Bug#840957: mupdf: CVE-2016-8674: heap-use-after-free

2016-10-27 Thread Salvatore Bonaccorso
Hi, On Sun, Oct 16, 2016 at 02:51:06PM +0200, Salvatore Bonaccorso wrote: > Source: mupdf > Version: 1.5-1 > Severity: grave > Tags: security upstream patch > > Hi, > > the following vulnerability was published for mupdf. > > CVE-2016-8674[0]: > heap-use-after-free > > The issue is reproducibl

Bug#828239: marked as done (asio: FTBFS with openssl 1.1.0)

2016-10-27 Thread Debian Bug Tracking System
Your message dated Fri, 28 Oct 2016 08:49:23 +0200 with message-id and subject line Re: Bug#828239: asio: FTBFS with openssl 1.1.0 has caused the Debian Bug report #828239, regarding asio: FTBFS with openssl 1.1.0 to be marked as done. This means that you claim that the problem has been dealt wit

Processed: Bug#842295 marked as pending

2016-10-27 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tag 842295 pending Bug #842295 [src:nginx] nginx: CVE-2016-1247 Added tag(s) pending. > thanks Stopping processing here. Please contact me if you need assistance. -- 842295: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=842295 Debian Bug Trac

Bug#842295: marked as pending

2016-10-27 Thread Christos Trochalakis
tag 842295 pending thanks Hello, Bug #842295 reported by you has been fixed in the Git repository. You can see the changelog below, and you can check the diff of the fix at: http://git.debian.org/?p=collab-maint/nginx.git;a=commitdiff;h=333595d --- commit 333595dc8382e728bc9d57c1e533fa656b2

Bug#839379: yelp: FTBFS: segmentation fault

2016-10-27 Thread Alberto Garcia
On Fri, Oct 28, 2016 at 03:38:46AM +0200, Michael Biebl wrote: > I built yelp inside a chroot (without X) and ran > docs/libyelp/libyelp-scan directly. The resulting backtrace from the > crash is attached. This looks to me like it's webkit2 related, so > I'm reassigning the bug. It looks like #83

Bug#835769: marked as done (goldencheetah: FTBFS: build-dependency not installable: libnss3-1d)

2016-10-27 Thread Debian Bug Tracking System
Your message dated Fri, 28 Oct 2016 06:44:08 + with message-id and subject line Bug#835769: fixed in goldencheetah 4.0.0~DEV1607-2 has caused the Debian Bug report #835769, regarding goldencheetah: FTBFS: build-dependency not installable: libnss3-1d to be marked as done. This means that you c

Bug#828466: opendkim: FTBFS with openssl 1.1.0

2016-10-27 Thread Scott Kitterman
On Thursday, October 27, 2016 09:55:03 PM Sebastian Andrzej Siewior wrote: > Control: tags - patch > > builds. Further testing is welcome. Thanks. I think this will do. Here's what I did: I re-enabled the test suite (it has about 5% random errors, so it's not run routinely) and tested both 2.

Bug#837823: can't upload to git

2016-10-27 Thread gustavo panizzo (gfa)
Hello I don't have perms to upload my changes to fprintd's git repo in alioth I placed a copy of the repo with my changes here git.debian.org:/srv/home/users/gfa-guest/public_git/fprintd Also I've requested to join the alioth team -- 1AE0 322E B8F7 4717 BDEA BF1D 44BB 1BA7 9F6C 6333 keybase

Bug#837420: #837420 - dietlibc: FTBFS with bindnow and PIE enabled

2016-10-27 Thread Christian Seiler
Hi Thorsten, Am 25. Oktober 2016 22:54:47 MESZ, schrieb Thorsten Glaser : >Christian Seiler dixit: > >>Yes, I fully intend to fix that - which is why I tagged the bug >>report "confirmed" when it was first reported, even while it >>was still of lower severity. I just had a lot of other stuff >>com

Bug#841665: closed by Gianfranco Costamagna (Bug#841665: fixed in boinc 7.6.33+dfsg-2)

2016-10-27 Thread Gianfranco Costamagna
>Thank you Gainfranco, molte grazie. de nada! :) G. On 23/10/16 22:00, Debian Bug Tracking System wrote: This is an automatic notification regarding your Bug report which was filed against the boinc-client package: #841665: boinc-client: The boinc-client init script has a badly constructed par

Processed: Bug#842276 marked as pending

2016-10-27 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tag 842276 pending Bug #842276 [src:nginx] nginx-common.config dpkg --compare-versions will mishandle return codes should the check fail Ignoring request to alter tags of bug #842276 to the same tags previously set > thanks Stopping processing he

Bug#842276: marked as pending

2016-10-27 Thread Christos Trochalakis
tag 842276 pending thanks Hello, Bug #842276 reported by you has been fixed in the Git repository. You can see the changelog below, and you can check the diff of the fix at: http://git.debian.org/?p=collab-maint/nginx.git;a=commitdiff;h=9e18152 --- commit 9e18152111b9f4f9b04f99ca5c34067f559

Bug#841050: [debian-mysql] Bug#841050: Security fixes from the October 2016 CPU

2016-10-27 Thread Salvatore Bonaccorso
Hi Lars, On Thu, Oct 27, 2016 at 10:36:59AM -0700, Lars Tangvald wrote: > Hi Salvatore, > - car...@debian.org wrote: > > > What is the status for src:mysql-5.5 for a possible jessie-security > > upload? (Btw, if-and-only-if the package is still needed due to > > rebuild, then let's please fix

Bug#828285: dogecoin: FTBFS with openssl 1.1.0

2016-10-27 Thread Kurt Roeckx
On Fri, Oct 28, 2016 at 12:53:51PM +0800, Keng-Yu Lin wrote: > Built on my local machine with the latest sid, the failure is not > reproducible any more. Please note that it's still in experimental. Kurt

Bug#842324: console-setup: During apt-get dist-upgrade stage, console-setup did not finish cleanly under ja_JP.UTF-8 locale.

2016-10-27 Thread ishikawa
Package: console-setup Version: 1.152 Severity: critical Tags: d-i l10n Justification: breaks the whole system Dear Maintainer, *** Reporter, please consider answering these questions, where appropriate *** * What led up to the situation? I ran "apt-get dist-upgrade" to upgrade to t

Bug#840691: ghostscript and evince/libspectre problem

2016-10-27 Thread Salvatore Bonaccorso
On Thu, Oct 27, 2016 at 08:54:39PM -0400, Roberto C. Sánchez wrote: > On Thu, Oct 27, 2016 at 11:43:01PM +0200, Francesco Poli wrote: > > On Thu, 27 Oct 2016 18:17:20 +0200 Salvatore Bonaccorso wrote: > > > > [...] > > > On Thu, Oct 27, 2016 at 09:50:02AM -0400, Roberto C. Sánchez wrote: > > > > I

Bug#828285: marked as done (dogecoin: FTBFS with openssl 1.1.0)

2016-10-27 Thread Debian Bug Tracking System
Your message dated Fri, 28 Oct 2016 12:53:51 +0800 with message-id and subject line Re: Bug#828285: dogecoin: FTBFS with openssl 1.1.0 has caused the Debian Bug report #828285, regarding dogecoin: FTBFS with openssl 1.1.0 to be marked as done. This means that you claim that the problem has been

Bug#840691: ghostscript and evince/libspectre problem

2016-10-27 Thread Salvatore Bonaccorso
Hi Francesco, On Thu, Oct 27, 2016 at 11:43:01PM +0200, Francesco Poli wrote: > On Thu, 27 Oct 2016 18:17:20 +0200 Salvatore Bonaccorso wrote: > > [...] > > On Thu, Oct 27, 2016 at 09:50:02AM -0400, Roberto C. Sánchez wrote: > > > Is your plan to release this as a -2 regression update to the prev

Processed: bug 823330 is forwarded to https://sourceforge.net/p/tsocks/bugs/27/

2016-10-27 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > forwarded 823330 https://sourceforge.net/p/tsocks/bugs/27/ Bug #823330 [tsocks] tsocks: The actual configure command disable host name resolution in tsocks.conf when it was supposed to enable it Set Bug forwarded-to-address to 'https://sourceforg

Bug#842319: gnome-sushi: Missing dependency gir1.2-evince-3.0

2016-10-27 Thread Kan-Ru Chen
Package: gnome-sushi Version: 3.21.91-1 Severity: grave Justification: renders package unusable Without gir1.2-evince-3.0 sushi always fail to start % sushi (sushi-start:10503): Gjs-WARNING **: JS ERROR: Error: Requiring Sushi, version none: Typelib file for namespace 'EvinceDocument', version

Bug#841665: closed by Gianfranco Costamagna (Bug#841665: fixed in boinc 7.6.33+dfsg-2)

2016-10-27 Thread Mike Brennan
Thank you Gainfranco, molte grazie. On 23/10/16 22:00, Debian Bug Tracking System wrote: > This is an automatic notification regarding your Bug report > which was filed against the boinc-client package: > > #841665: boinc-client: The boinc-client init script has a badly constructed > parameter fo

Processed: tsocks: diff for NMU version 1.8beta5-9.5

2016-10-27 Thread Debian Bug Tracking System
Processing control commands: > tags 815611 + patch Bug #815611 [src:tsocks] tsocks: Removal dh_undocumented debhelper command Added tag(s) patch. > tags 815611 + pending Bug #815611 [src:tsocks] tsocks: Removal dh_undocumented debhelper command Added tag(s) pending. > tags 823330 + patch Bug #8233

Processed: tsocks: diff for NMU version 1.8beta5-9.5

2016-10-27 Thread Debian Bug Tracking System
Processing control commands: > tags 815611 + patch Bug #815611 [src:tsocks] tsocks: Removal dh_undocumented debhelper command Ignoring request to alter tags of bug #815611 to the same tags previously set > tags 815611 + pending Bug #815611 [src:tsocks] tsocks: Removal dh_undocumented debhelper com

Bug#815611: tsocks: diff for NMU version 1.8beta5-9.5

2016-10-27 Thread gustavo panizzo (gfa)
Control: tags 815611 + patch Control: tags 815611 + pending Control: tags 823330 + patch Control: tags 823330 + pending Dear maintainer, I've prepared an NMU for tsocks (versioned as 1.8beta5-9.5) I'll look for an sponsor and upload it Regards. -- 1AE0 322E B8F7 4717 BDEA BF1D 44BB 1BA7 9F6C 6

Processed: Re: Bug#839379: yelp: FTBFS: segmentation fault

2016-10-27 Thread Debian Bug Tracking System
Processing control commands: > reassign -1 src:webkit2gtk 2.14.1-1 Bug #839379 [src:yelp] yelp: FTBFS: segmentation fault Bug reassigned from package 'src:yelp' to 'src:webkit2gtk'. No longer marked as found in versions yelp/3.22.0-1. Ignoring request to alter fixed versions of bug #839379 to the

Bug#839379: yelp: FTBFS: segmentation fault

2016-10-27 Thread Michael Biebl
Control: reassign -1 src:webkit2gtk 2.14.1-1 Control: affects -1 src:yelp Am 28.10.2016 um 01:52 schrieb Michael Biebl: > Am 01.10.2016 um 10:42 schrieb Lucas Nussbaum: >>> (process:32124): Gtk-CRITICAL **: gtk_icon_theme_get_for_screen: assertion >>> 'GDK_IS_SCREEN (screen)' failed >>> >>> ** (p

Bug#837629: OpenRD* with debian's u-boot 2016.09

2016-10-27 Thread Rick Thomas
On Oct 5, 2016, at 1:26 PM, Vagrant Cascadian wrote: > On 2016-10-03, Rick Thomas wrote: >> On Oct 1, 2016, at 3:39 PM, Vagrant Cascadian wrote: >>> On 2016-09-17, Rick Thomas wrote: On Sep 16, 2016, at 3:19 PM, Vagrant Cascadian wrote: > https://bugs.debian.org/837629 > ... >>> deb h

Bug#840691: ghostscript and evince/libspectre problem

2016-10-27 Thread Roberto C . Sánchez
On Thu, Oct 27, 2016 at 11:43:01PM +0200, Francesco Poli wrote: > On Thu, 27 Oct 2016 18:17:20 +0200 Salvatore Bonaccorso wrote: > > [...] > > On Thu, Oct 27, 2016 at 09:50:02AM -0400, Roberto C. Sánchez wrote: > > > Is your plan to release this as a -2 regression update to the previous > > > DSA?

Bug#842017: marked as done (haskell-hsopenssl-x509-system: FTBFS: '/usr/bin/haddock' exited with an error: Haddock failed (no modules?), refusing to create empty documentation package.)

2016-10-27 Thread Debian Bug Tracking System
Your message dated Fri, 28 Oct 2016 00:25:17 + with message-id <20161028002517.ga6...@scru.org> and subject line mathjax has caused the Debian Bug report #842017, regarding haskell-hsopenssl-x509-system: FTBFS: '/usr/bin/haddock' exited with an error: Haddock failed (no modules?), refusing to

Bug#839379: yelp: FTBFS: segmentation fault

2016-10-27 Thread Michael Biebl
Am 01.10.2016 um 10:42 schrieb Lucas Nussbaum: >> (process:32124): Gtk-CRITICAL **: gtk_icon_theme_get_for_screen: assertion >> 'GDK_IS_SCREEN (screen)' failed >> >> ** (process:32124): WARNING **: Unable to connect to dbus: Cannot spawn a >> message bus without a machine-id: Unable to load /var/

Bug#828610: marked as done (xrdp: FTBFS with openssl 1.1.0)

2016-10-27 Thread Debian Bug Tracking System
Your message dated Thu, 27 Oct 2016 23:34:28 + with message-id and subject line Bug#828610: fixed in xrdp 0.9.0~20161027+gitc524b06-1 has caused the Debian Bug report #828610, regarding xrdp: FTBFS with openssl 1.1.0 to be marked as done. This means that you claim that the problem has been

Bug#842311: node-grunt-cli: uninstallable due to wrong dependency

2016-10-27 Thread Alessandro Ghedini
Package: node-grunt-cli Version: 1.2.0-1 Severity: grave Justification: renders package unusable Hello, when trying to install the package I get: The following packages have unmet dependencies: node-grunt-cli : Depends: node-findup-sync (>= 0.3.0) but 0.1.3-1 is to be installed E: Unable

Processed: severity of 837786 is important ...

2016-10-27 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > severity 837786 important Bug #837786 [mutter] mutter: Issues repainting the display on mouse movement Severity set to 'important' from 'grave' > retitle 837786 mutter: repaint issues/flickering when using > CLUTTER_PAINT=disable-clipped-redraws:

Processed: Re: Bug#828245: Acknowledgement (balsa: FTBFS with openssl 1.1.0)

2016-10-27 Thread Debian Bug Tracking System
Processing control commands: > severity -1 wishlist Bug #828245 [src:balsa] balsa: FTBFS with openssl 1.1.0 Severity set to 'wishlist' from 'serious' > retitle -1 balsa: Stop using deprecated openssl functions Bug #828245 [src:balsa] balsa: FTBFS with openssl 1.1.0 Changed Bug title to 'balsa: Sto

Bug#828245: Acknowledgement (balsa: FTBFS with openssl 1.1.0)

2016-10-27 Thread Michael Biebl
Control: severity -1 wishlist Control: retitle -1 balsa: Stop using deprecated openssl functions On Sun, 3 Jul 2016 20:27:27 +0200 Kurt Roeckx wrote: > unblock 827061 by 828245 > thanks > > After upstream changes it no longer FTBFS: > https://breakpoint.cc/openssl-1.1-rebuild-2016-07-02/successf

Processed: reassign 836426 to libspice-client-gtk-3.0-5, severity of 836426 is important, fixed 836426 in 0.33-1

2016-10-27 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > reassign 836426 libspice-client-gtk-3.0-5 0.32-1 Bug #836426 [gnome-boxes] GTK+ 3.21 causes application redraw issues and warnings ("is drawn without a current allocation") Bug reassigned from package 'gnome-boxes' to 'libspice-client-gtk-3.0-5'.

Bug#837786: Severity of this bug

2016-10-27 Thread Keshav Kini
Hello, This bug was originally marked with severity Grave, with justification "causes non-serious data loss". I don't see anyone in the thread reporting data loss, including the OP. Can this bug be bumped down to Important, especially since it only affects a subset of users (those who had the /e

Bug#839104: marked as done (libsfml-window2.4: unusable applications after XCB conversion)

2016-10-27 Thread Debian Bug Tracking System
Your message dated Thu, 27 Oct 2016 22:30:01 + with message-id and subject line Bug#839104: fixed in libsfml 2.4.1~git15.b61c2f8+dfsg-1 has caused the Debian Bug report #839104, regarding libsfml-window2.4: unusable applications after XCB conversion to be marked as done. This means that you c

Bug#828389: marked as done (libcrypt-smime-perl: FTBFS with openssl 1.1.0)

2016-10-27 Thread Debian Bug Tracking System
Your message dated Thu, 27 Oct 2016 22:28:45 + with message-id and subject line Bug#828389: fixed in libcrypt-smime-perl 0.18-1 has caused the Debian Bug report #828389, regarding libcrypt-smime-perl: FTBFS with openssl 1.1.0 to be marked as done. This means that you claim that the problem ha

Bug#828442: marked as done (mosquitto: FTBFS with openssl 1.1.0)

2016-10-27 Thread Debian Bug Tracking System
Your message dated Thu, 27 Oct 2016 22:30:38 + with message-id and subject line Bug#828442: fixed in mosquitto 1.4.10-1 has caused the Debian Bug report #828442, regarding mosquitto: FTBFS with openssl 1.1.0 to be marked as done. This means that you claim that the problem has been dealt with.

Bug#842064: marked as done (libbabeltrace-ctf-dev: fails to upgrade from 'testing' - trying to overwrite /usr/include/babeltrace/ctf-writer/clock.h)

2016-10-27 Thread Debian Bug Tracking System
Your message dated Thu, 27 Oct 2016 22:21:00 + with message-id and subject line Bug#842064: fixed in babeltrace 1.5.0~rc1-3 has caused the Debian Bug report #842064, regarding libbabeltrace-ctf-dev: fails to upgrade from 'testing' - trying to overwrite /usr/include/babeltrace/ctf-writer/clock

Bug#840691: ghostscript and evince/libspectre problem

2016-10-27 Thread Francesco Poli
On Thu, 27 Oct 2016 18:17:20 +0200 Salvatore Bonaccorso wrote: [...] > On Thu, Oct 27, 2016 at 09:50:02AM -0400, Roberto C. Sánchez wrote: > > Is your plan to release this as a -2 regression update to the previous > > DSA? I assume that is what you plan to do, but I wanted to confirm to > > be ce

Processed: Re: Bug#841708: debci: FTBFS with bash as /bin/sh

2016-10-27 Thread Debian Bug Tracking System
Processing control commands: > severity -1 important Bug #841708 [src:debci] debci: FTBFS with bash as /bin/sh Severity set to 'important' from 'serious' -- 841708: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=841708 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems

Bug#841708: debci: FTBFS with bash as /bin/sh

2016-10-27 Thread Antonio Terceiro
Control: severity -1 important Hi, On Sat, Oct 22, 2016 at 03:15:40PM +0100, Chris Lamb wrote: > Source: debci > Version: 1.4 > Severity: serious > Justification: fails to build from source > User: reproducible-bui...@lists.alioth.debian.org > Usertags: ftbfs > X-Debbugs-Cc: reproducible-bui...@l

Bug#839104: libsfml-window2.4: unusable applications after XCB conversion (was: extremetuxracer takes the focus but no windows is displayed...)

2016-10-27 Thread James Cowgill
Control: tags -1 pending [+CC everyone affected by the bug] Hi all, On 27/10/16 11:28, James Cowgill wrote: > On 27/10/16 05:56, Marko Lindqvist wrote: >> Even my own build I last used a couple of months ago has broken this >> way. I suspect it was broken either SFML (etr no longer uses SDL) or

Processed: Bug#839104: libsfml-window2.4: unusable applications after XCB conversion (was: extremetuxracer takes the focus but no windows is displayed...)

2016-10-27 Thread Debian Bug Tracking System
Processing control commands: > tags -1 pending Bug #839104 [libsfml-window2.4] libsfml-window2.4: unusable applications after XCB conversion Added tag(s) pending. -- 839104: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=839104 Debian Bug Tracking System Contact ow...@bugs.debian.org with pro

Processed: will be handled upstream

2016-10-27 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > forwarded 828308 https://sourceforge.net/p/gdcm/bugs/397/ Bug #828308 [src:gdcm] missing include for 'X509_STORE_CTX cert_ctx' Set Bug forwarded-to-address to 'https://sourceforge.net/p/gdcm/bugs/397/'. > End of message, stopping processing here.

Bug#842303: [web2py] License problem and source missing

2016-10-27 Thread Bastien ROUCARIÈS
Package: web2py Version: 2.12.3-1 Severity: serious usertags: source-is-missing severity: serious X-Debbugs-CC: ftpmas...@debian.org Hi, your package includes some files that seem to lack sources in preferred forms of modification (analytic seems to be google analytic under non free license):

Bug#828252: qtcreator is marked for autoremoval from testing

2016-10-27 Thread Adam Majer
On 27/10/16 09:59 AM, Ondřej Surý wrote: I can probably generate two sets of packages with versioned symbols if I have some help with that. Cheers, Yes, but this will not help and I'm not sure it is required since OpenSSL is versioned already. The problem is that Qt5 is using dlopen for Op

Processed: bug 828610 is forwarded to https://github.com/neutrinolabs/xrdp/pull/459

2016-10-27 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > forwarded 828610 https://github.com/neutrinolabs/xrdp/pull/459 Bug #828610 [src:xrdp] xrdp: FTBFS with openssl 1.1.0 Set Bug forwarded-to-address to 'https://github.com/neutrinolabs/xrdp/pull/459'. > thanks Stopping processing here. Please contac

Processed: libcrypt-smime-perl: FTBFS with openssl 1.1.0

2016-10-27 Thread Debian Bug Tracking System
Processing control commands: > tags -1 patch fixed-upstream Bug #828389 [src:libcrypt-smime-perl] libcrypt-smime-perl: FTBFS with openssl 1.1.0 Added tag(s) fixed-upstream and patch. > forwarded -1 https://rt.cpan.org/Public/Bug/Display.html?id=118344 Bug #828389 [src:libcrypt-smime-perl] libcryp

Bug#828389: libcrypt-smime-perl: FTBFS with openssl 1.1.0

2016-10-27 Thread Sebastian Andrzej Siewior
control: tags -1 patch fixed-upstream control: forwarded -1 https://rt.cpan.org/Public/Bug/Display.html?id=118344 Crypt-SMIME-0.18 has the fix Sebastian

Processed: tagging 828610

2016-10-27 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tags 828610 + pending Bug #828610 [src:xrdp] xrdp: FTBFS with openssl 1.1.0 Added tag(s) pending. > thanks Stopping processing here. Please contact me if you need assistance. -- 828610: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=828610 Deb

Processed: Re: Bug#828466: Info received (opendkim: FTBFS with openssl 1.1.0)

2016-10-27 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tags 828466 patch Bug #828466 [src:opendkim] opendkim: FTBFS with openssl 1.1.0 Added tag(s) patch. > thanks Stopping processing here. Please contact me if you need assistance. -- 828466: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=828466 D

Bug#828466: opendkim: FTBFS with openssl 1.1.0

2016-10-27 Thread Sebastian Andrzej Siewior
Control: tags - patch builds. Further testing is welcome. Sebastian >From f6afa6be81eae0b149ad18a0642c67e75b148c69 Mon Sep 17 00:00:00 2001 From: Sebastian Andrzej Siewior Date: Thu, 27 Oct 2016 19:43:15 + Subject: [PATCH] opendkim: port to openssl 1.1.0 In configure.ac AC_SEARCH_LIBS([SSL_

Bug#842295: nginx: CVE-2016-1247

2016-10-27 Thread Salvatore Bonaccorso
Source: nginx Version: 1.6.2-5 Severity: grave Tags: security Justification: user security hole Control: fixed -1 1.6.2-5+deb8u3 Hi, the following vulnerability was published for nginx. This bug is to track the CVE-2016-1247 as well in the Debian BTS. CVE-2016-1247[0]: www-data to root privilege

Processed: nginx: CVE-2016-1247

2016-10-27 Thread Debian Bug Tracking System
Processing control commands: > fixed -1 1.6.2-5+deb8u3 Bug #842295 [src:nginx] nginx: CVE-2016-1247 Marked as fixed in versions nginx/1.6.2-5+deb8u3. -- 842295: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=842295 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems

Bug#836759: proftpd-dfsg: please drop the build dependency on hardening-wrapper

2016-10-27 Thread Hilmar Preusse
On 27.10.16 Mattia Rizzolo (mat...@debian.org) wrote: > On Thu, Oct 27, 2016 at 02:07:17PM +0200, Hilmar Preuße wrote: Hi, > > Sorry to bother you again. The generated configure script seems to be broken > > or incomplete: > > arggg :( > #842293, I've set you as submitter. > IMHO, this should

Processed: tagging 842276

2016-10-27 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tags 842276 + confirmed pending Bug #842276 [src:nginx] nginx-common.config dpkg --compare-versions will mishandle return codes should the check fail Added tag(s) confirmed and pending. > thanks Stopping processing here. Please contact me if you

Bug#841342: marked as done (zshdb: FTBFS under some locales (eg. fr_CH.UTF-8))

2016-10-27 Thread Debian Bug Tracking System
Your message dated Thu, 27 Oct 2016 18:29:12 + with message-id and subject line Bug#841342: fixed in zshdb 0.92-2 has caused the Debian Bug report #841342, regarding zshdb: FTBFS under some locales (eg. fr_CH.UTF-8) to be marked as done. This means that you claim that the problem has been dea

Processed: Merge #840786 & #841584

2016-10-27 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > severity 840786 serious Bug #840786 [src:mysql-workbench] mysql-workbench: Change libmysqlclient-dev build dependency to default-libmysqlclient-dev Severity set to 'serious' from 'important' > tags 840786 sid stretch Bug #840786 [src:mysql-workbe

Bug#842184: policykit-1: synaptic-pkexec no more work

2016-10-27 Thread Brian Vaughan
I can confirm that: A) Executing '/usr/lib/x86_64-linux-gnu/polkit-gnome-authentication-agent-1' on the command line enabled the expected dialog for launching Synaptic from XFCE; B) The issue has been resolved with policykit-1-gnome 0.105-5. Thank you. On Oct 27, 2016 2:00 AM, "Simon McVittie"

Processed: [bts-link] source package src:sqlobject

2016-10-27 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > # > # bts-link upstream status pull for source package src:sqlobject > # see http://lists.debian.org/debian-devel-announce/2006/05/msg1.html > # > user bts-link-upstr...@lists.alioth.debian.org Setting user to bts-link-upstr...@lists.alioth.de

Processed: [bts-link] source package src:jasper

2016-10-27 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > # > # bts-link upstream status pull for source package src:jasper > # see http://lists.debian.org/debian-devel-announce/2006/05/msg1.html > # > user bts-link-upstr...@lists.alioth.debian.org Setting user to bts-link-upstr...@lists.alioth.debia

Bug#842171: marked as done (musl: CVE-2016-8859: Regex integer overflow in buffer size computations)

2016-10-27 Thread Debian Bug Tracking System
Your message dated Thu, 27 Oct 2016 17:41:47 + with message-id and subject line Bug#842171: fixed in musl 1.1.15-2 has caused the Debian Bug report #842171, regarding musl: CVE-2016-8859: Regex integer overflow in buffer size computations to be marked as done. This means that you claim that

Bug#837574: marked as done (qemu: FTBFS with bindnow and PIE enabled)

2016-10-27 Thread Debian Bug Tracking System
Your message dated Thu, 27 Oct 2016 17:42:05 + with message-id and subject line Bug#837574: fixed in qemu 1:2.7+dfsg-3 has caused the Debian Bug report #837574, regarding qemu: FTBFS with bindnow and PIE enabled to be marked as done. This means that you claim that the problem has been dealt w

Bug#828427: marked as done (lua-sec: FTBFS with openssl 1.1.0)

2016-10-27 Thread Debian Bug Tracking System
Your message dated Thu, 27 Oct 2016 17:03:30 + with message-id and subject line Bug#828427: fixed in lua-sec 0.6-1 has caused the Debian Bug report #828427, regarding lua-sec: FTBFS with openssl 1.1.0 to be marked as done. This means that you claim that the problem has been dealt with. If thi

Bug#828361: marked as done (kamailio: FTBFS with openssl 1.1.0)

2016-10-27 Thread Debian Bug Tracking System
Your message dated Thu, 27 Oct 2016 16:58:01 + with message-id and subject line Bug#828361: fixed in kamailio 4.4.3-2 has caused the Debian Bug report #828361, regarding kamailio: FTBFS with openssl 1.1.0 to be marked as done. This means that you claim that the problem has been dealt with. If

Processed: affects 842276

2016-10-27 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > affects 842276 + release.debian.org,security.debian.org Bug #842276 [src:nginx] nginx-common.config dpkg --compare-versions will mishandle return codes should the check fail Added indication that 842276 affects release.debian.org and security.deb

Bug#841577: marked as done (ginkgocadx: FTBFS: build-dependency not installable: libmysqlclient-dev)

2016-10-27 Thread Debian Bug Tracking System
Your message dated Thu, 27 Oct 2016 16:56:05 + with message-id and subject line Bug#841577: fixed in ginkgocadx 3.8.3-2 has caused the Debian Bug report #841577, regarding ginkgocadx: FTBFS: build-dependency not installable: libmysqlclient-dev to be marked as done. This means that you claim

Bug#841050: [debian-mysql] Bug#841050: Security fixes from the October 2016 CPU

2016-10-27 Thread Salvatore Bonaccorso
Hi Lars, On Wed, Oct 19, 2016 at 10:38:22AM +0200, Lars Tangvald wrote: > Hi, > > On 10/19/2016 10:18 AM, Moritz Muehlenhoff wrote: > > Hi, > > > > On Wed, Oct 19, 2016 at 09:10:59AM +0200, Lars Tangvald wrote: > > > So for Linux we consider this fixed in 5.5.52, but the complete fix > > > was i

Bug#839498: marked as done (bup: FTBFS: Tests failures)

2016-10-27 Thread Debian Bug Tracking System
Your message dated Thu, 27 Oct 2016 16:51:42 + with message-id and subject line Bug#839498: fixed in bup 0.28.1-1.1 has caused the Debian Bug report #839498, regarding bup: FTBFS: Tests failures to be marked as done. This means that you claim that the problem has been dealt with. If this is n

Processed: tagging 842171

2016-10-27 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tags 842171 + pending Bug #842171 [src:musl] musl: CVE-2016-8859: Regex integer overflow in buffer size computations Added tag(s) pending. > thanks Stopping processing here. Please contact me if you need assistance. -- 842171: http://bugs.debia

Bug#828293: encfs: FTBFS with openssl 1.1.0

2016-10-27 Thread Agustin Martin
On Sun, Jun 26, 2016 at 12:21:34PM +0200, Kurt Roeckx wrote: > Source: encfs > Version: 1.8.1-3 > Severity: important > Control: block 827061 by -1 > > Hi, > > OpenSSL 1.1.0 is about to released. During a rebuild of all packages using > OpenSSL this package fail to build. A log of that build ca

Processed: Restore bug info

2016-10-27 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > forwarded 746005 https://code.google.com/p/lilypond/issues/detail?id=1055 Bug #746005 [lilypond] lilypond: please migrate to guile-2.0 Set Bug forwarded-to-address to 'https://code.google.com/p/lilypond/issues/detail?id=1055'. > thanks Stopping p

Bug#828252: qtcreator is marked for autoremoval from testing

2016-10-27 Thread Lisandro Damián Nicanor Pérez Meyer
On jueves, 27 de octubre de 2016 4:59:39 P. M. ART Ondřej Surý wrote: > I can probably generate two sets of packages with versioned symbols > if I have some help with that. That would be *very* kind of you! But before going ahead we might better contact the release team and see what they prefer h

Processed: Restore bug info

2016-10-27 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > severity 746005 serious Bug #746005 [lilypond] lilypond: please migrate to guile-2.0 Severity set to 'serious' from 'normal' > thanks Stopping processing here. Please contact me if you need assistance. -- 746005: http://bugs.debian.org/cgi-bin/b

Bug#840691: ghostscript and evince/libspectre problem

2016-10-27 Thread Salvatore Bonaccorso
Hi Roberto, On Thu, Oct 27, 2016 at 09:50:02AM -0400, Roberto C. Sánchez wrote: > Is your plan to release this as a -2 regression update to the previous > DSA? I assume that is what you plan to do, but I wanted to confirm to > be certain. Yes exactly, that's the plan. I would still like to hear

Processed (with 1 error): Fix block/unblock mess ...

2016-10-27 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > unblock 760986 by 746005 Failed to set blocking bugs of 760986: Not altering archived bugs; see unarchive. > block 830347 by 746005 841736 Bug #830347 [src:denemo] denemo: FTBFS: build-dependency not installable: lilypond 830347 was not blocked

Processed: Re: Bug#828361: kamailio: FTBFS with openssl 1.1.0

2016-10-27 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > forwarded 828361 https://github.com/kamailio/kamailio/issues/834 Bug #828361 [src:kamailio] kamailio: FTBFS with openssl 1.1.0 Changed Bug forwarded-to-address to 'https://github.com/kamailio/kamailio/issues/834' from 'https://github.com/kamaili

Processed: your mail

2016-10-27 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > block 828306 by 828239 Bug #828306 [src:galera-3] galera-3: FTBFS with openssl 1.1.0 828306 was not blocked by any bugs. 828306 was blocking: 827061 Added blocking bug(s) of 828306: 828239 > End of message, stopping processing here. Please contac

Processed (with 3 errors): Restore bug info

2016-10-27 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > # Restore bug info, accidentally deleted with a forcemerge > unblock 830347 by 746005 Bug #830347 [src:denemo] denemo: FTBFS: build-dependency not installable: lilypond 830347 was blocked by: 841736 746005 830347 was not blocking any bugs. Remove

Bug#842276: nginx-common.config dpkg --compare-versions will mishandle return codes should the check fail

2016-10-27 Thread Thomas Ward
Source: nginx Severity: serious Version: 1.6.2-5+deb8u3 This was originally identified as a result of my own failure downstream in Ubuntu when applying the patches from Debian for CVE-2016-1247. One of the things added was nginx-common.config. In this, the following set of code exists: log_syml

Processed (with 3 errors): Restore bug info

2016-10-27 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > # Restore bug info, accidentally deleted with a forcemerge > forcemerge 746005 841736 Bug #746005 [lilypond] lilypond: please migrate to guile-2.0 Bug #841736 [lilypond] lilypond in Testing? 830347 was blocked by: 746005 830347 was not blocking an

Bug#828252: qtcreator is marked for autoremoval from testing

2016-10-27 Thread Lisandro Damián Nicanor Pérez Meyer
On jueves, 27 de octubre de 2016 4:48:33 P. M. ART Ondřej Surý wrote: > So is there an option to not switch to openssl 1.1.0 for stretch? I was recently told something along that, but the problem is not easy actually. Some people might need botan switched, some not. And we are to expect crashes

Bug#828252: qtcreator is marked for autoremoval from testing

2016-10-27 Thread Ondřej Surý
I can probably generate two sets of packages with versioned symbols if I have some help with that. Cheers, -- Ondřej Surý Knot DNS (https://www.knot-dns.cz/) – a high-performance DNS server Knot Resolver (https://www.knot-resolver.cz/) – secure, privacy-aware, fast DNS(SEC) resolver Vše pro chle

Bug#828252: qtcreator is marked for autoremoval from testing

2016-10-27 Thread Ondřej Surý
So is there an option to not switch to openssl 1.1.0 for stretch? Cheers, -- Ondřej Surý Knot DNS (https://www.knot-dns.cz/) – a high-performance DNS server Knot Resolver (https://www.knot-resolver.cz/) – secure, privacy-aware, fast DNS(SEC) resolver Vše pro chleba (https://vseprochleba.cz) – Mo

Bug#828505: pjproject: FTBFS with openssl 1.1.0

2016-10-27 Thread Kurt Roeckx
On Thu, Oct 27, 2016 at 09:18:31AM +0200, Bernhard Schmidt wrote: > > I changed that to check for OPENSSL_init_ssl instead of > SSL_library_init, which makes configure enable SSL and ultimately leads > to the following build error Those are all very easy to fix. Maybe other files also have such p

Bug#828252: qtcreator is marked for autoremoval from testing

2016-10-27 Thread Lisandro Damián Nicanor Pérez Meyer
For what is wort Qt5 won't be switching to libssl 1.1, so if botan gets updated we will have to remove qtcreator from testing. On jueves, 27 de octubre de 2016 4:40:03 A. M. ART Debian testing autoremoval watch wrote: > qtcreator 4.1.0-2 is marked for autoremoval from testing on 2016-11-25 > >

Bug#828306: [debian-mysql] Bug#828306: Bug#828306: galera-3: FTBFS with openssl 1.1.0

2016-10-27 Thread Kurt Roeckx
On Thu, Oct 27, 2016 at 08:58:17AM +0300, Otto Kekäläinen wrote: > You increased the seriousness of this issue, with the result of > upcoming autoremoval of galera-3 from Debian testing despite OpenSSL > 1.1 not being available in testing yet, and not even in unstable yet. > Galera-3 currently buil

Bug#840691: ghostscript and evince/libspectre problem

2016-10-27 Thread Roberto C . Sánchez
On Thu, Oct 27, 2016 at 01:12:10PM +0200, Salvatore Bonaccorso wrote: > > Packages with that patch added are now as well on > > https://people.debian.org/~carnil/tmp/ghostscript/ > > Please test those if possible for you. > Salvatore, Is your plan to release this as a -2 regression update to

Processed: Bug#839498: bup: FTBFS: Tests failures

2016-10-27 Thread Debian Bug Tracking System
Processing control commands: > tags -1 pending Bug #839498 [src:bup] bup: FTBFS: Tests failures Added tag(s) pending. -- 839498: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=839498 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems

Bug#839498: bup: FTBFS: Tests failures

2016-10-27 Thread James Cowgill
Control: tags -1 pending Hi, I've uploaded the attached NMU to fix this bug. This will also trigger a rebuild on mipsel which (I hope) will fix the FTBFS there as well. Thanks, James diff -Nru bup-0.28.1/debian/changelog bup-0.28.1/debian/changelog --- bup-0.28.1/debian/changelog 2016-10-02 22:

Bug#828529: r-cran-openssl: FTBFS with openssl 1.1.0

2016-10-27 Thread Andreas Tille
Hi Jeroen, thanks for your quick and helpful response. On Thu, Oct 27, 2016 at 02:58:08PM +0200, Jeroen Ooms wrote: > I had a first attempt at fixing everything for libssl 1.1.0: > https://github.com/jeroenooms/openssl/commit/3066903e4e1d475616c1c784053e30bf290decd3 > > Things look good, but I n

Bug#840691: ghostscript and evince/libspectre problem

2016-10-27 Thread Roberto C . Sánchez
On Thu, Oct 27, 2016 at 03:31:15PM +0200, Edgar Fuß wrote: > > If it works, I will apply the same patch to the wheezy package and upload > > it. > I didn’t look at the jessie package but it is wheezy with debian-security > where I figured out that changing that ,,put’’ to ,,.forceput’’ made evinc

Bug#836070: marked as done (r-cran-sem: FTBFS: ERROR: dependencies 'MASS', 'boot' are not available for package 'sem')

2016-10-27 Thread Debian Bug Tracking System
Your message dated Thu, 27 Oct 2016 13:35:51 + with message-id and subject line Bug#836070: fixed in r-cran-sem 3.1.7-4 has caused the Debian Bug report #836070, regarding r-cran-sem: FTBFS: ERROR: dependencies 'MASS', 'boot' are not available for package 'sem' to be marked as done. This mea

Bug#840691: ghostscript and evince/libspectre problem

2016-10-27 Thread Edgar Fuß
> If it works, I will apply the same patch to the wheezy package and upload it. I didn’t look at the jessie package but it is wheezy with debian-security where I figured out that changing that ,,put’’ to ,,.forceput’’ made evince display PostScript again.

Bug#831142: marked as done (gcc-arm-none-eabi: FTBFS with GCC 6: cfns.gperf:101:1: error: 'const char* libc_name_p(const char*, unsigned int)' redeclared inline with 'gnu_inline' attribute)

2016-10-27 Thread Debian Bug Tracking System
Your message dated Thu, 27 Oct 2016 13:05:03 + with message-id and subject line Bug#831142: fixed in gcc-arm-none-eabi 15:5.4.1+svn241155-1 has caused the Debian Bug report #831142, regarding gcc-arm-none-eabi: FTBFS with GCC 6: cfns.gperf:101:1: error: 'const char* libc_name_p(const char*, u

Bug#836759: proftpd-dfsg: please drop the build dependency on hardening-wrapper

2016-10-27 Thread Mattia Rizzolo
On Thu, Oct 27, 2016 at 02:07:17PM +0200, Hilmar Preuße wrote: > Sorry to bother you again. The generated configure script seems to be broken > or incomplete: arggg :( > Should we open a new bug for all this? IMHO yes. > > > I suggest you bring that upstream, not being able to run > > auto

Bug#840528:

2016-10-27 Thread A. Jesse Jiryu Davis
Thanks Andreas, you're right. We'll submit 1.4.2 with the fix promptly. On Wed, Oct 26, 2016 at 6:34 PM, Andreas Beckmann wrote: > Control: reopen -1 > > On Wed, 12 Oct 2016 22:00:26 -0400 "A. Jesse Jiryu Davis" < > je...@mongodb.com> wrote: > > Version: 1.4.1-1 > > Nope. > > > Fixed in the upst

  1   2   >