About the security issues affecting mpg123 in Wheezy

2017-08-30 Thread Raphael Hertzog
Hello Sebastian, The Debian LTS team recently reviewed the security issue(s) affecting your package in Wheezy: https://security-tracker.debian.org/tracker/CVE-2017-12797 (and there are few other older issues that have been also ignored up to now) We decided that we would not prepare a wheezy secu

Bug#873718: Fixes for security vulnerabilities on libgig?

2017-08-30 Thread Raphael Hertzog
[ Copy to the Debian bugtracker ] Hello Christian, a few security issues have been reported against libgig: http://seclists.org/fulldisclosure/2017/Aug/39 The reproducer files are attached too: http://seclists.org/fulldisclosure/2017/Aug/att-39/poc_zip.bin I wanted to check that you were aware

Bug#873718: Multiple security issues (CVE-2017-12950 to CVE-2017-12954)

2017-08-30 Thread Raphael Hertzog
Source: libgig X-Debbugs-CC: t...@security.debian.org secure-testing-t...@lists.alioth.debian.org Severity: grave Tags: security Hi, the following vulnerabilities were published for libgig. See http://seclists.org/fulldisclosure/2017/Aug/39 for the initial report with reproducer files. CVE-2017

Wheezy update of lame?

2017-07-11 Thread Raphael Hertzog
Dear Fabian and other maintainer(s), The Debian LTS team would like to fix the security issues which are currently open in the Wheezy version of lame: https://security-tracker.debian.org/tracker/CVE-2017-9872 https://security-tracker.debian.org/tracker/CVE-2017-9871 https://security-tracker.debian

Bug#781806: squeeze update of das-watchdog?

2015-04-10 Thread Raphael Hertzog
Hello dear maintainer(s), the Debian LTS team would like to fix the security issues which are currently open in the Squeeze version of das-watchdog: https://security-tracker.debian.org/tracker/CVE-2015-2831 Would you like to take care of this yourself? We are still understaffed so any help is alw

Bug#780624: libmpeg2-4: introduces new symbols

2015-03-16 Thread Raphael Geissert
directly, perhaps picked up?, do not have a proper versioned dependency on libmpeg2-4. One such package is gstreamer1.0-plugins-ugly, though there might be others. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net ___ pkg

Bug#772403: rotter: bashism in /bin/sh script

2014-12-06 Thread Raphael Geissert
about how to fix bashisms can be found at: https://wiki.ubuntu.com/DashAsBinSh Thanks in advance, Raphael Geissert ___ pkg-multimedia-maintainers mailing list pkg-multimedia-maintainers@lists.alioth.debian.org http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-multimedia-maintainers

Bug#772347: xbmc: bashism in /bin/sh script

2014-12-06 Thread Raphael Geissert
and the script, and determine what the proper severity of the bug is, and adjust it accordingly. If it's important or greater please hurry to get this fixed for jessie. Hints about how to fix bashisms can be found at: https://wiki.ubuntu.com/DashAsBinSh Thanks in advance, Raphael Geissert _

Bug#772354: mjpegtools: bashism in /bin/sh script

2014-12-06 Thread Raphael Geissert
ry to get this fixed for jessie. Hints about how to fix bashisms can be found at: https://wiki.ubuntu.com/DashAsBinSh Thanks in advance, Raphael Geissert ___ pkg-multimedia-maintainers mailing list pkg-multimedia-maintainers@lists.alioth.debian.org http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-multimedia-maintainers

Bug#772264: din: bashism in /bin/sh script

2014-12-06 Thread Raphael Geissert
dash is the default /bin/sh. Please closely examine the above output and the script, and determine what the proper severity of the bug is, and adjust it accordingly. If it's important or greater please hurry to get this fixed for jessie. Hints about how to fix bashisms can be found at: https

Bug#772257: dvblast: bashism in /bin/sh script

2014-12-06 Thread Raphael Geissert
found at: https://wiki.ubuntu.com/DashAsBinSh Thanks in advance, Raphael Geissert ___ pkg-multimedia-maintainers mailing list pkg-multimedia-maintainers@lists.alioth.debian.org http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-multimedia-maintainers

Bug#772223: bristol: bashism in /bin/sh script

2014-12-06 Thread Raphael Geissert
Hints about how to fix bashisms can be found at: https://wiki.ubuntu.com/DashAsBinSh Thanks in advance, Raphael Geissert ___ pkg-multimedia-maintainers mailing list pkg-multimedia-maintainers@lists.alioth.debian.org http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-multimedia-maintainers

Re: Bug#729203: [FFmpeg-devel] Reintroducing FFmpeg to Debian

2014-07-30 Thread Raphael Geissert
(and personal) O, if you want to see ffmpeg in Jessie or later, you should replace libav - i.e. no silly one binary + libraries that won't work for anything else. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net ___ pk

Re: Re: Bug#729203: [FFmpeg-devel] Reintroducing FFmpeg to Debian

2014-07-29 Thread Raphael Geissert
On Tuesday 29 July 2014 18:43:17 Andreas Cadhalpun wrote: > On 29.07.2014 09:47, Raphael Geissert wrote: > > Andreas Cadhalpun wrote: > >> According to the changelog[1], there have been 8 security updates for > >> ffmpeg in squeeze. > > > > There wou

Re: Bug#729203: [FFmpeg-devel] Reintroducing FFmpeg to Debian

2014-07-29 Thread Raphael Geissert
xample, for incomplete checks - checks that don't exist in the 0.5 branch. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net ___ pkg-multimedia-maintainers mailing list pkg-multimedia-maintainers@lists.alioth.debi

Bug#737534: vlc: unsafe use of libtar

2014-02-03 Thread Raphael Geissert
about to be extracted that none contains a ../, and something similar for symlinks. Alternatively, vlc could just use tar(1) to unpack the tarballs, or drop support for skins or skins in tarballs. What do you think? This should probably be forwarded to upstream. Cheers, -- Raphael Geissert

Bug#705601: libflac-dev conflicting with boost::shared_ptr

2013-04-19 Thread raphael
first looking for header files in user specified search paths. raphael:~/programowanie/test/flac_bug $ g++ main.cpp `pkg-config --cflags flac` --verbose Using built-in specs. COLLECT_GCC=g++ COLLECT_LTO_WRAPPER=/usr/lib/gcc/i486-linux-gnu/4.7/lto-wrapper Target: i486-linux-gnu Configured with: .

Bug#705601: libflac-dev conflicting with boost::shared_ptr

2013-04-17 Thread raphael
Package: libflac-dev Version: 1.2.1-6 When I used together this libraries I couldn't build a project. Here is a simple example (including my simple and ugly solution): $ cat main.cpp #include class test { public: int method() {return 1;} }; int main() { boost::shared_ptr a(new t

libflac-dev conflicting with boost::shared_ptr

2013-04-16 Thread raphael
To: pkg-multimedia-maintainers@lists.alioth.debian.org From: raph...@gfreedom.org Subject: libflac-dev conflicting with boost::shared_ptr Package: libflac-dev Version: 1.2.1-6 When I used together this libraries I couldn't build a project. Here is a simple example (including my simple and ugly s

Bug#690617: mjpegtools: bashism in /bin/sh script

2012-10-15 Thread Raphael Geissert
hich doesn't provide such an extra feature) as /bin/sh is likely to lead to errors or unexpected behaviours. You can find hints about how to fix bashisms at: https://wiki.ubuntu.com/DashAsBinSh Thank you, Raphael Geissert ___ pkg-multimedia-maintai

Bug#661197: CVE-2012-0270: buffer overflows

2012-02-24 Thread Raphael Geissert
Package: csound Severity: grave Tags: security Hi, Two vulnerabilities have been found in csound. Please refer to the following page for more information: http://secunia.com/secunia_research/2012-3/ Regards, Raphael Geissert ___ pkg-multimedia

The trigger in your Debian packages

2011-06-03 Thread Raphael Hertzog
in Domingo dictionaries-common Benjamin Drung vlc (U) Sebastian Dröge gconf (U) gdk-pixbuf (U) glib2.0 (U) gnome-icon-theme (U) hal (U) shared-mime-info Free Ekanayaka twisted (U) twisted-conch (U) twisted-runner (U) Rene Engelhard dictionarie

Bug#598283: ardour: CVE-2010-3349: insecure library loading

2010-09-27 Thread Raphael Geissert
VE-2010-3349. Please make sure you mention it when forwarding this report to upstream and when fixing this bug (everywhere: upstream and here at Debian.) [0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3349 [1] http://security-tracker.debian.org/tracker/CVE-2010-3349 Si

Bug#598285: bristol: CVE-2010-3351: insecure library loading

2010-09-27 Thread Raphael Geissert
name.cgi?name=CVE-2010-3351 [1] http://security-tracker.debian.org/tracker/CVE-2010-3351 Sincerely, Raphael Geissert ___ pkg-multimedia-maintainers mailing list pkg-multimedia-maintainers@lists.alioth.debian.org http://lists.alioth.debian.org/m

Bug#598282: ardour-i686: CVE-2010-3349: insecure library loading

2010-09-27 Thread Raphael Geissert
id CVE-2010-3349. Please make sure you mention it when forwarding this report to upstream and when fixing this bug (everywhere: upstream and here at Debian.) [0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3349 [1] http://security-tracker.debian.org/tracker/CVE-2010-3349 Si

Bug#567442: mediatomb: incorrect init scripts dependencies

2010-02-03 Thread Raphael Geissert
On 3 February 2010 15:43, Mehdi wrote: > On  0, Raphael Geissert wrote: >> Package: mediatomb >> Version: 0.12.0~svn2018-4 >> Severity: important >> User:     initscripts-ng-de...@lists.alioth.debian.org >> Usertags: incorrect-dependency >> > [...] >

Bug#567442: mediatomb: incorrect init scripts dependencies

2010-01-28 Thread Raphael Geissert
, possibly preventing the other script from working properly. Please fix the dependencies. P.S. this is a release goal. Regards, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net ___ pkg-multimedia-maintainers mailing list pkg