Bug#496411: marked as done (The possibility of attack with the help of symlinks in some Debian packages)

2008-11-06 Thread Debian Bug Tracking System
Your message dated Thu, 06 Nov 2008 09:33:54 +0100 with message-id <[EMAIL PROTECTED]> and subject line Closing has caused the Debian Bug report #496411, regarding The possibility of attack with the help of symlinks in some Debian packages to be marked as done. This means that you claim that the

Bug#504000: chrony: init script hangs for a while might break

2008-11-06 Thread Michael Meskes
> With just “aptitude install chrony”, the “starting” step took a very long > while, several minutes before doing anything. People might (quite rightfully) > consider it hung, and interrupt the package installation/upgrade, which then > leaves the package management system in a bad state. > > That

Bug#504352: marked as done (eog: Python scripts load modules from current directory)

2008-11-06 Thread Debian Bug Tracking System
Your message dated Thu, 06 Nov 2008 09:17:14 + with message-id <[EMAIL PROTECTED]> and subject line Bug#504352: fixed in eog 2.22.3-2 has caused the Debian Bug report #504352, regarding eog: Python scripts load modules from current directory to be marked as done. This means that you claim tha

Bug#504467: Update

2008-11-06 Thread David Baron
Actually, start-stop-daemon WILL start boinc just fine. The pid file contains a different pid than that yielded by pidof boinc. This does not sit well with the distribution boinc_client init.d script. Workaround: either explicitely set the pidfile content to pidof boinc or change the isrunning f

Bug#504696: ndiswrapper-source: longs ESSIDs can expose security vulnerability

2008-11-06 Thread Kel Modderman
Package: ndiswrapper-source Version: 1.53-1 Severity: grave Tags: security patch Justification: user security hole >From [0]: Anders Kaseorg discovered that ndiswrapper did not correctly handle long ESSIDs. For a system using ndiswrapper, a physically near-by attacker could generate specially craf

Bug#504323:

2008-11-06 Thread Tim Richardson
What happens if you create a new user, log in as the new user, and try starting OOo? -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Bug#504696: ndiswrapper-source: longs ESSIDs can expose security vulnerability

2008-11-06 Thread Kel Modderman
Attached is debdiff, have uploaded a package to mentors.debian.net: http://mentors.debian.net/debian/pool/main/n/ndiswrapper/ndiswrapper_1.53-2.dsc --- diff -u ndiswrapper-1.53/debian/changelog ndiswrapper-1.53/debian/changelog --- ndiswrapper-1.53/debian/changelog +++ ndiswrapper-1.53/debian/chang

Bug#504000: chrony: init script hangs for a while might break

2008-11-06 Thread Cyril Brulebois
Helmut Grohne <[EMAIL PROTECTED]> (06/11/2008): > Did you notice that the bug was reported on i386 initially? So it is > even a bit cross-architecture. Sure, but I wasn't going to emphasize something that I didn't experience personally. ;) Mraw, KiBi. signature.asc Description: Digital signatur

Bug#504703: ERROR: Command "/sbin/iptables -A smurfs -s tcpflags -j DROP" Failed

2008-11-06 Thread xcomm
Package: shorewall-common Version: 4.0.14-3 Severity: grave Justification: renders package unusable shorewall start Compiling... Initializing... Determining Zones... IPv4 Zones: net Firewall Zone: fw Validating interfaces file... Validating hosts file... Pre-processing Actions... Pre-proc

Processed: neko: Did not remove conffiles when purged

2008-11-06 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > reassign 504627 libapache2-mod-neko Bug#504627: neko: Did not remove conffiles when purged Bug reassigned from package `neko' to `libapache2-mod-neko'. > thanks Stopping processing here. Please contact me if you need assistance. Debian bug tracking s

Bug#504627: neko: Did not remove conffiles when purged

2008-11-06 Thread Evgeni Golov
reassign 504627 libapache2-mod-neko thanks Hi Sam, *, I can't reproduce this on my Sid box. I installed neko and libapache2-mod-neko, it correctly created /etc/apache2/mods-available/neko.{conf,load} and apt-get remove --purge correctly removed this two. At no point, I had a /etc/apache/conf.d/mo

Bug#504656: xserver-xorg-input-synaptics: Stops working after logoff

2008-11-06 Thread Julien Cristau
On Wed, Nov 5, 2008 at 01:53:07 +0300, Max Dmitrichenko wrote: > Package: xserver-xorg-input-synaptics > Version: 0.14.7~git20070706-4~dmitrmax.1 > Severity: grave > Tags: patch > Justification: renders package unusable > Actually, it works just fine here, so that justification seems wrong. You

Bug#504000: chrony: init script hangs for a while might break

2008-11-06 Thread John Hasler
Cyril writes: > All of the boxes in my company are. Too bad I can't test on more > systems. That's quite different from “a single system”. And it's not like > amd64 is an obscure architecture, last time I checked. It works fine on amd64 here as well as on two different i386 boxes. It has to do wi

Bug#504000: chrony: init script hangs for a while might break

2008-11-06 Thread John Hasler
Michael writes: > I beg to disagree because this bug seems to hit only some systems but not all. > Of course I agree that this is bad if your system is hit, but with a lot of > systm not being hit I do not consider this release critical. > Aynway, the best solution is to fix this, if it is fixabl

Bug#504659: tasksel: Gnome pushes File and DNS server and language tasks off CD1

2008-11-06 Thread Josselin Mouette
Le jeudi 06 novembre 2008 à 00:01 +0100, Frans Pop a écrit : > It looks like the main reason for this is the recent changes in the > gnome-desktop task, which changed its "key" package to 'gnome' from > 'gnome-desktop-environment'. You’re raising quite a while after we discussed it. I wonder why

Bug#504000: Works for me

2008-11-06 Thread Helmut Grohne
> It does. This may be related to a known upstream problem with some > motherboards. Please try commenting out the rtcfile directive in > /etc/chrony/chrony.conf. After commenting out rtcfile upgrading the package again works, so that might at least be a work around. Still I think that this regr

Bug#504656: xserver-xorg-input-synaptics: Stops working after logoff

2008-11-06 Thread Max Dmitrichenko
2008/11/6, Julien Cristau <[EMAIL PROTECTED]>: > Actually, it works just fine here, so that justification seems wrong. > You didn't send your config or log, though, so it's hard to tell. Indeed. It works. This behavior seems to be linked with similar evdev bug because now with new evdev driver syn

Bug#504000: chrony: init script hangs for a while might break

2008-11-06 Thread Cyril Brulebois
Michael Meskes <[EMAIL PROTECTED]> (06/11/2008): > I beg to disagree because this bug seems to hit only some systems but > not all. I didn't upgrade to grave, only to serious. > Of course I agree that this is bad if your system is hit, but with a > lot of system not being hit I do not consider th

Bug#504000: chrony: init script hangs for a while might break

2008-11-06 Thread Helmut Grohne
> All of the boxes in my company are. Too bad I can't test on more > systems. That's quite different from ???a single system???. And it's not > like amd64 is an obscure architecture, last time I checked. Did you notice that the bug was reported on i386 initially? So it is even a bit cross-architec

Processed: #504181 - found in 0.7.17...

2008-11-06 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > package apt Ignoring bugs not assigned to: apt > found 504181 0.7.17 Bug#504181: apt_0.7.17~exp4 (ia64/experimental): FTBFS: doc/apt-cache.8: No such file or directory Bug marked as found in version 0.7.17. > thanks Stopping processing here. Please

Bug#504000: Works for me

2008-11-06 Thread Helmut Grohne
> I had problems with /dev/rtc before, sometimes related to HPET which in > combination with chrony even froze my system. This kernel bug has been fixed > recently. Also I had problems when using the wrong module. Are you sure you > use > the right one? Does hwclock work for you? I don't really k

Bug#504700: does not rotate logfile /var/log/mailman/mischief

2008-11-06 Thread Helmut Grohne
Package: mailman Version: 1:2.1.9-7 Severity: serious Justification: Policy 10.8 The stable (etch) version of mailman does not rotate the logfile /var/log/mailman/mischief. It is used to record login failures and similar things from the cgi scripts mailman provides. As the log file is not rotated

Bug#504714: uptimed: Filesystem full leads to records loss

2008-11-06 Thread Sylvain Veyri?
Package: uptimed Version: 1:0.3.12-2 Severity: grave Justification: causes non-serious data loss (Hello Thibaud, comment ça va depuis le temps ?) When the /var filsystem is full, uptimed, starting or stopping, makes the /var/spool/uptimed/records file become empty. For stop-daemon, I think it s

Bug#504696: marked as done (ndiswrapper-source: longs ESSIDs can expose security vulnerability)

2008-11-06 Thread Debian Bug Tracking System
Your message dated Thu, 06 Nov 2008 14:17:05 + with message-id <[EMAIL PROTECTED]> and subject line Bug#504696: fixed in ndiswrapper 1.53-2 has caused the Debian Bug report #504696, regarding ndiswrapper-source: longs ESSIDs can expose security vulnerability to be marked as done. This means t

Processed: Re: Bug#504714: uptimed: Filesystem full leads to records loss

2008-11-06 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > severity 504714 important Bug#504714: uptimed: Filesystem full leads to records loss Severity set to `important' from `grave' > tags 504714 confirmed Bug#504714: uptimed: Filesystem full leads to records loss There were no tags set. Tags added: confirm

Bug#504714: uptimed: Filesystem full leads to records loss

2008-11-06 Thread Thibaut VARENE
severity 504714 important tags 504714 confirmed thanks On Thu, Nov 6, 2008 at 3:31 PM, Sylvain Veyri? <[EMAIL PROTECTED]> wrote: > (Hello Thibaud, comment ça va depuis le temps ?) Ca va > When the /var filsystem is full, uptimed, starting or stopping, makes > the /var/spool/uptimed/records file

Bug#504200: recite: stack trace points to 1950 dB sound

2008-11-06 Thread Steve Cotton
I can replicate this with a rebuilt, debugging version of the program (and also with the official package). Program received signal SIGSEGV, Segmentation fault. 0x00407458 in DBtoLIN (dB=1950) at klatt/parwave.c:584 584 lgtemp = amptable[dB] * .001; (gdb) bt #0 0x00407

Bug#504181: #504181 - found in 0.7.17...

2008-11-06 Thread Eugene V. Lyubimkin
Strange bug... Michael Vogt will re-upload soon. -- Eugene V. Lyubimkin aka JackYF signature.asc Description: PGP signature signature.asc Description: OpenPGP digital signature

Bug#504359: csound: Python scripts load modules from current directory

2008-11-06 Thread Felipe Sateler
reassign 504359 python-csoundac tags 504359 pending El 02/11/08 22:50 James Vega escribió: > Package: csound > Version: 1:5.08.2~dfsg-1 > Severity: grave > Tags: security patch > Justification: user security hole > Usertags: pythonpath > > csound's python interface calls PySys_SetArgv with an argv

Processed (with 5 errors): Re: Bug#504359: csound: Python scripts load modules from current directory

2008-11-06 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > reassign 504359 python-csoundac Bug#504359: csound: Python scripts load modules from current directory Bug reassigned from package `csound' to `python-csoundac'. > tags 504359 pending Bug#504359: csound: Python scripts load modules from current directo

Bug#504719: ecryptfs-utils: FTBFS: error: no suitable Python interpreter found

2008-11-06 Thread Kurt Roeckx
Package: ecryptfs-utils Version: 64-1 Severity: serious Hi, Your package is failing to build with the following error: checking for a Python interpreter with version >= 2.5... none configure: error: no suitable Python interpreter found make: *** [config.status] Error 1 dpkg-buildpackage: failure:

Bug#504722: libcairo2: incompatibilities with libpangocairo

2008-11-06 Thread Eric Valette
Package: libcairo2 Version: 1.8.2-2 Severity: critical Justification: breaks the whole system After today's upgrade to libcairo2, libpango breaks with unresolved symbols: /usr/lib/icedove/icedove-bin: symbol lookup error: /usr/lib/libpangocairo-1.0.so.0: undefined symbol: cairo_has_show_text_gly

Bug#504725: gfontview should depend on libgif4, not on the transitional package libungif4g

2008-11-06 Thread Vincent Lefevre
Package: gfontview Version: 0.5.0-9+b1 Severity: serious Justification: Policy 7.2 gfontview has "libungif4g (>= 4.1.4)" in its dependencies. However libungif4g is a transitional package that provides nothing. According to ldd, gfontview uses /usr/lib/libungif.so.4, so that it needs to depend on

Bug#504726: insecure /tmp dir

2008-11-06 Thread Thomas Viehmann
X-Debbugs-CC: [EMAIL PROTECTED], [EMAIL PROTECTED], [EMAIL PROTECTED] Package: universalindentgui Severity: serious Version: 0.8.1-1 Hi, as discussed for other packages and on debian-devel at great lengths, using fixed dirs in /tmp is not a good idea. Please be sure to fix this when you take care

Processed: found 504359 in 1:5.08.0.dfsg2-8, found 504359 in 1:5.08.2~dfsg-1

2008-11-06 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > found 504359 1:5.08.0.dfsg2-8 Bug#504359: csound: Python scripts load modules from current directory Bug marked as found in version 1:5.08.0.dfsg2-8. > found 504359 1:5.08.2~dfsg-1 Bug#504359: csound: Python scripts load modules from current directory

Bug#504728: [slapd] Modification of cn=config prevents to bind at next directory restart

2008-11-06 Thread Maykel Moya
Package: slapd Version: 2.4.11-1 Severity: grave Tags: patch If you modify cn=config and restart you won't be able to bind to the DSA. You will see an error like: PROXIED attributeDescription "DC" inserted. Please see upstream bug 5795[1] and 5783[2]. A fix is available here[3]. Regards,

Bug#504719: marked as done (ecryptfs-utils: FTBFS: error: no suitable Python interpreter found)

2008-11-06 Thread Debian Bug Tracking System
Your message dated Thu, 06 Nov 2008 17:02:03 + with message-id <[EMAIL PROTECTED]> and subject line Bug#504719: fixed in ecryptfs-utils 64-2 has caused the Debian Bug report #504719, regarding ecryptfs-utils: FTBFS: error: no suitable Python interpreter found to be marked as done. This means

Bug#503859: ExtensionClass completely broken with python 2.5

2008-11-06 Thread Chris Lamb
Thomas Viehmann wrote: > python -c 'import ExtensionClass ; print ExtensionClass.ExtensionClass' > Segmentation fault [..] > The overall options seem to be > a) (have someone else or learn how python extensions work and) fix >ExtensionClass to pass minimal tests with python2.5, I was working

Bug#504731: texlive-fonts-extra: cirth is nosell/nonfree

2008-11-06 Thread Norbert Preining
Package: texlive-fonts-extra Version: 2007.dfsg.8-1 Severity: serious Justification: nosell license from cirth.mf: % Copyright 1992 Jo Grant [EMAIL PROTECTED] % c/o 44 Bancroft Avenue, Tallaght, Dublin 24, Ireland. % Everyone is granted permission to copy, and redistribute % this file, provided t

Bug#489610: 489610/496244 sear: Sear-Media requires update for Sear > 0.6.1

2008-11-06 Thread Michael Hafen
In reply to Steve Cotton, I created a symbolic link in /usr/share/sear from sear-media-0.6 to sear-media-0.7 That gave me the splash image, or background, as shown on the web page you linked. I tried a couple other things before this, and they didn't have any apparent effect. I tried setting th

Bug#503589: Wireshark CVE patches

2008-11-06 Thread Joost Yervante Damad
On Wednesday 05 November 2008 22:24:38 Mark Purcell wrote: > On Monday 03 November 2008 04:44:42 Stefan Lesicnik wrote: > > I have uploaded 3 debdiffs for the CVE's for Ubuntu - these are > > currently awaiting review > > Stefan, > > Thanks for your work on this. > > Frederic, Joost, > > Are you in

Bug#500336: patch for grub detection

2008-11-06 Thread Raphael Hertzog
On Fri, 31 Oct 2008, Ian Campbell wrote: > > Please find the patch attached. It works here at least. > > I'm happy with it too since it works in domU (no change). Several days passed and I saw no reaction from the maintainers. Robert, can you apply the patch and upload a fixed package to get rid

Bug#504740: FTBFS: ep93xx.c:221: error: incompatible type for argument 1 of 'nanosleep'

2008-11-06 Thread Riku Voipio
Package: openocd Severity: serious Version: 0.0+r1130-1 The armel build now fails with: > cd . && CC="cc" CXX="g++" CFLAGS="-g -O2 -g -Wall -O2" CXXFLAGS="-g -O2 -g > -Wall -O2" CPPFLAGS="" LDFLAGS="" /build/buildd/openocd-0.0+r1130/./configure > --build=arm-linux-gnueabi --prefix=/usr --includ

Processed: found 504181 in 0.7.17

2008-11-06 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > # Automatically generated email from bts, devscripts version 2.10.35 > found 504181 0.7.17 Bug#504181: apt_0.7.17~exp4 (ia64/experimental): FTBFS: doc/apt-cache.8: No such file or directory Bug marked as found in version 0.7.17. > End of message, stop

Bug#504604: bug, same but the conditions are different.

2008-11-06 Thread Leonardo Boselli
Yes, it ist bug https://bugs.launchpad.net/openoffice/+bug/210153 but you miss one row in my line: To simplify this, I think you are saying that in v2.4, you see that a formula like this =if(A1-B1<>0;1;C1) returns an error 529 when C1 contains "" and A1 and B1 are empty no, it is ok, but when C1

Bug#504682: patch

2008-11-06 Thread marcos.marado
A patch that fixes this, by making dokuwiki depend of php-geshi. http://talkerspt.no-ip.org/~mbooster/dokuwiki-geshi-fix.patch Best regards, -- Marcos Marado -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Bug#504681: patch

2008-11-06 Thread marcos.marado
Hi there, Here's a patch that fixes this by using php-geshi: http://talkerspt.no-ip.org/~mbooster/pgfouine-geshi-fix.patch Best regards, -- Marcos Marado -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Bug#500336: patch for grub detection

2008-11-06 Thread Robert Millan
On Thu, Nov 06, 2008 at 07:45:09PM +0100, Raphael Hertzog wrote: > On Fri, 31 Oct 2008, Ian Campbell wrote: > > > Please find the patch attached. It works here at least. > > > > I'm happy with it too since it works in domU (no change). > > Several days passed and I saw no reaction from the mainta

Bug#504747: gnu-fdisk: wipes out MBR when used on GPT partitions

2008-11-06 Thread Michael Renner
Package: gnu-fdisk Version: 1.0-3+b1 Severity: grave Justification: causes non-serious data loss gnu-fdisk wipes out the Code Area in the MBR of a given device when modifying a GPT partition. If this happens to be the boot device, this can cause serious trouble. The behaviour can be easily veri

Processed (with 1 errors): Apt FTBFS with dpkg-buildpackage -B (was apt_0.7.17~exp4 (ia64/experimental): FTBFS: doc/apt-cache.8: No such file or directory)

2008-11-06 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > retititle 504181 apt FTBFS with dpkg-buildpackage -B Unknown command or malformed arguments to command. > tags 504181 +patch Bug#504181: apt_0.7.17~exp4 (ia64/experimental): FTBFS: doc/apt-cache.8: No such file or directory There were no tags set. Tag

Bug#504181: Apt FTBFS with dpkg-buildpackage -B (was apt_0.7.17~exp4 (ia64/experimental): FTBFS: doc/apt-cache.8: No such file or directory)

2008-11-06 Thread peter green
retititle 504181 apt FTBFS with dpkg-buildpackage -B tags 504181 +patch thanks In my amd64 chroot that the package builds with a straight dpkg-buildpackage but fails with dpkg-buildpackage -B . Since the buildds always use -B this would explain it building for the maintainers but not on any of

Bug#504200: How about espeak ?

2008-11-06 Thread Marco Rodrigues
Hi! Maybe this package should be removed from Debian and people can use a better one.. like espeak. At Paul Miller's Homepage, I don't see anything about "recite", so it should be dead upstream. -- Marco Rodrigues http://Marco.Tondela.org -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with

Bug#503775: glassfish: java bytecode / java runtime version mismatch

2008-11-06 Thread Torsten Werner
Hi, On Tue, Oct 28, 2008 at 9:26 AM, Matthias Klose <[EMAIL PROTECTED]> wrote: > Package: glassfish > Version: 1:2ur2-b04-1 > Severity: serious > User: [EMAIL PROTECTED] > Usertags: jbc-mismatch > > This package builds with openjdk-6 or cacao-oj6, which is not the > default jvm in testing/unstable

Processed: tagging 503775

2008-11-06 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > # Automatically generated email from bts, devscripts version 2.10.35 > tags 503775 + moreinfo Bug#503775: glassfish: java bytecode / java runtime version mismatch There were no tags set. Tags added: moreinfo > End of message, stopping processing here.

Bug#503702: lockvc: Segfaults.

2008-11-06 Thread Kurt Roeckx
On Sat, Nov 01, 2008 at 06:29:10PM +0200, Guillem Jover wrote: > Hi, > > On Wed, 2008-10-29 at 21:25:50 +0100, Moritz Muehlenhoff wrote: > > Kurt Roeckx wrote: > > > Package: lockvc > > > Version: 4.0.5-6 > > > Severity: serious > > > > It seems that lockvc sometimes segfaults on me. It's not do

Bug#503795: marked as done (libjdic-java: java bytecode / java runtime version mismatch)

2008-11-06 Thread Debian Bug Tracking System
Your message dated Thu, 6 Nov 2008 22:12:39 +0100 with message-id <[EMAIL PROTECTED]> and subject line Re: Bug#503795: libjdic-java: java bytecode / java runtime version mismatch has caused the Debian Bug report #503795, regarding libjdic-java: java bytecode / java runtime version mismatch to be

Bug#504181: Apt FTBFS with dpkg-buildpackage -B (was apt_0.7.17~exp4 (ia64/experimental): FTBFS: doc/apt-cache.8: No such file or directory)

2008-11-06 Thread Eugene V. Lyubimkin
peter green wrote: > In my amd64 chroot that the package builds with a straight > dpkg-buildpackage but fails with dpkg-buildpackage -B . Since the > buildds always use -B this would explain it building for the maintainers > but not on any of the buildds. > > It appears the man pages in question a

Bug#504758: gforge-plugins-extra ships security issues-prone code copies

2008-11-06 Thread Raphael Geissert
Package: gforge-plugins-extra Severity: serious Version: 4.7~rc2-5 Tags: security Hi, By taking a look at the list of files shipped by gforge-plugins-extra I can easily see several scripts which are already in the Debian archive. I'm using 'serious' as the severity given the fact that in many o

Bug#504279: Wodering..

2008-11-06 Thread Moritz Muehlenhoff
On Wed, Nov 05, 2008 at 12:07:04PM +0100, Romain Beauxis wrote: > Hi ! > > After some discussion with upstream, it appears that the issue cannot be > fixed > for the version currently in testing. > > I'm now with two alternatives: > * Ask for a removal of the package > * Excplicitely ma

Bug#504200: marked as done (segmentation violation when running recite)

2008-11-06 Thread Debian Bug Tracking System
Your message dated Thu, 06 Nov 2008 21:32:08 + with message-id <[EMAIL PROTECTED]> and subject line Bug#504200: fixed in recite 1.0-8.1 has caused the Debian Bug report #504200, regarding segmentation violation when running recite to be marked as done. This means that you claim that the probl

Bug#503589: Wireshark CVE patches

2008-11-06 Thread Moritz Muehlenhoff
On Thu, Nov 06, 2008 at 07:08:00PM +0100, Joost Yervante Damad wrote: > On Wednesday 05 November 2008 22:24:38 Mark Purcell wrote: > > On Monday 03 November 2008 04:44:42 Stefan Lesicnik wrote: > > > I have uploaded 3 debdiffs for the CVE's for Ubuntu - these are > > > currently awaiting review > >

Bug#504681: marked as done (SA32559: GeSHi Unspecified Code Execution Vulnerability)

2008-11-06 Thread Debian Bug Tracking System
Your message dated Thu, 06 Nov 2008 22:32:09 + with message-id <[EMAIL PROTECTED]> and subject line Bug#504681: fixed in pgfouine 1.0-1.1 has caused the Debian Bug report #504681, regarding SA32559: GeSHi Unspecified Code Execution Vulnerability to be marked as done. This means that you claim

Bug#503591: Ruby and timezones

2008-11-06 Thread Philip Ross
Hi Roberto, 2008/10/31 Roberto C. Sánchez <[EMAIL PROTECTED]>: > On Fri, Oct 31, 2008 at 07:32:13PM +, Philip Ross wrote: >> 2008/10/31 Roberto C. Sánchez <[EMAIL PROTECTED]>: >> > 3. Modify tzinfo to no longer embed the zone data and use the data from >> >/usr/share/zoneinfo instead. >>

Bug#504680: marked as done (yzis: symlink attack vulnerability)

2008-11-06 Thread Debian Bug Tracking System
Your message dated Thu, 06 Nov 2008 22:17:11 + with message-id <[EMAIL PROTECTED]> and subject line Bug#504680: fixed in yzis 1.0~alpha1-2 has caused the Debian Bug report #504680, regarding yzis: symlink attack vulnerability to be marked as done. This means that you claim that the problem ha

Bug#504681: NMU for 504681

2008-11-06 Thread Barry deFreese
Hi, Here is a debdiff of the NMU I uploaded. Thank you, Barry deFreese reverted: --- pgfouine-1.0/.pc/.version +++ pgfouine-1.0.orig/.pc/.version @@ -1 +0,0 @@ -2 diff -u pgfouine-1.0/debian/rules pgfouine-1.0/debian/rules --- pgfouine-1.0/debian/rules +++ pgfouine-1.0/debian/rules @@ -11,6 +1

Bug#504279: Wodering..

2008-11-06 Thread Romain Beauxis
Le Thursday 06 November 2008 22:25:13 Moritz Muehlenhoff, vous avez écrit : > > What do users think about these two alternatives ? > > jbidwatcher will likely break for the US ebay page at some point > in time as well once Ebay changes their website the next time. > > I'd recommend to remove it fro

Bug#503591: Ruby and timezones

2008-11-06 Thread Roberto C . Sánchez
Hi Phil, On Thu, Nov 06, 2008 at 10:48:52PM +, Philip Ross wrote: > > I've attached a patch against TZInfo 0.3.11 that makes it use zoneinfo > files instead of the built in timezone modules. By default it will try > and locate a zoneinfo directory in /usr/share, /usr/share/lib and > /etc. Thi

Bug#503591: Ruby and timezones

2008-11-06 Thread Philip Ross
Hi Roberto, 2008/11/6 Roberto C. Sánchez <[EMAIL PROTECTED]>: > On Thu, Nov 06, 2008 at 10:48:52PM +, Philip Ross wrote: >> I've tested this by comparing the output for all timezones in tzdata >> v2008i against the output of zdump (see the /utils/zdumptestall.sh >> test script in SVN). Note th

Bug#503591: [TZInfo-users] Ruby and timezones

2008-11-06 Thread Roberto C . Sánchez
On Thu, Nov 06, 2008 at 11:26:10PM +, Philip Ross wrote: > Hi Roberto, > > 2008/11/6 Roberto C. Sánchez <[EMAIL PROTECTED]>: > > On Thu, Nov 06, 2008 at 10:48:52PM +, Philip Ross wrote: > >> I've tested this by comparing the output for all timezones in tzdata > >> v2008i against the output

Bug#504703: ERROR: Command "/sbin/iptables -A smurfs -s tcpflags -j DROP" Failed

2008-11-06 Thread Roberto C . Sánchez
severity 504703 minor thanks On Thu, Nov 06, 2008 at 12:42:59PM +0100, xcomm wrote: > Creating Interface Chains... > Setting up SMURF control... > iptables v1.4.1.1: host/network `tcpflags' not found > Try `iptables -h' or 'iptables --help' for more information. >ERROR: Command "/sbin/iptables

Processed: severity of 504703 is minor

2008-11-06 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > # Automatically generated email from bts, devscripts version 2.10.25~bpo40+1 > severity 504703 minor Bug#504703: ERROR: Command "/sbin/iptables -A smurfs -s tcpflags -j DROP" Failed Severity set to `minor' from `grave' > End of message, stopping proces

Processed (with 1 errors): stopping bug appearing on turmzimmer

2008-11-06 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > #marking as fixed in the version in testing since this was closed as a > false positive using the version number from unstable Unknown command or malformed arguments to command. > #which makes turmzimmer wrongly think it is a current bug in testing > c

Bug#504767: Character set conversion bug that can cause files to be truncated; patch available

2008-11-06 Thread Jason Spiro
X-Debbugs-Cc: [EMAIL PROTECTED] Package: medit Version: 0.9.2-1+b2 Tags: patch Severity: critical Justification: data loss bug in a text editor Hello, and thanks for maintaining medit. [1] says a new version of medit has been released (0.9.4) which fixes some critical data-loss bugs found by lone

Bug#504767: Character set conversion bug that can cause files to be truncated; patch available

2008-11-06 Thread Jason Spiro
By the way: I asked Yevgen if this bug affects medit 0.8.2. Yevgen replied "I think yes". -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Bug#504771: wordpress can be subject of delayed attacks via cookies

2008-11-06 Thread Raphael Geissert
Package: wordpress Version: 2.0.7-1 Severity: grave Tags: security Hi, Due to the completely incorrect usage of $_REQUEST almost all over the place wordpress is subject to delayed attacks via cookies. The attack can be performed as long as there is some way to inject a cookie which is sent by

Bug#432264: marked as done (XSS vulnerability)

2008-11-06 Thread Debian Bug Tracking System
Your message dated Fri, 07 Nov 2008 03:02:12 + with message-id <[EMAIL PROTECTED]> and subject line Bug#432264: fixed in moodle 1.8.2-2 has caused the Debian Bug report #432264, regarding XSS vulnerability to be marked as done. This means that you claim that the problem has been dealt with. I

Bug#489533: marked as done (moodle: CVE-2008-1502 _bad_protocol_once function allows XSS and possibly code execution)

2008-11-06 Thread Debian Bug Tracking System
Your message dated Fri, 07 Nov 2008 03:02:12 + with message-id <[EMAIL PROTECTED]> and subject line Bug#489533: fixed in moodle 1.8.2-2 has caused the Debian Bug report #489533, regarding moodle: CVE-2008-1502 _bad_protocol_once function allows XSS and possibly code execution to be marked as

Bug#471158: marked as done (ships embedded copy of smarty with security bug)

2008-11-06 Thread Debian Bug Tracking System
Your message dated Fri, 07 Nov 2008 03:02:12 + with message-id <[EMAIL PROTECTED]> and subject line Bug#471158: fixed in moodle 1.8.2-2 has caused the Debian Bug report #471158, regarding ships embedded copy of smarty with security bug to be marked as done. This means that you claim that the

Bug#504235: marked as done (CVE-2008-4796: missing input sanitising in embedded copy of Snoopy.class.php)

2008-11-06 Thread Debian Bug Tracking System
Your message dated Fri, 07 Nov 2008 03:02:12 + with message-id <[EMAIL PROTECTED]> and subject line Bug#504235: fixed in moodle 1.8.2-2 has caused the Debian Bug report #504235, regarding CVE-2008-4796: missing input sanitising in embedded copy of Snoopy.class.php to be marked as done. This

Bug#429339: marked as done (Needs to use libphp-phpmailer)

2008-11-06 Thread Debian Bug Tracking System
Your message dated Fri, 07 Nov 2008 03:02:12 + with message-id <[EMAIL PROTECTED]> and subject line Bug#429339: fixed in moodle 1.8.2-2 has caused the Debian Bug report #429339, regarding Needs to use libphp-phpmailer to be marked as done. This means that you claim that the problem has been d

Bug#496069: marked as done (moodle: domxml-php4-php5.php is not DFSG-free)

2008-11-06 Thread Debian Bug Tracking System
Your message dated Fri, 07 Nov 2008 03:02:12 + with message-id <[EMAIL PROTECTED]> and subject line Bug#496069: fixed in moodle 1.8.2-2 has caused the Debian Bug report #496069, regarding moodle: domxml-php4-php5.php is not DFSG-free to be marked as done. This means that you claim that the pr

Bug#504604:

2008-11-06 Thread Tim Richardson
In the launchpad bug report (the link above) there is a discussion about why OOo now behaves like this. I understood from this discussion that upstream deliberate made this change for improved Excel compatibility. I'm an experienced Excel user, and I certainly expect Excel to behave the way OOo now

Bug#504783: libtasn1-3_1.5-2(hppa/experimental): FTBFS: test failures

2008-11-06 Thread Frank Lichtenheld
Package: libtasn1-3 Version: 1.5-2 Severity: serious Hi, your package failed to build from source. The problem seems to be pretty architecture specific, as all other builds succeeded so far. | Automatic build of libtasn1-3_1.5-2 on meitner by sbuild/hppa 98-farm | Build started at 20081107-0132