Bug#1020404: luakit: aborts at start

2022-09-22 Thread Arne Wichmann
Moin, begin quotation from Markus Demleitner (in <20220921185014.db6o56sxwieo3vnm@victor>): > On Wed, Sep 21, 2022 at 11:36:08AM +0200, Arne Wichmann wrote: > > Bail out! ERROR:common/util.c:67:strip_ansi_escapes: assertion failed (err > > == NULL): Error while compili

Bug#1020404: luakit: aborts at start

2022-09-21 Thread Arne Wichmann
Package: luakit Version: 1:2.2.1-1 Severity: grave Justification: renders package unusable Luakit aborts saying: Bail out! ERROR:common/util.c:67:strip_ansi_escapes: assertion failed (err == NULL): Error while compiling regular expression ?[\u001b\u009b][[()#;?]*(?:[0-9]{1,4}(?:;[0-9]{0,4})*)?[

Bug#785326: libavcodec56: CVE-2014-7937 - Multiple off-by-one errors in libavcodec/vorbisdec.c

2015-05-19 Thread Arne Wichmann
> > On Sat, May 16, 2015 at 03:07:57PM +0200, Sebastian Ramacher wrote: > > > > On 2015-05-15 15:22:28, Alessandro Ghedini wrote: > > > > > On Fri, May 15, 2015 at 11:05:17AM +0200, Sebastian Ramacher wrote: > > > > > > On 2015-05-14 20:41:15, Arne W

Bug#785326: libavcodec56: CVE-2014-7937 - Multiple off-by-one errors in libavcodec/vorbisdec.c

2015-05-16 Thread Arne Wichmann
6:11.3-1 > > > > > > On 2015-05-14 20:41:15, Arne Wichmann wrote: > > > > Package: libavcodec56 > > > > Version: 6:11.3-2 > > > > Severity: grave > > > > Tags: security > > > > Justification: user security hole > >

Bug#785326: libavcodec56: CVE-2014-7937 - Multiple off-by-one errors in libavcodec/vorbisdec.c

2015-05-14 Thread Arne Wichmann
Package: libavcodec56 Version: 6:11.3-2 Severity: grave Tags: security Justification: user security hole Hi, as far as I can see this has not yet been reported or fixed: CVE-2014-7937 : Multiple off-by-one errors in libavcodec/vorbisdec.c in FFmpeg before 2.4.2, as used in Google Chrome before 40

Bug#738572: libav-tools: CVE-2011-3935

2014-02-10 Thread Arne Wichmann
Package: libav-tools Version: 6:9.11-1 Severity: grave Tags: security Justification: user security hole Hi... As far as I can see, CVE-2011-3935 [1] applies to libav-tools. As the descriptions for the problem are bit low on information I use a high severity - feel free to lower it if that is not

Bug#726578: Ping: pwgen: Multiple vulnerabilities in passwords generation

2014-01-14 Thread Arne Wichmann
Thank you for reacting quickly! begin quotation from Theodore Ts'o (in <20140112234500.ga15...@thunk.org>): > On Sun, Jan 12, 2014 at 09:27:14PM +0100, Arne Wichmann wrote: > > This grave problem is now open for more than two months. Is there any plan > > to resolve

Bug#722540: Ping: CVE-2013-4289 CVE-2013-4290

2014-01-12 Thread Arne Wichmann
self. (crag, on Debian Planet) Arne Wichmann (a...@linux.de) signature.asc Description: Digital signature

Bug#726578: Ping: pwgen: Multiple vulnerabilities in passwords generation

2014-01-12 Thread Arne Wichmann
ou but yourself. (crag, on Debian Planet) Arne Wichmann (a...@linux.de) signature.asc Description: Digital signature

Bug#712840: CVE-2013-1961 in tiff3 - fix for stable?

2013-08-23 Thread Arne Wichmann
Hi! Is there any fix in stable for tiff3 planned? cu AW -- [...] If you don't want to be restricted, don't agree to it. If you are coerced, comply as much as you must to protect yourself, just don't support it. Noone can free you but yourself. (crag, on Debian Planet) A

Bug#717009: libavcodec53: CVEs CVE-2013-0844 to CVE-2013-0874, CVE-2013-3670, CVE-2013-3672, CVE-2013-3674

2013-07-15 Thread Arne Wichmann
Package: libavcodec53 Version: 6:0.8.7-1 Severity: grave Tags: security Justification: user security hole Dear Maintainer, I have here another series of CVEs for libav. Some of these are fixed, some of these I was not able to check. Those without comment were checked by me and seem valid - at lea

Bug#703071: CVE-2011-1187, CVE-2012-0475, CVE-2013-{0773,0775,0776,0780,0782,0783}

2013-04-30 Thread Arne Wichmann
ly as much as you must to protect yourself, just don't support it. Noone can free you but yourself. (crag, on Debian Planet) Arne Wichmann (a...@linux.de) signature.asc Description: Digital signature

Bug#703071: CVE-2011-1187, CVE-2012-0475, CVE-2013-{0773,0775,0776,0780,0782,0783}

2013-03-14 Thread Arne Wichmann
self. (crag, on Debian Planet) Arne Wichmann (a...@linux.de) -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#684889: CVE-2012-3480 - stable update?

2013-02-05 Thread Arne Wichmann
Hi! Is there any plan to fix CVE-2012-3480 / #684889 in stable? cu AW -- [...] If you don't want to be restricted, don't agree to it. If you are coerced, comply as much as you must to protect yourself, just don't support it. Noone can free you but yourself. (crag, on Debi

Bug#694483: CVEs: CVE-2012-2882 CVE-2012-5359 CVE-2012-5360 CVE-2012-5361

2013-01-04 Thread Arne Wichmann
Mon, Nov 26, 2012 at 8:30 PM, Arne Wichmann wrote: > > > I have here another series of CVEs for ffmpeg/libav: > > > > CVE-2012-2882 > > Libav's ogg decoder is a bit different to the one in FFmpeg. Can you > please provide a testfile so that we can test if this is

Bug#694483: CVEs: CVE-2012-2882 CVE-2012-5359 CVE-2012-5360 CVE-2012-5361

2012-11-26 Thread Arne Wichmann
Source: libav Version: 0.8.4 Severity: grave Tags: security Justification: user security hole Dear Maintainer, I have here another series of CVEs for ffmpeg/libav: CVE-2012-2882 CVE-2012-5359 CVE-2012-5360 CVE-2012-5361 For the last 3 http://technet.microsoft.com/en-us/security/msvr/msvr12-017

Bug#688847: Unclear status of CVE-2012-2774 CVE-2012-2783 CVE-2012-2791 CVE-2012-2797 CVE-2012-2803 CVE-2012-2804

2012-11-26 Thread Arne Wichmann
? Are they fixed? cu AW -- [...] If you don't want to be restricted, don't agree to it. If you are coerced, comply as much as you must to protect yourself, just don't support it. Noone can free you but yourself. (crag, on Debian Planet) Arne Wichmann (a...@linux.de) signature.

Bug#677195: CVE-2012-2673 - still open in stable

2012-09-21 Thread Arne Wichmann
Hi... This bug is still open in stable - is there any plan for a fix? cu AW -- [...] If you don't want to be restricted, don't agree to it. If you are coerced, comply as much as you must to protect yourself, just don't support it. Noone can free you but yourself. (crag, on Debi

Bug#684527: openssl: CVE-2011-5095 - The remote SSL/TLS server accepts a weak Diffie-Hellman public value

2012-08-10 Thread Arne Wichmann
Package: openssl Version: 0.9.8o-4squeeze13 Severity: grave Tags: security Justification: user security hole openssl in squeeze (at least up to 0.9.8o-4squeeze13) is vulnerable to CVE-2011-5095 [1]. For reference you might have a look at [2] - the problem seems to be that fips/dh/fips_dh_key.c doe

Bug#663579: CVE-2012-1147 - Not on *nix

2012-07-16 Thread Arne Wichmann
an free you but yourself. (crag, on Debian Planet) Arne Wichmann (a...@linux.de) signature.asc Description: Digital signature

Bug#670636: April security release - fixed in stable-security

2012-07-16 Thread Arne Wichmann
one can free you but yourself. (crag, on Debian Planet) Arne Wichmann (a...@linux.de) signature.asc Description: Digital signature

Bug#483217: texlive-latex-base: 483217: status?

2012-06-29 Thread Arne Wichmann
begin quotation from Norbert Preining (in <20120627143050.ge25...@gamma.logic.tuwien.ac.at>): > On Mi, 27 Jun 2012, Arne Wichmann wrote: > > Given that, the relevant files should be removed from debian, as they are > > not DFSG-free. Am I wrong there? > > Yes

Bug#618968: Ping - netgen license problems

2012-06-28 Thread Arne Wichmann
begin quotation from Francesco Poli (in <20120625215725.69523c3a3df0a27f62672...@paranoici.org>): > On Mon, 25 Jun 2012 10:36:50 +0200 Arne Wichmann wrote: > > > So, at least as far as I can see, there are a number of things to be done > > in various time frames: >

Bug#483217: texlive-latex-base: 483217: status?

2012-06-27 Thread Arne Wichmann
begin quotation from Norbert Preining (in <20120619024124.gd14...@gamma.logic.tuwien.ac.at>): > On Sa, 16 Jun 2012, Arne Wichmann wrote: > > > Bug #483217 about licensing issues in files by Donald Arseneau was given > > > an exception for lenny. Do you plan to do

Bug#618968: Ping - netgen license problems

2012-06-25 Thread Arne Wichmann
begin quotation from Francesco Poli (in <20120620232034.ae7eb33bd4efe458d8ed7...@paranoici.org>): > On Sat, 16 Jun 2012 18:38:00 +0200 Arne Wichmann wrote: > > This serious bug is now open without any action for more than a year. Is > > that supposed to change? >

Bug#631051: Ping - onemore build problem

2012-06-17 Thread Arne Wichmann
crag, on Debian Planet) Arne Wichmann (a...@linux.de) signature.asc Description: Digital signature

Bug#618876: Ping - non-free data

2012-06-17 Thread Arne Wichmann
crag, on Debian Planet) Arne Wichmann (a...@linux.de) signature.asc Description: Digital signature

Bug#637488: Ping - remove t1lib

2012-06-17 Thread Arne Wichmann
begin quotation from Adam D. Barratt (in <1339930157.7014.2.ca...@jacala.jungle.funky-badger.org>): > On Sun, 2012-06-17 at 12:14 +0200, Arne Wichmann wrote: > > Just to remember... As far as I can see there are no more rdepends left. > > Are there any more reasons not to r

Bug#634131: Ping - import error

2012-06-17 Thread Arne Wichmann
self. (crag, on Debian Planet) Arne Wichmann (a...@linux.de) signature.asc Description: Digital signature

Bug#637488: Ping - remove t1lib

2012-06-17 Thread Arne Wichmann
t it. Noone can free you but yourself. (crag, on Debian Planet) Arne Wichmann (a...@linux.de) signature.asc Description: Digital signature

Bug#629730: Ping - FTBFS

2012-06-16 Thread Arne Wichmann
yourself. (crag, on Debian Planet) Arne Wichmann (a...@linux.de) signature.asc Description: Digital signature

Bug#629154: Ping - packages using python-support are configured before they are usable

2012-06-16 Thread Arne Wichmann
but yourself. (crag, on Debian Planet) Arne Wichmann (a...@linux.de) signature.asc Description: Digital signature

Bug#609537: Ping - /etc/init.d/mysql stop problems

2012-06-16 Thread Arne Wichmann
ou must to protect yourself, just don't support it. Noone can free you but yourself. (crag, on Debian Planet) Arne Wichmann (a...@linux.de) signature.asc Description: Digital signature

Bug#627174: Ping - FTBFS

2012-06-16 Thread Arne Wichmann
crag, on Debian Planet) Arne Wichmann (a...@linux.de) signature.asc Description: Digital signature

Bug#626391: Ping - venkman crashes

2012-06-16 Thread Arne Wichmann
27;t support it. Noone can free you but yourself. (crag, on Debian Planet) Arne Wichmann (a...@linux.de) signature.asc Description: Digital signature

Bug#623382: Ping - gnat fatal error - gone away?

2012-06-16 Thread Arne Wichmann
self, just don't support it. Noone can free you but yourself. (crag, on Debian Planet) Arne Wichmann (a...@linux.de) signature.asc Description: Digital signature

Bug#599523: Ping - unexpected downgrades

2012-06-16 Thread Arne Wichmann
self. (crag, on Debian Planet) Arne Wichmann (a...@linux.de) signature.asc Description: Digital signature

Bug#618968: Ping - netgen license problems

2012-06-16 Thread Arne Wichmann
ou but yourself. (crag, on Debian Planet) Arne Wichmann (a...@linux.de) signature.asc Description: Digital signature

Bug#610885: Ping

2012-06-16 Thread Arne Wichmann
crag, on Debian Planet) Arne Wichmann (a...@linux.de) signature.asc Description: Digital signature

Bug#579522: Ping

2012-06-16 Thread Arne Wichmann
ne can free you but yourself. (crag, on Debian Planet) Arne Wichmann (a...@linux.de) signature.asc Description: Digital signature

Bug#603405: Ping

2012-06-16 Thread Arne Wichmann
yourself. (crag, on Debian Planet) Arne Wichmann (a...@linux.de) signature.asc Description: Digital signature

Bug#538822: Ping

2012-06-16 Thread Arne Wichmann
ne can free you but yourself. (crag, on Debian Planet) Arne Wichmann (a...@linux.de) signature.asc Description: Digital signature

Bug#483217: texlive-latex-base: 483217: status?

2012-06-16 Thread Arne Wichmann
se his work in a more useful > way? And for wheezy again? cu AW -- [...] If you don't want to be restricted, don't agree to it. If you are coerced, comply as much as you must to protect yourself, just don't support it. Noone can free you but yourself. (crag, on Debi

Bug#665012: CVE-2012-1570 not yet fixed in stable

2012-06-03 Thread Arne Wichmann
begin quotation from Moritz Mühlenhoff (in <20120416154357.GA4565@pisco.westfalen.local>): > On Mon, Apr 16, 2012 at 12:43:40AM +0100, Nicholas Bamber wrote: > > On 15/04/12 16:18, Arne Wichmann wrote: > > >Found: 665012 1.4.03-1.1 > > > > > >As far as

Bug#628455: CVE-2011-1521 again

2012-06-03 Thread Arne Wichmann
icted, don't agree to it. If you are coerced, comply as much as you must to protect yourself, just don't support it. Noone can free you but yourself. (crag, on Debian Planet) Arne Wichmann (a...@linux.de) signature.asc Description: Digital signature

Bug#672660: linux-2.6: CVE-2012-0810 kernel-rt: stack corruption when task gets scheduled out using the debug stack

2012-05-12 Thread Arne Wichmann
Package: linux-2.6 Version: 3.2.16-1 Severity: grave Tags: security Justification: user security hole This seems to have slipped through the kernel-sec repository... Citing Redhat: The issue is that the int3 handler uses a per CPU debug stack, and calls do_traps() with interrupts enabled but pre

Bug#665012: CVE-2012-1570 not yet fixed in stable

2012-04-15 Thread Arne Wichmann
crag, on Debian Planet) Arne Wichmann (a...@linux.de) signature.asc Description: Digital signature

Bug#641738: Ping

2011-11-14 Thread Arne Wichmann
self. (crag, on Debian Planet) Arne Wichmann (a...@linux.de) signature.asc Description: Digital signature

Bug#628843: Ping

2011-10-19 Thread Arne Wichmann
begin quotation from Nicolas François (in <20111017211732.gj16...@nekral.nekral.homelinux.net>): > On Sun, Oct 16, 2011 at 05:20:31PM +0200, bubu...@debian.org wrote: > > Quoting Arne Wichmann (a...@anhrefn.saar.de): > > > This critical bug is now pending for more tha

Bug#628843: Ping

2011-10-15 Thread Arne Wichmann
yourself. (crag, on Debian Planet) Arne Wichmann (a...@linux.de) signature.asc Description: Digital signature

Bug#621866: Bug fixed in unstable/testung/experimental

2011-10-05 Thread Arne Wichmann
just don't support it. Noone can free you but yourself. (crag, on Debian Planet) Arne Wichmann (a...@linux.de) signature.asc Description: Digital signature

Bug#621866: Ping

2011-08-25 Thread Arne Wichmann
yourself. (crag, on Debian Planet) Arne Wichmann (a...@linux.de) signature.asc Description: Digital signature

Bug#623551: Ping

2011-08-05 Thread Arne Wichmann
self. (crag, on Debian Planet) Arne Wichmann (a...@linux.de) signature.asc Description: Digital signature

Bug#606922: jpake not enabled in sid

2010-12-16 Thread Arne Wichmann
efile.in: auth2-none.o auth2-passwd.o auth2-pubkey.o auth2-jpake.o \ Keep up the good work, AW -- [...] If you don't want to be restricted, don't agree to it. If you are coerced, comply as much as you must to protect yourself, just don't support it. Noone can free you but your

Bug#584653: RC bugs in upcoming stable

2010-12-01 Thread Arne Wichmann
Noone can free you but yourself. (crag, on Debian Planet) Arne Wichmann (a...@linux.de) signature.asc Description: Digital signature

Bug#525549: Ping

2010-07-17 Thread Arne Wichmann
Hi, Is there any progress on this issue? cu AW -- [...] If you don't want to be restricted, don't agree to it. If you are coerced, comply as much as you must to protect yourself, just don't support it. Noone can free you but yourself. (crag, on Debian Planet) Arne Wichmann

Bug#520485: Ping

2010-07-17 Thread Arne Wichmann
Hi, Is there any progress on this issue? cu AW -- [...] If you don't want to be restricted, don't agree to it. If you are coerced, comply as much as you must to protect yourself, just don't support it. Noone can free you but yourself. (crag, on Debian Planet) Arne Wichmann

Bug#518250: Is this a bug?

2010-07-17 Thread Arne Wichmann
an free you but yourself. (crag, on Debian Planet) Arne Wichmann (a...@linux.de) signature.asc Description: Digital signature

Bug#514220: Ping

2010-07-17 Thread Arne Wichmann
Hi... Is there any progress on this? cu AW -- [...] If you don't want to be restricted, don't agree to it. If you are coerced, comply as much as you must to protect yourself, just don't support it. Noone can free you but yourself. (crag, on Debian Planet) Arne Wichmann

Bug#511582: Ping

2010-07-17 Thread Arne Wichmann
n Debian Planet) Arne Wichmann (a...@linux.de) signature.asc Description: Digital signature

Bug#508589: Reassigning as it seems to be a kernel problem after all

2010-07-17 Thread Arne Wichmann
ou must to protect yourself, just don't support it. Noone can free you but yourself. (crag, on Debian Planet) Arne Wichmann (a...@linux.de) signature.asc Description: Digital signature

Bug#575742: Intend to NMU 575742 (was: CVE-2009-3995 CVE-2009-3996: Multiple heap-based buffer overflows)

2010-06-12 Thread Arne Wichmann
ou but yourself. (crag, on Debian Planet) Arne Wichmann (a...@linux.de) diff -u libmikmod-3.1.11/debian/changelog libmikmod-3.1.11/debian/changelog --- libmikmod-3.1.11/debian/changelog +++ libmikmod-3.1.11/debian/changelog @@ -1,3 +1,11 @@ +libmikmod (3.1.11-6.2) unstable; urgency=high + + * Non-ma

Bug#286905: perl-modules: File::Path::rmtree makes setuid

2005-02-08 Thread Arne Wichmann
Hi. As this Bug is now lying around for more than one month I decided to look into a fix. It is not a very beautiful one, it is only partially tested and it only works for systems which can fork, so please look over it before applying it. The idea is to fork off a process, change into the director