[Pkg-javascript-devel] Bug#1104246: Bug#1104246: node-formidable: CVE-2025-46653

2025-04-27 Thread Yadd
On 4/27/25 20:41, Salvatore Bonaccorso wrote: Source: node-formidable Version: 3.2.5+20221017git493ec88+~cs4.0.9-1 Severity: important Tags: security upstream X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerability was published for node-formidable. CVE-2025-4665

[Pkg-javascript-devel] Bug#1104246: node-formidable: CVE-2025-46653

2025-04-27 Thread Salvatore Bonaccorso
Source: node-formidable Version: 3.2.5+20221017git493ec88+~cs4.0.9-1 Severity: important Tags: security upstream X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerability was published for node-formidable. CVE-2025-46653[0]: | Formidable (aka node-formidable) 2.1.0 t

[Pkg-javascript-devel] Processed: Re: Bug#1101456: not false positive

2025-04-27 Thread Debian Bug Tracking System
Processing control commands: > found -1 javascript-common/11+nmu1 Bug #1101456 [javascript-common] fails to upgrade Marked as found in versions javascript-common/11+nmu1. > tags -1 = confirmed Bug #1101456 [javascript-common] fails to upgrade Added tag(s) confirmed; removed tag(s) moreinfo. > seve

[Pkg-javascript-devel] Bug#1101456: not false positive

2025-04-27 Thread VA
Le 27/04/2025 à 16:32, Chris Hofstaedtler a écrit : a) /etc/apache2/conf-available/javascript-common.conf does NOT exist? indeed. I don't remember ever touching this file. b) Does the following print anything?    dpkg -C javascript-common ``` The following packages are only half configured

[Pkg-javascript-devel] Bug#1101456: not false positive

2025-04-27 Thread Chris Hofstaedtler
Control: found -1 javascript-common/11+nmu1 Control: tags -1 = confirmed Control: severity -1 serious Here's a scripted reproducer: mmdebstrap --variant=apt --chrooted-customize-hook='cd / && apt download javascript-common && dpkg -i ./javascript-common_*.deb && rm /etc/apache2/conf-availab

[Pkg-javascript-devel] Bug#1101456: not false positive

2025-04-27 Thread Chris Hofstaedtler
* VA [250427 15:46]: Hi Chris, (Thanks for putting me in CC so I'm notified as I wasn't aware someone had closed the issue) Le 27/04/2025 à 15:22, Chris Hofstaedtler a écrit : | > a2query -c javascript-common | > echo $? I gave it above, but I'll repeat it, a2query prints `No conf matches

[Pkg-javascript-devel] Bug#1101456: not false positive

2025-04-27 Thread Chris Hofstaedtler
Control: found -1 javascript-common/12 Hi VA, On Sun, Apr 27, 2025 at 02:50:17PM +0200, VA wrote: > The given commands output `No conf matches javascript-common` and `1`. [..] please provide the additional info requested by Fiona: On Fri, 11 Apr, 2025, Fiona Ebner wrote: [..] | AFAICT, the post

[Pkg-javascript-devel] Bug#1101456: not false positive

2025-04-27 Thread VA
Hi Chris, (Thanks for putting me in CC so I'm notified as I wasn't aware someone had closed the issue) Le 27/04/2025 à 15:22, Chris Hofstaedtler a écrit : | > a2query -c javascript-common | > echo $? I gave it above, but I'll repeat it, a2query prints `No conf matches javascript-common` an

[Pkg-javascript-devel] Processed: Re: Bug#1101456: not false positive

2025-04-27 Thread Debian Bug Tracking System
Processing control commands: > found -1 javascript-common/12 Bug #1101456 [javascript-common] fails to upgrade Ignoring request to alter found versions of bug #1101456 to the same values previously set -- 1101456: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1101456 Debian Bug Tracking Sys

[Pkg-javascript-devel] Processed: found 1101456 in 12

2025-04-27 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > found 1101456 12 Bug #1101456 [javascript-common] fails to upgrade Marked as found in versions javascript-common/12. > thanks Stopping processing here. Please contact me if you need assistance. -- 1101456: https://bugs.debian.org/cgi-bin/bugrepo

[Pkg-javascript-devel] Bug#1101456: not false positive

2025-04-27 Thread VA
The given commands output `No conf matches javascript-common` and `1`. Also now: ``` # LANG=C dpkg --configure --pending Setting up javascript-common (12) ... ln: failed to create symbolic link '/etc/lighttpd/conf-enabled/90-javascript-alias.conf': File exists dpkg: error processing package ja

[Pkg-javascript-devel] Processed: not false positive

2025-04-27 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > reopen 1101456 Bug #1101456 {Done: Yadd } [javascript-common] fails to upgrade Bug reopened Ignoring request to alter fixed versions of bug #1101456 to the same values previously set > thanks Stopping processing here. Please contact me if you ne

[Pkg-javascript-devel] Bug#1101456: not false positive

2025-04-27 Thread VA
reopen 1101456 thanks That's definitely not a false positive. It still fails to upgrade and thus now no package depending on it (like dokuwiki) can be installed on my system since javascript-common fails. -- Pkg-javascript-devel mailing list Pkg-javascript-devel@alioth-lists.debian.net https:

[Pkg-javascript-devel] Bug#1076350: Segfault with shared libuv on x86

2025-04-27 Thread Jérémy Lal
Le sam. 26 avr. 2025 à 19:03, Kurt Roeckx a écrit : > Is the problem that it just needs to be rebuild with the proper LFS flags? > > It's marked as pending, but I don't see anything pending in salsa. > I didn't push the changelog commit yet. The commit that fixes the rebuild is https://salsa.deb