Bug#643967: prelink -u fails on some binaries; this breaks debsums

2012-06-10 Thread Michael Gilbert
severity 643967 important tag 643967 -security thanks This problem should not be considered a security issue. Anyone utilizing prelink should be aware of the fact that it changes binaries, and there is the possibility that those changes aren't reversible; leading to differing checksums in tools l

Bug#692318: python-scientific: needs to build-depend and depend python-numpy >= 1:1.6.1-1

2012-11-04 Thread Michael Gilbert
package: python-scientific version: 2.8-3 severity: serious Due to unintended abi change in numpy 1.6.1 affecting PyArray_CHAR, this package needs to depend python-numpy >= 1:1.6.1-1. See: http://bugs.debian.org/685812 http://thread.gmane.org/gmane.comp.python.numeric.general/51931 Best wishes,

Bug#692342: apt-move move command deletes all files without moving them

2012-11-06 Thread Michael Gilbert
control: tag -1 confirmed Confirming that "apt-move get && apt-move move" behaves like this. Building and installing 4.2.27-1 on wheezy doesn't help. Testing on squeeze, it does work. Best wishes, Mike -- To UNSUBSCRIBE, email to debian-qa-packages-requ...@lists.debian.org with a subject of "

Bug#695215: bzr: breaks bzr-loom 2.2.0-2

2012-12-05 Thread Michael Gilbert
control: reassign -1 bzr control: found -1 2.6.0~bzr6571-1 control: retitle -1 bzr: breaks bzr-loom 2.2.0-2 Only experimental bzr has this problem. Best wishes, Mike -- To UNSUBSCRIBE, email to debian-qa-packages-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listma

Bug#706292: Acknowledgement (qpid-python: python can't import qpid)

2013-04-27 Thread Michael Gilbert
So, I've found that this version of python-qpid needs an amqp 0-10 spec file, but a bsd-licensed version seems to not exist (and I've spent about an hour doing search variants for that): http://www.amqp.org/specification/0-10/amqp-org-download Interestingly enough, all of the other amqp versions o

Bug#555267: otrs2: embeds prototype.js

2009-11-08 Thread Michael Gilbert
package: otrs2 version: 2.3.4-5 severity: important tags: security Hi, Your package embeds prototype.js, which makes security updates very cumbersome, difficult, and potentially error-prone. Please update your package to make use of the system prototype.js provided by the libjs-prototype binary p

Bug#555266: otrs2: CVE-2007-2383 and CVE-2008-7720 prototypejs vulnerabilities

2009-11-08 Thread Michael Gilbert
package: otrs2 version: 2.3.4-5 severity: serious tags: security Hi, Your package contains an embedded version of prototype.js that is vulnerable to either CVE-2007-2383 (affecting prototype.js before 1.5.1) [0], CVE-2008-7220 (affecting prototype.js before 1.6.0.2) [1], or both. Your package em

Bug#559814: CVE-2009-3736 local privilege escalation

2009-12-06 Thread Michael Gilbert
Package: hamlib Severity: grave Tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) id was published for libtool. I have determined that this package embeds a vulnerable copy of the libtool source code. However, since this is a mass bug filing (due to so many packages embe

Bug#559812: CVE-2009-3736 local privilege escalation

2009-12-06 Thread Michael Gilbert
Package: graphviz Severity: grave Tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) id was published for libtool. I have determined that this package embeds a vulnerable copy of the libtool source code. However, since this is a mass bug filing (due to so many packages em

Bug#559829: CVE-2009-3736 local privilege escalation

2009-12-06 Thread Michael Gilbert
Package: synfig Severity: grave Tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) id was published for libtool. I have determined that this package embeds a vulnerable copy of the libtool source code. However, since this is a mass bug filing (due to so many packages embe

Bug#560920: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: matanza severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many packa

Bug#560940: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-12 Thread Michael Gilbert
package: tla severity: serious tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) ids were published for expat. I have determined that this package embeds a vulnerable copy of xmlparse.c and xmltok_impl.c. However, since this is a mass bug filing (due to so many packages

Bug#778418: ndisc6: fails to build on kfreebsd

2015-02-14 Thread Michael Gilbert
package: src:ndisc6 severity: important version: 1.0.1-1 This package no longer builds on the freebsd architectures: https://buildd.debian.org/ndisc6 Best wishes, Mike -- To UNSUBSCRIBE, email to debian-qa-packages-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact list