[Secure-testing-commits] r18112 - data/DSA

2012-01-10 Thread Luk Claes
Author: luk Date: 2012-01-10 22:25:12 + (Tue, 10 Jan 2012) New Revision: 18112 Modified: data/DSA/list Log: Complete squeeze and lenny fixed versions for openttd Modified: data/DSA/list === --- data/DSA/list 2012-01-10

Bug#655333: installation-report: no graphical install, btrfs I/O errors, configuring grub failed

2012-01-10 Thread Luk Claes
Package: installation-reports Version: 2.45 Severity: important Dear Maintainer, When I tried the graphical install, it just hang. So I continued with the non-graphical install. After partitioning (choosing btrfs for all but the swap partition), when installing the base system the root

Bug#655333: installation-report: no graphical install, btrfs I/O errors, configuring grub failed

2012-01-10 Thread Luk Claes
Package: installation-reports Version: 2.45 Severity: important Dear Maintainer, When I tried the graphical install, it just hang. So I continued with the non-graphical install. After partitioning (choosing btrfs for all but the swap partition), when installing the base system the root

[Secure-testing-commits] r18092 - data/DSA

2012-01-08 Thread Luk Claes
Author: luk Date: 2012-01-09 06:59:18 + (Mon, 09 Jan 2012) New Revision: 18092 Modified: data/DSA/list Log: Prepare DSA for cacti Modified: data/DSA/list === --- data/DSA/list 2012-01-09 05:20:44 UTC (rev 18091) +++

Re: zram Usage as Default in Debian (?)

2012-01-08 Thread Luk Claes
On 01/08/2012 04:22 AM, Paul Wise wrote: On Sun, Jan 8, 2012 at 1:48 AM, Rainer Dorsch wrote: I recently setup zram (for compressed swap space in RAM) on an older low RAM machine. I was quite happy with the result and started now to do the same setup also on my other machines. I am wondering

Bug#654176: O: libxml2 -- GNOME XML library

2012-01-08 Thread Luk Claes
On 01/08/2012 08:10 PM, Andrew Shadura wrote: Hello, On Fri, 06 Jan 2012 12:48:03 +1000 Alexander Zangerl a...@snafu.priv.at wrote: On Mon, 02 Jan 2012 23:14:52 +0100, Luk Claes writes: I want to help with the packaging of libxml2 and libxslt, though would like to have co-maintainers, so

Bug#654176: O: libxml2 -- GNOME XML library

2012-01-08 Thread Luk Claes
On 01/08/2012 08:10 PM, Andrew Shadura wrote: Hello, On Fri, 06 Jan 2012 12:48:03 +1000 Alexander Zangerl a...@snafu.priv.at wrote: On Mon, 02 Jan 2012 23:14:52 +0100, Luk Claes writes: I want to help with the packaging of libxml2 and libxslt, though would like to have co-maintainers, so

[Secure-testing-commits] r18044 - data/CVE

2012-01-05 Thread Luk Claes
Author: luk Date: 2012-01-05 20:39:18 + (Thu, 05 Jan 2012) New Revision: 18044 Modified: data/CVE/list Log: Mark openldap as fixed Modified: data/CVE/list === --- data/CVE/list 2012-01-05 20:12:15 UTC (rev 18043) +++

Bug#654701: [Pkg-samba-maint] Bug#654701: cifs-utils: Windows share cannot be mounted anymore after dist-upgrade on wheezy (5.1 - 5.2)

2012-01-05 Thread Luk Claes
On 01/05/2012 11:43 AM, Didier Trosset wrote: I have been mounting a Windows share for years. Since I 'apt-get dist-upgrade' my Debian 'wheezy' testing yesterday (Wed Jan 4th 2012), I cannot mount it anymore. This upgrade brings in cifs-utils version 5.2. The share used to be mounted

[Secure-testing-commits] r18004 - data/CVE

2012-01-03 Thread Luk Claes
Author: luk Date: 2012-01-03 17:39:57 + (Tue, 03 Jan 2012) New Revision: 18004 Modified: data/CVE/list Log: mark ax25-tools as fixed Modified: data/CVE/list === --- data/CVE/list 2012-01-03 09:14:21 UTC (rev 18003) +++

[Secure-testing-commits] r18005 - data/CVE

2012-01-03 Thread Luk Claes
Author: luk Date: 2012-01-03 17:45:48 + (Tue, 03 Jan 2012) New Revision: 18005 Modified: data/CVE/list Log: Mark tinyproxy as fixed Modified: data/CVE/list === --- data/CVE/list 2012-01-03 17:39:57 UTC (rev 18004) +++

[Secure-testing-commits] r18006 - data/CVE

2012-01-03 Thread Luk Claes
Author: luk Date: 2012-01-03 17:56:08 + (Tue, 03 Jan 2012) New Revision: 18006 Modified: data/CVE/list Log: update on rails Modified: data/CVE/list === --- data/CVE/list 2012-01-03 17:45:48 UTC (rev 18005) +++

Accepted ax25-tools 0.0.8-13.2 (source i386)

2012-01-03 Thread Luk Claes
...@lists.debian.org Changed-By: Luk Claes l...@debian.org Description: ax25-tools - tools for AX.25 interface configuration ax25-xtools - tools for AX.25 interface configuration -- X11-based Closes: 638198 Changes: ax25-tools (0.0.8-13.2) unstable; urgency=medium . * Non-maintainer upload. * ax25

[Secure-testing-commits] r18000 - data/CVE

2012-01-02 Thread Luk Claes
Author: luk Date: 2012-01-02 23:09:28 + (Mon, 02 Jan 2012) New Revision: 18000 Modified: data/CVE/list Log: rails issues Modified: data/CVE/list === --- data/CVE/list 2012-01-02 20:02:40 UTC (rev 17999) +++

[Secure-testing-commits] r18001 - data/CVE

2012-01-02 Thread Luk Claes
Author: luk Date: 2012-01-02 23:21:31 + (Mon, 02 Jan 2012) New Revision: 18001 Modified: data/CVE/list Log: mark asterisk as fixed Modified: data/CVE/list === --- data/CVE/list 2012-01-02 23:09:28 UTC (rev 18000) +++

Bug#654176: O: libxml2 -- GNOME XML library

2012-01-02 Thread Luk Claes
Hi Mike On 01/02/2012 09:24 AM, Mike Hommey wrote: Due to lack of time and interest, I intend to orphan the libxml2 package. I want to help with the packaging of libxml2 and libxslt, though would like to have co-maintainers, so I hope some more people join in. Cheers Luk -- To

Bug#654176: O: libxml2 -- GNOME XML library

2012-01-02 Thread Luk Claes
Hi Mike On 01/02/2012 09:24 AM, Mike Hommey wrote: Due to lack of time and interest, I intend to orphan the libxml2 package. I want to help with the packaging of libxml2 and libxslt, though would like to have co-maintainers, so I hope some more people join in. Cheers Luk -- To

[Secure-testing-commits] r17954 - data/CVE

2012-01-01 Thread Luk Claes
Author: luk Date: 2012-01-01 10:34:29 + (Sun, 01 Jan 2012) New Revision: 17954 Modified: data/CVE/list Log: Mark some packages as removed, mark some with newly named packages Modified: data/CVE/list === --- data/CVE/list

[Secure-testing-commits] r17955 - bin

2012-01-01 Thread Luk Claes
Author: luk Date: 2012-01-01 10:35:28 + (Sun, 01 Jan 2012) New Revision: 17955 Modified: bin/get-todo-items Log: Also show CVEs that are not numbered correctly Modified: bin/get-todo-items === --- bin/get-todo-items

[Secure-testing-commits] r17956 - data/CVE

2012-01-01 Thread Luk Claes
Author: luk Date: 2012-01-01 10:52:37 + (Sun, 01 Jan 2012) New Revision: 17956 Modified: data/CVE/list Log: Mark some more as removed Modified: data/CVE/list === --- data/CVE/list 2012-01-01 10:35:28 UTC (rev 17955) +++

[Secure-testing-commits] r17958 - data/CVE

2012-01-01 Thread Luk Claes
Author: luk Date: 2012-01-01 15:02:07 + (Sun, 01 Jan 2012) New Revision: 17958 Modified: data/CVE/list Log: Some more removed, mark doctrine as fixed, mark evince as not-affected in unstable Modified: data/CVE/list === ---

[Secure-testing-commits] r17962 - data/CVE

2012-01-01 Thread Luk Claes
Author: luk Date: 2012-01-01 18:44:52 + (Sun, 01 Jan 2012) New Revision: 17962 Modified: data/CVE/list Log: Mark libxml2 as fixed Modified: data/CVE/list === --- data/CVE/list 2012-01-01 16:59:59 UTC (rev 17961) +++

[Secure-testing-commits] r17964 - data/CVE

2012-01-01 Thread Luk Claes
Author: luk Date: 2012-01-01 19:36:35 + (Sun, 01 Jan 2012) New Revision: 17964 Modified: data/CVE/list Log: mark other libxml2 issue as fixed, thttpd as removed Modified: data/CVE/list === --- data/CVE/list 2012-01-01

[Secure-testing-commits] r17976 - data/CVE

2012-01-01 Thread Luk Claes
Author: luk Date: 2012-01-01 23:32:44 + (Sun, 01 Jan 2012) New Revision: 17976 Modified: data/CVE/list Log: Mark xen-3.0 and mozilla* as removed Modified: data/CVE/list === --- data/CVE/list 2012-01-01 23:07:58 UTC (rev

[Secure-testing-commits] r17977 - data/CVE

2012-01-01 Thread Luk Claes
Author: luk Date: 2012-01-01 23:46:01 + (Sun, 01 Jan 2012) New Revision: 17977 Modified: data/CVE/list Log: nagios3 is affected Modified: data/CVE/list === --- data/CVE/list 2012-01-01 23:32:44 UTC (rev 17976) +++

[Secure-testing-commits] r17978 - data/CVE

2012-01-01 Thread Luk Claes
Author: luk Date: 2012-01-01 23:57:38 + (Sun, 01 Jan 2012) New Revision: 17978 Modified: data/CVE/list Log: mantis confirmed to be fixed Modified: data/CVE/list === --- data/CVE/list 2012-01-01 23:46:01 UTC (rev 17977)

[Secure-testing-commits] r17986 - data/CVE

2012-01-01 Thread Luk Claes
Author: luk Date: 2012-01-02 06:31:40 + (Mon, 02 Jan 2012) New Revision: 17986 Modified: data/CVE/list Log: django-celery not affected Modified: data/CVE/list === --- data/CVE/list 2012-01-02 03:56:25 UTC (rev 17985)

[Secure-testing-commits] r17987 - data/CVE

2012-01-01 Thread Luk Claes
Author: luk Date: 2012-01-02 06:39:26 + (Mon, 02 Jan 2012) New Revision: 17987 Modified: data/CVE/list Log: iscsitarget confirmed to be affected Modified: data/CVE/list === --- data/CVE/list 2012-01-02 06:31:40 UTC (rev

[Secure-testing-commits] r17988 - data/CVE

2012-01-01 Thread Luk Claes
Author: luk Date: 2012-01-02 06:47:15 + (Mon, 02 Jan 2012) New Revision: 17988 Modified: data/CVE/list Log: confirmed libspring-2.5-java not affected Modified: data/CVE/list === --- data/CVE/list 2012-01-02 06:39:26 UTC

[Secure-testing-commits] r17989 - data/CVE

2012-01-01 Thread Luk Claes
Author: luk Date: 2012-01-02 07:01:16 + (Mon, 02 Jan 2012) New Revision: 17989 Modified: data/CVE/list Log: ruby1.8 confirmed to be affected and fixed in unstable Modified: data/CVE/list === --- data/CVE/list 2012-01-02

Accepted libxml2 2.7.8.dfsg-5.1 (source i386 all)

2012-01-01 Thread Luk Claes
: high Maintainer: Debian XML/SGML Group debian-xml-sgml-p...@lists.alioth.debian.org Changed-By: Luk Claes l...@debian.org Description: libxml2- GNOME XML library libxml2-dbg - Debugging symbols for the GNOME XML library libxml2-dev - Development files for the GNOME XML library libxml2-doc

Bug#651620: ~/.rocksndiamonds/ is world-writable

2012-01-01 Thread Luk Claes
Hi I guess at least below needs changing. Probably there also needs to be some existing modes be changed (in the postinst?). Cheers Luk --- rocksndiamonds-3.3.0.1+dfsg1.orig/src/libgame/setup.c 2010-03-27 21:40:16.0 +0100 +++ rocksndiamonds-3.3.0.1+dfsg1/src/libgame/setup.c

Bug#644289: polipo denial of service (CVE-2011-3596)

2012-01-01 Thread Luk Claes
Hi There seems to be a pointer to a patch in the RedHat tracker [1]. Cheers Luk [1] https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-3596 -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#639890: hammerhead: insecure temporary file use

2012-01-01 Thread Luk Claes
Hi The easiest way to fix this is probably to make sure the following directives are sanely set in the default configuration (SOURCE/doc/test.conf - /etc/hh.conf currently) and make sure these exist or can be created without problems: Scenario_directory Log_filename Report_Log Cheers Luk --

Bug#638198: ax25-tools: diff for NMU version 0.0.8-13.2

2012-01-01 Thread Luk Claes
/changelog --- ax25-tools-0.0.8/debian/changelog +++ ax25-tools-0.0.8/debian/changelog @@ -1,3 +1,11 @@ +ax25-tools (0.0.8-13.2) unstable; urgency=medium + + * Non-maintainer upload. + * ax25/beacon.c: fix possible privilege escalation CVE-2011-2910 +Closes: #638198. + + -- Luk Claes l

Bug#651620: ~/.rocksndiamonds/ is world-writable

2012-01-01 Thread Luk Claes
Hi I guess at least below needs changing. Probably there also needs to be some existing modes be changed (in the postinst?). Cheers Luk --- rocksndiamonds-3.3.0.1+dfsg1.orig/src/libgame/setup.c 2010-03-27 21:40:16.0 +0100 +++ rocksndiamonds-3.3.0.1+dfsg1/src/libgame/setup.c

Bug#638198: ax25-tools: diff for NMU version 0.0.8-13.2

2012-01-01 Thread Luk Claes
/changelog --- ax25-tools-0.0.8/debian/changelog +++ ax25-tools-0.0.8/debian/changelog @@ -1,3 +1,11 @@ +ax25-tools (0.0.8-13.2) unstable; urgency=medium + + * Non-maintainer upload. + * ax25/beacon.c: fix possible privilege escalation CVE-2011-2910 +Closes: #638198. + + -- Luk Claes l

[Secure-testing-commits] r17933 - data/CVE

2011-12-31 Thread Luk Claes
Author: luk Date: 2011-12-31 09:11:59 + (Sat, 31 Dec 2011) New Revision: 17933 Modified: data/CVE/list Log: Mark ecryptfs-utils issues as fixed, one of them also affect kernel (to be checked) Modified: data/CVE/list === ---

[Secure-testing-commits] r17934 - data/CVE

2011-12-31 Thread Luk Claes
Author: luk Date: 2011-12-31 09:14:59 + (Sat, 31 Dec 2011) New Revision: 17934 Modified: data/CVE/list Log: Mark another ecryptfs-utils issue as fixed Modified: data/CVE/list === --- data/CVE/list 2011-12-31 09:11:59

[Secure-testing-commits] r17938 - data/CVE

2011-12-31 Thread Luk Claes
Author: luk Date: 2011-12-31 13:50:40 + (Sat, 31 Dec 2011) New Revision: 17938 Modified: data/CVE/list Log: mark doctrine and cherokee as fixed in squeeze (pu), mark some old ones Modified: data/CVE/list === --- data/CVE/list

[Secure-testing-commits] r17939 - bin

2011-12-31 Thread Luk Claes
Author: luk Date: 2011-12-31 13:51:45 + (Sat, 31 Dec 2011) New Revision: 17939 Modified: bin/get-todo-items Log: Also show proper CVE when RESERVED Modified: bin/get-todo-items === --- bin/get-todo-items 2011-12-31 13:50:40

[Secure-testing-commits] r17943 - data/CVE

2011-12-31 Thread Luk Claes
Author: luk Date: 2011-12-31 14:06:28 + (Sat, 31 Dec 2011) New Revision: 17943 Modified: data/CVE/list Log: Revert for cherokee, it's already in next-point-update.txt Modified: data/CVE/list === --- data/CVE/list

[Secure-testing-commits] r17944 - doc

2011-12-31 Thread Luk Claes
Author: luk Date: 2011-12-31 14:16:07 + (Sat, 31 Dec 2011) New Revision: 17944 Modified: doc/narrative_introduction Log: Fix typo and add next-point-update.txt (pu) handling Modified: doc/narrative_introduction === ---

[Secure-testing-commits] r17953 - data/CVE

2011-12-31 Thread Luk Claes
Author: luk Date: 2012-01-01 01:06:25 + (Sun, 01 Jan 2012) New Revision: 17953 Modified: data/CVE/list Log: Mark clearsilver and t1lib as fixed Modified: data/CVE/list === --- data/CVE/list 2011-12-31 21:14:21 UTC (rev

Accepted clearsilver 0.10.5-1.3 (source i386)

2011-12-31 Thread Luk Claes
jesus.clim...@hispalinux.es Changed-By: Luk Claes l...@debian.org Description: clearsilver-dev - headers and static library for clearsilver libclearsilver-perl - Perl bindings for clearsilver python-clearsilver - Python bindings for clearsilver Closes: 649322 Changes: clearsilver (0.10.5-1.3) unstable

Accepted t1lib 5.1.2-3.3 (source all i386)

2011-12-31 Thread Luk Claes
Changed-By: Luk Claes l...@debian.org Description: libt1-5- Type 1 font rasterizer library - runtime libt1-5-dbg - Type 1 font rasterizer library - debugging runtime libt1-dev - Type 1 font rasterizer library - development libt1-doc - Type 1 font rasterizer library - developers

Accepted ipmitool 1.8.11-2+squeeze2 (source i386)

2011-12-31 Thread Luk Claes
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Format: 1.8 Date: Wed, 28 Dec 2011 13:53:15 +0100 Source: ipmitool Binary: ipmitool Architecture: source i386 Version: 1.8.11-2+squeeze2 Distribution: stable-security Urgency: high Maintainer: Matthew Johnson mj...@debian.org Changed-By: Luk Claes l

Accepted ipmitool 1.8.9-2+squeeze1 (source i386)

2011-12-31 Thread Luk Claes
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Format: 1.8 Date: Fri, 30 Dec 2011 09:12:15 +0100 Source: ipmitool Binary: ipmitool Architecture: source i386 Version: 1.8.9-2+squeeze1 Distribution: oldstable-security Urgency: high Maintainer: Matthew Johnson mj...@debian.org Changed-By: Luk Claes l

[Secure-testing-commits] r17922 - data/CVE

2011-12-30 Thread Luk Claes
Author: luk Date: 2011-12-30 18:31:04 + (Fri, 30 Dec 2011) New Revision: 17922 Modified: data/CVE/list Log: oprofile confirmed to be fixed in squeeze Modified: data/CVE/list === --- data/CVE/list 2011-12-30 17:28:40 UTC

[Secure-testing-commits] r17923 - data/CVE

2011-12-30 Thread Luk Claes
Author: luk Date: 2011-12-30 18:59:52 + (Fri, 30 Dec 2011) New Revision: 17923 Modified: data/CVE/list Log: dillo issue got fixed quite some time ago Modified: data/CVE/list === --- data/CVE/list 2011-12-30 18:31:04 UTC

[Secure-testing-commits] r17926 - data/CVE

2011-12-30 Thread Luk Claes
Author: luk Date: 2011-12-30 22:31:55 + (Fri, 30 Dec 2011) New Revision: 17926 Modified: data/CVE/list Log: Also mark XSS vulnerability in feedparser as fixed Modified: data/CVE/list === --- data/CVE/list 2011-12-30

[Secure-testing-commits] r17927 - data/CVE

2011-12-30 Thread Luk Claes
Author: luk Date: 2011-12-30 22:35:02 + (Fri, 30 Dec 2011) New Revision: 17927 Modified: data/CVE/list Log: feh got fixed in a new upstream version Modified: data/CVE/list === --- data/CVE/list 2011-12-30 22:31:55 UTC

[Secure-testing-commits] r17928 - data/CVE

2011-12-30 Thread Luk Claes
Author: luk Date: 2011-12-30 22:43:23 + (Fri, 30 Dec 2011) New Revision: 17928 Modified: data/CVE/list Log: Also mark other issue as fixed for hplip Modified: data/CVE/list === --- data/CVE/list 2011-12-30 22:35:02 UTC

[Secure-testing-commits] r17929 - data/CVE

2011-12-30 Thread Luk Claes
Author: luk Date: 2011-12-30 22:53:22 + (Fri, 30 Dec 2011) New Revision: 17929 Modified: data/CVE/list Log: libcloud got fixed in new upstream version Modified: data/CVE/list === --- data/CVE/list 2011-12-30 22:43:23

[Secure-testing-commits] r17930 - data/CVE

2011-12-30 Thread Luk Claes
Author: luk Date: 2011-12-30 23:51:55 + (Fri, 30 Dec 2011) New Revision: 17930 Modified: data/CVE/list Log: mark one offlineimap issue as fixed Modified: data/CVE/list === --- data/CVE/list 2011-12-30 22:53:22 UTC (rev

[Secure-testing-commits] r17931 - data/CVE

2011-12-30 Thread Luk Claes
Author: luk Date: 2011-12-31 00:01:27 + (Sat, 31 Dec 2011) New Revision: 17931 Modified: data/CVE/list Log: mark qemu-kvm issue as fixed Modified: data/CVE/list === --- data/CVE/list 2011-12-30 23:51:55 UTC (rev 17930)

[Secure-testing-commits] r17932 - data/CVE

2011-12-30 Thread Luk Claes
Author: luk Date: 2011-12-31 00:26:41 + (Sat, 31 Dec 2011) New Revision: 17932 Modified: data/CVE/list Log: mark vlc issue as fixed Modified: data/CVE/list === --- data/CVE/list 2011-12-31 00:01:27 UTC (rev 17931) +++

Bug#652352: libxml2: diff for NMU version 2.7.8.dfsg-5.1

2011-12-30 Thread Luk Claes
. + * parser.c: Make sure parser returns when getting a Stop order. +CVE-2011-3905. + * Both closes: #652352. + + -- Luk Claes l...@debian.org Fri, 30 Dec 2011 18:31:13 +0100 + libxml2 (2.7.8.dfsg-5) unstable; urgency=low * xpath.c, xpointer.c, include/libxml/xpath.h: Hardening of XPath evaluation

Bug#653757: pu: package nfs-utils/1:1.2.2-4squeeze2

2011-12-30 Thread Luk Claes
mtab file (Closes: #629420) + + -- Luk Claes l...@debian.org Fri, 30 Dec 2011 18:58:07 +0100 + nfs-utils (1:1.2.2-4squeeze1) stable; urgency=low * Build with patch d6c1b35c6b40243bfd6fba2591c9f8f2653078c0 from upstream diff -Nru nfs-utils-1.2.2/debian/patches/17-fix-CVE-2011-1749.patch nfs

Bug#613857: [Pkg-cacti-maint] RFA: cacti -- Frontend to rrdtool for monitoring systems and services

2011-12-30 Thread Luk Claes
On 12/30/2011 08:08 PM, Mahyuddin Susanto wrote: Hello On Thu, Dec 29, 2011 at 6:08 PM, Luk Claes l...@debian.org wrote: In 05_no-adodb.patch why did you change the include_once to an include? Are you sure it's not included multiple times? In any way it's more clear if it would

Bug#613857: [Pkg-cacti-maint] RFA: cacti -- Frontend to rrdtool for monitoring systems and services

2011-12-30 Thread Luk Claes
On 12/30/2011 08:08 PM, Mahyuddin Susanto wrote: Hello On Thu, Dec 29, 2011 at 6:08 PM, Luk Claes l...@debian.org wrote: In 05_no-adodb.patch why did you change the include_once to an include? Are you sure it's not included multiple times? In any way it's more clear if it would

Bug#652352: libxml2: diff for NMU version 2.7.8.dfsg-5.1

2011-12-30 Thread Luk Claes
. + * parser.c: Make sure parser returns when getting a Stop order. +CVE-2011-3905. + * Both closes: #652352. + + -- Luk Claes l...@debian.org Fri, 30 Dec 2011 18:31:13 +0100 + libxml2 (2.7.8.dfsg-5) unstable; urgency=low * xpath.c, xpointer.c, include/libxml/xpath.h: Hardening of XPath evaluation

Bug#653757: pu: package nfs-utils/1:1.2.2-4squeeze2

2011-12-30 Thread Luk Claes
mtab file (Closes: #629420) + + -- Luk Claes l...@debian.org Fri, 30 Dec 2011 18:58:07 +0100 + nfs-utils (1:1.2.2-4squeeze1) stable; urgency=low * Build with patch d6c1b35c6b40243bfd6fba2591c9f8f2653078c0 from upstream diff -Nru nfs-utils-1.2.2/debian/patches/17-fix-CVE-2011-1749.patch nfs

[Secure-testing-commits] r17910 - data/CVE

2011-12-29 Thread Luk Claes
Author: luk Date: 2011-12-29 21:52:30 + (Thu, 29 Dec 2011) New Revision: 17910 Modified: data/CVE/list Log: mapserver was fixed in new upstream version Modified: data/CVE/list === --- data/CVE/list 2011-12-29 21:14:24

Bug#613857: [Pkg-cacti-maint] RFA: cacti -- Frontend to rrdtool for monitoring systems and services

2011-12-29 Thread Luk Claes
On 12/29/2011 02:20 AM, Mahyuddin Susanto wrote: Hi, On 12/29/2011 04:57 AM, Luk Claes wrote: Hi It's apparently taking a long time before an upload happens. I know that Sean is kind of on VAC, but maybe I can help out and sponsor some upload and work on the security bugs? Sure, we

Bug#628456: CVE-2011-0766: cryptographic weakness

2011-12-29 Thread Luk Claes
Hi It looks like this bug still needs fixing in squeeze. I'm not sure what impact the VSN changes have in the upstream patch [1]. Can you have a look and maybe prepare and test a fixed package? Cheers Luk [1] https://github.com/erlang/otp/commit/f228601de45c5 -- To UNSUBSCRIBE, email to

Bug#628456: [Pkg-erlang-devel] Bug#628456: CVE-2011-0766: cryptographic weakness

2011-12-29 Thread Luk Claes
On 12/29/2011 12:38 PM, Sergei Golovan wrote: Hi! On Thu, Dec 29, 2011 at 12:48 PM, Luk Claes l...@debian.org wrote: Hi It looks like this bug still needs fixing in squeeze. I'm not sure what impact the VSN changes have in the upstream patch [1]. Can you have a look and maybe prepare

Bug#628456: [Pkg-erlang-devel] Bug#628456: Bug#628456: CVE-2011-0766: cryptographic weakness

2011-12-29 Thread Luk Claes
On 12/29/2011 01:13 PM, Sergei Golovan wrote: On Thu, Dec 29, 2011 at 4:05 PM, Luk Claes l...@debian.org wrote: Are you sure the Security Team thinks it does not warrant a DSA? I would send the patch to the Security Team to see if they want to issue a DSA or rather have it go via proposed

Bug#613857: [Pkg-cacti-maint] RFA: cacti -- Frontend to rrdtool for monitoring systems and services

2011-12-29 Thread Luk Claes
On 12/29/2011 11:01 AM, Mahyuddin Susanto wrote: On 12/29/2011 03:33 PM, Luk Claes wrote: Can you upload the package for unstable to mentors.debian.net [1]? That would make my job as a sponsor easier. Thanks already! Yes, here there are: - for unstable: http://mentors.debian.net

Bug#649322: clearsilver: diff for NMU version 0.10.5-1.3

2011-12-29 Thread Luk Claes
vulnerability CVE-2011-4357 (Closes: #649322). + + -- Luk Claes l...@debian.org Thu, 29 Dec 2011 21:57:11 +0100 + clearsilver (0.10.5-1.2) unstable; urgency=low * Non-maintainer upload. diff -Nru clearsilver-0.10.5/debian/patches/CVE-2011-4357.diff clearsilver-0.10.5/debian/patches/CVE-2011-4357.diff

Bug#592797: ITA: smarty -- Template engine for PHP

2011-12-29 Thread Luk Claes
Hi smarty3 was introduced. I guess it obsoletes this smarty package and this one should get removed? In that case this bug should probably be reassigned and retitled appropriately and smarty3 should add a Provides: smarty so reverse dependencies don't stop working. Cheers Luk -- To

Bug#653635: t1lib: diff for NMU version 5.1.2-3.3

2011-12-29 Thread Luk Claes
pointer (Closes: #652996). + * Don't ship .la file anymore (Closes: #633247). + + -- Luk Claes l...@debian.org Thu, 29 Dec 2011 23:21:33 +0100 + t1lib (5.1.2-3.2) unstable; urgency=low * Non-maintainer upload. (version 5.1.2-3.2 triggered a problem with dak) diff -u t1lib-5.1.2/debian/patches

Bug#613857: [Pkg-cacti-maint] RFA: cacti -- Frontend to rrdtool for monitoring systems and services

2011-12-29 Thread Luk Claes
On 12/29/2011 02:20 AM, Mahyuddin Susanto wrote: Hi, On 12/29/2011 04:57 AM, Luk Claes wrote: Hi It's apparently taking a long time before an upload happens. I know that Sean is kind of on VAC, but maybe I can help out and sponsor some upload and work on the security bugs? Sure, we

Bug#613857: [Pkg-cacti-maint] RFA: cacti -- Frontend to rrdtool for monitoring systems and services

2011-12-29 Thread Luk Claes
On 12/29/2011 11:01 AM, Mahyuddin Susanto wrote: On 12/29/2011 03:33 PM, Luk Claes wrote: Can you upload the package for unstable to mentors.debian.net [1]? That would make my job as a sponsor easier. Thanks already! Yes, here there are: - for unstable: http://mentors.debian.net

Bug#592797: ITA: smarty -- Template engine for PHP

2011-12-29 Thread Luk Claes
Hi smarty3 was introduced. I guess it obsoletes this smarty package and this one should get removed? In that case this bug should probably be reassigned and retitled appropriately and smarty3 should add a Provides: smarty so reverse dependencies don't stop working. Cheers Luk -- To

Bug#628456: CVE-2011-0766: cryptographic weakness

2011-12-29 Thread Luk Claes
Hi It looks like this bug still needs fixing in squeeze. I'm not sure what impact the VSN changes have in the upstream patch [1]. Can you have a look and maybe prepare and test a fixed package? Cheers Luk [1] https://github.com/erlang/otp/commit/f228601de45c5 -- To UNSUBSCRIBE, email to

Bug#628456: [Pkg-erlang-devel] Bug#628456: CVE-2011-0766: cryptographic weakness

2011-12-29 Thread Luk Claes
On 12/29/2011 12:38 PM, Sergei Golovan wrote: Hi! On Thu, Dec 29, 2011 at 12:48 PM, Luk Claes l...@debian.org wrote: Hi It looks like this bug still needs fixing in squeeze. I'm not sure what impact the VSN changes have in the upstream patch [1]. Can you have a look and maybe prepare

Bug#628456: [Pkg-erlang-devel] Bug#628456: Bug#628456: CVE-2011-0766: cryptographic weakness

2011-12-29 Thread Luk Claes
On 12/29/2011 01:13 PM, Sergei Golovan wrote: On Thu, Dec 29, 2011 at 4:05 PM, Luk Claes l...@debian.org wrote: Are you sure the Security Team thinks it does not warrant a DSA? I would send the patch to the Security Team to see if they want to issue a DSA or rather have it go via proposed

Bug#649322: clearsilver: diff for NMU version 0.10.5-1.3

2011-12-29 Thread Luk Claes
vulnerability CVE-2011-4357 (Closes: #649322). + + -- Luk Claes l...@debian.org Thu, 29 Dec 2011 21:57:11 +0100 + clearsilver (0.10.5-1.2) unstable; urgency=low * Non-maintainer upload. diff -Nru clearsilver-0.10.5/debian/patches/CVE-2011-4357.diff clearsilver-0.10.5/debian/patches/CVE-2011-4357.diff

Accepted ipmitool 1.8.11-5 (source i386)

2011-12-28 Thread Luk Claes
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Format: 1.8 Date: Wed, 28 Dec 2011 12:34:15 +0100 Source: ipmitool Binary: ipmitool Architecture: source i386 Version: 1.8.11-5 Distribution: unstable Urgency: high Maintainer: Matthew Johnson mj...@debian.org Changed-By: Luk Claes l...@debian.org

Bug#613857: RFA: cacti -- Frontend to rrdtool for monitoring systems and services

2011-12-28 Thread Luk Claes
Hi It's apparently taking a long time before an upload happens. I know that Sean is kind of on VAC, but maybe I can help out and sponsor some upload and work on the security bugs? Cheers Luk -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe.

Bug#613857: RFA: cacti -- Frontend to rrdtool for monitoring systems and services

2011-12-28 Thread Luk Claes
Hi It's apparently taking a long time before an upload happens. I know that Sean is kind of on VAC, but maybe I can help out and sponsor some upload and work on the security bugs? Cheers Luk -- To UNSUBSCRIBE, email to debian-wnpp-requ...@lists.debian.org with a subject of unsubscribe.

Accepted cifs-utils 2:4.5-2+squeeze1 (source i386)

2011-12-17 Thread Luk Claes
...@lists.alioth.debian.org Changed-By: Luk Claes l...@debian.org Description: cifs-utils - Common Internet File System utilities smbfs - Common Internet File System utilities - compatibility package Changes: cifs-utils (2:4.5-2+squeeze1) stable; urgency=low . * Stable update to prevent mtab corruption

Bug#651897: pu: package cifs-utils/2:4.5-2+squeeze1

2011-12-14 Thread Luk Claes
On 12/14/2011 08:55 PM, Adam D. Barratt wrote: On Mon, 2011-12-12 at 23:54 +0100, Luk Claes wrote: The security team asked us to consider an upload to pu fixing 2 low severity security issues (which don't warrant a DSA). [...] +cifs-utils (2:4.5-2+squeeze1) stable; urgency=low

Bug#651897: pu: package cifs-utils/2:4.5-2+squeeze1

2011-12-14 Thread Luk Claes
On 12/14/2011 08:55 PM, Adam D. Barratt wrote: On Mon, 2011-12-12 at 23:54 +0100, Luk Claes wrote: The security team asked us to consider an upload to pu fixing 2 low severity security issues (which don't warrant a DSA). [...] +cifs-utils (2:4.5-2+squeeze1) stable; urgency=low

Bug#651826: Cannot create symlink /run/sendsigs.omit.d/rpcbind during upgrade

2011-12-13 Thread Luk Claes
severity 651826 important thanks On 12/13/2011 07:22 PM, Michael Schmitt wrote: apt-listbugs made me aware of this bugreport, I thought giving it a try nevertheless to 1.) get an english error-message 2.) see if it happens at all as the reporter mentioned a second reconfigure run did fix the

Bug#651826: Cannot create symlink /run/sendsigs.omit.d/rpcbind during upgrade

2011-12-13 Thread Luk Claes
severity 651826 important thanks On 12/13/2011 07:22 PM, Michael Schmitt wrote: apt-listbugs made me aware of this bugreport, I thought giving it a try nevertheless to 1.) get an english error-message 2.) see if it happens at all as the reporter mentioned a second reconfigure run did fix the

Bug#651897: pu: package cifs-utils/2:4.5-2+squeeze1

2011-12-12 Thread Luk Claes
to prevent mtab corruption +- CVE-2011-1678 +- CVE-2011-2724 + + -- Luk Claes l...@debian.org Mon, 12 Dec 2011 23:21:58 +0100 + cifs-utils (2:4.5-2) unstable; urgency=low * Lintian override for the suid-root binary. diff -Nru cifs-utils-4.5/debian/patches/CVE-2011-1678.patch cifs-utils

Bug#651897: pu: package cifs-utils/2:4.5-2+squeeze1

2011-12-12 Thread Luk Claes
to prevent mtab corruption +- CVE-2011-1678 +- CVE-2011-2724 + + -- Luk Claes l...@debian.org Mon, 12 Dec 2011 23:21:58 +0100 + cifs-utils (2:4.5-2) unstable; urgency=low * Lintian override for the suid-root binary. diff -Nru cifs-utils-4.5/debian/patches/CVE-2011-1678.patch cifs-utils

Bug#651619: curl: dependencies insufficient, application fails to load

2011-12-11 Thread Luk Claes
On 12/11/2011 04:53 PM, Alessandro Ghedini wrote: On Sat, Dec 10, 2011 at 06:30:17PM +0100, Alessandro Ghedini wrote: For reasons I do not know the shlibs version of the libcurl3 package was overridden by one of the previous maintainers of the package and hasn't been updated for long. I will

Bug#651619: curl: dependencies insufficient, application fails to load

2011-12-11 Thread Luk Claes
On 12/11/2011 06:46 PM, Alessandro Ghedini wrote: On Sun, Dec 11, 2011 at 05:07:43PM +0100, Luk Claes wrote: On 12/11/2011 04:53 PM, Alessandro Ghedini wrote: On Sat, Dec 10, 2011 at 06:30:17PM +0100, Alessandro Ghedini wrote: For reasons I do not know the shlibs version of the libcurl3

Bug#651619: curl: dependencies insufficient, application fails to load

2011-12-11 Thread Luk Claes
On 12/11/2011 04:53 PM, Alessandro Ghedini wrote: On Sat, Dec 10, 2011 at 06:30:17PM +0100, Alessandro Ghedini wrote: For reasons I do not know the shlibs version of the libcurl3 package was overridden by one of the previous maintainers of the package and hasn't been updated for long. I will

Bug#651619: curl: dependencies insufficient, application fails to load

2011-12-11 Thread Luk Claes
On 12/11/2011 06:46 PM, Alessandro Ghedini wrote: On Sun, Dec 11, 2011 at 05:07:43PM +0100, Luk Claes wrote: On 12/11/2011 04:53 PM, Alessandro Ghedini wrote: On Sat, Dec 10, 2011 at 06:30:17PM +0100, Alessandro Ghedini wrote: For reasons I do not know the shlibs version of the libcurl3

Accepted cifs-utils 2:5.2-1 (source i386)

2011-12-10 Thread Luk Claes
Changed-By: Luk Claes l...@debian.org Description: cifs-utils - Common Internet File System utilities smbfs - Common Internet File System utilities - compatibility package Closes: 651580 Changes: cifs-utils (2:5.2-1) unstable; urgency=low . * New upstream release (Closes: #651580

Bug#651580: [Pkg-samba-maint] Bug#651580: cifs-utils 5.2 released

2011-12-10 Thread Luk Claes
Hi Christian Thanks for the reminder, though I got 2 reminders before this one already ;-) I'll try to upload it today or tomorrow. Cheers Luk On 12/10/2011 07:55 AM, Christian PERRIER wrote: Package: cifs-utils Severity: wishlist - Forwarded message from Jeff Layton

Accepted nfs-utils 1:1.2.5-3 (source i386)

2011-12-09 Thread Luk Claes
Changed-By: Luk Claes l...@debian.org Description: nfs-common - NFS support files common to client and server nfs-kernel-server - support for NFS kernel server Closes: 633034 644358 651354 Changes: nfs-utils (1:1.2.5-3) unstable; urgency=low . [ Roger Leigh ] * /run transition: nfs-common

Bug#651507: Uninstallable, does not even upgrade

2011-12-09 Thread Luk Claes
Package: cups-driver-gutenprint Version: 5.2.7-2 Severity: serious Hi cups-driver-gutenprint is not installable as it depends on printer-driver-gutenprint which conflicts with it. The conflicts should be versioned and is only needed to prevent installing an old cups-driver-gutenprint while a

Bug#651507: Uninstallable, does not even upgrade

2011-12-09 Thread Luk Claes
Package: cups-driver-gutenprint Version: 5.2.7-2 Severity: serious Hi cups-driver-gutenprint is not installable as it depends on printer-driver-gutenprint which conflicts with it. The conflicts should be versioned and is only needed to prevent installing an old cups-driver-gutenprint while a

Bug#651507: Uninstallable, does not even upgrade

2011-12-09 Thread Luk Claes
Package: cups-driver-gutenprint Version: 5.2.7-2 Severity: serious Hi cups-driver-gutenprint is not installable as it depends on printer-driver-gutenprint which conflicts with it. The conflicts should be versioned and is only needed to prevent installing an old cups-driver-gutenprint while a

Bug#633034: nfs-utils: /run transition: Please switch to /run/sendsigs.omit.d

2011-12-07 Thread Luk Claes
On 12/07/2011 04:14 PM, Roger Leigh wrote: On Wed, Dec 07, 2011 at 02:55:55PM +, Roger Leigh wrote: On Wed, Dec 07, 2011 at 02:41:39PM +, Ben Hutchings wrote: On Wed, 2011-12-07 at 09:52 +, Roger Leigh wrote: tags 633034 + patch thanks On Thu, Jul 07, 2011 at 11:33:01PM +0100,

<    1   2   3   4   5   6   7   8   9   10   >