Bug#504255: CVE-2007-3215: remote shell command execution in class.phpmailer.php

2008-11-02 Thread Raphael Geissert
Package: phpgroupware-felamimail Severity: grave Version: 0.9.16.011-2.2 Tags: security patch Hi, The following CVE (Common Vulnerabilities & Exposures) id was published for PHPMailer, which affects the embedded copy shipped in phpgroupware-felamimail[0]. CVE-2007-3215[1]: > PHPMailer 1.7, whe

Bug#504258: CVE-2008-4796: missing input sanitising in embedded copy of Snoopy.class.php

2008-11-02 Thread Raphael Geissert
Package: gforge-plugin-scmcvs Severity: grave Version: 4.5.14-5 Tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) id was published for snoopy, which affects the embedded copy shipped by gforge-plugin-scmcvs [0]. CVE-2008-4796[1]: > The _httpsrequest function (Snoopy/Snoo

Bug#504220: Missing dependencies

2008-11-02 Thread Reinhard Tartler
Sebastian Dröge <[EMAIL PROTECTED]> writes: > Although these are in Requires.private the -dev packages _must_ depend > on the corresponding -dev packages (libraw1394-dev, libtheora-dev, > libvorbis-dev) as otherwise pkg-config will refuse to use the pkg-config > files (and configure checks will a

Bug#504220: Missing dependencies

2008-11-02 Thread Reinhard Tartler
digging a bit further in the configure script: enabled libdc1394 && append pkg_requires "libraw1394" enabled libdirac && append pkg_requires "dirac" enabled libtheora && append pkg_requires "theora" enabled libvorbis && append pkg_requires "vorbisenc" [...] # build pkg-config files pkgconfig_gen

Bug#479607: marked as done (lilo fails to boot 2.6.25 kernel image due to wrongly passing initramfs)

2008-11-02 Thread Debian Bug Tracking System
Your message dated Sun, 02 Nov 2008 09:17:04 + with message-id <[EMAIL PROTECTED]> and subject line Bug#479607: fixed in lilo 1:22.8-6.1 has caused the Debian Bug report #479607, regarding lilo fails to boot 2.6.25 kernel image due to wrongly passing initramfs to be marked as done. This mean

Bug#504255: CVE-2007-3215: remote shell command execution in class.phpmailer.php

2008-11-02 Thread Olivier Berger
Le dimanche 02 novembre 2008 à 00:56 -0600, Raphael Geissert a écrit : > Hi, > > The following CVE (Common Vulnerabilities & Exposures) id was published for > PHPMailer, which affects the embedded copy shipped in > phpgroupware-felamimail[0]. > > CVE-2007-3215[1]: > > PHPMailer 1.7, when confi

Bug#504255: CVE-2007-3215: remote shell command execution in class.phpmailer.php

2008-11-02 Thread Olivier Berger
Le dimanche 02 novembre 2008 à 11:13 +0100, Olivier Berger a écrit : > Thanks for spotting this problem. > > The referred [2] patch is actually not exactly apllicable to the version > of class.phpmailer.php shipped in phpgroupware 0.9.11, and the correct > one is attached. > > I'll try and work

Processed: Re: #443948 libphp-snoopy, now it is a package in debian unstable.

2008-11-02 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > tags 443948 + patch Bug#443948: libphp-snoopy, now it is a package in debian unstable. There were no tags set. Tags added: patch > thanks Stopping processing here. Please contact me if you need assistance. Debian bug tracking system administrator (ad

Bug#504279: ebay changes break jbidwatcher for most german auctions

2008-11-02 Thread Erich Schubert
Package: jbidwatcher Version: 1:1.0.2+dfsg-1 Severity: grave Justification: renders package unusable Recent changes by ebay render jbidwatcher mostly unuseable for German users (at least, and many other non-US users, too). Apparently this is caused by the following combination: - Ebay requires US

Bug#504172: marked as done (CVE-2008-4796: missing input sanitising in Snoopy.class.php)

2008-11-02 Thread Debian Bug Tracking System
Your message dated Sun, 02 Nov 2008 11:17:09 + with message-id <[EMAIL PROTECTED]> and subject line Bug#504172: fixed in mediamate 0.9.3.6-5 has caused the Debian Bug report #504172, regarding CVE-2008-4796: missing input sanitising in Snoopy.class.php to be marked as done. This means that yo

Bug#504144: htop: Does not filter non-printable characters in process names

2008-11-02 Thread Nico Golde
Hi Josh, * Josh Triplett <[EMAIL PROTECTED]> [2008-11-02 12:12]: > Nico Golde wrote: > >* Josh Triplett <[EMAIL PROTECTED]> [2008-11-01 04:16]: [...] > >> top changes the non-printable characters to question marks. htop > >> prints them unchanged, and thus corrupts its own display. More subtle >

Bug#503315: Can you add some info, please?

2008-11-02 Thread Santiago Garcia Mantinan
Hi! I'd like to look at this bug from the swfdec side, but I don't even have a url or file that is causing this. Could you please send us a url or file to reproduce this bug? Maybe it would also be good to know what other add-ons do you have installed on your mozilla and any other info that you

Bug#443948: #443948 libphp-snoopy, now it is a package in debian unstable.

2008-11-02 Thread Evgeni Golov
Oups, now actually attach the diff ;) diff -u wordpress-2.5.1/debian/control wordpress-2.5.1/debian/control --- wordpress-2.5.1/debian/control +++ wordpress-2.5.1/debian/control @@ -8,7 +8,7 @@ Package: wordpress Architecture: all -Depends: apache2 | httpd, virtual-mysql-client, libapache2-mod-

Bug#467652: marked as done (vlc: CVE-2008-0984 arbitrary code execution via crafted mp4 file)

2008-11-02 Thread Debian Bug Tracking System
Your message dated Sun, 2 Nov 2008 13:18:58 +0100 with message-id <[EMAIL PROTECTED]> and subject line closing has caused the Debian Bug report #467652, regarding vlc: CVE-2008-0984 arbitrary code execution via crafted mp4 file to be marked as done. This means that you claim that the problem has

Bug#504282: program aborts due to assertion

2008-11-02 Thread hungerburg
Package: oxine Version: 0.7.1-3 Severity: grave hello, (bug tagged grave, though maybe its only happening here.) on this system I cannot play anything. the initial menu comes up fine. then I select eg. "Watch Films", for a split second "Please Wait" appears, then oxine quits. Console reads: o

Bug#504082: marked as done (dovecot: assertion failures on amd64 suspected to be from being built using broken flex)

2008-11-02 Thread Debian Bug Tracking System
Your message dated Sun, 2 Nov 2008 13:22:22 +0100 with message-id <[EMAIL PROTECTED]> and subject line Re: Bug#504082: dovecot: assertion failures on amd64 suspected to be from being built using broken flex has caused the Debian Bug report #504082, regarding dovecot: assertion failures on amd64

Bug#504283: CVE-2007-3215: phpmailer issue (embedded code-copy)

2008-11-02 Thread Steffen Joeris
Package: phpgroupware Severity: grave Tags: security, patch Justification: user security hole Hi Peter, the following CVE (Common Vulnerabilities & Exposures) id was published for egroupware-core. CVE-2007-3215[0]: | PHPMailer 1.7, when configured to use sendmail, allows remote | attackers to exe

Bug#504118: #504118: unreproducible

2008-11-02 Thread Evgeni Golov
tags 504118 + unreproducible thanks I can't reproduce this bug. Neither with sbcl 1:0.9.16.0-1 (Etch/i386), nor 1:1.0.18.0-1 (Lenny/sparc), nor 1:1.0.18.0-2 (Sid/i386). Dear submitter, can you provide a bit more information? regards Evgeni pgpy7w8WL6NQB.pgp Description: PGP signature

Bug#504255: CVE-2007-3215: remote shell command execution in

2008-11-02 Thread Steffen Joeris
On Sun, 2 Nov 2008 09:49:32 pm Olivier Berger wrote: > Le dimanche 02 novembre 2008 à 11:13 +0100, Olivier Berger a écrit : > > Thanks for spotting this problem. > > > > The referred [2] patch is actually not exactly apllicable to the version > > of class.phpmailer.php shipped in phpgroupware 0.9.1

Processed: #504118: unreproducible

2008-11-02 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > tags 504118 + unreproducible Bug#504118: sbcl: install fails through apt-get but succeeds otherwise There were no tags set. Tags added: unreproducible > thanks Stopping processing here. Please contact me if you need assistance. Debian bug tracking sy

Bug#502345: marked as done (lilo: fails to boot linux-image-2.6.26-1-amd64)

2008-11-02 Thread Debian Bug Tracking System
Your message dated Sun, 02 Nov 2008 09:17:04 + with message-id <[EMAIL PROTECTED]> and subject line Bug#479607: fixed in lilo 1:22.8-6.1 has caused the Debian Bug report #479607, regarding lilo: fails to boot linux-image-2.6.26-1-amd64 to be marked as done. This means that you claim that the

Bug#504279: ebay changes break jbidwatcher for most german auctions

2008-11-02 Thread Romain Beauxis
Hi ! Le Sunday 02 November 2008 12:59:08 Erich Schubert, vous avez écrit : > Just from what I figured from the forums. > Upstream is already working on that, but for the 2.0 versions. Yes, I came to that conclusion. However, the only solution that I find is to ask for a removal jbidwatche

Bug#475993: Bug#494340: fslview package fixing RC-bugs

2008-11-02 Thread Adeodato Simó
* Michael Hanke [Wed, 15 Oct 2008 07:14:06 +0200]: > On Mon, Oct 13, 2008 at 04:14:54PM +0300, Riku Voipio wrote: > > On Sun, Oct 12, 2008 at 04:41:42PM +0200, Adeodato Simó wrote: > > > > http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=475993#37 > > > > which has its origin in the VTK package a

Bug#502539: marked as done (virtualbox-ose-modules-2.6.26-1-686 contains outdated module for VirtualBox)

2008-11-02 Thread Debian Bug Tracking System
Your message dated Sun, 2 Nov 2008 10:40:08 +0100 with message-id <[EMAIL PROTECTED]> and subject line Closing has caused the Debian Bug report #502346, regarding virtualbox-ose-modules-2.6.26-1-686 contains outdated module for VirtualBox to be marked as done. This means that you claim that the

Bug#504212: gimp: crash on 'new image' operation with small theme

2008-11-02 Thread Sergey I. Sharybin
I investigated this question today's morning. This bug was because of strange usage of gtk calls in candido engine. I'll try to send patch to this engine's maintainer. Issue about gimp is closed. Thanks for your help. -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscr

Bug#504255: CVE-2007-3215: remote shell command execution in class.phpmailer.php

2008-11-02 Thread Olivier Berger
Le dimanche 02 novembre 2008 à 00:56 -0600, Raphael Geissert a écrit : > However, it would be > better if phpgroupware-felamimail just depended on libphp-phpmailer (also > available in etch) and the include/require calls changed to use the copy > provided by that package, to avoid shipping yet a

Bug#443948: #443948 libphp-snoopy, now it is a package in debian unstable.

2008-11-02 Thread Evgeni Golov
tags 443948 + patch thanks Hi Marcelo, hi Andrea, attached is a debdiff for a NMU for this bug. It's untested, as I don't have any wordpress installations here, but should work :) Can someone please test? Marcelo, will you ask for a freeze unblock for snoopy because of the security issue in Lenn

Bug#504273: redcloth_4.0.4-1(sparc/experimental): FTBFS: no such file to load -- mkmf (LoadError)

2008-11-02 Thread Frank Lichtenheld
Package: redcloth Version: 4.0.4-1 Severity: serious Hi, your package failed to build from source. | Automatic build of redcloth_4.0.4-1 on njoerd by sbuild/sparc 98-farm | Build started at 20081102-0737 | ** | Checking

Bug#503543: more glitches

2008-11-02 Thread Sven Hoexter
Looks like there are some more glitches: [...] Running fmtutil-sys. This may take some time. ... /usr/share/texmf/web2c/mktexupd: /var/lib/texmf/web2c/ptex not a directory. from postinst during an etch->lenny upgrade. Sven -- If God passed a mic to me to speak I'd say stay in bed, world Sleep i

Processed: Re: Bug#502960: I got a "Locking assertion failure" from inside libX11 called from, kinput2-wnn.

2008-11-02 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > severity 502960 normal Bug#502960: I got a "Locking assertion failure" from inside libX11 called from, kinput2-wnn. Severity set to `normal' from `serious' > thanks Stopping processing here. Please contact me if you need assistance. Debian bug track

Bug#492918: marked as done ([PANIC][REGRESSION] linux-image-2.6.25-2-amd64: kernel fails to mount root on LVM2)

2008-11-02 Thread Debian Bug Tracking System
Your message dated Sun, 02 Nov 2008 09:17:04 + with message-id <[EMAIL PROTECTED]> and subject line Bug#479607: fixed in lilo 1:22.8-6.1 has caused the Debian Bug report #479607, regarding [PANIC][REGRESSION] linux-image-2.6.25-2-amd64: kernel fails to mount root on LVM2 to be marked as done.

Bug#502346: marked as done (virtualbox-ose-modules package older than virtualbox-ose)

2008-11-02 Thread Debian Bug Tracking System
Your message dated Sun, 2 Nov 2008 10:40:08 +0100 with message-id <[EMAIL PROTECTED]> and subject line Closing has caused the Debian Bug report #502346, regarding virtualbox-ose-modules package older than virtualbox-ose to be marked as done. This means that you claim that the problem has been dea

Bug#504169: marked as done (CVE-2008-4796: missing input sanitising in Snoopy.class.php)

2008-11-02 Thread Debian Bug Tracking System
Your message dated Sun, 02 Nov 2008 10:47:03 + with message-id <[EMAIL PROTECTED]> and subject line Bug#504169: fixed in ampache 3.4.1-2 has caused the Debian Bug report #504169, regarding CVE-2008-4796: missing input sanitising in Snoopy.class.php to be marked as done. This means that you cl

Bug#503796: marked as done (sat4j: java bytecode / java runtime version mismatch)

2008-11-02 Thread Debian Bug Tracking System
Your message dated Sun, 02 Nov 2008 12:47:06 + with message-id <[EMAIL PROTECTED]> and subject line Bug#503796: fixed in sat4j 2.0.4-1 has caused the Debian Bug report #503796, regarding sat4j: java bytecode / java runtime version mismatch to be marked as done. This means that you claim that

Processed: reassign 486334 to xulrunner-1.9, forcibly merging 486334 482415

2008-11-02 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > reassign 486334 xulrunner-1.9 Bug#486334: segfault in iceweasel 3.0~rc2-1 Bug#486354: iceweasel: Iceweasel rc2 does not start Bug#492488: iceweasel: crashes on startup (x64) Bug reassigned from package `iceweasel' to `xulrunner-1.9'. > forcemerge 48633

Processed: Re: Bug#503315: iceweasel: Iceweasel shutdowns and triggers bug reporter

2008-11-02 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > reassign 503315 swfdec-mozilla Bug#503315: iceweasel: Iceweasel shutdowns and triggers bug reporter Bug reassigned from package `iceweasel' to `swfdec-mozilla'. > thanks Stopping processing here. Please contact me if you need assistance. Debian bug t

Processed: bug 504255 is forwarded to https://savannah.gnu.org/bugs/?24725

2008-11-02 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > # Automatically generated email from bts, devscripts version 2.10.35 > forwarded 504255 https://savannah.gnu.org/bugs/?24725 Bug#504255: CVE-2007-3215: remote shell command execution in class.phpmailer.php Noted your statement that Bug has been forwarde

Processed: setting package to python-xpcom xulrunner-1.9 libmozjs1d libmozillainterfaces-java libmozjs1d-dbg xulrunner xulrunner-dev xulrunner-1.9-dbg libmozjs-dev spidermonkey-bin xulrunner-1.9-gnome

2008-11-02 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > #xulrunner (1.9.0.3-2) UNRELEASED; urgency=low > # > # * browser/app/mozilla.in: Do exec instead of uselessly forking. > #Closes: #496626. > # * debian/xulrunner-1.9.preinst: If /usr/lib/xulrunner-1.9/chrome is an > #empty directory, remove it

Bug#479607: lilo fails to boot 2.6.25 kernel image due to wrongly passing initramfs

2008-11-02 Thread Paul Wise
On Sat, 2008-11-01 at 18:13 +0100, Luk Claes wrote: > Christian is the expert and already reviewed it and you tested it > AFAICS. The patch looks also not invasive and would be very welcome from > a user point of view. > > Please upload. Done. -- bye, pabs http://wiki.debian.org/PaulWise si

Bug#504220: Missing dependencies

2008-11-02 Thread Loïc Minier
On Sun, Nov 02, 2008, Reinhard Tartler wrote: > However no Requires.private. Can you perhaps point me to some better > documentation what "Requires.private" is supposed to mean? Perhaps > upstream rather meant to use Libs.private instead, which would probably > "fix" this problem as well? Require

Bug#503315: iceweasel: Iceweasel shutdowns and triggers bug reporter

2008-11-02 Thread Mike Hommey
reassign 503315 swfdec-mozilla thanks On Fri, Oct 24, 2008 at 12:01:43PM -0500, Dennis Wicks wrote: > Subject: iceweasel: Iceweasel shutdowns and triggers bug reporter > Package: iceweasel > Version: 3.0.1-1 > Severity: grave > Justification: renders package unusable I overlooked the stacktrace..

Bug#443948: #443948 libphp-snoopy, now it is a package in debian unstable.

2008-11-02 Thread Andrea De Iacovo
> tags 443948 + patch > thanks > > Hi Marcelo, hi Andrea, > > attached is a debdiff for a NMU for this bug. It's untested, as I don't > have any wordpress installations here, but should work :) > Can someone please test? > > Marcelo, will you ask for a freeze unblock for snoopy because of the >

Bug#504255: CVE-2007-3215: remote shell command execution in

2008-11-02 Thread Steffen Joeris
On Sun, 2 Nov 2008 11:34:28 pm Steffen Joeris wrote: > On Sun, 2 Nov 2008 09:49:32 pm Olivier Berger wrote: > > Le dimanche 02 novembre 2008 à 11:13 +0100, Olivier Berger a écrit : > > > Thanks for spotting this problem. > > > > > > The referred [2] patch is actually not exactly apllicable to the >

Bug#443948: #443948 libphp-snoopy, now it is a package in debian unstable.

2008-11-02 Thread Marcelo Jorge Vieira (metal)
hi Evgeni , hi Andrea, the new upstream version of libphp-snoopy is in sid; and I have already sent message to unblock the package Cheers, On Sun, 2008-11-02 at 14:53 +0100, Andrea De Iacovo wrote: > > tags 443948 + patch > > thanks > > > > Hi Marcelo, hi Andrea, > > > > attached is a debdif

Bug#504273: marked as done (redcloth_4.0.4-1(sparc/experimental): FTBFS: no such file to load -- mkmf (LoadError))

2008-11-02 Thread Debian Bug Tracking System
.0.4-1 Severity: serious Hi, your package failed to build from source. | Automatic build of redcloth_4.0.4-1 on njoerd by sbuild/sparc 98-farm | Build started at 20081102-0737 | ** | Checking available source ve

Bug#504285: libao-pulse: should this package be removed (at least from testing?)

2008-11-02 Thread Adeodato Simó
Package: libao-pulse Version: 0.9.3-1 Severity: serious Hello, CJ. I have in my inbox a mail exchange with you from May 2007 in which I proposed to remove this package because libao2 had started providing the libao-pulse plugin. You commented that you didn't think it was a good idea, because the

Processed: Reopening bugs on static libs and installation problem

2008-11-02 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > reopen 502232 = Bug#502232: libopenmpi-dev: No static libraries in the package 'reopen' may be inappropriate when a bug has been closed with a version; you may need to use 'found' to remove fixed versions. Bug reopened, originator not changed. > reopen

Bug#499414: marked as done (evtest is using an ioctl() wrong)

2008-11-02 Thread Debian Bug Tracking System
Your message dated Sun, 02 Nov 2008 14:02:03 + with message-id <[EMAIL PROTECTED]> and subject line Bug#499414: fixed in joystick 20051019-5 has caused the Debian Bug report #499414, regarding evtest is using an ioctl() wrong to be marked as done. This means that you claim that the problem ha

Bug#504287: virt-viewer_0.0.3-3(ia64/experimental): FTBFS: rm: cannot remove `/usr/lib/mozilla/plugins/virt-viewer-plugin.a': Permission denied

2008-11-02 Thread Philipp Kern
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Package: virt-viewer Version: 0.0.3-3 Severity: serious There was an error while trying to autobuild your package: > Automatic build of virt-viewer_0.0.3-3 on alkman.ayous.org by sbuild/ia64 > 98-farm > Build started at 2008

Processed: fnonlinear_270.74-2(powerpc/unstable): still FTBFS due to fImport

2008-11-02 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > found 504215 270.74-2 Bug#504215: fnonlinear: FTBFS: there is no package called 'fImport' Bug marked as found in version 270.74-2 and reopened. > thanks Stopping processing here. Please contact me if you need assistance. Debian bug tracking system ad

Bug#504215: fnonlinear_270.74-2(powerpc/unstable): still FTBFS due to fImport

2008-11-02 Thread Philipp Kern
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 found 504215 270.74-2 thanks Package: fnonlinear Version: 270.74-2 Severity: serious Followup-For: Bug #504215 There was an error while trying to autobuild your package: > Automatic build of fnonlinear_270.74-2 on voltaire by sbuild/powerpc 99.999 >

Processed: bug 486334 is not forwarded

2008-11-02 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > notforwarded 486334 Bug#486334: segfault in iceweasel 3.0~rc2-1 Bug#482415: iceweasel: crashes immediately upon startup Bug#486354: iceweasel: Iceweasel rc2 does not start Bug#492488: iceweasel: crashes on startup (x64) Removed annotation that Bug had b

Bug#504215: fnonlinear_270.74-2(powerpc/unstable): still FTBFS due to fImport

2008-11-02 Thread Dirk Eddelbuettel
On 2 November 2008 at 15:24, Philipp Kern wrote: | -BEGIN PGP SIGNED MESSAGE- | Hash: SHA1 | | found 504215 270.74-2 | thanks So the fGarch package (ie r-cran-fgarch) you pulled is old too. Will add a versioned Depends. Thanks, Dirk | Package: fnonlinear | Version: 270.74-2 | Severity

Bug#504291: libtoolize --ltdl fails

2008-11-02 Thread Marc-Andre Lureau
Package: libtool Version: 2.2.2-1 Severity: grave Justification: renders package unusable Note: installing libltdl7-dev fix the issue. Maybe the dependency should be stronger? Step to reproduce: mkdir /tmp/test cd /tmp/test /tmp/lt$ libtoolize --ltdl libtoolize: linking file `libltdl/config/comp

Bug#504291: libtoolize --ltdl fails

2008-11-02 Thread Kurt Roeckx
severity 504291 normal thanks On Sun, Nov 02, 2008 at 04:56:08PM +0200, Marc-Andre Lureau wrote: > Package: libtool > Version: 2.2.2-1 > Severity: grave > Justification: renders package unusable > > Note: installing libltdl7-dev fix the issue. Maybe the dependency should > be stronger? > > Step

Processed: Re: Bug#504291: libtoolize --ltdl fails

2008-11-02 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > severity 504291 normal Bug#504291: libtoolize --ltdl fails Severity set to `normal' from `grave' > thanks Stopping processing here. Please contact me if you need assistance. Debian bug tracking system administrator (administrator, Debian Bugs databas

Bug#503616: closed by Stefano Zacchiroli <[EMAIL PROTECTED]> (Bug#503616: fixed in ocamlnet 2.2.9-3+lenny1)

2008-11-02 Thread Dave Benjamin
Stefano Zacchiroli wrote: On Thu, Oct 30, 2008 at 07:57:29AM -0700, Dave Benjamin wrote: Thanks for looking into this issue. I will try the module again as soon as I can find the updated packages in unstable. Were you able to get it to load successfully? Yes, sure, I was able to. The packa

Processed: adding tag patches

2008-11-02 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > tags 504161 + confirmed patch Bug#504161: libopenmpi-dev: Package cannot be installed There were no tags set. Tags added: confirmed, patch > tags 502232 + confirmed patch Bug#502232: libopenmpi-dev: No static libraries in the package There were no tags

Bug#489045: cups: infinite loop, 100%CPU use, while trying to print with HPJetDirect

2008-11-02 Thread Andreas Mohr
Environment clarification: HPLJ4000TN JetDirect J3111A Firmware G.08.49 (newest), on a BNC(!) connection. This being a 10Mbps BNC connection here could be another indication that this 100% CPU lockup issue possibly happens on slower connections only (this issue does not seem to be too wide-spread,

Bug#504255: CVE-2007-3215: remote shell command execution in

2008-11-02 Thread Olivier Berger
Le dimanche 02 novembre 2008 à 23:34 +1100, Steffen Joeris a écrit : > > Can someone from the security team take care of review and the upload ? > The patch looks good. I'll sponsor the upload. Thanks for your work. > Thanks. > P.S. If you want to use phpmailer stuff again, please use a depend

Bug#482629: marked as done (kmymoney2-plugin-aqbanking: FTBFS with kmymoney2 0.9-1: Missing header files)

2008-11-02 Thread Debian Bug Tracking System
Your message dated Sun, 02 Nov 2008 17:43:35 +0100 with message-id <[EMAIL PROTECTED]> and subject line This bug is fixed for Lenny has caused the Debian Bug report #482629, regarding kmymoney2-plugin-aqbanking: FTBFS with kmymoney2 0.9-1: Missing header files to be marked as done. This means th

Bug#504161: marked as done (libopenmpi-dev: Package cannot be installed)

2008-11-02 Thread Debian Bug Tracking System
Your message dated Sun, 02 Nov 2008 16:47:05 + with message-id <[EMAIL PROTECTED]> and subject line Bug#504161: fixed in openmpi 1.2.8-3 has caused the Debian Bug report #504161, regarding libopenmpi-dev: Package cannot be installed to be marked as done. This means that you claim that the pro

Processed: Re: Bug#504283: CVE-2007-3215: phpmailer issue (embedded code-copy)

2008-11-02 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > reassign 504283 egroupware Bug#504283: CVE-2007-3215: phpmailer issue (embedded code-copy) Bug reassigned from package `phpgroupware' to `egroupware'. > thanks Stopping processing here. Please contact me if you need assistance. Debian bug tracking sy

Bug#504283: CVE-2007-3215: phpmailer issue (embedded code-copy)

2008-11-02 Thread Olivier Berger
reassign 504283 egroupware thanks #504255 was already filed on phpgroupware, so I suppose that this one was meant for egroupware instead. #504255 mentions a likely patch for egroupware, should felamimail still be around (even if a better fix may be to depend on updated libphp-phpmailer, of cou

Processed: Re: Bug#504283: CVE-2007-3215: phpmailer issue (embedded code-copy)

2008-11-02 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > reassign 504283 egroupware-felamimail Bug#504283: CVE-2007-3215: phpmailer issue (embedded code-copy) Bug reassigned from package `egroupware' to `egroupware-felamimail'. > thanks Stopping processing here. Please contact me if you need assistance. De

Processed: Re: Bug#504283: CVE-2007-3215: phpmailer issue (embedded code-copy)

2008-11-02 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > reassign 504283 egroupware-core Bug#504283: CVE-2007-3215: phpmailer issue (embedded code-copy) Bug reassigned from package `egroupware-felamimail' to `egroupware-core'. > thanks Stopping processing here. Please contact me if you need assistance. Deb

Bug#504283: CVE-2007-3215: phpmailer issue (embedded code-copy)

2008-11-02 Thread Olivier Berger
reassign 504283 egroupware-core thanks Damn, sorry again, I supposed that the code was in the same place as for phpgroupware source, but it appears to be in egroupware-core instead :( Should have checked the package's contents in the first place. Best regards, Le dimanche 02 novembre 2008 à 18:

Bug#504283: CVE-2007-3215: phpmailer issue (embedded code-copy)

2008-11-02 Thread Olivier Berger
reassign 504283 egroupware-felamimail thanks oops, my fault, sorry, should have directed it for -felamimail instead. Regards, Le dimanche 02 novembre 2008 à 17:44 +0100, Olivier Berger a écrit : > reassign 504283 egroupware > thanks -- Olivier BERGER <[EMAIL PROTECTED]> http://www-public.it-su

Bug#503589: Wireshark CVE patches

2008-11-02 Thread Stefan Lesicnik
User: [EMAIL PROTECTED] Usertags: origin-ubuntu ubuntu-patch intrepid Hi. I have uploaded 3 debdiffs for the CVE's for Ubuntu - these are currently awaiting review. The Ubuntu bug is here https://bugs.edge.launchpad.net/ubuntu/+source/wireshark/+bug/290716 The POC's for each CVE are also attache

Bug#504220: Missing dependencies

2008-11-02 Thread Sebastian Dröge
Am Sonntag, den 02.11.2008, 09:10 +0100 schrieb Reinhard Tartler: > [...] > That indicates that Requires.private is indeed used on purpose. [1] > indicates that you are right, and the -dev packages are indeed missing > depedencies. However I'd love to see some more authoritative > documentation on

Bug#504287: marked as done (virt-viewer_0.0.3-3(ia64/experimental): FTBFS: rm: cannot remove `/usr/lib/mozilla/plugins/virt-viewer-plugin.a': Permission denied)

2008-11-02 Thread Debian Bug Tracking System
th problems --- Begin Message --- -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Package: virt-viewer Version: 0.0.3-3 Severity: serious There was an error while trying to autobuild your package: > Automatic build of virt-viewer_0.0.3-3 on alkman.ayous.org by sbuild/ia64 > 98-farm > Build star

Bug#503616: missing symbol sqrt

2008-11-02 Thread Stéphane Glondu
Dave Benjamin wrote: > [...] I still can't get Apache to start: > > $ sudo /etc/init.d/apache2 start > Starting web server: apache2apache2: Syntax error on line 187 of > /etc/apache2/apache2.conf: Syntax error on line 1 of > /etc/apache2/mods-enabled/netcgi_apache.load: Cannot load > /usr/lib/apac

Bug#503616: missing symbol sqrt

2008-11-02 Thread Dave Benjamin
On Sun, 2 Nov 2008, Stéphane Glondu wrote: FWIW, I cannot reproduce the problem now. I get no errors with a sid and a lenny chroot (with ocamlnet 2.2.9-4). I am on a i386 architecture. I have tried with the 3 flavours of apache2. Maybe your system is not up-to-date w.r.t other (non-OCaml-relate

Bug#443948: #443948 libphp-snoopy, now it is a package in debian unstable.

2008-11-02 Thread Andrea De Iacovo
> hi Evgeni , hi Andrea, > > the new upstream version of libphp-snoopy is in sid; > and I have already sent message to unblock the package Great! Wordpress will depend on it in the next days. Cheers. Andrea signature.asc Description: Questa è una parte del messaggio firmata digitalmente

Bug#504323: openoffice.org-core: Segmentation fault at startup

2008-11-02 Thread F. Goujeon
Package: openoffice.org-core Version: 1:2.4.1-11 Severity: grave Justification: renders package unusable OOo (either writer or impress or...) crashes at startup (while showing splash screen) because of a segmentation fault. The installation of OOo is fresh, without any extension. Deleting ~/.openo

Bug#504220: Missing dependencies

2008-11-02 Thread Loïc Minier
On Sun, Nov 02, 2008, Sebastian Dröge wrote: > if it's in Libs.private -dev packages only need to depend on it if they > ship static libraries (AFAIK). If they ship *only* static libraries, perhaps; otherwise, static linking is just for users, in theory not for Debian consumption, and we just p

Bug#504220: Missing dependencies

2008-11-02 Thread Reinhard Tartler
tags 504220 help stop Sebastian Dröge <[EMAIL PROTECTED]> writes: > No idea about pkg-config documentation... it's one of the most used but > worst documented pieces of software :) Then that's something that should be fixed first. There is no point in adding further breakage and inconsistencies

Processed: Re: Bug#504220: Missing dependencies

2008-11-02 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > tags 504220 help Bug#504220: Missing dependencies There were no tags set. Tags added: help > stop Stopping processing here. Please contact me if you need assistance. Debian bug tracking system administrator (administrator, Debian Bugs database) --

Processed: Re: Bug#504323: openoffice.org-core: Segmentation fault at startup

2008-11-02 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > tag 504323 + moreinfo Bug#504323: openoffice.org-core: Segmentation fault at startup There were no tags set. Tags added: moreinfo > tag 504323 + unreproducible Bug#504323: openoffice.org-core: Segmentation fault at startup Tags were: moreinfo Tags adde

Bug#504323: openoffice.org-core: Segmentation fault at startup

2008-11-02 Thread Rene Engelhard
tag 504323 + moreinfo tag 504323 + unreproducible thanks F. Goujeon wrote: > OOo (either writer or impress or...) crashes at startup (while showing splash > screen) because of a segmentation fault. [...] > Only writer (and its dependencies) is installed. This contradicts. When you had only -write

Processed: severity of 503926 is normal, retitle 503926 to epiphany links statically to libxpcomglue

2008-11-02 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > # Automatically generated email from bts, devscripts version 2.9.26 > severity 503926 normal Bug#503926: epiphany-gecko: Needs to be rebuilt _every_ time xulrunner is updated Severity set to `normal' from `serious' > #We’re forced to do that anyway

Bug#504285: libao-pulse: should this package be removed (at least from testing?)

2008-11-02 Thread CJ van den Berg
On Sun, Nov 02, 2008 at 02:54:25PM +0100, Adeodato Simó wrote: > I won't insist that this package should be removed from unstable, > because maybe development on it starts again -- should that happen, then > we can stop shipping libao-pulse in libao2, and Suggest/Recommend > libao-pulse instead. >

Bug#501151: why was ocfs2 support removed from lenny?

2008-11-02 Thread Jeremy Lainé
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 > as far as i see there was no security reason to remove this package. > > The only other reason i could see is that there would be no possible > upgrade path from 1.2.x to 1.4.x. Maybe someone can explain me? > > I think lenny without ocfs2 support

Bug#503616: missing symbol sqrt

2008-11-02 Thread Dave Benjamin
On Sun, 2 Nov 2008, Stéphane Glondu wrote: Maybe your system is not up-to-date w.r.t other (non-OCaml-related) packages? Or there is some bad interaction with another Apache module? I upgraded all of my Apache 2 packages to the latest versions and disabled every module, re-enabling them one-b

Bug#503616: missing symbol sqrt

2008-11-02 Thread Stéphane Glondu
Dave Benjamin wrote: >> Maybe your system is not up-to-date w.r.t other (non-OCaml-related) >> packages? Or there is some bad interaction with another Apache module? > > I upgraded all of my Apache 2 packages to the latest versions and > disabled every module, re-enabling them one-by-one until I c

Bug#504323: openoffice.org-core: Segmentation fault at startup

2008-11-02 Thread Rene Engelhard
Hi, please keep the bug in the Cc otherwise stuff won't be recorded. Cc'ing the bug now and fullquoting for it. Florian Goujeon wrote: > Rene Engelhard a écrit : >> This contradicts. When you had only -writer and its deps installed you don't >> have impress. > It doesn't. I encountered the bug

Bug#501151: why was ocfs2 support removed from lenny?

2008-11-02 Thread Frederik Schüler
Hi! I am preparing an upload of version 1.4.1, hopefully this will make it into Lenny. Best regards Frederik Schüler On Sunday 02 November 2008 22:50:02 Jeremy Lainé wrote: > > > as far as i see there was no security reason to remove this package. > > > > The only other reason i could see is t

Bug#503616: missing symbol sqrt

2008-11-02 Thread Dave Benjamin
On Sun, 2 Nov 2008, Stéphane Glondu wrote: Did you upgrade completely your system? Your system should be fully up-to-date, at least w.r.t. testing. No, I'll do a dist-upgrade now. It'll take me a little bit of time because I'm low on hard drive space and probably about six months behind on th

Bug#503616: missing symbol sqrt

2008-11-02 Thread Julien Cristau
On Sun, Nov 2, 2008 at 23:38:26 +0100, Stéphane Glondu wrote: > Dave Benjamin wrote: > >> Maybe your system is not up-to-date w.r.t other (non-OCaml-related) > >> packages? Or there is some bad interaction with another Apache module? > > > > I upgraded all of my Apache 2 packages to the latest v

Bug#504347: Info: line 4: Unsupported features in require line

2008-11-02 Thread Drew Calcott
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Package: dovecot-common Version: 1.0.rc15-2etch4 Severity: serious Also in - 1.0.rc17-1ubuntu2.1 - and, according to all reports, all versions of dovecot 1.0. This is happening when a sieve server attempts to pass require: regex, as per reported here:

Bug#504323: openoffice.org-core: Segmentation fault at startup

2008-11-02 Thread Florian Goujeon
Rene Engelhard a écrit : please keep the bug in the Cc otherwise stuff won't be recorded. Cc'ing the bug now and fullquoting for it. Sorry, I clicked the wrong button :-/ And a full dist-upgrade? Maybe it worked just by chance for you in sid? Still crashing… I must have run OOo for the l

Processed: domxml-php4-php5 is not DFSG-free

2008-11-02 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > found 496071 0.68.2-1 Bug#496071: glpi: includes a copy of domxml-php4-php5 library without a mention in copyright file Bug marked as found in version 0.68.2-1. > found 496069 1.6.3-2 Bug#496069: moodle: includes a copy of domxml-php4-php5 library wit

Bug#504323: openoffice.org-core: Segmentation fault at startup

2008-11-02 Thread Rene Engelhard
Hi, Florian Goujeon wrote: > Rene Engelhard a écrit : >> please keep the bug in the Cc otherwise stuff won't be recorded. Cc'ing the >> bug now and >> fullquoting for it. >> > Sorry, I clicked the wrong button :-/ > > >> And a full dist-upgrade? Maybe it worked just by chance for you in sid? >

Processed: cloning 503616, reassign -1 to ocaml ...

2008-11-02 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > # Automatically generated email from bts, devscripts version 2.10.35 > clone 503616 -1 Bug#503616: libapache2-mod-ocamlnet: mod_netcgi_apache.so will not load Bug 503616 cloned as bug 504348. > reassign -1 ocaml Bug#504348: libapache2-mod-ocamlnet: mod

Processed: reopening 504348

2008-11-02 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > # Automatically generated email from bts, devscripts version 2.10.35 > reopen 504348 Bug#504348: libcamlrun_shared: should be linked with -lm, -ldl, etc. Bug reopened, originator not changed. > End of message, stopping processing here. Please contact

Bug#504348: libcamlrun_shared: should be linked with -lm, -ldl, etc.

2008-11-02 Thread Stéphane Glondu
forwarded 504348 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504348 thanks [NOTE: bug cloned, reopened and reassigned to ocaml] Julien Cristau wrote: > Why do we care? The proper fix is easy enough, just add -lm to the > linker command line (libcamlrun_shared.so seems to also reference > sy

Processed: libcamlrun_shared: should be linked with -lm, -ldl, etc.

2008-11-02 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > forwarded 504348 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504348 Bug#504348: libcamlrun_shared: should be linked with -lm, -ldl, etc. Noted your statement that Bug has been forwarded to http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504348.

Processed: bug 504348 is forwarded to http://caml.inria.fr/mantis/view.php?id=4636

2008-11-02 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > # Automatically generated email from bts, devscripts version 2.10.35 > forwarded 504348 http://caml.inria.fr/mantis/view.php?id=4636 Bug#504348: libcamlrun_shared: should be linked with -lm, -ldl, etc. Forwarded-to-address changed from http://bugs.debi

Bug#504352: eog: Python scripts load modules from current directory

2008-11-02 Thread James Vega
Package: eog Version: 2.22.3-1 Severity: grave Tags: security patch Justification: user security hole Usertags: pythonpath eog's python interface calls PySys_SetArgv with an argv[0] that doesn't resolve to a filename. This causes Python to prepend sys.path with an empty string which, due to the u

Bug#503616: missing symbol sqrt

2008-11-02 Thread Dave Benjamin
On Sun, 2 Nov 2008, Stéphane Glondu wrote: Did you upgrade completely your system? Your system should be fully up-to-date, at least w.r.t. testing. After upgrading all the packages starting with "lib", my Apache 2 finally starts! I don't know which particular library it was - there were 529 o

  1   2   >