Re: Fixes for CVE-2020-13696 (#962221)

2020-07-05 Thread Vasyl Gello
Hi Jeremy! Thanks for contributing the security release! I checked your changes and pushed them to the team repo. I do not have an upload rights, so CCing Sebastian and Mattia. --  Vasyl Gello == Certified SolidWorks Expert Mob.:+380 (98) 465 66 77

Re: Bug#964359: smplayer: Please remove smplayer from the main repositories. It pops a dialog box asking for a donation every so many sessions. This is detrimental to Debian reputation. If others foll

2020-07-05 Thread Vasyl Gello
Hi Eduardo! I briefly checked smplayer Salsa git and it seems that the nag is controlled by DONATE_REMINDER define: https://salsa.debian.org/multimedia-team/smplayer/-/blob/master/src/basegui.h#L76 I can try patching it in Debian but I am not smplayer user so I will need some time to start smpl

sonic-visualiser is marked for autoremoval from testing

2020-07-05 Thread Debian testing autoremoval watch
sonic-visualiser 4.0.1-1 is marked for autoremoval from testing on 2020-08-11 It (build-)depends on packages with these RC bugs: 963855: capnproto: FTBFS on IPv6-only environments

Bug#964359: smplayer: Please remove smplayer from the main repositories. It pops a dialog box asking for a donation every so many sessions. This is detrimental to Debian reputation. If others follow t

2020-07-05 Thread Eduardo GV
Package: smplayer Version: 18.10.0~ds0-1 Severity: wishlist Dear Maintainer, *** Reporter, please consider answering these questions, where appropriate *** * What led up to the situation? Every so many times Smplayer is used, an anoying dialog box asking for money pops up. For now it is only

vlc_3.0.11-3~exp2_source.changes ACCEPTED into experimental

2020-07-05 Thread Debian FTP Masters
Accepted: -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Format: 1.8 Date: Mon, 06 Jul 2020 00:15:39 +0200 Source: vlc Architecture: source Version: 3.0.11-3~exp2 Distribution: experimental Urgency: medium Maintainer: Debian Multimedia Maintainers Changed-By: Sebastian Ramacher Changes: vl

Processing of vlc_3.0.11-3~exp2_source.changes

2020-07-05 Thread Debian FTP Masters
vlc_3.0.11-3~exp2_source.changes uploaded successfully to localhost along with the files: vlc_3.0.11-3~exp2.dsc vlc_3.0.11-3~exp2.debian.tar.xz Greetings, Your Debian queue daemon (running on host usper.debian.org)

vlc_3.0.11-3~exp1_source.changes ACCEPTED into experimental

2020-07-05 Thread Debian FTP Masters
Accepted: -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Format: 1.8 Date: Sun, 05 Jul 2020 23:24:14 +0200 Source: vlc Architecture: source Version: 3.0.11-3~exp1 Distribution: experimental Urgency: medium Maintainer: Debian Multimedia Maintainers Changed-By: Sebastian Ramacher Changes: vl

Processing of vlc_3.0.11-3~exp1_source.changes

2020-07-05 Thread Debian FTP Masters
vlc_3.0.11-3~exp1_source.changes uploaded successfully to localhost along with the files: vlc_3.0.11-3~exp1.dsc vlc_3.0.11-3~exp1.debian.tar.xz Greetings, Your Debian queue daemon (running on host usper.debian.org)

libmatroska_1.6.0-1_amd64.changes is NEW

2020-07-05 Thread Debian FTP Masters
binary:libmatroska7 is NEW. binary:libmatroska7 is NEW. Your package has been put into the NEW queue, which requires manual action from the ftpteam to process. The upload was otherwise valid (it had a good OpenPGP signature and file hashes are valid), so please be patient. Packages are routinely

libebml_1.4.0-1_amd64.changes is NEW

2020-07-05 Thread Debian FTP Masters
binary:libebml5 is NEW. binary:libebml5 is NEW. Your package has been put into the NEW queue, which requires manual action from the ftpteam to process. The upload was otherwise valid (it had a good OpenPGP signature and file hashes are valid), so please be patient. Packages are routinely processe

Processing of libebml_1.4.0-1_amd64.changes

2020-07-05 Thread Debian FTP Masters
libebml_1.4.0-1_amd64.changes uploaded successfully to localhost along with the files: libebml_1.4.0-1.dsc libebml_1.4.0.orig.tar.xz libebml_1.4.0-1.debian.tar.xz libebml-dev_1.4.0-1_amd64.deb libebml5-dbgsym_1.4.0-1_amd64.deb libebml5_1.4.0-1_amd64.deb libebml_1.4.0-1_amd64.buildinfo

Processing of libmatroska_1.6.0-1_amd64.changes

2020-07-05 Thread Debian FTP Masters
libmatroska_1.6.0-1_amd64.changes uploaded successfully to localhost along with the files: libmatroska_1.6.0-1.dsc libmatroska_1.6.0.orig.tar.xz libmatroska_1.6.0-1.debian.tar.xz libmatroska-dev_1.6.0-1_amd64.deb libmatroska7-dbgsym_1.6.0-1_amd64.deb libmatroska7_1.6.0-1_amd64.deb lib

Bug#964311: libmatroska6v5: New upstream release 1.6.0

2020-07-05 Thread Matteo F. Vescovi
On 2020-07-05 at 14:48 (+02), Christian Marillat wrote: > Package: libmatroska6v5 > > Dear Maintainer, > > Please package this new version needed by mkvtoolnix 48.0.0 FYI, both libebml and libmatroska had a SONAME bump within their new releases v1.4.0 and v1.6.0, respectively. Packages are now in

Processed: severity of 964311 is wishlist

2020-07-05 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > severity 964311 wishlist Bug #964311 [libmatroska6v5] libmatroska6v5: New upstream release 1.6.0 Severity set to 'wishlist' from 'normal' > thanks Stopping processing here. Please contact me if you need assistance. -- 964311: https://bugs.debian

Fixes for CVE-2020-13696 (#962221)

2020-07-05 Thread Jeremy Sowden
I've forked the xawtv Salsa repo and pushed some changes to my fork to fix #962221: https://salsa.debian.org/azazel/xawtv There are a couple of housekeeping patches, I've imported the latest upstream release (3.107), and I've added the patch mentioned in the notes at the bottom of the CVE page:

Bug#936805: kodi: Python2 removal in sid/bullseye

2020-07-05 Thread Mattia Rizzolo
A few people are already working on kodi 19, and packages will start to appear in a few days in experimental. Actually there are related packages in NEW: dav1d was accepted a couple days ago, shairplay and libudfread. They are not compulsory dependencies, so not strictly blocking, but they were u

Bug#936805: kodi: Python2 removal in sid/bullseye

2020-07-05 Thread Nicholas D Steeves
Hi, On Fri, Aug 30, 2019 at 07:22:18AM +, Matthias Klose wrote: > Package: src:kodi > Version: 2:17.6+dfsg1-4 > Severity: normal > Tags: sid bullseye > User: debian-pyt...@lists.debian.org > Usertags: py2removal > > Python2 becomes end-of-live upstream, and Debian aims to remove > Python2 fro

Bug#964312: libswscale5: general protection fault in libswscale.so.5.7.100 / Segmentation fault

2020-07-05 Thread Joerg
Package: libswscale5 Version: 7:4.3-3 Severity: normal Dear Maintainer, dvbcut closes with a segmentation fault after the index file was created. 6453 Segmentation fault nice -n 19 dvbcut -idx "${pathname}/${filename}.idx" "${pathname}/${filename}" dmesg provides: traps: dvbcut[4884] gene

Bug#964311: libmatroska6v5: New upstream release 1.6.0

2020-07-05 Thread Christian Marillat
Package: libmatroska6v5 Version: 1.5.2-3 Severity: normal Dear Maintainer, Please package this new version needed by mkvtoolnix 48.0.0 Christian -- System Information: Debian Release: bullseye/sid APT prefers buildd-unstable APT policy: (500, 'buildd-unstable'), (500, 'unstable') Architectu

Bug#964253: libbluray: Include list_titles and bdsplice utilities

2020-07-05 Thread Vasyl Gello
Source: libbluray Followup-For: Bug #964253 PS: reportbug sent the reply without attachment. Attaching one again. -- System Information: Debian Release: bullseye/sid APT prefers unstable APT policy: (500, 'unstable') Architecture: amd64 (x86_64) Foreign Architectures: i386 Kernel: Linux 4.15

Bug#964253: libbluray: Include list_titles and bdsplice utilities

2020-07-05 Thread Vasyl Gello
Source: libbluray Followup-For: Bug #964253 Hi Sebastian, I hold the actual Git upload until JB confirms the renaming of list_titles. In the meantime, I attach the patch for review. Vasyl PS: I know about bugtracker but I am following the initial email conversation with JB. If I am told to use

Bug#964277: picard: Current version is unusable due to GUI glitches

2020-07-05 Thread Sebastian Ramacher
Control: tags -1 confirmed Control: forwarded -1 https://tickets.metabrainz.org/browse/PICARD-1814 On 2020-07-04 22:53:55 +0200, eb wrote: > Package: picard > Version: 2.3.2-1 > Severity: important > > Dear Maintainer, > > After the last upgrade, Picard become unusable due to GUI glitches. I > h

Processed: Re: Bug#964277: picard: Current version is unusable due to GUI glitches

2020-07-05 Thread Debian Bug Tracking System
Processing control commands: > tags -1 confirmed Bug #964277 [picard] picard: Current version is unusable due to GUI glitches Added tag(s) confirmed. > forwarded -1 https://tickets.metabrainz.org/browse/PICARD-1814 Bug #964277 [picard] picard: Current version is unusable due to GUI glitches Set Bu

Bug#964306: liboggz2: FPE Arithmetic Exception in oggz_metric_default_linear()

2020-07-05 Thread Rafael Dutra
Package: liboggz2 Version: 1.1.1-7 Severity: important Tags: security, upstream Dear Maintainer, This bug causes a crash in the application when a specially crafted input file is parsed. It's an arithmetic exception at src/liboggz/metric_internal.c:105:46 in oggz_metric_default_linear(). To repr

Bug#964305: blender FTBFS on non-i386 32bit: BLI_STATIC_ASSERT(sizeof(struct Scene) == 6124) fails

2020-07-05 Thread Adrian Bunk
Source: blender Version: 2.83.1+dfsg-1 Severity: serious Tags: ftbfs https://buildd.debian.org/status/package.php?p=blender&suite=sid ... In file included from /<>/obj-arm-linux-gnueabihf/source/blender/makesdna/intern/dna_verify.c:2: /<>/source/blender/blenlib/BLI_assert.h:102:37: error: static

Bug#964304: liboggz2: Segmentation Fault (read) in auto_calc_theora()

2020-07-05 Thread Rafael Dutra
Package: liboggz2 Version: 1.1.1-7 Severity: important Tags: security, upstream Dear Maintainer, This bug causes a crash in the application when a specially crafted input file is parsed. It's a read violation to address NULL at src/liboggz/oggz_auto.c:604:8 in auto_calc_theora(). To reproduce: I

Bug#964303: liboggz2: Segmentation Fault (heap buffer overflow) in oggz_comments_decode()

2020-07-05 Thread Rafael Dutra
Package: liboggz2 Version: 1.1.1-7 Severity: important Tags: security, upstream Dear Maintainer, This bug causes a crash in the application when a specially crafted input file is parsed. It's a read violation of about 43k bytes caused by a heap buffer overflow at src/liboggz/oggz_comments.c:604:4

Bug#964302: liboggz2: Segmentation Fault in oggz_comment_cmp()

2020-07-05 Thread Rafael Dutra
Package: liboggz2 Version: 1.1.1-7 Severity: important Tags: security, upstream Dear Maintainer, This bug causes a crash in the application when a specially crafted input file is parsed. It's a read violation to address NULL at src/liboggz/oggz_comments.c:217:7 in oggz_comment_cmp(). To reproduc

Bug#964301: liboggz2: Segmentation Fault (write) in auto_calc_theora()

2020-07-05 Thread Rafael Dutra
Package: liboggz2 Version: 1.1.1-7 Severity: important Tags: security, upstream Dear Maintainer, This bug causes a crash in the application when a specially crafted input file is parsed. It's a write violation to address NULL at src/liboggz/oggz_auto.c:591:41 in auto_calc_theora(). To reproduce:

Bug#964300: liboggz2: Segmentation Fault in dirac_parse_info()

2020-07-05 Thread Rafael Dutra
Package: liboggz2 Version: 1.1.1-7 Severity: important Tags: security, upstream Dear Maintainer, This bug causes a crash in the application when a specially crafted input file is parsed. It's a read violation at src/tools/./../liboggz/dirac.c in dirac_parse_info(). To reproduce: Install oggz-too

Bug#964253: libbluray: Include list_titles and bdsplice utilities

2020-07-05 Thread Sebastian Ramacher
Hi Vasyl On 2020-07-05 10:12:45 +, Vasyl Gello wrote: > Sebastian, > > Maybe it is good idea to rename that tool upstream to bd_list_titles. > > Jean-Baptiste, what do you think of it? If you are fine with it, please make > a new tag as usual :) FWIW, the bug tracker for libbluray is at ht

Bug#964253: libbluray: Include list_titles and bdsplice utilities

2020-07-05 Thread Vasyl Gello
Also, we can upstream debian/bd_info.1 manpage and the similar manpages I am creating for bdsplice and bd_list_titles. --  Vasyl Gello == Certified SolidWorks Expert Mob.:+380 (98) 465 66 77 E-Mail: vasek.ge...@gmail.com Skype: vasek.gello ===

Bug#964253: libbluray: Include list_titles and bdsplice utilities

2020-07-05 Thread Vasyl Gello
Sebastian, Maybe it is good idea to rename that tool upstream to bd_list_titles. Jean-Baptiste, what do you think of it? If you are fine with it, please make a new tag as usual :) --  Vasyl Gello == Certified SolidWorks Expert Mob.:+380 (98) 465 6

Processed: retitle 964252 to libbluray: FTBFS if texlive is installed in non-minimal build environment

2020-07-05 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > retitle 964252 libbluray: FTBFS if texlive is installed in non-minimal build > environment Bug #964252 [src:libbluray] Failure to build from source on buster Changed Bug title to 'libbluray: FTBFS if texlive is installed in non-minimal build env

mpg123_1.26.2-1_source.changes ACCEPTED into unstable

2020-07-05 Thread Debian FTP Masters
Accepted: -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Format: 1.8 Date: Sun, 05 Jul 2020 11:08:35 +0200 Source: mpg123 Architecture: source Version: 1.26.2-1 Distribution: unstable Urgency: medium Maintainer: Debian Multimedia Maintainers Changed-By: Sebastian Ramacher Closes: 963205 Cha

Processing of mpg123_1.26.2-1_source.changes

2020-07-05 Thread Debian FTP Masters
mpg123_1.26.2-1_source.changes uploaded successfully to localhost along with the files: mpg123_1.26.2-1.dsc mpg123_1.26.2.orig.tar.bz2 mpg123_1.26.2.orig.tar.bz2.asc mpg123_1.26.2-1.debian.tar.xz Greetings, Your Debian queue daemon (running on host usper.debian.org)

Bug#963205: marked as done (libmpg123-dev no longer multiarch installable)

2020-07-05 Thread Debian Bug Tracking System
Your message dated Sun, 05 Jul 2020 09:49:12 + with message-id and subject line Bug#963205: fixed in mpg123 1.26.2-1 has caused the Debian Bug report #963205, regarding libmpg123-dev no longer multiarch installable to be marked as done. This means that you claim that the problem has been deal

Bug#964253: libbluray: Include list_titles and bdsplice utilities

2020-07-05 Thread sramacher
Hi Nils, Vasyl, On 2020-07-05 09:30:26 +, Vasyl Gello wrote: > Control: block -1 by 964242 > Control: owner -1 ! > > Hi Nils, > > I am building the fix locally, however please note that ANY clean-room build > (be it pbuilder / cowbuilder / sbuild) targeting unstable will end up failing > to

Bug#964253: libbluray: Include list_titles and bdsplice utilities

2020-07-05 Thread Vasyl Gello
Control: block -1 by 964242 Control: owner -1 ! Hi Nils, I am building the fix locally, however please note that ANY clean-room build (be it pbuilder / cowbuilder / sbuild) targeting unstable will end up failing to resolve a broken dependency of bsdmainutils on bsdextrautils (Bug #964242). To wo

Processed: Re: libbluray: Include list_titles and bdsplice utilities

2020-07-05 Thread Debian Bug Tracking System
Processing control commands: > block -1 by 964242 Bug #964253 [libbluray-bin] libbluray: Include list_titles and bdsplice utilities 964253 was not blocked by any bugs. 964253 was not blocking any bugs. Added blocking bug(s) of 964253: 964242 > owner -1 ! Bug #964253 [libbluray-bin] libbluray: Inc

Bug#963205: Next round

2020-07-05 Thread Thomas Orgis
Great. I released 1.26.2 now so that the package here can be updated. pgpVH6BLdt5Ir.pgp Description: Firma digital OpenPGP