Bug#776303: CVE-2014-9601

2015-01-26 Thread Moritz Muehlenhoff
Source: pillow Severity: important Tags: security This was fixed upstream in 2.7.0 and was assigned CVE-2014-9601: http://pillow.readthedocs.org/releasenotes/2.7.0.html#png-text-chunk-size-limits Isolated fix is here:

Bug#504804: info

2015-01-26 Thread Henri Salo
This was closed because of https://bugs.debian.org/504804#13 It is about the inconsistence between --file=some_file and --file some_file THE EQUAL = sign. This is a different bug than =~ case. -- Henri Salo -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org

Bug#776034: fsck runs in parallel on same physical disk

2015-01-26 Thread Phillip Susi
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 1/26/2015 7:34 AM, Daniel Pocock wrote: The performance impact is not trivial. I have 28 LVs on my main /dev/md and 47 on an external disk that is used to replicate other filesystems. Both of these disks make a horrible thrashing sound

Bug#776296: Make it explicit that a space is not valid in -SField

2015-01-26 Thread Guillem Jover
Hi! On Mon, 2015-01-26 at 11:42:33 +, Chris Lamb wrote: Package: dpkg-dev Version: 1.17.23 Severity: wishlist Tags: patch Please clarify in the docs that a space is not valid in calls to -SField. For example, this is valid: $ dpkg-parsechangelog --show-field Field .. but this

Bug#776079: tkrplot: FTBFS in unstable - fatal error: tk.h: No such file or directory

2015-01-26 Thread Dirk Eddelbuettel
On 23 January 2015 at 17:17, James Cowgill wrote: | Source: tkrplot | Version: 0.0.23-2 | Severity: serious | Tags: sid | | Hi, | | tkrplot seems to FTBFS in unstable (but not in jessie) with the error: | gcc -std=gnu99 -I/usr/share/R/include -DNDEBUG -I/usr/include/tcl8.6

Bug#774748: #774748: ruby-redcloth: CVE-2012-6684

2015-01-26 Thread Moritz Mühlenhoff
On Fri, Jan 09, 2015 at 10:57:13PM +0100, Christian Hofstaedtler wrote: AFAICT there is no publicly available patch, and upstream is more or less dead. Redmine's patched redcloth3 looks very different from the current redcloth 4.x sources, so I have my doubts if forward porting this is

Bug#776306: mpdscribble: Fails to start because of error in pidfile creation

2015-01-26 Thread Marco Solieri
Package: mpdscribble Version: 0.22-5 Severity: grave Justification: renders package unusable With default configuration the service tries to create its pidfile in folder '/var/run/mpdscribble', but such a folder is not created by installation script, nor it persists to system reboot. This cause

Bug#776281: Aw: Re: Bug#776281: webkit2gtk FTBFS on hppa architecture (patch attached)

2015-01-26 Thread Helge Deller
The attached trivial patch fixes this. Thanks, we can include it in the next upload. Thanks! Does the browser run fine with this patch? epiphany runs partly OK. Simple webpages show up correctly. Complex webpages seem to generate problems. In both cases the webbrowser sometimes shows a

Bug#775866: vlc: multiple vulnerabilities

2015-01-26 Thread Moritz Mühlenhoff
On Tue, Jan 20, 2015 at 09:47:26PM +0100, Yves-Alexis Perez wrote: * The potential invalid writes in modules/services_discovery/sap.c and modules/access/ftp.c were not fixed as I did not provide a trigger. Note, that the code looks very similar to the confirmed bug in

Bug#774854: race condition between fur and fex_cleanup

2015-01-26 Thread Kilian Krause
Hi Moritz, On Mon, Jan 26, 2015 at 12:28:00PM +0100, Moritz Mühlenhoff wrote: On Mon, Dec 22, 2014 at 10:33:50PM +0100, Kilian Krause wrote: Package: fex Version: 20140917-1 Severity: serious Tags: security patch upstream pending confirmed jessie As upstream has released a new

Bug#776276: unblock: open-iscsi/2.0.873+git0.3b4b4500-4

2015-01-26 Thread Michael Biebl
Am 26.01.2015 um 08:43 schrieb Ritesh Raj Sarraf: Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock Please unblock package open-iscsi open-iscsi currently using SysV init scripts for operation. The current init scripts, when run

Bug#776281: Re: Bug#776281: webkit2gtk FTBFS on hppa architecture (patch attached)

2015-01-26 Thread Alberto Garcia
On Mon, Jan 26, 2015 at 03:40:57PM +0100, Helge Deller wrote: Complex webpages seem to generate problems. In both cases the webbrowser sometimes shows a screen like the one attached (screenshot attached). Ok, interesting... this is unrelated to this bug, though, but if you want to file a

Bug#766938: systemd: network-pre.target doesn't seem to be guaranteed to run before the network is up

2015-01-26 Thread Martin Pitt
Control: tag -1 pending Hey Christoph, Christoph Anton Mitterer [2014-10-27 3:09 +0100]: Maybe I just miss something, but AFAIU, network-pre.target is not guaranteed to run before any networking is brougt up (which is the whole point of network-pre.target). network.target has an After= on

Bug#776034: fsck runs in parallel on same physical disk

2015-01-26 Thread Karel Zak
On Mon, Jan 26, 2015 at 10:36:02AM +0100, Daniel Pocock wrote: On 26/01/15 10:32, Karel Zak wrote: On Mon, Jan 26, 2015 at 02:24:04AM +0100, Michael Biebl wrote: -l Create an exclusive flock(2) lock file (/run/fsck/diskname.lock) for whole-disk device.

Bug#726119: also affected by this bug

2015-01-26 Thread Ralph J.Mayer
sshoptions don't make it into the duplicity config Viele Grüße / Kind Regards / Cordiali Saluti / Met vriendelijke groet Ralph J.Mayer -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#776281: webkit2gtk FTBFS on hppa architecture (patch attached)

2015-01-26 Thread Alberto Garcia
Control: tags -1 pending The attached trivial patch fixes this. Thanks, we can include it in the next upload. Does the browser run fine with this patch? By the way, it seems ALPHA needs a similiar patch: It would be nice if someone could try it first. Berto -- To UNSUBSCRIBE, email to

Bug#775715: [Pkg-javascript-devel] Bug#775715: libv8-3.14: limiting security support

2015-01-26 Thread Bálint Réczey
Hi Michael, Control: tags -1 pending 2015-01-19 7:17 GMT+01:00 Michael Gilbert mgilb...@debian.org: package: libv8-3.14 version: 3.14.5.8-8 severity: grave tags: security Hi, the security team has decided that this package will not receive security support for jessie. This has already

Bug#775662: oss4: Insufficient validation of USB device descriptors

2015-01-26 Thread Moritz Mühlenhoff
On Sun, Jan 18, 2015 at 10:24:30AM +, Ben Hutchings wrote: Source: oss4 Version: 4.2-build2006-2 Severity: critical Tags: security In kernel/drv/oss_usb/oss_usb.c: OSS maintainers, did you forward this upstream? Cheers, Moritz -- To UNSUBSCRIBE, email to

Bug#776300: Add 'go back' button to review choices

2015-01-26 Thread Georg Herrmann
Package: reportbug Version: 6.4.4+deb7u1 Severity: normal reportbug-gtk shows a 'Quit' and a 'Continue' button for each of it's dumb assistents step. But there's no ' go back' or 'review' button, so every and every wrong click means to close that dumb assistent and start over from the very

Bug#776285: [SoB] Bug#776285: RFS: nfft/3.3.0~alpha4 -- non-uniform Fourier transform [upload to experimental]

2015-01-26 Thread Andreas Tille
Hi Ghislain, On Mon, Jan 26, 2015 at 11:57:33AM +, Ghislain Vaillant wrote: Hi everyone, I have updated the packaging for NFFT to version 3.3.0 and filed this RFS [1]. I am now looking for a sponsor via SoB and filed a new task [2]. The package is lintian clean and builds happily on

Bug#774854: race condition between fur and fex_cleanup

2015-01-26 Thread Moritz Mühlenhoff
On Mon, Jan 26, 2015 at 01:41:54PM +0100, Kilian Krause wrote: Hi Moritz, On Mon, Jan 26, 2015 at 12:28:00PM +0100, Moritz Mühlenhoff wrote: On Mon, Dec 22, 2014 at 10:33:50PM +0100, Kilian Krause wrote: Package: fex Version: 20140917-1 Severity: serious Tags: security patch

Bug#504804: Processed: notfound 504804 in 2.12-2

2015-01-26 Thread santiago
Control: reopen -1 Control: tags -1 + confirmed Hi, Unfortunately, this is still present in 2.20-4: % echo a ~/tmp-pattern % echo hola | grep --file=/home/santiago/tmp-pattern hola % echo hola | LANG=C grep --file=~/tmp-pattern grep: ~/tmp-pattern: No such file or directory Cheers,

Bug#776277: Typo

2015-01-26 Thread Vincas Dargis
Sorry, I ment VisualSVN instead of WinSVN.

Bug#771523: systemd-journal-upload

2015-01-26 Thread Michael Biebl
Am 26.01.2015 um 10:05 schrieb Paul Elliott: 771...@bugs.debian.org systemd-journal-upload is also needed. I have a low memory computer, and need to ship journals to another computer. This is not something you should ignore, journal can be useless without it. The journal forwards

Bug#776251: ack-grep fails to install due to diversion problem

2015-01-26 Thread gregor herrmann
On Mon, 26 Jan 2015 01:01:03 +0100, Axel Beckert wrote: $ dpkg-divert --list *ack* local diversion of /usr/bin/ack-grep to /usr/bin/ack ^ ... which backs my assumption that a _local_ diversion (i.e. none made by a package) is the cause. That's my interpretation as well. I tend to

Bug#776285: Did you commited nfft/3.3.0~alpha4 to Git (and if yes, what branch)?

2015-01-26 Thread Andreas Tille
Hi, I failed to find the packaging stuff in Git and I only regard the Git status for sponsering. Kind regards Andreas. -- http://fam-tille.de -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact

Bug#776002: Other problems

2015-01-26 Thread Vincas Dargis
On Sun, 25 Jan 2015 14:34:52 + Ben Hutchings b...@decadent.org.uk wrote: What if you set it to linux-image/wheezy-backports initramfs-tools/wheezy-backports? Thank you, that helped! But...I have other problem - ifupdown package is removed during install, and so I have system without

Bug#776210: r-cran-digest: First line missing in package description

2015-01-26 Thread Dirk Eddelbuettel
Hi Beatrice, On 25 January 2015 at 15:27, Beatrice Torracca wrote: | Package: r-cran-digest | Severity: minor | | Hi! | | with the recent change of the package description [1], the first line | got lost. The description currently (0.6.7-1) starts with | | «of hash digests of arbitrary R

Bug#775892: unblock (pre-approval): python-django/1.7.3-1

2015-01-26 Thread Moritz Mühlenhoff
On Fri, Jan 23, 2015 at 02:26:06PM +0100, Raphael Hertzog wrote: On Wed, 21 Jan 2015, Raphael Hertzog wrote: Some notes: - the final upload will include the bug closure of #775375 - there's a small tweak of a Suggests dependency, it was not intended for jessie but I don't see how it can

Bug#776304: dpkg: allows child processes to inherit file handles for triggers

2015-01-26 Thread Russell Coker
Package: dpkg Version: 1.17.23 Severity: normal Below are some AVC messages from a fairly routine dpkg upgrade. As you can see the programs setfiles, load_policy, and restorecon which are run from postinst scripts are inheriting a file handle for /var/lib/dpkg/triggers/Unincorp . type=AVC

Bug#776302: psensor-server

2015-01-26 Thread herrmann
Package: psensor-server Version: 0.6.2.17-2+b1 Severity: important psensor-server don't collect or deliver any data. While psensor in standalone mode works flawless, psensor-server seems to do nothing on the very same machine. After starting psensor-server in debug mode, I try to connct to it

Bug#774748: #774748: ruby-redcloth: CVE-2012-6684

2015-01-26 Thread Christian Hofstaedtler
* Moritz Mühlenhoff j...@inutil.org [150126 13:45]: On Fri, Jan 09, 2015 at 10:57:13PM +0100, Christian Hofstaedtler wrote: AFAICT there is no publicly available patch, and upstream is more or less dead. Redmine's patched redcloth3 looks very different from the current redcloth 4.x

Bug#776151: Installation bug in Expert mode

2015-01-26 Thread Cyril Brulebois
Andreas Weber ae...@worldwideweber.ch (2015-01-26): On 2015-01-26 00:27, Cyril Brulebois wrote: Just to make sure, can you please give us the full URL to the installation medium you're using. This would be handy to try and reproduce your issue (with either Beta 2 or RC 1). I went to

Bug#776218: installation-reports: Reportbug needs python-vte, which is not installed in the default installation

2015-01-26 Thread Cyril Brulebois
Josselin Mouette j...@debian.org (2015-01-26): Cyril Brulebois k...@debian.org wrote: (major) The missing packages should be installed from the beginning. These are python-vte and python-gtkspell (which reportbug also wants). Might be a good idea for some

Bug#776305: libdrm-intel1: steam games won't start with optirun

2015-01-26 Thread Bozhan Boiadzhiev
Package: libdrm-intel1 Severity: normal Dear Maintainer, steam games won't start with optirun, they run with previous version. Game crash with(TM2 for example) : malloc: unknown:0: assertion botched free: called with unallocated block argument last command: (null) Aborting...Aborted Game

Bug#776299: twitter-bootstrap: please make the build reproducible

2015-01-26 Thread Chris Lamb
Source: twitter-bootstrap Version: 2.0.2+dfsg-5 Severity: wishlist Tags: patch User: reproducible-bui...@lists.alioth.debian.org Usertags: timestamps X-Debbugs-Cc: reproducible-bui...@lists.alioth.debian.org Hi, While working on the reproducible builds effort [1], we have noticed that

Bug#776034: fsck runs in parallel on same physical disk

2015-01-26 Thread Daniel Pocock
On 26/01/15 13:21, Karel Zak wrote: On Mon, Jan 26, 2015 at 10:36:02AM +0100, Daniel Pocock wrote: On 26/01/15 10:32, Karel Zak wrote: On Mon, Jan 26, 2015 at 02:24:04AM +0100, Michael Biebl wrote: -l Create an exclusive flock(2) lock file (/run/fsck/diskname.lock) for

Bug#776064: pinfo mouse selection

2015-01-26 Thread Kai Lüke
Thanks for the tip, but I would consider this as secret knowledge ;) And man/info do also allow straight selection, so that clicking on links would be the less common case and pressing a modifier acceptable. Anyway as there will be a new upstream release soon, I've discarded the NMU. Bye -- To

Bug#776310: unblock: virtualbox/4.3.18-dfsg-2

2015-01-26 Thread Ritesh Raj Sarraf
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock Please unblock package virtualbox There were a bunch of CVEs that this upload has fixed. All details are present in bug #775888 unblock virtualbox/4.3.18-dfsg-2 -- System Information:

Bug#776311: nginx: Please add nginx-http-shibboleth to nginx-extras

2015-01-26 Thread Luca Bruno
Source: nginx Severity: wishlist Tags: patch Hi, we recently did some work to make shibboleth being independent of apache. Current shibboleth package can be used to authenticate whatever server, over a fastcgi socket. The other half missing is some support into nginx. Unfortunately upstream nginx

Bug#775588: [Pkg-haskell-maintainers] Bug#775588: darcs: Missing copyright information

2015-01-26 Thread beuc
Hi, How about lowering the severity of this bug? I just received this: fusionforge 5.3.2+20141104-3 is marked for autoremoval from testing on 2015-03-02 It (build-)depends on packages with these RC bugs: 775588: darcs: Missing copyright information Cheers! Sylvain -- To

Bug#776307: libgtk2.0: print-preview asumes evince

2015-01-26 Thread Ricardo Peliquero
Package: libgtk2.0-0 Version: 2.24.25-1 Severity: normal File: libgtk2.0 Dear Maintainer, When trying a print preview from e.g. Sylpheed, gtk expects evince to be installed and gives a warning if it is not. Is it possible to use any pdf-viewer virtual package in Debian to resolve this? Or,

Bug#776308: nagios-nrpe-server: Bad SSL_shutdown() causes Return code of 141 is out of bounds SIGPIPE/TCP RST

2015-01-26 Thread Ivan Vilata i Balaguer
Package: nagios-nrpe-server Version: 2.13-3 Severity: normal Tags: upstream patch Hi, I wanted to report that the version on ``nagios-nrpe-server`` in Wheezy suffers from [Nagios bug #305](http://tracker.nagios.org/view.php?id=305), which (at least in out case) causes some test to alternatively

Bug#776261: tecnoballz: Collision detection not accurate

2015-01-26 Thread Markus Koschany
On 26.01.2015 02:45, Celelibi wrote: Package: tecnoballz Version: 0.93.1-2 Severity: normal Hello, Sometime the balls can go through the corner ball launchers without being captured. This just happened to me when the ball has been bounced by the malus eye. Best regards, Celelibi

Bug#776263: tecnoballz: Right click cause game over

2015-01-26 Thread Markus Koschany
Control: tags 776263 confirmed On 26.01.2015 02:46, Celelibi wrote: Package: tecnoballz Version: 0.93.1-2 Severity: normal Hello, Apparently, right clicking when loosing the last ball cause a game over instead of simply loosing a life. It seems that this bug is easier to reproduce when

Bug#776262: tecnoballz: Bouncer position restricted in boss levels

2015-01-26 Thread Markus Koschany
On 26.01.2015 02:46, Celelibi wrote: Package: tecnoballz Version: 0.93.1-2 Severity: normal Hello, It looks like in the boss levels the position of the bouncer cannot reach the side walls allowing the balls to fall without any way to catch them. The minimum distance from the bouncer

Bug#754785: Progress?

2015-01-26 Thread Samuel Hym
Hi Sergey, Did you manage to make any progress on this ITP? (I merged it with an old RFP for the same font, I suppose there is definitely some interest in it, to have two wnpp reports… ;-) Best regards -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of

Bug#768897: MBR disklabels also yield destructive pvcreate

2015-01-26 Thread Steve McIntyre
Control: severity -1 important Control: clone -1 -2 Control: retitle -2 Installation manual should warn about the use of LVM partition types Control: reassign -2 installation-guide On Sun, Jan 18, 2015 at 04:24:43PM +, Steve McIntyre wrote: On Wed, Nov 19, 2014 at 03:36:19PM -0600, Drake

Bug#776276: unblock: open-iscsi/2.0.873+git0.3b4b4500-4

2015-01-26 Thread Christian Seiler
(Since I didn't get cc'd in the original reply, I'm replying here. Sorry about that.) Am 26.01.2015 um 16:12 schrieb Ritesh Raj Sarraf: On 01/26/2015 07:54 PM, Michael Biebl wrote: unblock open-iscsi/2.0.873+git0.3b4b4500-4 That patch doesn't look right. Calling systemctl from an init script

Bug#776304: dpkg: allows child processes to inherit file handles for triggers

2015-01-26 Thread Guillem Jover
Hi! On Tue, 2015-01-27 at 00:55:21 +1100, Russell Coker wrote: Package: dpkg Version: 1.17.23 Severity: normal Below are some AVC messages from a fairly routine dpkg upgrade. As you can see the programs setfiles, load_policy, and restorecon which are run from postinst scripts are

Bug#776297: jajuk: please make the build reproducible

2015-01-26 Thread Emmanuel Bourg
Hi Chris, Thank you for the patch. It can be even simpler by setting the build.time property in debian/rules instead of patching the upstream build. This will look like this: DEB_ANT_ARGS := -Dbuild.time='$(shell dpkg-parsechangelog --show-field Date)' With Ant the properties defined on the

Bug#775778: Bug#776276: unblock: open-iscsi/2.0.873+git0.3b4b4500-4

2015-01-26 Thread Ritesh Raj Sarraf
On 01/26/2015 07:54 PM, Michael Biebl wrote: unblock open-iscsi/2.0.873+git0.3b4b4500-4 That patch doesn't look right. Calling systemctl from an init script is a big no-go. Second, shipping a generated unit file which does run /etc/init.d/foo is a hack at best. I'd be really unhappy,

Bug#775888: virtualbox: CVE-2014-6588 CVE-2014-6589 CVE-2014-6590 CVE-2014-6595 CVE-2015-0418 CVE-2015-0427

2015-01-26 Thread Ritesh Raj Sarraf
On 01/21/2015 01:23 PM, Moritz Muehlenhoff wrote: In the past someone from upstream posted the upstream commits to the bug log, maybe you can contact them for more information so that we can merge the isolated fixes into the jessie version? Cheers, Moritz Moritz, For unstable, I've pushed

Bug#775866: vlc: multiple vulnerabilities

2015-01-26 Thread Sebastian Ramacher
On 2015-01-26 13:49:26, Moritz Mühlenhoff wrote: On Tue, Jan 20, 2015 at 09:47:26PM +0100, Yves-Alexis Perez wrote: * The potential invalid writes in modules/services_discovery/sap.c and modules/access/ftp.c were not fixed as I did not provide a trigger. Note, that the code looks very

Bug#776309: fglrx-driver: Hung PC with black screen and solid white cursor in upper left corner

2015-01-26 Thread Greg Futia
Package: fglrx-driver Version: 1:14.12-1 Severity: critical Justification: breaks the whole system Dear Fglrx Maintainers, When this package is installed the system boots to a completely hung state with a solid cursor in the upper left hand corner. The hang leaves the system unaccessible

Bug#776312: coquelicot: please make build reproducible

2015-01-26 Thread Jérémy Bobbio
Source: coquelicot Version: 0.9.2-4 Severity: wishlist Tags: patch User: reproducible-bui...@lists.alioth.debian.org Usertags: timestamps X-Debbugs-Cc: reproducible-bui...@lists.alioth.debian.org Hi, While working on the reproducible builds effort [1], we have noticed that coquelicot could not

Bug#775888: virtualbox: CVE-2014-6588 CVE-2014-6589 CVE-2014-6590 CVE-2014-6595 CVE-2015-0418 CVE-2015-0427

2015-01-26 Thread Ritesh Raj Sarraf
On 01/26/2015 09:07 PM, Ritesh Raj Sarraf wrote: On 01/21/2015 01:23 PM, Moritz Muehlenhoff wrote: In the past someone from upstream posted the upstream commits to the bug log, maybe you can contact them for more information so that we can merge the isolated fixes into the jessie version?

Bug#770657: tcc: fails with struct defined in function

2015-01-26 Thread Thomas Preud'homme
Control: forwarded -1 http://lists.nongnu.org/archive/html/tinycc-devel/2014-08/msg00050.html Control: tags -1 + upstream A patch has been floating on the mailing list but was not of good enough quality to be included. I shall be able to commit soon again to this project and will try to move

Bug#707275: #707275 - ansible: disable syslog logging

2015-01-26 Thread Mattia Rizzolo
Control: tag -1 - moreinfo On Sat, 12 Apr 2014 21:32:17 -0400 Harlan Lieberman-Berg h.liebermanb...@gmail.com wrote: Upstream says that this functionality may have been added by no_log becoming a task parameter. Does this functionality solve your issue? It does not solve mine. The perfect

Bug#776178: ITP: python-xcffib -- A drop in replacement for xpyb

2015-01-26 Thread Klee Dienes
Wow! Thanks for writing this! I *just* finished a rough port of xpyb to Python 3, and you're right that it's got a lot of issues. https://github.com/BurntSushi/xpyb I also recently ported xpybutil to python3 ... this weekend I'll try it out against xcffib. I note that you filed a WNPP and not

Bug#776072: dpkg-maintscript-helper dir_to_symlink explodes on subtree in cups-pdf package

2015-01-26 Thread Guillem Jover
On Fri, 2015-01-23 at 17:38:12 +0100, Guillem Jover wrote: On Fri, 2015-01-23 at 17:25:22 +0100, Andreas Beckmann wrote: Control: severity -1 important Control: reopen -1 Control: retitle -1 dpkg-maintscript-helper: document required package qualification on arch:all = arch:any switches

Bug#775306: pxz: race condition in setting permissions on output file

2015-01-26 Thread Holger Levsen
Hi Moritz, On Montag, 26. Januar 2015, Moritz Mühlenhoff wrote: Patch attached, can you take care of an upload and unblock with the release team? thanks for the patch, can do! cheers, Holger signature.asc Description: This is a digitally signed message part.

Bug#691273: netcdf-bin: nccopy produces bogus output

2015-01-26 Thread Ross Gammon
Control: tags -1 moreinfo unreproducible Hi Paul, We are currently preparing a new version of netcdf. Unfortunately, I am not able to reproduce this bug in 1:4.1.3-7.2 using my Wheezy machine. I only had one file to play with though. If you are still affected by this bug, could you please

Bug#776318: devscripts: [mk-origtargz] creates string with duplicate entries of files to exclude

2015-01-26 Thread Andreas Tille
Package: devscripts Version: 2.15.1 Severity: normal Dear Maintainer, when trying to upgrade gnumed-client using debcheckout gnumed-client and than running `debian/rules get-orig-source` this failed. It boils down to the following problem $ LC_ALL=C mk-origtargz ../gnumed-client.1.5.2.tgz

Bug#776260: tecnoballz: Version dependancy to libsdl-mixer1.2

2015-01-26 Thread Manuel A. Fernandez Montecelo
2015-01-26 11:25 GMT+00:00 Markus Koschany a...@gambaru.de: On 26.01.2015 02:44, Celelibi wrote: Package: tecnoballz Version: 0.93.1-2 Severity: normal Hello, The sound of tecnoballz version 0.93.1-2 wasn't working with libsdl-mixer1.2:i386 version 1.2.12-5. The error message was:

Bug#776042: Please make

2015-01-26 Thread Tianon Gravi
Control: tags -1 + pending On 23 January 2015 at 03:26, Riku Voipio riku.voi...@iki.fi wrote: A multi-arch: foreign stanza is needed to install docker.io recommends on a foreign architecture. The attached patch does it, although it is totally trivial. With this patch and similar fixes to other

Bug#776253: dependency on libwv-1.2-4 too weak

2015-01-26 Thread Daniel Walrond
On Mon, Jan 26, 2015 at 12:25:07AM +0100, Helmut Grohne wrote: Package: wv Version: 1.2.9-4+b1 Severity: serious Justification: policy 12.3 footnote 2 Tags: patch wv contains a symlink /usr/share/doc/wv which points to libwv-1.2-4. Its dependency on libwv-1.2-4 is unversioned though which

Bug#773577: libssh: CVE-2014-8132: Double free on dangling pointers in initial key exchange packet

2015-01-26 Thread Moritz Mühlenhoff
On Sat, Dec 27, 2014 at 02:27:29PM +0100, Laurent Bigonville wrote: On Sat, 20 Dec 2014 08:18:29 +0100 Salvatore Bonaccorso car...@debian.org wrote: Hi, Hello, the following vulnerability was published for libssh. CVE-2014-8132[0]: Possible double free on a dangling pointer

Bug#776301: New upstream release: 0.5.2

2015-01-26 Thread Alessio Treglia
Source: gpac Severity: wishlist Upstream has released a new version: https://github.com/gpac/gpac/tree/v0.5.2 Cheers. -- System Information: Debian Release: jessie/sid APT prefers utopic-updates APT policy: (500, 'utopic-updates'), (500, 'utopic-security'), (500, 'utopic'), (100,

Bug#776214: [Pkg-iscsi-maintainers] multipath not automounting iscsi devices listed in fstab

2015-01-26 Thread Christian Seiler
Am 26.01.2015 um 08:47 schrieb Ritesh Raj Sarraf: On 01/25/2015 09:43 PM, Christian Seiler wrote: The same fix that was implemented for open-iscsi in principle also applies for multipath-tools, i.e. make sure that for systemd systems the unit is ordered before remote-fs-pre.target. I don't use

Bug#776320: flashplugin-nonfree: Fullscreen videos cannot be exited with escape or by clicking restore button

2015-01-26 Thread Buddy Moore
Package: flashplugin-nonfree Version: 1:3.6.1 Severity: normal Dear Maintainer, When going fullscreen on various sites (youtube to name one, but I have verified with others), the escape key will not exit fullscreen mode. Luckily, I can Ctrl+Shift+Arrow to another workspace to exit fullscreen,

Bug#776322: RM: moodle -- ROM; No maintainer, security issues, DFSG

2015-01-26 Thread Riley Baird
Package: ftp.debian.org Severity: normal Hi, Moodle has several DFSG issues (e.g. #763800, #746594, #752615, #754565) and unfixed security issues (#775842). I have spoken to the maintainers - both upstream [1] and within Debian[2], and they support the removal of moodle as they are no longer

Bug#776316: [Pkg-samba-maint] Bug#776316: samba: failed to build on mips

2015-01-26 Thread Jelmer Vernooij
On Mon, Jan 26, 2015 at 01:42:51PM -0500, Michael Gilbert wrote: package: src:samba version: 2:4.1.13+dfsg-4 severity: serious The latest upload failed to build on the mips buildd: https://buildd.debian.org/status/package.php?p=samba See the comment in the build log: 21:17:20 runner

Bug#775882: [debian-mysql] Bug#775882: mariadb-10.0: affected by CVEs of the Oracle Patch Update for January 2015?

2015-01-26 Thread Otto Kekäläinen
The page https://mariadb.com/kb/en/security/ has updated and includes info about these latest CVEs. It seems most issues were fixed in 5.5.41/10.0.16. One was for 5.5.39/10.0.13. 10.0.16 hasn't been yet released, but I'll expect it is released soon and I will try to be as fast as possible in

Bug#744145: [Python-modules-team] Bug#744145: pip3 breaks after upgrading requests

2015-01-26 Thread W. Martin Borgert
On 2015-01-26 10:25, Chris Kuehl wrote: I wonder whether such a change should at least be documented in the release notes, even if we can't address it because of the freeze? Yes, good idea. This would allow users to remove such libraries first and then upgrade Debian. Would you file a bug

Bug#775306: pxz: race condition in setting permissions on output file

2015-01-26 Thread Moritz Mühlenhoff
On Wed, Jan 14, 2015 at 05:25:02AM +0100, Holger Levsen wrote: control: severity -1 important Hi Alexander, On Dienstag, 13. Januar 2015, Alexander Cherepanov wrote: pxz sets the mode of an output file to be the same as the one of an input file but does it only after compression is

Bug#776317: Jessie RC1 amd64 mini image missing efi bootloader

2015-01-26 Thread Jack Truong
Package: cdimage.debian.org Apologies if this is the wrong package. I'm using the jessie rc1 amd64 mini.iso and the EFI partition doesn't seem to have anything in it. It should have efi/boot/bootarch.efi for EFI firmware to load properly. It also doesn't seem to exist in the i386 image

Bug#752479: 1.0.5 available in a ppa

2015-01-26 Thread Holger Levsen
Hi, https://launchpad.net/~tuxpoldo/+archive/ubuntu/roundcube has 1.0.5, for those interested. I haven't tested them yet, but will do so shortly. cheers, Holger signature.asc Description: This is a digitally signed message part.

Bug#776321: unblock: wv/1.2.9-4.1

2015-01-26 Thread Helmut Grohne
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock Please unblock package wv The wv binary package links its documentation to libwv-1.2-4 without using dh_installdocs --linkdoc and lacks the (= ${binary:Version}) dependency required by the

Bug#774048: CVE-2014-9390

2015-01-26 Thread Moritz Mühlenhoff
On Mon, Jan 05, 2015 at 01:47:40AM +1100, Russell Sim wrote: Moritz Muehlenhoff j...@debian.org writes: Source: libgit2 Severity: important Tags: security libgit2 is also affected by the recent git vulnerability: http://openwall.com/lists/oss-security/2014/12/18/21 Thanks for the

Bug#776319: CVE-2015-0361

2015-01-26 Thread Moritz Muehlenhoff
Source: xen Severity: important Tags: security Hi, please see http://xenbits.xen.org/xsa/advisory-116.html for details and a patch. Cheers, Moritz -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact

Bug#776034: fsck runs in parallel on same physical disk

2015-01-26 Thread Daniel Pocock
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 26/01/15 14:51, Phillip Susi wrote: On 1/26/2015 7:34 AM, Daniel Pocock wrote: The performance impact is not trivial. I have 28 LVs on my main /dev/md and 47 on an external disk that is used to replicate other filesystems. Both of these

Bug#776178: ITP: python-xcffib -- A drop in replacement for xpyb

2015-01-26 Thread Klee Dienes
On 01/26/2015 12:18 PM, Tycho Andersen wrote: I note that you filed a WNPP and not an ITP for this. Is there some way that I can help? That's probably because I am new at Debian packaging and screwed it up. I've uploaded a draft to mentors, any reviews would be much appreciated!

Bug#776315: foomatic-filters: foomatic-rip can't properly execute text filters

2015-01-26 Thread Martín Ferrari
Package: foomatic-filters Version: 4.0.17-5 Severity: normal While trying to setup a printer directly with foomatic and rlpr, I executed the documented command to get a printout of config values: $ foomatic-rip -P printer -o docs /proc/cpuinfo I noticed errors, and the command waiting on stdin,

Bug#776304: dpkg: allows child processes to inherit file handles for triggers

2015-01-26 Thread Russell Coker
close 776304 thanks On Tue, 27 Jan 2015, Guillem Jover guil...@debian.org wrote: Are you sure these messages are from dpkg 1.17.23 and not from an earlier version? This was supposedly fixed in 1.17.11 (see #751021). After reviewing the logs it appears that the package was upgraded after I

Bug#776121: xapers-adder uses incorrect options for x-terminal-emulator

2015-01-26 Thread Jameson Graef Rollins
On Fri, Jan 23 2015, Kacper Gutowski mwgam...@gmail.com wrote: When x-terminal-emulator is provided by an implementation that does not support -title option (e.g. stterm), xapers-adder fails when trying to launch a terminal. By DPM § 11.8.3, x-terminal-emulator is only required to support -e

Bug#776174: git bash completion script missing

2015-01-26 Thread Erik Esterer
Hello Freddie, the script isn't missing, it just moved to /usr/share/bash-completion/completions/. See #698055 for details. -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#775625: [pkg-php-pear] symfony: Review, upload and unblock needed to fix #775625 (FTBFS in jessie)

2015-01-26 Thread David Prévot
Hi, Le 21/01/2015 14:23, David Prévot a écrit : Le 19/01/2015 13:34, Daniel Beyer a écrit : I'm not 100% sure if it really fixes the problem, since I'm not able to reproduce those errors on my local system (neither local, nor with pbuilder sid/jessie). Same here, even within sbuild.

Bug#775866: vlc: multiple vulnerabilities

2015-01-26 Thread Moritz Muehlenhoff
On Mon, Jan 26, 2015 at 05:33:30PM +0100, Sebastian Ramacher wrote: On 2015-01-26 13:49:26, Moritz Mühlenhoff wrote: On Tue, Jan 20, 2015 at 09:47:26PM +0100, Yves-Alexis Perez wrote: * The potential invalid writes in modules/services_discovery/sap.c and modules/access/ftp.c were not

Bug#776178: ITP: python-xcffib -- A drop in replacement for xpyb

2015-01-26 Thread Tycho Andersen
Hi Klee, On Jan 26, 2015 8:41 AM, Klee Dienes k...@debian.org wrote: Wow! Thanks for writing this! Sure, no problem :-) I *just* finished a rough port of xpyb to Python 3, and you're right that it's got a lot of issues. https://github.com/BurntSushi/xpyb I also recently ported

Bug#759786: Bug is in intel drm, not gdm3, bug is still present.

2015-01-26 Thread John Hughes
Well, I spoke too soon - it doesn't work with 3.14.1-3, the problem is still present. I'm now convinced that it's a kernel bug - in the intel driver. Often, when I try to change the Gnome primary display from the built-in lvds panel to the external (HDMI) monitor I get errrors like: [

Bug#767019: xscreensaver: postinst overwrites /etc/X11/app-defaults/XScreenSaver without asking

2015-01-26 Thread Alex Goebel
On Sat, Dec 20, 2014 at 9:02 AM, Michael Gilbert wrote: if [ -L /etc/X11/app-defaults/XScreenSaver ]; then if [ $(readlink /etc/X11/app-defaults/XScreenSaver) = XScreenSaver-nogl -o \ $(readlink /etc/X11/app-defaults/XScreenSaver) = XScreenSaver-gl]; then

Bug#775882: [debian-mysql] Bug#775882: mariadb-10.0: affected by CVEs of the Oracle Patch Update for January 2015?

2015-01-26 Thread Salvatore Bonaccorso
Control: tags -1 upstream fixed-upstream Control: retitle -1 mariadb-10.0: CVE-2015-0411 CVE-2015-0382 CVE-2015-0381 CVE-2015-0432 CVE-2014-6568 CVE-2015-0374 Hi Otto, On Fri, Jan 23, 2015 at 08:46:46AM +0200, Otto Kekäläinen wrote: I started to search information about this 2 days ago, but so

Bug#744145: [Python-modules-team] Bug#744145: pip3 breaks after upgrading requests

2015-01-26 Thread Chris Kuehl
Hi Stefano, On Mon, Jan 26, 2015 at 05:12:42AM +0200, Stefano Rivera wrote: I don't think I consider this bug to be RC. Debian packages have declared dependencies on other Debian packages. Replacing one with something newer from upstream, is quite likely to break things. Thanks for

Bug#775888: virtualbox: CVE-2014-6588 CVE-2014-6589 CVE-2014-6590 CVE-2014-6595 CVE-2015-0418 CVE-2015-0427

2015-01-26 Thread Moritz Mühlenhoff
On Mon, Jan 26, 2015 at 09:07:19PM +0530, Ritesh Raj Sarraf wrote: On 01/21/2015 01:23 PM, Moritz Muehlenhoff wrote: In the past someone from upstream posted the upstream commits to the bug log, maybe you can contact them for more information so that we can merge the isolated fixes into the

Bug#774693: sysdig-dkms: does not compile for 3.19-rc3

2015-01-26 Thread Evgeni Golov
Hi again, On Sat, Jan 24, 2015 at 11:58:47AM +0100, Evgeni Golov wrote: Hi The patch was against upstream git aka 0.1.95. Sorry, I forgot to check against the version in Debian. Can you try upstream? Upstream won't work either. They removed msg_iov(len)? from struct msghdr in

Bug#776314: /var/log/faillog is never updated

2015-01-26 Thread roger21
Package: login Version: 1:4.1.5.1-1 while auth.log and laslog are updated faillog is not # faillog -a all the lines are like : root00 01/01/70 01:00:00 +0100 user00 01/01/70 01:00:00 +0100 of course i did fail some login with a user and root i

Bug#776316: samba: failed to build on mips

2015-01-26 Thread Michael Gilbert
package: src:samba version: 2:4.1.13+dfsg-4 severity: serious Hi, The latest upload failed to build on the mips buildd: https://buildd.debian.org/status/package.php?p=samba Best wishes, Mike -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe.

Bug#306501: mpd: request for read-only mode

2015-01-26 Thread Florian Schlichting
tags 306501 + moreinfo thanks Hi Vincent, mpd should have a read-only mode for clients. Currently, if a user wants to be able to play files of the playlist, he needs the control permission, i.e. password password@read,control in the /etc/mpd.conf file. But the control permission also

Bug#776327: repsnapper: corrupted gcode generation

2015-01-26 Thread lkcl
Package: repsnapper Version: 2.3.2a5-1 Severity: normal Tags: upstream certain STL files generate completely incorrect (corrupted) gcode. followup files to be attached in separate report -- System Information: Debian Release: 7.4 APT prefers unstable APT policy: (500, 'unstable'), (500,

  1   2   3   >