Re: Bug#559802: CVE-2009-3736 local privilege escalation

2009-12-08 Thread Steffen Joeris
On Tue, 8 Dec 2009 04:23:41 pm Michael Gilbert wrote: > On Tue, 8 Dec 2009 03:13:06 +1100, Steffen Joeris wrote: > > > > > The following CVE (Common Vulnerabilities & Exposures) id was > > > > > published for libtool. I have determined that this package embe

Re: Bug#559802: CVE-2009-3736 local privilege escalation

2009-12-07 Thread Steffen Joeris
Hi > > > The following CVE (Common Vulnerabilities & Exposures) id was > > > published for libtool. I have determined that this package embeds a > > > vulnerable copy of the libtool source code. However, since this is a > > > mass bug filing (due to so many packages embedding libtool), I have n

Re: Bits from the FTPMaster meeting

2009-11-15 Thread Steffen Joeris
On Mon, 16 Nov 2009 02:04:28 pm Carlo Segre wrote: > On Sun, 15 Nov 2009, Joerg Jaspert wrote: > > The current "winning" opinion is to go with the source+throw away > > binaries route. We are close to being able to achieve this, it is > > simply that it has not yet been enabled. Before any versio

Re: packages that use deprecated SQL escape functions

2009-10-14 Thread Steffen Joeris
Hi Charles On Thu, 15 Oct 2009 01:50:35 pm Charles Plessy wrote: > Le Thu, Oct 15, 2009 at 01:26:14PM +1100, Steffen Joeris a écrit : > > In the near future, I will try to do the archive scan again and file bugs > > with severity "normal" for the packages below that are

packages that use deprecated SQL escape functions

2009-10-14 Thread Steffen Joeris
Hi everyone We had a few issues in the past with insufficient database escaping, which lead to possible SQL injections due to the use of the deprecated functions mysql_escape_string() and PQescapeString(). These functions do not take the encoding of the established connection into account, whic

Re: Bits from the release team: Release goals, schedule, state of the union

2009-08-26 Thread Steffen Joeris
On Wed, 26 Aug 2009 04:58:24 pm Andreas Barth wrote: > * Steffen Joeris (steffen.joe...@skolelinux.de) [090826 08:53]: > > For kernel-security support, we have Dann Frazier in the security team, > > who is also working in the kernel team (and of course other kernel team > >

Re: Bits from the release team: Release goals, schedule, state of the union

2009-08-25 Thread Steffen Joeris
Hi Marc On Wed, 26 Aug 2009 04:23:09 pm Marc 'HE' Brockschmidt wrote: > Steffen Joeris writes: > > On Wed, 26 Aug 2009 06:51:48 am Marc 'HE' Brockschmidt wrote: > >> Release Goals > >> = > > [...] > > >> - kFreeBS

Re: Bits from the release team: Release goals, schedule, state of the union

2009-08-25 Thread Steffen Joeris
On Wed, 26 Aug 2009 06:51:48 am Marc 'HE' Brockschmidt wrote: > Heya, > > This mail should be the first in a row of roughly monthly mails > informing the project about the state of the release. Please don't > hesitate to contact us on debian-rele...@lists.debian.org whenever > you have questions. >

Re: webapps in stable release cyles Was: flashplugin-nonfree in Debian

2009-04-22 Thread Steffen Joeris
Hi Romain (and others) On Thu, 23 Apr 2009 09:23:24 am Romain Beauxis wrote: > Le Wednesday 22 April 2009 18:52:48 Raphael Geissert, vous avez écrit : > > > I gave this example precisely because mediawiki upstream release > > > management is one of the most serious I know in webapps. And even > >

Re: Bug#522996: ITP: jruby1.2 -- 100% pure-Java implementation of Ruby

2009-04-08 Thread Steffen Joeris
On Wed, 8 Apr 2009 05:10:12 pm Romain Beauxis wrote: > Le Tuesday 07 April 2009 22:59:00 Sebastien Delafond, vous avez écrit : > > On Apr/07, Mike Hommey wrote: > > > While I see why it can be needed for python, I fail to see how it is > > > important for jruby... > > > > to have 2 versions of jrub

Re: New Security Team Members

2009-03-12 Thread Steffen Joeris
Hi Raphael > Can i ask how they started to work and develop with security? My dream is > to become an security developer/professional. All the neccessary documentation to start with is here[0]. It is most important that we keep our security tracker[1] up to date, evaluate the issues and fix the

Re: problems with the concept of unstable -> testing

2008-12-15 Thread Steffen Joeris
Hi Russell > If I upload a significantly newer version to unstable (which I would like > to do for some of my packages as part of ongoing development that will lead > to Lenny+1) then AKAIK there is no way to put a minor update in Lenny > (unless I was to use an epoch change which would be horribl

Re: [Foo2zjs-maintainer] Bug#449497: Direction on foo2zjs and web fetching scripts

2008-11-03 Thread Steffen Joeris
On Tue, 4 Nov 2008 03:40:22 pm Michael Gilbert wrote: > Dear release team, > > Thank you for making a decision on the direction for bug #449497 in > foo2zjs [1]. I believe that this is a reasonable choice for now due > to the impending release. However, I would really like to see an > honest and

Re: Bug Sprint results (draft)

2008-11-02 Thread Steffen Joeris
On Mon, 3 Nov 2008 02:39:47 am John H. Robinson, IV wrote: > Chris Bannister wrote: > > On Fri, Oct 31, 2008 at 07:48:21PM +0100, Moritz Muehlenhoff wrote: > > > Stefano Zacchiroli wrote: > > > >=2E.. hence, given that Lenny hasn't been release yet, when are we > > > > gonna make another one? :) >

Re: Bits from Testing Security team

2008-06-30 Thread Steffen Joeris
On Sat, 28 Jun 2008 08:45:54 pm Holger Levsen wrote: > Hi Testing Security team, > > thanks for the announce-mail and your work! > > On Wednesday 25 June 2008 11:08, Nico Golde wrote: > > General security support for testing > > > > [...] > > > kernel. Also, we

RFA: gpsim -- Simulator for Microchip's PIC microcontrollers

2007-12-22 Thread Steffen Joeris
Package: wnpp Severity: normal Hi My debian time is already taken by other debian things, so I am not finding enough time to maintain this package properly. If you are willing to take it over, be my guest. However, I guess it is a good idea to also adopt the documentation package (gpsim-doc), the

Re: Bits from the MIA team

2007-12-08 Thread Steffen Joeris
On Sat, 8 Dec 2007 06:39:15 pm Raphael Hertzog wrote: > On Sat, 08 Dec 2007, Nico Golde wrote: > > > To make sure packages don't end up with only inactive (co-)maintainers. > > > > That could be avoided if you check that every maintainer of > > the package is MIA. > > A MIA-check is not something i

Re: Bits from the MIA team

2007-12-08 Thread Steffen Joeris
On Sat, 8 Dec 2007 06:39:15 pm Raphael Hertzog wrote: > On Sat, 08 Dec 2007, Nico Golde wrote: > > > To make sure packages don't end up with only inactive (co-)maintainers. > > > > That could be avoided if you check that every maintainer of > > the package is MIA. > > A MIA-check is not something i

Packages looking for a new home (RFAs)

2007-10-12 Thread Steffen Joeris
Hi folks Unfortunately, I have to admit that I can not give all my packages the best care anymore. My spare time is limited and a lot is already used for other debian stuff. I will try to keep up with the other packages and see how that goes. If I find out that they are better off without me, I

Re: Bug#429872: RFH: foo2zjs

2007-06-20 Thread Steffen Joeris
On Thu, 21 Jun 2007 01:44:39 am Evgeni Golov wrote: > On Wed, 20 Jun 2007 23:11:50 +0200 Steffen Joeris wrote: > > I would like to request some help with the foo2zjs package. > > Well, I do not have such a printer, but after looking at the homepage, > I'm a bit scared. >

Bug#429873: RFH: kradio -- Comfortable Radio Application for KDE

2007-06-20 Thread Steffen Joeris
Package: wnpp Severity: normal Hi I request assistance with maintaining the kradio package. Right now I do not have a working card anymore, which makes it hard to test it properly. I would act as the maintainer or the co-maintainer. I am also happy to completely give up maintainership, if that is

Bug#429872: RFH: foo2zjs

2007-06-20 Thread Steffen Joeris
Package: wnpp Severity: normal Hi I would like to request some help with the foo2zjs package. At the moment, I do not have a printer to test the package with. Therefore, I would welcome a co-maintainer, or I would act as a co-maintainer. If somebody wants to take it over completely, he is also we

Re: Handling of (inactive) Debian Accounts

2007-02-12 Thread Steffen Joeris
Hi mate > > As far as I can see right now there are plenty of people listed > > there with no packages and they can be the targets for the first > > run. > > [EMAIL PROTECTED]:/org/qa.debian.org/mia$ ./mia-todo needs-wat > 0 maintainers in possible need of needs-wat Try it again please, the mia db

Re: Handling of (inactive) Debian Accounts

2007-02-11 Thread Steffen Joeris
Hi mates > This is the part I'm unsure about. I think, as che recently > mentioned, he has been missing for years. His packages were > properly orphaned, but the account cleanup never happened. > > I am given the impression that the primary focus of the MIA > process is taking c

Bug#406522: RFH: gpsdrive

2007-01-11 Thread Steffen Joeris
Package: wnpp Severity: normal Hi I am writing this request after some communication with the current maintainer. Frank is still working on this package, but would also appreciate a co-maintainer who can help him a bit. If you intend to become a co-maintainer of gpsdrive (be aware that it needs s

Bug#403120: marking lsb-base essential?

2006-12-14 Thread Steffen Joeris
Package: lsb-base Version: 3.1-22 Severity: wishlist Hi Yesterday I saw a package which uses the shell functions provided by lsb-base but did not have a dependency against it and I came across this topic. Currently lsb-base is required and prodivdes the init script functions which should be used

Bug#400616: ITP: marble -- geographical earth map widget

2006-11-27 Thread Steffen Joeris
Package: wnpp Severity: wishlist Owner: Steffen Joeris <[EMAIL PROTECTED]> * Package name: marble Version : 0.2 Upstream Author : Torsten Rahn <[EMAIL PROTECTED]> * URL : svn://anonsvn.kde.org/home/kde/trunk/playground/base/marble * License : LGP

Re: ITP: adun.app -- a Molecular Simulator

2006-08-30 Thread Steffen Joeris
Hi On Thursday 31 August 2006 01:58, Gürkan Sengün wrote: > Package: wnpp > Severity: wishlist > > * Package name: adun.app Maybe I miss some essential parts, but I always wonder why some people add a .app to the software name? Can you please give me a short explanation or point me to a prev

Re: Orphaned Packages

2006-08-17 Thread Steffen Joeris
Hi Klaus > So is there a way to give official packages to debian without being a > official maintainer? Sure, you can prepare the package and then give it to an official debian developer who can upload it for you and therefore act as a kind of sponsor. You are still responsible for the package a

ITP: dc-qt -- GUI frontend for the dc protocol

2006-08-10 Thread Steffen Joeris
Package: wnpp Owner: Steffen Joeris <[EMAIL PROTECTED]> Severity: wishlist * Package name: dc-qt Version : 0.2.0-alpha Upstream Author : Arsenij Vodjanov <[EMAIL PROTECTED]> * URL : http://dc-qt.sourceforge.net/wiki/index.php/Main_Page * License

Bug#372930: ITP: kolabadmin -- administration tool for kolab groupware

2006-06-12 Thread Steffen Joeris
Package: wnpp Severity: wishlist Owner: Steffen Joeris <[EMAIL PROTECTED]> * Package name: kolabadmin Version : not yet released, talking to author Upstream Author : Tobias König <[EMAIL PROTECTED]> * URL : http://wgess16.dyndns.org/~tobias/qt/kolabadmi

Re: Bug#348728: ITP: php-net-imap -- PHP PEAR module implementing IMAP protocol

2006-01-18 Thread Steffen Joeris
> You should be aware that per the current REJECT_FAQ [1] > your package will be automatically rejected because it uses the PHP > License. Several weeks ago I emailed the FTP Masters[2], requesting that > they accept the PHP Licence for all PHP Group software, backed up by > extensive debian-legal

Bug#348728: ITP: php-net-imap -- PHP PEAR module implementing IMAP protocol

2006-01-18 Thread Steffen Joeris
Package: wnpp Severity: wishlist Owner: Steffen Joeris <[EMAIL PROTECTED]> * Package name: php-net-imap Version : 1.0.3 Upstream Author : Damian Alejandro Fernandez Sosa <[EMAIL PROTECTED]> * URL : http://pear.php.net/package/Net_IMAP * License :

Bug#345715: ITP: k3dsurf -- tool for mathematical surfaces

2006-01-02 Thread Steffen Joeris
Package: wnpp Severity: wishlist Owner: Steffen Joeris <[EMAIL PROTECTED]> * Package name: k3dsurf Version : 0.5.4 Upstream Author : Abderrahman Taha ([EMAIL PROTECTED]) * URL : http://k3dsurf.sourceforge.net/ * License : GPL Description : to

Re: Package Submission

2005-12-27 Thread Steffen Joeris
On Tuesday 27 December 2005 19:38, David Seff wrote: > Hello, > > I am new to the list. Could anybody point me in the direction for > submitting a new package to Debian? Is there a documented procedure? > > Thanks. > > -Dave Seff Welcome Maybe you want to ask on [EMAIL PROTECTED] The debian-devel

Bug#342951: ITP: qliss3d -- demonstration tool for Lissajous physiques

2005-12-11 Thread Steffen Joeris
Package: wnpp Severity: wishlist Owner: Steffen Joeris <[EMAIL PROTECTED]> * Package name: qliss3d Version : 1.3.2 Upstream Author : Daniel Gruen <[EMAIL PROTECTED]> * URL : * http://www.schule-bw.de/service/foerderprog/ccteam/projekte/qliss3d_ht

Bug#341954: ITP: kradio -- Comfortable Radio Application for KDE

2005-12-04 Thread Steffen Joeris
Package: wnpp Severity: wishlist Owner: Steffen Joeris <[EMAIL PROTECTED]> * Package name: kradio Version : 0.1beta1.0snapshot20051127 Upstream Author : Ernst Martin Witte <[EMAIL PROTECTED]> * URL : http://kradio.sourceforge.net/ * License : GPL

Re: adept

2005-12-03 Thread Steffen Joeris
Sorry this mail was not for debian-devel (although here was a thread about adept), it was for enrico. Greetings Steffen pgpZdgoVxGMi8.pgp Description: PGP signature

adept

2005-12-03 Thread Steffen Joeris
Hi I am a small Debian-Edu Developer (not yet a DD ;(, but in NM ;) ). There was a RFP for adept and a friend asked me to take it. After some time I came to a problem and after some searching (also in the web) i found out that it is easier to read the mails first and then start to debianize :) T

Bug#341012: ITP: kalgebra -- calculator based on MathML language

2005-11-27 Thread Steffen Joeris
Package: wnpp Severity: wishlist Owner: Steffen Joeris <[EMAIL PROTECTED]> * Package name: kalgebra Version : 0.4 Upstream Author : Aleix Pol <[EMAIL PROTECTED]> * URL : http://kalgebra.berlios.de/ * License : GPL Description : calculator bas

Bug#338678: ITP: italc -- teaching tool

2005-11-11 Thread Steffen Joeris
Package: wnpp Severity: wishlist Owner: Steffen Joeris <[EMAIL PROTECTED]> * Package name: italc Version : 0.9.6.2 Upstream Author : Tobias Doerffel <[EMAIL PROTECTED]> * URL : http://italc.sourceforge.net/download.php * License : GPL

Bug#338530: ITP: 915resolution -- resolution modify tool for Intel 915/999/1000 graphic chipsets

2005-11-10 Thread Steffen Joeris
Package: wnpp Severity: wishlist Owner: Steffen Joeris <[EMAIL PROTECTED]> * Package name: 915resolution Version : 0.4.7 Upstream Author : Steve Tomljenovic [EMAIL PROTECTED] * URL : http://www.geocities.com/stomljen/download.html * License : under

Bug#336852: ITP: libfacile-dev -- functional constraint library implemented in objective caml

2005-11-01 Thread Steffen Joeris
Package: wnpp Severity: wishlist Owner: Steffen Joeris <[EMAIL PROTECTED]> I think the lib is needed by some kde applications. The Kalzium developer told me that this lib is needed during the build of Kalzium. * Package name: libfacile-dev Version : 1.1 Upstream

Bug#335508: ITP: qa-assistant -- checklist assistant

2005-10-24 Thread Steffen Joeris
Package: wnpp Severity: wishlist Owner: Steffen Joeris <[EMAIL PROTECTED]> * Package name: qa-assistant Version : 0.4.90.4 Upstream Author : Toshio Kuratomi <[EMAIL PROTECTED]> * URL : http://developer.berlios.de/projects/qa-assistant/ * License

Bug#335367: ITP: abakus -- KDE calculator

2005-10-23 Thread Steffen Joeris
Package: wnpp Severity: wishlist Owner: Steffen Joeris <[EMAIL PROTECTED]> * Package name: abakus Version : 0.90 Upstream Author : Michael Pyne <[EMAIL PROTECTED]> * URL : http://grammarian.homelinux.net/abakus/ * License : GPL Descripti

Re: Please check if it is needed and if yes please help

2005-10-14 Thread Steffen Joeris
On Saturday 15 October 2005 02:36, Steffen Joeris wrote: > Hi > > I started to debianize UniGnuplot, a graphical frontend for Gnuplot. > Now I am at a point where I can't maintain it, because there are some bugs > which may be easy for a Tcl/Tk coder, but not for me ;=) >

Please check if it is needed and if yes please help

2005-10-14 Thread Steffen Joeris
Hi I started to debianize UniGnuplot, a graphical frontend for Gnuplot. Now I am at a point where I can't maintain it, because there are some bugs which may be easy for a Tcl/Tk coder, but not for me ;=) The package seems to have a dead upstream!!! If someone here is interested in maintaining th

alternative for pdf-viewer

2005-10-06 Thread Steffen Joeris
Hi Is it possible to get an alternative for a pdf-viewer, so that you can choose /etc/alternatives/pdf-viewer in the code and this will link to a free viewer, e.g. kghostview or gpdf? Greetings Steffen -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Co

Bug#331636: ITP: scorereadingtrainer -- Trainer for reading music notes

2005-10-04 Thread Steffen Joeris
Package: wnpp Severity: wishlist Owner: Steffen Joeris <[EMAIL PROTECTED]> * Package name: scorereadingtrainer Version : 0.1.3 Upstream Author : José Pablo Ezequiel "Pupeno" Fernández <[EMAIL PROTECTED]> * URL : http:/

Consultant advertisements on -devel (was: Developer support)

2005-09-14 Thread Steffen Joeris
> Just for the record: Credativ is surely a good company, but there are > a lot more companies offering Debian support. To keep them all from > publicly answering requests on mailing lists, thus cluttering them, it > would be nice if we could restrict ourselves to pointers to the > consultants page

Re:Developer support

2005-09-13 Thread Steffen Joeris
I got an advice that it is not ok to send advertising material over the ML. Sorry for that I only wanted to help. Greetings Steffen signature.asc Description: This is a digitally signed message part

Re: Developer support

2005-09-13 Thread Steffen Joeris
You can ask for support at the credativ GmbH. There are several DebianDevelopers, look at www.credativ.com . Do not hesitate to contact us for questions. Greetings Steffen signature.asc Description: This is a digitally signed message part

Bug#302868: ITP: vym --- View your mind

2005-08-16 Thread Steffen Joeris
Package: wnpp Followup-For: Bug #302868 Owner: Steffen Joeris <[EMAIL PROTECTED]> I intend to package vym. Debian-edu is very interested in it, because of educational purposes. -- System Information: Debian Release: testing/unstable APT prefers unstable APT policy: (500, &#x

Bug#302538: ITP: unignuplot --- Graphical frontend for GNUPlot

2005-08-15 Thread Steffen Joeris
Package: wnpp Followup-For: Bug #302538 Owner: Steffen Joeris <[EMAIL PROTECTED]> I intend to package unignuplot. We (Debian-edu) are interested in unignuplot, because of educational purposes. -- System Information: Debian Release: testing/unstable APT prefers unstable APT policy