http://anonscm.debian.org/cgit/collab-maint/unrtf.git/ comments welcome. thanks Wi

Bug#751005: Bug #751005:

2014-12-21 Thread Thomas Vincent
Hello, Damien 'drazzib' Raude-Morvan and I tried to investigate this bug. We reproduced the ftbfs on armhf for version 2.49-10, but also 2.49-9. Since builds for 2.49-9 were successful according to buildd, it may be the result of a side effect from a build-dependency. FYI, clisp's build seems to

Bug#773670: marked as done (google-chrome: Google chrome repeatedly freezes after update to Jessie, it was working before.)

2014-12-21 Thread Debian Bug Tracking System
Your message dated Sun, 21 Dec 2014 15:25:58 -0500 with message-id and subject line Re: Bug#773670: google-chrome: Google chrome repeatedly freezes after update to Jessie, it was working before. has caused the Debian Bug report #773670, regarding google-chrome: Google chrome repeatedly freezes a

Bug#767037: Grub EFI fallback - patches for review

2014-12-21 Thread Steve McIntyre
On Sun, Dec 21, 2014 at 10:49:59AM +, Ian Campbell wrote: >On Sat, 2014-12-20 at 09:45 +0100, David Härdeman wrote: >> one option that doesn't seem to have been considered would be to create >> a separate package (let's call it UEFIx) that installs an UEFI binary to >> EFI/boot/bootx64.efi. Tha

Bug#760385: lowering severity of bugs not tracked by release team

2014-12-21 Thread Michael Gilbert
On Sun, Dec 21, 2014 at 9:11 AM, Bálint Réczey wrote: >> The problem still remains that the backlog of libv8 security issues >> never get fixed (except for a new upstream every now and then), so >> treating this one as RC but not the others is rather inconsistent: >> https://security-tracker.debian

Bug#767037: Grub EFI fallback - patches for review

2014-12-21 Thread Steve McIntyre
On Sat, Dec 20, 2014 at 09:45:30AM +0100, David Härdeman wrote: >Hi, Hi! >one option that doesn't seem to have been considered would be to create >a separate package (let's call it UEFIx) that installs an UEFI binary to >EFI/boot/bootx64.efi. That binary could then do what the UEFI BIOS >should'v

Bug#773671: libv8-3.14: multiple security issues

2014-12-21 Thread Michael Gilbert
package: src:libv8-3.14 severity: grave tags: security Hi, the following vulnerabilities were published for libv8-3.14. CVE-2013-2632[0]: | Google V8 before 3.17.13, as used in Google Chrome before 27.0.1444.3, | allows remote attackers to cause a denial of service (application | crash) or possi

Bug#773670: google-chrome: Google chrome repeatedly freezes after update to Jessie, it was working before.

2014-12-21 Thread Khizar Karim
Package: google-chrome Severity: grave Justification: renders package unusable Dear Maintainer, *** Reporter, please consider answering these questions, where appropriate *** * What led up to the situation? I usually browse the Internet using Google Chrome. It crashes randomly, usually eithe

Bug#773579: fontypython: diff for NMU version 0.4.4-1.3

2014-12-21 Thread Olly Betts
Control: tags 773579 + patch Output from nmudiff showing the fix mentioned in my previous comment. Cheers, Olly diff -Nru fontypython-0.4.4/debian/changelog fontypython-0.4.4/debian/changelog --- fontypython-0.4.4/debian/changelog 2014-12-14 21:41:50.0 +1300 +++ fontypython-0.4.4/debi

Bug#773579: fontypython should be ported to wx 3.0 (yes, again)

2014-12-21 Thread Olly Betts
On Sun, Dec 21, 2014 at 12:41:19AM +0100, Pietro Battiston wrote: > Il giorno sab, 20/12/2014 alle 10.37 +, Olly Betts ha scritto: > > On Sat, Dec 20, 2014 at 10:10:53AM +0100, Pietro Battiston wrote: > > > So using wx 2.8 is not an option in jessie, and the original bug must be > > > solved. >

Processed: fontypython: diff for NMU version 0.4.4-1.3

2014-12-21 Thread Debian Bug Tracking System
Processing control commands: > tags 773579 + patch Bug #773579 [fontypython] fontypython should be ported to wx 3.0 (yes, again) Added tag(s) patch. -- 773579: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=773579 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems -- To U

Bug#731583: sudo FQDN issue: upstream fixed it

2014-12-21 Thread Michael Gilbert
On Sun, Dec 14, 2014 at 11:02 AM, Christian Kastner wrote: > On 2014-11-16 15:07, Christian Kastner wrote: >> I only now realized that the version of sudo in testing is still at >> 1.8.10p3-1. The diff to 1.8.11p2-1 is not trivial. However, given that >> 1.8.11p1-1 was uploaded on Oct 20th, and the

Processed: your mail

2014-12-21 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tag 772365 patch, pending Bug #772365 [simpleburn] simpleburn: bashism in /bin/sh script Added tag(s) pending and patch. > thanks Stopping processing here. Please contact me if you need assistance. -- 772365: http://bugs.debian.org/cgi-bin/bugre

Bug#772811: marked as done (unrtf: CVE-2014-9274 CVE-2014-9275)

2014-12-21 Thread Debian Bug Tracking System
Your message dated Sun, 21 Dec 2014 19:36:52 + with message-id and subject line Bug#772811: fixed in unrtf 0.21.8-clean-1 has caused the Debian Bug report #772811, regarding unrtf: CVE-2014-9274 CVE-2014-9275 to be marked as done. This means that you claim that the problem has been dealt with

Bug#752726: Bug #752726: Unable to reproduce

2014-12-21 Thread Thomas Vincent
Hello, Damien 'drazzib' Raude-Morvan and I tried to reproduce this bug in chroots (with sbuild) in both jessie and sid: * using the current stumpwm package from sid and setting clisp as the compiler * creating a complete chroot from snapshot.debian.org (20140625) corresponding to the date t

Bug#773576: ntp: CVE-2014-9293 CVE-2014-9294 CVE-2014-9295 CVE-2014-9296

2014-12-21 Thread Noah Meyerhans
On Sun, Dec 21, 2014 at 10:16:37AM -0800, Noah Meyerhans wrote: > I'm putting an NMU targeting sid/jessie together now. Unless someone > beats me to it, I should be uploading today. Not sure why, but I don't have commit access to the ntp svn repo. Going to upload anyway, and will follow up with sv

Bug#731583: marked as done (Compares hostname no longer using FQDN)

2014-12-21 Thread Debian Bug Tracking System
Your message dated Sun, 21 Dec 2014 19:04:16 + with message-id and subject line Bug#731583: fixed in sudo 1.8.11p2-1.1 has caused the Debian Bug report #731583, regarding Compares hostname no longer using FQDN to be marked as done. This means that you claim that the problem has been dealt wit

Bug#701680: marked as done (Segfault when attempting to read a file)

2014-12-21 Thread Debian Bug Tracking System
Your message dated Sun, 21 Dec 2014 18:48:49 + with message-id and subject line Bug#674753: fixed in djmount 0.71-7 has caused the Debian Bug report #674753, regarding Segfault when attempting to read a file to be marked as done. This means that you claim that the problem has been dealt with.

Bug#674753: marked as done (djmount: Cannot read any media from mounted DLNA server)

2014-12-21 Thread Debian Bug Tracking System
Your message dated Sun, 21 Dec 2014 18:48:49 + with message-id and subject line Bug#701680: fixed in djmount 0.71-7 has caused the Debian Bug report #701680, regarding djmount: Cannot read any media from mounted DLNA server to be marked as done. This means that you claim that the problem has

Bug#701680: marked as done (Segfault when attempting to read a file)

2014-12-21 Thread Debian Bug Tracking System
Your message dated Sun, 21 Dec 2014 18:48:49 + with message-id and subject line Bug#701680: fixed in djmount 0.71-7 has caused the Debian Bug report #701680, regarding Segfault when attempting to read a file to be marked as done. This means that you claim that the problem has been dealt with.

Bug#674753: marked as done (djmount: Cannot read any media from mounted DLNA server)

2014-12-21 Thread Debian Bug Tracking System
Your message dated Sun, 21 Dec 2014 18:48:49 + with message-id and subject line Bug#674753: fixed in djmount 0.71-7 has caused the Debian Bug report #674753, regarding djmount: Cannot read any media from mounted DLNA server to be marked as done. This means that you claim that the problem has

Bug#748728: Bug#772679: unblock: libuser/1:0.60~dfsg-1.1

2014-12-21 Thread Michael Gilbert
On Wed, Dec 10, 2014 at 11:39 AM, Julien Cristau wrote: > Because that's not what policy says Conflicts is for. If typing 'lid' > runs an entirely different command depending on the phase of the moon, > we've done something wrong, and we should fix it. It's quite possible > the least disruptive o

Bug#748728: Bug#772679: unblock: libuser/1:0.60~dfsg-1.1

2014-12-21 Thread Michael Gilbert
On Sun, Dec 21, 2014 at 1:32 PM, Michael Gilbert wrote: > Here is a proposal, rename "lid" in id-utils to "qid". Here is the logic: Also, no other package provides a "qid" binary in any of the bin dirs. Best wishes, Mike -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with

Processed: tagging 701680

2014-12-21 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tags 701680 + pending Bug #701680 [djmount] Segfault when attempting to read a file Bug #674753 [djmount] djmount: Cannot read any media from mounted DLNA server Added tag(s) pending. Added tag(s) pending. > thanks Stopping processing here. Pleas

Bug#773576: ntp: CVE-2014-9293 CVE-2014-9294 CVE-2014-9295 CVE-2014-9296

2014-12-21 Thread Noah Meyerhans
On Sun, Dec 21, 2014 at 01:05:04PM -0500, Michael Gilbert wrote: > > What about fixes for unstable? > > What about asking for an RFS? I'm putting an NMU targeting sid/jessie together now. Unless someone beats me to it, I should be uploading today. noah signature.asc Description: Digital signa

Processed: your mail

2014-12-21 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > found 773626 6:0.8.5-1 Bug #773626 [src:libav] libav: multiple security issues Marked as found in versions libav/6:0.8.5-1. > notfound 773626 6:0.8.8-1 Bug #773626 [src:libav] libav: multiple security issues No longer marked as found in versions l

Bug#764630: RFS: javatools 0.48 [RC]

2014-12-21 Thread tony mancill
On 12/14/2014 09:50 AM, Markus Koschany wrote: > On 12.12.2014 07:05, tony mancill wrote: > [...] >> Any concerns from the team? This is kind of a brute force approach, but >> seems reasonable. My question is: >> >> Do we feel confident that this the lists below are representative for >> for jess

Bug#773576: ntp: CVE-2014-9293 CVE-2014-9294 CVE-2014-9295 CVE-2014-9296

2014-12-21 Thread Michael Gilbert
On Sun, Dec 21, 2014 at 12:59 PM, Christoph Anton Mitterer wrote: > What about fixes for unstable? What about asking for an RFS? Best wishes, Mike -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#772365: simpleburn: bashism in /bin/sh script

2014-12-21 Thread Mateusz Łukasik
On 21.12.2014 18:51, Georges Khaznadar wrote: Hello, here is my contribution to Jessie's bug squash. I attach a patch with various fixes for bashisms (not fully tested). Best regards, Georges. Control: +patch Contro: +pending Hello, Thanks for patch, I will upload fixed p

Bug#773576: ntp: CVE-2014-9293 CVE-2014-9294 CVE-2014-9295 CVE-2014-9296

2014-12-21 Thread Christoph Anton Mitterer
What about fixes for unstable? Cheers, Chris. smime.p7s Description: S/MIME cryptographic signature

Processed: your mail

2014-12-21 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > found 773626 6:0.8.8-1 Bug #773626 [src:libav] libav: multiple security issues Marked as found in versions libav/6:0.8.8-1. > thanks Stopping processing here. Please contact me if you need assistance. -- 773626: http://bugs.debian.org/cgi-bin/bu

Processed (with 1 errors): your mail

2014-12-21 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > notfound 773626 6:0.8.16-1 Bug #773626 [src:libav] libav: multiple security issues No longer marked as found in versions libav/6:0.8.16-1. > found 6:0.8.8-1 Unknown command or malformed arguments to command. > thanks Stopping processing here. Ple

Bug#772365: simpleburn: bashism in /bin/sh script

2014-12-21 Thread Georges Khaznadar
Hello, here is my contribution to Jessie's bug squash. I attach a patch with various fixes for bashisms (not fully tested). Best regards, Georges. -- Georges KHAZNADAR et Jocelyne FOURNIER 22 rue des mouettes, 59240 Dunkerque France. Téléphone +33 (0)3 28 29 17 70 Index: simp

Bug#771700: marked as done ([freecol] freecol freezes on intro)

2014-12-21 Thread Debian Bug Tracking System
Your message dated Sun, 21 Dec 2014 17:17:06 + with message-id and subject line Bug#771700: fixed in freecol 0.10.5+dfsg-1+deb7u1 has caused the Debian Bug report #771700, regarding [freecol] freecol freezes on intro to be marked as done. This means that you claim that the problem has been de

Bug#768509: marked as done (GOsa gui fails to provide correctly encoded LDAP admin password after decryption with php 5.4.34)

2014-12-21 Thread Debian Bug Tracking System
Your message dated Sun, 21 Dec 2014 17:02:21 + with message-id and subject line Bug#768509: fixed in gosa 2.7.4-4.3~deb7u2 has caused the Debian Bug report #768509, regarding GOsa gui fails to provide correctly encoded LDAP admin password after decryption with php 5.4.34 to be marked as done.

Bug#773463: marked as done (jasper: CVE-2014-8137 CVE-2014-8138)

2014-12-21 Thread Debian Bug Tracking System
Your message dated Sun, 21 Dec 2014 17:02:22 + with message-id and subject line Bug#773463: fixed in jasper 1.900.1-13+deb7u2 has caused the Debian Bug report #773463, regarding jasper: CVE-2014-8137 CVE-2014-8138 to be marked as done. This means that you claim that the problem has been dealt

Bug#765129: tcos: diff for NMU version 0.89.93+nmu1

2014-12-21 Thread Tobias Hansen
Am 21.12.2014 um 17:09 schrieb Mario Izquierdo Rodríguez: > >> >> Hi, >> >> I just realized that there are already different versions in testing and >> unstable. That means we have to upload a targeted fix for the bug for >> the package version that is in testing (0.89.93) to >> testing-proposed-u

Bug#765129: tcos: diff for NMU version 0.89.93+nmu1

2014-12-21 Thread Mario Izquierdo Rodríguez
Hi, I just realized that there are already different versions in testing and unstable. That means we have to upload a targeted fix for the bug for the package version that is in testing (0.89.93) to testing-proposed-updates. Is the start-stop-daemon bug relevant for that version? Also, we can

Bug#765129: tcos: diff for NMU version 0.89.93+nmu1

2014-12-21 Thread Tobias Hansen
Am 21.12.2014 um 16:31 schrieb Mario Izquierdo Rodríguez: > El 21/12/14 a las 16:17, Tobias Hansen escribió: >> Am 21.12.2014 um 16:05 schrieb Mario Izquierdo Rodríguez: >>> El 19/12/14 a las 22:03, Tobias Hansen escribió: On Tue, 02 Dec 2014 21:29:29 +0100 =?UTF-8?B?TWFyaW8gSXpxdWllcmRvI

Bug#765129: tcos: diff for NMU version 0.89.93+nmu1

2014-12-21 Thread Mario Izquierdo Rodríguez
El 21/12/14 a las 16:17, Tobias Hansen escribió: Am 21.12.2014 um 16:05 schrieb Mario Izquierdo Rodríguez: El 19/12/14 a las 22:03, Tobias Hansen escribió: On Tue, 02 Dec 2014 21:29:29 +0100 =?UTF-8?B?TWFyaW8gSXpxdWllcmRvIFJvZHLDrWd1ZXo=?= wrote: El 24/11/14 a las 15:28, Jonathan Wiltshire

Bug#765129: tcos: diff for NMU version 0.89.93+nmu1

2014-12-21 Thread Tobias Hansen
Am 21.12.2014 um 16:05 schrieb Mario Izquierdo Rodríguez: > El 19/12/14 a las 22:03, Tobias Hansen escribió: >> On Tue, 02 Dec 2014 21:29:29 +0100 >> =?UTF-8?B?TWFyaW8gSXpxdWllcmRvIFJvZHLDrWd1ZXo=?= >>wrote: >>> El 24/11/14 a las 15:28, Jonathan Wiltshire escribió: On Mon, Nov 24, 2014 at

Bug#765129: tcos: diff for NMU version 0.89.93+nmu1

2014-12-21 Thread Mario Izquierdo Rodríguez
El 19/12/14 a las 22:03, Tobias Hansen escribió: On Tue, 02 Dec 2014 21:29:29 +0100 =?UTF-8?B?TWFyaW8gSXpxdWllcmRvIFJvZHLDrWd1ZXo=?= wrote: El 24/11/14 a las 15:28, Jonathan Wiltshire escribió: On Mon, Nov 24, 2014 at 12:05:21AM +0100, Mario Izquierdo Rodríguez wrote: El 23/11/14 a las 19

Processed: tagging 772811

2014-12-21 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tags 772811 + fixed-upstream Bug #772811 [unrtf] unrtf: CVE-2014-9274 CVE-2014-9275 Added tag(s) fixed-upstream. > thanks Stopping processing here. Please contact me if you need assistance. -- 772811: http://bugs.debian.org/cgi-bin/bugreport.cgi

Bug#772811: unrtf: CVE-2014-9274 CVE-2014-9275

2014-12-21 Thread Dave Davey
On Sun, Dec 21, 2014 at 03:08:00PM +0100, Salvatore Bonaccorso wrote: > Hi Willi, > > On Sun, Dec 14, 2014 at 10:10:58AM +0100, Willi Mann wrote: > > Hi Dave, > > > > does 0.21.7 solve both security issues reported? If yes, could point > > send me the individual patches that fix these issues? The

Bug#772811: unrtf: CVE-2014-9274 CVE-2014-9275

2014-12-21 Thread Salvatore Bonaccorso
Control: tags -1 + patch Hi Willi Attached are two patches separated per CVEs. Regards, Salvatore Description: CVE-2014-9274: out-of-bounds memory access UnRTF allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code as demonstrated by a file containing

Processed: Re: Bug#772811: unrtf: CVE-2014-9274 CVE-2014-9275

2014-12-21 Thread Debian Bug Tracking System
Processing control commands: > tags -1 + patch Bug #772811 [unrtf] unrtf: CVE-2014-9274 CVE-2014-9275 Added tag(s) patch. -- 772811: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=772811 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems -- To UNSUBSCRIBE, email to debian

Bug#760385: lowering severity of bugs not tracked by release team

2014-12-21 Thread Bálint Réczey
Hi Mike, First, I had to cancel the upload because of too strict reverse dependencies. Dear fellow JavaScript maintainers please figure out a less strict dependency graph because every otherwise fully compatible libv8 update would break several packages. 2014-12-21 2:13 GMT+01:00 Michael Gilbert

Bug#772811: unrtf: CVE-2014-9274 CVE-2014-9275

2014-12-21 Thread Salvatore Bonaccorso
Hi Willi, On Sun, Dec 14, 2014 at 10:10:58AM +0100, Willi Mann wrote: > Hi Dave, > > does 0.21.7 solve both security issues reported? If yes, could point > send me the individual patches that fix these issues? The Debian branch > for the next stable distribution is already frozen, so I cannot fix

Bug#771877: original symlink target is not an absolute path on libdb5.3-java_5.3.28-7~deb8u1

2014-12-21 Thread Tangui Morlier
The post-removal script fails during the upgrade of libdb5.3-java from version 5.3.28-6 to 5.3.28-7~deb8u1. dpkg-maintscript-helper says « error: original symlink target is not an absolute path ». I assume this is linked to the symlink_to_dir that has been solved but my apt stays blocked on this

Bug#772233: bashism in /bin/sh script

2014-12-21 Thread Holger Levsen
Hi, On Samstag, 20. Dezember 2014, Bálint Réczey wrote: > I made a typo in the bug number, please see the fixed patch attached. > I also reuploaded the package to DELAYED/2. looks good to me, thanks for your work, Balint! cheers, Holger signature.asc Description: This is a digitall

Bug#773633: marked as done (flashplugin-nonfree: should have Pre-Depends: ca-certificates)

2014-12-21 Thread Debian Bug Tracking System
Your message dated Sun, 21 Dec 2014 11:03:54 + with message-id and subject line Bug#773633: fixed in flashplugin-nonfree 1:3.6.1 has caused the Debian Bug report #773633, regarding flashplugin-nonfree: should have Pre-Depends: ca-certificates to be marked as done. This means that you claim th

Bug#773629: marked as done (pepperflashplugin-nonfree: ca-certificate triggers processed after download attempt)

2014-12-21 Thread Debian Bug Tracking System
Your message dated Sun, 21 Dec 2014 11:04:44 + with message-id and subject line Bug#773629: fixed in pepperflashplugin-nonfree 1.8.1 has caused the Debian Bug report #773629, regarding pepperflashplugin-nonfree: ca-certificate triggers processed after download attempt to be marked as done. T

Bug#773629: pepperflashplugin-nonfree: ca-certificates triggers processed after download attempt

2014-12-21 Thread Bart Martens
Illustrating that this solves the issue: | # apt-get install pepperflashplugin-nonfree | Reading package lists... | Building dependency tree... | Reading state information... | The following extra packages will be installed: |ca-certificates wget ... | Setting up ca-certifi

Bug#773191: python-ogg-dbg: unhandled symlink to directory conversion: /usr/share/doc/PACKAGE

2014-12-21 Thread Sandro Tosi
Hi Jean-Michel, Thanks for your work, I will fix the package soon from dpmt repo; and yes the right solution is to use dpkg maint scripts to fix the dir-link transition. Regards, Sandro Il 21/dic/2014 02:57 "Jean-Michel Nirgal Vourgère" ha scritto: > Jean-Michel Nirgal Vourgère: > > This problem

Bug#767037: Grub EFI fallback - patches for review

2014-12-21 Thread Ian Campbell
On Sat, 2014-12-20 at 09:45 +0100, David Härdeman wrote: > one option that doesn't seem to have been considered would be to create > a separate package (let's call it UEFIx) that installs an UEFI binary to > EFI/boot/bootx64.efi. That binary could then do what the UEFI BIOS > should've done (i.e. l

Bug#773633: flashplugin-nonfree: should have Pre-Depends: ca-certificates

2014-12-21 Thread Bart Martens
Illustrating that moving ca-certificates to Pre-Depends solves the issue: | # apt-get install flashplugin-nonfree | Reading package lists... Done | Building dependency tree | Reading state information... Done | The following extra packages will be installed: |ca-certifi

Processed: fixed 772793 in 2.11-4+deb6u1

2014-12-21 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > # add back fixed version for squeeze-lts > fixed 772793 2.11-4+deb6u1 Bug #772793 [cpio] cpio: CVE-2014-9112 Marked as fixed in versions cpio/2.11-4+deb6u1. > thanks Stopping processing here. Please contact me if you need assistance. -- 772793:

Bug#773629: pepperflashplugin-nonfree: ca-certificates triggers processed after download attempt

2014-12-21 Thread Bart Martens
On Sun, Dec 21, 2014 at 12:56:44AM -0500, Michael Gilbert wrote: > A pre-depends ca-certificates will probably solve the problem. I agree with that. Illustrated below: | # apt-get install pepperflashplugin-nonfree | Reading package lists... Done | Building dependency tree | Rea

Bug#773633: flashplugin-nonfree: should have Pre-Depends: ca-certificates

2014-12-21 Thread Bart Martens
Package: flashplugin-nonfree Version: 1:3.6 Severity: serious As illustrated below, flashplugin-nonfree should have "Pre-Depends: ca-certificates". | # apt-get install flashplugin-nonfree | Reading package lists... Done | Building dependency tree | Reading state information...