import (CVE-2021-33038). (Closes: #989183)
>
> -- Jonas Meurer Fri, 28 May 2021 11:00:26 +0200
Kind regards
jonas
diff -Nru hyperkitty-1.3.4/debian/changelog hyperkitty-1.3.4/debian/changelog
--- hyperkitty-1.3.4/debian/changelog 2021-04-29 11:55:45.0 +0200
+++ hyperkitty-1.3.4/debian/
rib/mailman-web: New wrapper script to configure mailman3-web
django project. (Closes: #982935)
-- Jonas Meurer Mon, 08 Mar 2021 17:07:33 +0100
```
[ Checklist ]
[x] all changes are documented in the d/changelog
[x] I reviewed all changes and I approve them
[x] attach debdiff against th
t and testing. (Closes: #987654)
>
> -- Jonas Meurer Thu, 29 Apr 2021 11:55:45 +0200
[ Checklist ]
[x] all changes are documented in the d/changelog
[x] I reviewed all changes and I approve them
[x] attach debdiff against the package in testing
unblock hyperkitty/1.3.4-3
Thanks for
01_settings_py.patch:
+- Switch back from ruby-sass to sassc. Ruby-sass became unmaintained
+ and abandoned recently. Thanks to Christian Ehrhardt for bugreport
+ and patch. (Closes: #924629)
+
+ -- Jonas Meurer Fri, 07 Jun 2019 20:03:29 +0200
+
+mailman-suite (0+20180916-7) unstable; urgen
e to lessc/node-less. Mailman3
django projects don't. (Related to #924961)
-- Jonas Meurer Sat, 08 Jun 2019 17:29:26 +0200
I thoroughly tested the new packages.
For further context, see the discussions at
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=924961 and
https://mail.pyth
curity fix in Buster.
Here's the changelog:
libgd2 (2.2.5-5.2) unstable; urgency=high
* Non-maintainer upload.
* Fix CVE-2019-11038: Uninitialized read in gdImageCreateFromXbm
(Closes: #929821)
-- Jonas Meurer Tue, 11 Jun 2019 16:21:57 +0200
Please find the debdiff attach
'important', it would be nice to have
this security fix in Buster.
Here's the changelog:
libgd2 (2.2.4-2+deb9u5) stretch; urgency=high
* Fix CVE-2019-11038: Uninitialized read in gdImageCreateFromXbm
(Closes: #929821)
-- Jonas Meurer Tue, 11 Jun 2019 17:33:42 +0200
Please f
Hello,
On Tue, 19 Nov 2019 17:11:05 +0800 Daniel Kahn Gillmor
wrote:
> thunderbird 68 is now in buster-new and in security.debian.org
>
> sadly, the enigmail upstream versions are closely tied to the
> thunderbird versions. (enigmail 2.0.x works with TB 60, but 2.1.x works
> with TB 68) See ht
Hello,
again, thanks a lot to dkg for your hard work to bring Enigmail 2.0 to
Stretch! Once again it's amazing to follow your work and see how
thorough you are :)
On Sun, 14 Oct 2018 18:58:33 -0400 Daniel Kahn Gillmor
wrote:
> Hi release team, security team:
>
> over in #910398, i wrote:
>
> O
Pirate Praveen:
> On 12/28/18 11:06 AM, Thomas Goirand wrote:
>> If the problem is hardware and connectivity, then IMO you can easily
>> find a sponsor for it. My company could well offer it for example
>> (hosted in Geneva with very nice connectivity to almost everywhere).
>>
>> Setting-up a repos
Pirate Praveen:
> On 2018, ഡിസംബർ 31 5:19:22 PM IST, Jonas Meurer wrote:
>> Pirate Praveen:
>>> On 12/28/18 11:06 AM, Thomas Goirand wrote:
>>>> If the problem is hardware and connectivity, then IMO you can easily
>>>> find a sponsor for it. My company co
(Closes: #924330)
+ * d/mailman3-web-postinst:
+- Fix logic to run init_django at install and update_django at upgrade.
+
+ -- Jonas Meurer Tue, 12 Mar 2019 13:07:32 +0100
+
mailman-suite (0+20180916-6) unstable; urgency=medium
* d/contrib/settings_local.py.sample:
diff -Nru mailman-suite
Hi there,
the upcoming upload of cryptsetup 2.0.0-1 will bump the libcryptsetup
soname from 4 to 12. According to (the very thoughtful) upstream, the
API (old functions) is backwards-compatible, so simple rebuilds of the
reverse depenencies should be enough.
Here's a list of reverse depends:
bru
Package: release.debian.org
Severity: normal
User: release.debian@packages.debian.org
Usertags: transition
Hey there,
the upcoming upload of cryptsetup 2.0.0-1 will bump the libcryptsetup
soname from 4 to 12. According to (the very thoughtful) upstream, the
API (old functions) is backwards-co
Am 17.12.2017 um 13:32 schrieb Cyril Brulebois:
>> How shall we proceed? The package is ready to be uploaded. Shall we go
>> ahead? Will you (the Release Managers) trigger the binary rebuilds
>> afterwards? Or can/shall we do this ourselves?
>
> You would usually request a transition slot through
Hi there,
Am 18.12.2017 um 19:38 schrieb Emilio Pozuelo Monfort:
> On 18/12/17 19:32, Emilio Pozuelo Monfort wrote:
>> Control: tags -1 confirmed
>>
>> On 17/12/17 19:27, Jonas Meurer wrote:
>>> Package: release.debian.org
>>> Severity: normal
>>&
possible race conditions. This is a workaround. (closes: #601886)
-- Jonas Meurer Wed, 09 Mar 2011 21:21:11 +0100
the debdiff is attached.
greetings,
jonas
diff '--exclude=.svn' -rNu tags/2:1.1.3-4/debian/changelog branches/squeeze/debian/changelog
--- tags/2:1.1.3-4/debian/changelog
On 09/03/2011 Adam D. Barratt wrote:
> On Wed, 2011-03-09 at 21:52 +0100, Jonas Meurer wrote:
> > cryptsetup (2:1.1.3-4squeeze1) stable-proposed-updates; urgency=low
> >
> > * NOT RELEASED YET
>
> I was going to grumble about that, but then realised it's not in t
hey,
On 10/03/2011 Jonas wrote:
> On 09/03/2011 Adam D. Barratt wrote:
> > On Wed, 2011-03-09 at 21:52 +0100, Jonas Meurer wrote:
> > > cryptsetup (2:1.1.3-4squeeze1) stable-proposed-updates; urgency=low
> > >
> > > * NOT RELEASED YET
> >
>
ether the
solution we've choosen is ok for them for the time being. Please send us
your comments in case you've any.
On behalf of the Debian Zope2 packagers,
Jonas Meurer
signature.asc
Description: Digital signature
r bugreport and patch, Ben
Hutchings and Yves-Alexis Perez for help with debugging. (closes: #507721)
* urgency=medium due to several important fixes.
-- Jonas Meurer Wed, 17 Dec 2008 21:25:45 +0100
Please don't hesitate to ask when you've questions regarding the upload.
;/' with '\/' instead of '\\/' in device names.
- disable error message 'failed to setup lvm device' (LP 151532).
-- Jonas Meurer Mon, 06 Apr 2009 08:49:14 +0200
greetings,
jonas
--
To UNSUBSCRIBE, email to debian-release-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org
hey again,
On 02/06/2009 Jonas Meurer wrote:
> cryptsetup/2:1.0.6+20090405.svn49-1 has been in unstable for 59 days now
> without migrating to testing. I guess that this is due to the udeb it
> creates. It would be great if you could hint it for migration to
> testing/squeeze.
>
1469). Fix
sed to replace '/' with '\/' instead of '\\/' in device names.
- disable error message 'failed to setup lvm device' (LP 151532).
-- Jonas Meurer Mon, 06 Apr 2009 08:49:14 +0200
greetings,
jonas
--
To UNSUBSCRIBE, email to debian-re
On 08/06/2009 Jonas Meurer wrote:
> hey again,
>
> On 02/06/2009 Jonas Meurer wrote:
> > cryptsetup/2:1.0.6+20090405.svn49-1 has been in unstable for 59 days now
> > without migrating to testing. I guess that this is due to the udeb it
> > creates. It would be gre
Hey debian-release,
Just wanted to bring up that topic again. I believe it's far to late for
changing the default syslog daemon for lenny to rsyslog, albeit I think
it would be really desirable.
According to http://wiki.debian.org/Rsyslog all preliminary tasks are
already done, so as far as I can
On 10/07/2008 Michael Biebl wrote:
> Jonas Meurer wrote:
>> Just wanted to bring up that topic again. I believe it's far to late for
>> changing the default syslog daemon for lenny to rsyslog, albeit I think
>> it would be really desirable.
>>
>> According
On 11/07/2008 Luk Claes wrote:
> Hi
Hey Luk,
> > Just wanted to bring up that topic again. I believe it's far to late for
> > changing the default syslog daemon for lenny to rsyslog, albeit I think
> > it would be really desirable.
>
> It's not too late for that, though I would rather have that
On 12/07/2008 Michael Biebl wrote:
> This topic was already discussed at length a few months ago [1] with a
> broad consent afaict that switching to rsyslog would be a good idea.
> Some issues were raised, and I tried to address them.
I just checked the dependencies again, and found one packag
On 12/07/2008 Luk Claes wrote:
> > I'm not sure if it makes sense to restart a new discussion and reiterate
> > what's already been said. Or am I missing something?
> >
> > What imho is required now is an "Ok" from the release team and action by
> > the ftpmaster team.
>
> Well, you expect an 'Ok
On 12/07/2008 Julien Cristau wrote:
> On Sat, Jul 12, 2008 at 11:58:10 +0200, Jonas Meurer wrote:
>
> > About changing the default, I'm not not sure whether ftpmasters approval
> > is actually needed at all.
> > If Joey agrees, you could do a coordinated upload of
On 12/07/2008 Joerg Jaspert wrote:
> On 11444 March 1977, Jonas Meurer wrote:
>
> > At least one lenny release manager mentioned that he doesn't object
> > against the change and that it's not to late for lenny either yet
> > [7],[8].
>
> Those two links c
On 13/07/2008 Jonas Meurer wrote:
> On 12/07/2008 Joerg Jaspert wrote:
> > On 11444 March 1977, Jonas Meurer wrote:
> >
> > > At least one lenny release manager mentioned that he doesn't object
> > > against the change and that it's not to late for len
On 13/07/2008 Marc Haber wrote:
> On Sun, Jul 13, 2008 at 10:49:33AM +0200, Philipp Kern wrote:
> > On Sun, Jul 13, 2008 at 10:39:14AM +0200, Joerg Jaspert wrote:
> > > The discussion just raised again on -release. Joey got CCed in one or
> > > two mails now. Pushing with the bug on the same day is
On 15/07/2008 Joerg Jaspert wrote:
> I just did the requested switch, sysklogd/klogd are now priority extra,
> rsyslog (not its -mysql -pgsql packages) are now priority important.
>
> If something else, like Tasks or so, needs to be changed too: Whoever
> needs to do that please do it. Thanks.
th
at <[EMAIL PROTECTED]> (closes: #490199)
* Use askpass in init scripts as well (closes: #489033, #477203)
[ Jonas Meurer ]
* Don't copy_exec libgcc1 in cryptopensc initramfs hook, as it's already
copied by copy_exec /usr/sbin/pcscd automaticly. Thanks to Evgeni Golov
&
).
greetings,
jonas
cryptsetup (2:1.0.6-4) unstable; urgency=medium
[ David Härdeman ]
* Make sure $IGNORE is reset as necessary, patch by Thomas Luzat
<[EMAIL PROTECTED]> (closes: #490199)
* Use askpass in init scripts as well (closes: #489033, #477203)
[ Jonas Meurer ]
* Don
hello,
tidy-proxy is a small http proxy written in perl. a new upstream version
0.95 has been released some weeks ago. unfortunately i didn't manage to
upload it in time before the freeze.
0.95 introduces some new useful features and I updated packaging related
stuff like manpages etc.
as tidy-p
: #492552)
* bump standards-version to 3.8.0
- Add a README.source which references /usr/share/doc/quilt/README.source.
- Add support for debian build option parallel=n to debian/rules.
-- Jonas Meurer <[EMAIL PROTECTED]> Tue, 29 Jul 2008 00:29:17 +0200
signature.asc
Description: D
from do_start and do_stop to cryptdisks_start and
cryptdisks_stop to fix "keyscript | cryptsetup". (closes: #493622)
* This upload fixes two RC bugs, thus upload with severity=high.
-- Jonas Meurer <[EMAIL PROTECTED]> Wed, 06 Aug 2008 10:19:21 +0200
diff -u cryptsetup-1.0.6/de
On 06/08/2008 Jonas Meurer wrote:
> I just uploaded cryptsetup 2:1.0.6-5, which fixes two release-critical
> bugs, to unstable. Please consider a freeze exception for this upload.
Argh, unfortunately the submitter of bug #493848 mentioned that the fix
in 2:1.0.6-5 was not enough just at th
ain upload with urgency=high.
-- Jonas Meurer <[EMAIL PROTECTED]> Sat, 09 Aug 2008 13:36:31 +0200
cryptsetup (2:1.0.6-5) unstable; urgency=high
* Fix watch file to not report -pre and -rc releases as superior.
* Remove the global var $SIZE from cryptdisks.functions again but keep
; urgency=low
* add russian debconf translation, thanks to Yuri Kozlov (closes: #494451)
* remove paths from invokation of programs in $PATH in postinst and postrm.
-- Jonas Meurer <[EMAIL PROTECTED]> Thu, 14 Aug 2008 16:01:24 +0200
debdiff is attached.
greetings,
jonas
diff -u lurker-2.1/
issues, thanks to Christian Perrier for coordination:
- update japanese debconf translation, thanks to Noritada Kobayashi
(closes: #496064)
- update spanish debconf translation, thanks to germana (closes: #470307,
#495861)
-- Jonas Meurer <[EMAIL PROTECTED]> Tue, 26 Aug 2008
On 29/04/2005 Daniel Knauth wrote:
> The mysql-python version shipped with Debian 3.1 has a connection leak
> that makes the database unusable if any Python client is under load.
>
> Obviously, this affects *all* mysql clients, not just Python clients.
> It has been fixed in the upstream mysql-pyt
hello,
please push lurker 1.3-2 into sarge. the version currently in sarge
(1.2-5) has some annoying bugs like problems with timestamp, and lurker
1.3 is a bugfix-only release. additionally several template translation
updates would make it into sarge with 1.3-2.
please wait for 1.3-2, as it inclu
On 10/05/2005 Andreas Barth wrote:
> * Jonas Meurer ([EMAIL PROTECTED]) [050510 18:15]:
> > please push lurker 1.3-2 into sarge. the version currently in sarge
> > (1.2-5) has some annoying bugs like problems with timestamp, and lurker
> > 1.3 is a bugfix-only release.
On 12/05/2005 To Debian-Release wrote:
> > sorry, but I can't exactly say that 1.3-2 is an "important and above
> > bugfix-only release" in relation to 1.2-5 -- which might be related to
> > the fact that I might not have recognized the bugs. Could you please
> > give more details why all these cha
hello,
assuming that zope is a medium to highly used package and that it needs
more maintainer activity than most packages require, maybe a zope
maintainer group would be nice.
to give an argument, for me it's quite important to have zope in debian
for continuing my job as debian sysadmin and webm
hello,
lurker 1.2 is in debian/unstable since more than 2 weeks now, and it's
not in sarge yet, because the depend on libmimelib1 3.3.0-2 from the
source package 'kdepim' holds it back.
as the version in sarge is 1.0, an upgrade would be very usefull, to fix
some bugs in lurker, and make the data
hello,
please remove zope-xron from sarge, as it's rather useless.
see bug #281938 for more detailed information.
bye
jonas
:
cryptsetup (2:1.4.3-4) unstable; urgency=medium
* change recommends for busybox to busybox | busybox-static. Thanks to
Armin Haas for the bugreport. (closes: #692151)
-- Jonas Meurer Wed, 07 Nov 2012 16:12:25 +0100
cryptsetup (2:1.4.3-3) unstable; urgency=medium
* add recommends for
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1
Hello,
Am 10.11.2012 18:20, schrieb Adam D. Barratt:
> Control: tags -1 + confirmed d-i
>
> On Sat, 2012-11-10 at 18:01 +0100, intrigeri wrote:
>> Jonas Meurer wrote (08 Nov 2012 16:31:14 GMT) :
>>> Only easy fixes, docum
changelog follows, debdiff attached.
Cheers,
jonas
cryptsetup (2:1.6.6-4) unstable; urgency=medium
[ Simon McVittie ]
* debian/initramfs/cryptroot-script: decrypt /usr as well as / so that
split-/usr will work with initramfs-tools (>= 0.118). (closes: #767832)
[ Jonas Meurer ]
* deb
e insufficient grep regex for
detecting a running cryptdisks-udev (upstart) init script.
-- Jonas Meurer Thu, 22 Jan 2015 21:22:08 +0100
unblock cryptsetup/2:1.6.6-5
Cheers,
jonas
-- System Information:
Debian Release: jessie/sid
APT prefers utopic-updates
APT policy: (500, 'utopic-
>>detect a currently running cryptdisks-udev (upstart) init script.
>>>
>>> The debdiff is attached and here's the full changelog for this upload:
>>>
>>> cryptsetup (2:1.6.6-5) unstable; urgency=high
>>>
>>> * debian/cryptdisk
Hi again,
Am 29.01.2015 um 22:51 schrieb Jonas Meurer:
> Hi,
>
> Am 29.01.2015 um 19:26 schrieb Cyril Brulebois:
>> Niels Thykier (2015-01-29):
>>> Ack from RT, adding KiBi to CC for a d-i ack.
>>>
>>
>> Why isn't the BTS updated with the inform
Control: tags -1 -moreinfo
Hi,
Am 01.02.2015 um 19:27 schrieb Jonas Meurer:
> Hi again,
>
> Am 29.01.2015 um 22:51 schrieb Jonas Meurer:
>> Hi,
>>
>> Am 29.01.2015 um 19:26 schrieb Cyril Brulebois:
>>> Niels Thykier (2015-01-29):
>>>&
able; urgency=medium
[ Simon McVittie ]
* debian/initramfs/cryptroot-script: decrypt /usr as well as / so that
split-/usr will work with initramfs-tools (>= 0.118). (closes: #767832)
[ Jonas Meurer ]
* Move cryptdisks_{start,stop} symlink creation from debian/rules to
postinst. N
ume groups. thanks to Christoph
Anton Mitterer for the suggestion. (closes: #554506, #591626)
* remove /etc/bash_completion.d from debian/cryptsetup.dirs
* set urgency=high as this upload fixes two release-critical bugs.
-- Jonas Meurer Thu, 04 Nov 2010 20:36:45 +0100
greetin
hello,
apt-get update is still very verbose about the pdiff updates:
[about 300 lines with "Get: ..."]
Get:334 2006-09-26-1322.12.pdiff [10.7kB]
Get:335 2006-09-26-1322.12.pdiff [10.7kB]
Get:336 2006-09-27-1319.38.pdiff [4821B]
Get:337 2006-09-26-1322.12.pdiff [10.7kB]
Get:338 2006-09-27-1319.38.
Hello,
David Härdeman and I just prepared cryptsetup 1.0.4+svn16-1. it fixes
one reported and two unreported bugs, and otherwise is similar to
1.0.4-8 which just entered testing/etch.
I'm writing to you because I plan to upload 1.0.4+svn16-1 into unstable
an because we would love to see it in etc
On 28/11/2006 Frans Pop wrote:
> On Tuesday 28 November 2006 03:51, Jonas Meurer wrote:
> > David Härdeman and I just prepared cryptsetup 1.0.4+svn16-1. it fixes
> > one reported and two unreported bugs, and otherwise is similar to
> > 1.0.4-8 which just entered testing/etch
Hello,
I just uploaded cryptsetup 1.0.4+svn26-1 with urgency=high to unstable.
It fixes one critical (#403426), one important (#402417), two normal and
one minor bugs:
cryptsetup (2:1.0.4+svn26-1) unstable; urgency=high
[ Jonas Meurer ]
* New upstream svn snapshot 1.0.4+svn26
- contains
Hello release managers,
it would be great if you could unblock lurker 2.1-7. It contains only
i18n changes.
greetings
jonas
--
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1
Hello,
Am 08.02.2012 14:34, schrieb Niels Thykier:
> For no change-rebuilds, please file a binNMU request against
> release.debian.org (exception being for arch:all packages).
>
> In the given situation, it appears that cryptsetup bumped its
> SONAM
Hi Gordon,
thanks for the bugreport. I escalate this bugreport to the
debian-release team, asking for advice: would you accept another
cryptsetup upload targeted to jessie in order to add 'plymouth' to the
list of recommended packages?
Am 03.03.2015 um 03:43 schrieb Gordon Morehouse:
> Booting in
Hello,
Am 2015-03-20 16:49, schrieb Gordon Morehouse:
On 03/19/2015 06:58 PM, Michael Biebl wrote:
As pointed out, a recommends does not really help for new installs,
since they have no effect when installing the base system.
A recommends at least provides users a pointer towards fixing a rea
as
diff -u smstools-3.1.15/debian/changelog smstools-3.1.15/debian/changelog
--- smstools-3.1.15/debian/changelog
+++ smstools-3.1.15/debian/changelog
@@ -1,3 +1,17 @@
+smstools (3.1.15-1.1+deb8u1) stable; urgency=high
+
+ * NMU by Jonas Meurer to push the fix into Jessie.
+ * Fix initscript (deb
Hi,
is there a particular reason, why RMs didn't comment on this bugreport
yet? It would be awesome to have a fixed smstools in proposed-updates in
time for the first Jessie point release :)
Cheers,
jonas
On Sun, 17 May 2015 12:11:28 +0200 Jonas Meurer
wrote:
> Package: release.de
Hi Adam,
Am 25.05.2015 um 00:37 schrieb Adam D. Barratt:
> On Sun, 2015-05-24 at 23:45 +0200, Jonas Meurer wrote:
>> Hi,
>>
>> is there a particular reason, why RMs didn't comment on this bugreport
>> yet? It would be awesome to have a fixed smstools in proposed-
po in initscript
* [a2c78a1] Stop status.cgi from listing unauthorized hosts and
services in servicegroup view (CVE-2013-2214)
Thanks to Jonas Meurer for the report and the patch (Closes: #714171)
* [51fb59b] Backport upstream r1953 to fix downtime retention across
restarts.
Thanks to Didier
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1
Hello,
Am 15.11.2013 23:30, schrieb Jonathan Wiltshire:
> On 2013-11-01 14:45, Jonas Meurer wrote:
>> the nagios3 package in wheezy suffers from at least one minor
>> security bug and a regression. I prepared nagios3/3.4.1+deb7u
73 matches
Mail list logo