Bug#1069679: ofono: CVE-2023-2794

2024-04-22 Thread Moritz Mühlenhoff
Source: ofono X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerability was published for ofono. CVE-2023-2794[0]: | A flaw was found in ofono, an Open Source Telephony on Linux. A | stack overflow bug is triggered within the decode_deliver() function

Bug#1069678: openjdk-8: CVE-2024-21011 CVE-2024-21068 CVE-2024-21085 CVE-2024-21094

2024-04-22 Thread Moritz Mühlenhoff
Source: openjdk-8 X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerabilities were published for openjdk-8. CVE-2024-21011[0]: | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle | GraalVM Enterprise Edition product of Oracle Java SE

Bug#1069677: rust-rustls: CVE-2024-32650

2024-04-22 Thread Moritz Mühlenhoff
Source: rust-rustls X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerability was published for rust-rustls. CVE-2024-32650[0]: | Rustls is a modern TLS library written in Rust. | `rustls::ConnectionCommon::complete_io` could fall into an infinite |

Bug#1004863: Bootstrapping a Fedora produces a system with an empty package database

2024-04-22 Thread Luca Boccassi
On Sat, 20 Apr 2024 20:48:06 +0100 Luca Boccassi wrote: > On Mon, 15 Apr 2024 at 10:34, Peter Pentchev wrote: > > > > On Sun, Apr 14, 2024 at 07:39:54PM +0100, Luca Boccassi wrote: > > > > Le 2/13/22 à 09:00, Mihai Moldovan a écrit : > > > > > > > > > I'm pretty sure that we can, at some point

Bug#1069676: timeshift-launcher unable to start on fresh install. pkexec required but not listed as dependency.

2024-04-22 Thread MA Jansma
Package: timeshift Version: 22.11.2-1 Severity: normal X-Debbugs-Cc: marnixjan...@gmail.com Dear Maintainer, I manually installed timeshift using apt. I tried launching the graphical interface from the applications menu and it failed with no feedback. Running it from the terminal indicated

Bug#1069675: pure-ftpd broken APPE after STOU

2024-04-22 Thread Federico Sabbatini
Package: pure-ftpd Version: 1.0.50 When I run a STOU command I can't run an APPE properly. It seems to run a STOR instead. Here is an example using Python's ftplib. ```python #!/usr/bin/env python3 from ftplib import FTP pureftp = FTP('ftphost') pureftp.login('username', 'password')

Bug#1060330: sccache: Please enable distributed storage before the migration to testing/next release

2024-04-22 Thread Jonas Smedegaard
Quoting Sylvestre Ledru (2024-04-22 15:28:30) > Le 09/01/2024 à 23:27, Jonas Smedegaard a écrit : > > Quoting Sylvestre Ledru (2024-01-09 19:07:47) > >> I really would like to avoid shipping sccache without distributed support. > >> Currently, these key features have been disabled: > >>

Bug#1069674: openssh-client: multiplexed connections use incorrect DISPLAY etc, but no TOKENS exist to modify the connection socket

2024-04-22 Thread Tim Connors
Package: openssh-client Version: 1:9.2p1-2+deb12u2 Severity: normal With .ssh/config: ControlMaster auto ControlPath ~/.ssh/cm_master/%r@%h:%p ControlPersist yes Set up the mux master on host a to host c: > echo $DISPLAY :0 > ssh c xterm xterm fires up on host a. Kill that Now,

Bug#1060330: sccache: Please enable distributed storage before the migration to testing/next release

2024-04-22 Thread Sylvestre Ledru
Hello, Le 09/01/2024 à 23:27, Jonas Smedegaard a écrit : Quoting Sylvestre Ledru (2024-01-09 19:07:47) I really would like to avoid shipping sccache without distributed support. Currently, these key features have been disabled:

Bug#1069673: RM: openstack-nose -- ROM; obsolete, nose removal

2024-04-22 Thread Thomas Goirand
Package: ftp.debian.org Severity: normal User: ftp.debian@packages.debian.org Usertags: remove X-Debbugs-Cc: openstack-n...@packages.debian.org Control: affects -1 + src:openstack-nose Hi, Swift was the only use of this plugin, but I have just uploaded removing that build-depends from Swift,

Bug#1069672: bookworm-pu: package flatpak/1.14.6-1~deb12u1 or 1.14.7-1~deb12u1

2024-04-22 Thread Simon McVittie
Package: release.debian.org Severity: normal Tags: bookworm User: release.debian@packages.debian.org Usertags: pu X-Debbugs-Cc: flat...@packages.debian.org Control: affects -1 + src:flatpak After the dust has settled from CVE-2024-32462, I would like to do a stable-update of Flatpak using the

Bug#1069671: linux-image-6.6.15-amd64: stalled processes

2024-04-22 Thread Michael Becker
Package: src:linux Version: 6.6.15-2 Severity: normal If I start a compile run on a ramdisk or download a file of some GB to the ramdisk and switch to another virtual desktop in the meantime to browse the internet I often have the effect theaz the make or download is stalled during my activity

Bug#1069614: erfs: isolation-machine autopkgtest fails: sshfs failed

2024-04-22 Thread Skyper x
The erfs service was shut down and this tool is no longer functional. It should be removed. > On 21 Apr 2024, at 14:57, Paul Gevers wrote: > > Source: erfs > Version: 1.4-1 > Severity: important > User: debian...@lists.debian.org > Usertags: isolation-machine > > Dear maintainer(s), > >

Bug#1069670: RFP: qft -- Resilient P2P UDP file transfer

2024-04-22 Thread Jari Aalto
Package: wnpp Severity: wishlist * Package name: qft Version : 0.5.6 Upstream Author : * URL : https://github.com/tudbut/qft * License : GP-3 Programming Lang: Rust Description : Resilient P2P UDP file transfer UDP file transfer program for two

Bug#1069669: rust-uuid: please update to v1.7

2024-04-22 Thread Jonas Smedegaard
Source: rust-uuid Version: 1.6.1-1 Severity: normal Tags: upstream -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Please update to at least v1.7. -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEn+Ppw2aRpp/1PMaELHwxRsGgASEFAmYmQIMACgkQLHwxRsGg

Bug#1069668: python3-colored: Please provide PEP-0561 "py.typed" marker

2024-04-22 Thread Niels Thykier
Package: python3-colored Version: 2.2.3-1 Severity: normal Tags: upstream X-Debbugs-Cc: ni...@thykier.net Hi When depending on `python3-colored` and using `mypy`, `mypy` will complain about `python3-colored` is not typed. Upstream does seem to have some typing, but has not marked the their

Bug#1069667: rust-chrono: please update to v0.4.33

2024-04-22 Thread Jonas Smedegaard
Source: rust-chrono Version: 0.4.31-2 Severity: normal Tags: upstream -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Please update to at least v0.4.33. -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEn+Ppw2aRpp/1PMaELHwxRsGgASEFAmYmPp4ACgkQLHwxRsGg

Bug#1064459: refining DEP17 patches for glibc and base-files

2024-04-22 Thread Santiago Vila
I've updated my demo repository with your patch. https://salsa.debian.org/helmutg/bootstrap-usrmerge-demo/-/commit/6425c8cde53596199cd37bb1625d1dfb2a4b74d0 Great. I'll take a look. I'm happy to call it guest upload while I find team upload slightly misleading. I avoid patching changelogs in

Bug#1066491: libt3window: FTBFS: .config.c:8:13: error: implicit declaration of function ‘setupterm’; did you mean ‘set_term’? [-Werror=implicit-function-declaration]

2024-04-22 Thread Bo YU
Hi, On Wed, Mar 13, 2024 at 12:52:51PM +0100, Lucas Nussbaum wrote: https://wiki.debian.org/qa.debian.org/FTBFS#A2024-03-13_-Werror.3Dimplicit-function-declaration Relevant part (hopefully): gcc -g -O2 -Werror=implicit-function-declaration -ffile-prefix-map=/<>=. -fstack-protector-strong

Bug#1059412: netcat-openbsd: diff for NMU version 1.226-1.1

2024-04-22 Thread Guilhem Moulin
Hi Chris, On Mon, 22 Apr 2024 at 01:43:26 +0200, Chris Hofstaedtler wrote: > I've prepared an NMU for netcat-openbsd (versioned as 1.226-1.1) and > uploaded it to DELAYED/7. Please feel free to tell me if I > should delay it longer. Ooops sorry, that bug fell off-screen. No issue with the NMU,

Bug#1069666: python-levenshtein: Current upstream looks dead, consider rebasing on https://github.com/rapidfuzz/Levenshtein

2024-04-22 Thread Niels Thykier
Package: python3-levenshtein Version: 0.12.2-2+b5 Severity: normal X-Debbugs-Cc: ni...@thykier.net Hi Based on the discussions in https://github.com/ztane/python-Levenshtein/issues/86, it seems that the current upstream has been superseded by https://github.com/rapidfuzz/Levenshtein/ This

Bug#1053334: galera-4: FTBFS because of expired certificates

2024-04-22 Thread Santiago Vila
El 22/4/24 a las 8:47, Otto Kekäläinen escribió: I was able to reproduce this for Bookworm both locally and in CI at https://salsa.debian.org/mariadb-team/galera-4/-/jobs/5620032 After importing latest upstream build/test passes: https://salsa.debian.org/otto/galera/-/jobs/5624466 Stable

Bug#1069665: rust-predicates: please update to v3.1.0

2024-04-22 Thread Jonas Smedegaard
Source: rust-predicates Version: 3.0.3-1 Severity: normal Tags: upstream -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Please update to at least v3.1.0. -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEn+Ppw2aRpp/1PMaELHwxRsGgASEFAmYmORQACgkQLHwxRsGg

Bug#1069664: rust-is-terminal: please update to v0.4.12

2024-04-22 Thread Jonas Smedegaard
Source: rust-is-terminal Version: 0.4.9-2 Severity: normal Tags: upstream -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Please update to at least v0.4.12. -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEn+Ppw2aRpp/1PMaELHwxRsGgASEFAmYmOKIACgkQLHwxRsGg

Bug#1069102: Acknowledgement (linux-image-6.1.0-20-amd64 and cifs mount problem on some folders which get hidden on shares)

2024-04-22 Thread Manfred Larcher
Hi, any news on this? Regards Manfred Am 16.04.24 um 14:21 schrieb Debian Bug Tracking System: Thank you for filing a new Bug report with Debian. You can follow progress on this Bug here: 1069102: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1069102. This is an automatically generated

Bug#1060448: patches for both debcheckout and chdist

2024-04-22 Thread Georgios Zarkadas
The attached patches, for the git repository at salsa.debian.org, remove the depreciation warnings. I have installed them in my system (version of devscripts: 2.23.7) and they appear to work fine till now (note: I have tested only git, bzr and svn repositories; could not find other types).

Bug#1069663: dub: please make the build reproducible

2024-04-22 Thread Chris Lamb
Source: dub Version: 1.36.0-1 Severity: wishlist Tags: patch User: reproducible-bui...@lists.alioth.debian.org Usertags: timestamps X-Debbugs-Cc: reproducible-b...@lists.alioth.debian.org Hi, Whilst working on the Reproducible Builds effort [0], we noticed that dub could not be built

Bug#1069662: RFS: libt3window/0.4.0-1.1 [NMU] [RC] -- Library for creating window-based terminal programs

2024-04-22 Thread Bo YU
Package: sponsorship-requests Severity: important Tags: patch X-Debbugs-Cc: 1066...@bugs.debian.org Dear mentors, I am looking for a sponsor for my package "libt3window": * Package name : libt3window Version : 0.4.0-1.1 Upstream contact : Gertjan Halkes * URL

Bug#1069661: samba: apparmor integration broken since change to local systemd units in 2:4.19.4+dfsg-1

2024-04-22 Thread Michael Tokarev
Control: tag -1 + pending 22.04.2024 12:18, Alex Murray wrote: Package: samba Version: 2:4.19.5+dfsg-4 Severity: normal Tags: patch User: ubuntu-de...@lists.ubuntu.com Usertags: origin-ubuntu noble ubuntu-patch Dear Maintainer, *** /tmp/tmpz7e0qwfp/bug_body In Ubuntu, the attached patch was

Bug#1069643: dh_installman: doesn't honor nodoc build profile

2024-04-22 Thread Niels Thykier
Fab Stz: [...] If dh_installman doesn't support nodoc as written in its manpage, then maybe the manpage should be changed. For instance this may have to be removed since I was mistaken by it. "In compat 11 and later, it also supports the default searchdir plus -- sourcedir like dh_install(1)

Bug#1069661: samba: apparmor integration broken since change to local systemd units in 2:4.19.4+dfsg-1

2024-04-22 Thread Alex Murray
Package: samba Version: 2:4.19.5+dfsg-4 Severity: normal Tags: patch User: ubuntu-de...@lists.ubuntu.com Usertags: origin-ubuntu noble ubuntu-patch Dear Maintainer, *** /tmp/tmpz7e0qwfp/bug_body In Ubuntu, the attached patch was applied to achieve the following: When samba was updated to ship

Bug#1068234: efibootguard upstream

2024-04-22 Thread Gylstorff Quirin
This is a upstream bug. Thanks for reporting Quirin forwarded 1068234 efibootguard-...@googlegroups.com -- Quirin Gylstorff Siemens AG Technology

Bug#1069593: libsequoia-octopus-librnp: dpkg-divert in preinst doesn't happen on upgrade

2024-04-22 Thread Holger Levsen
hi dkg, thanks for these bugreports! I've commited fixes and am doing test builds now and will upload shortly. On Sun, Apr 21, 2024 at 04:29:10AM -0400, Daniel Kahn Gillmor wrote: > Why does the package exclude the diversion when preinst runs on upgrade? I guess because I used a bad example...

Bug#1069301: linux-image-6.1.0-20-amd64: bluetooth causes kernel BUG - list_del corruption, (address)->prev is LIST_POISON2

2024-04-22 Thread Diederik de Haas
Control: tag -1 -moreinfo +upstream Control: forwarded -1 https://lore.kernel.org/linux-bluetooth/CADRbXaDqx6S+7tzdDPPEpRu9eDLrHQkqoWTTGfKJSRxY=ht...@mail.gmail.com/ On Monday, 22 April 2024 10:32:00 CEST Jeremy Lainé wrote: > Over the weekend I reported the issue to the linux-bluetooth mailing

Bug#1069372: efibootguard: FTBFS on arm64: kernel-stub/fdt.c:169:49: error: passing argument 2 of ‘CopyMem’ discards ‘const’ qualifier from pointer target type [-Werror=discarded-qualifiers]

2024-04-22 Thread Gylstorff Quirin
This is a upstream bug. Thanks for reporting, Quirin forwarded 1069372 efibootguard-...@googlegroups.com On 4/20/24 2:01 PM, Lucas Nussbaum wrote: Source: efibootguard Version: 0.16-2 Severity: serious Justification: FTBFS Tags: trixie sid ftbfs User: lu...@debian.org Usertags: ftbfs-20240420

Bug#1069657: libgeo-gpx-perl: Waypoint name encoding utf-8 does not work

2024-04-22 Thread Sebastiaan Couwenberg
Control: tags -1 upstream Control: forwarded -1 https://github.com/patjoly/geo-gpx/issues/6 I've forwarded this issue upstream. Please followup there. Kind Regards, Bas -- GPG Key ID: 4096R/6750F10AE88D4AF1 Fingerprint: 8182 DE41 7056 408D 6146 50D1 6750 F10A E88D 4AF1

Bug#1069643: dh_installman: doesn't honor nodoc build profile

2024-04-22 Thread Fab Stz
> I do not see anything in that commit that suggests that `dh_installman` > does not honor `nodoc`. What I am getting is that you wish that `dh` > would skip hook targets for any program that might react to `nodoc` > similar to `nostrip`. > > Assuming we agree on this being the ask, my answer

Bug#1069660: directvnc: Allow password file to be supplied vs just commandline

2024-04-22 Thread Tim Connors
Package: directvnc Version: 0.7.8-1 Severity: normal man 1 directvnc: -p, --password password string to be passed to the server for authentication. Use this with care! OK, so what's care? Well, the password is available for all system users and crackers to view with just

Bug#1069659: ITP: rust-lifeguard -- An object pool manager in Rust

2024-04-22 Thread Loren M. Lang
Package: wnpp Severity: wishlist Owner: "Loren M. Lang" X-Debbugs-Cc: debian-de...@lists.debian.org, lor...@north-winds.org * Package name: rust-lifeguard Version : 0.6.1 Upstream Contact: Zack Slayton * URL : https://crates.io/crates/lifeguard * License :

Bug#1069658: python3-lib389: dsconf security subcommand does not work due to misnamed function parameters

2024-04-22 Thread Jörg Behrmann
Package: python3-lib389 Version: 2.3.1+dfsg1-1 Severity: important Tags: patch Dear maintaner, when following the 389ds documentation [1] to enable TLS for 389ds I noticed that the step dsconf security rsa set \ --tls-allow-rsa-certificates on \ --nss-token "internal

Bug#1069657: libgeo-gpx-perl: Waypoint name encoding utf-8 does not work

2024-04-22 Thread Florian Lohoff
Package: libgeo-gpx-perl Version: 1.10-1 Severity: normal -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Hi, i was trying to create gpx waypoints with an utf-8 name which does not work: perl -Mutf8 -MGeo::Gpx -e '$g=Geo::Gpx->new(); $g->waypoints_add({ lat => 0, lon => 0, name => "üöä" });

Bug#1069600: dm-writeboost: isolation-machine autopkgtest fails: sudo: not found

2024-04-22 Thread Andreas Beckmann
On 21/04/2024 13.16, Paul Gevers wrote: Your package has an autopkgtest, great. I recently added support for isolation-machine tests on ci.debian.net for amd64 and added your package to the list to use that. However, it fails. Can you please Nice. Is there a chance to get isolation-machine

Bug#1069656: rust-clap-complete: please update to v4.5.1

2024-04-22 Thread Jonas Smedegaard
Source: rust-clap-complete Version: 4.4.9-2 Severity: normal Tags: upstream -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Please update to at least v4.5.1. -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEn+Ppw2aRpp/1PMaELHwxRsGgASEFAmYmILQACgkQLHwxRsGg

Bug#1069643: dh_installman: doesn't honor nodoc build profile

2024-04-22 Thread Niels Thykier
Control: tags -1 moreinfo On Mon, 22 Apr 2024 09:37:55 +0200 Fab Stz wrote: Package: debhelper Version: 13.15.3 Severity: normal Dear Maintainer, According to dh_installman, it should honor the nodoc build profile. However, it doesn't. As well as execute_before_dh_install. [...] Hi,

Bug#1069643: dh_installman: doesn't honor nodoc build profile

2024-04-22 Thread Fab Stz
Control: tags -1 - moreinfo Le lundi 22 avril 2024 10:12:45 CEST, vous avez écrit : > Control: tags -1 moreinfo > > On Mon, 22 Apr 2024 09:37:55 +0200 Fab Stz wrote: > > Package: debhelper > > Version: 13.15.3 > > Severity: normal > > > > Dear Maintainer, > > > > According to dh_installman,

Bug#1069301: Bug reported upstream

2024-04-22 Thread Jeremy Lainé
Over the weekend I reported the issue to the linux-bluetooth mailing list, which led to bisecting the issue down to a single commit: https://lore.kernel.org/linux-bluetooth/CADRbXaDqx6S+7tzdDPPEpRu9eDLrHQkqoWTTGfKJSRxY=ht...@mail.gmail.com/ Jeremy

Bug#1069642: linux-image-6.1.0-20-amd64: kernel panic after 2024-04-20

2024-04-22 Thread Damian
Same problem here, but with a different call trace. The RIP logline had one of `security_file_permission` and `security_netlink_send`, I don't remember which one.

Bug#1037903: xrt: ftbfs with GCC-13

2024-04-22 Thread Gianfranco Costamagna
On Sat, 16 Sep 2023 20:13:12 +0200 Jonathan Bergh wrote: Control: tags -1 + patch Fixes 1037903 due to upgrade to gcc-13 Hello, I had to add another one for arm64 build failure --- xrt-202210.2.13.466+dfsg.orig/src/runtime_src/core/edge/user/aie/common_layer/adf_api_config.h +++

Bug#1069655: libkf6userfeedback-data: missing Breaks+Replaces: libkuserfeedbackcoreqt6-1 (<< 6)

2024-04-22 Thread Andreas Beckmann
Package: libkf6userfeedback-data Version: 6.0.0-1 Severity: serious User: debian...@lists.debian.org Usertags: piuparts fileconflict Hi, during a test with piuparts I noticed your package fails to upgrade from 'sid' to 'experimental'. It installed fine in 'sid', then the upgrade to

Bug#1069654: RM: salt -- RoQA; no maintainers left

2024-04-22 Thread Bastian Blank
Package: ftp.debian.org Severity: normal X-Debbugs-Cc: s...@packages.debian.org, bdr...@debian.org, on...@debian.org, wa...@debian.org Control: affects -1 + src:salt User: ftp.debian@packages.debian.org Usertags: remove Please remove package salt. It was not released in stable. No response

Bug#884713: approx: systemd's approx.socket should be configured to not have any trigger limit

2024-04-22 Thread Arnaud Rebillout
On Mon, 18 Dec 2017 16:40:40 +0100 =?utf-8?q?Rapha=C3=ABl_Hertzog?= wrote: > But IMO the default configuration should work even when you make heavy use > of the package repositories... so I would like to see this in your default > approx.socket. Or at least you should raise the limit to

Bug#1069653: rust-toml: please update to v0.8.12

2024-04-22 Thread Jonas Smedegaard
Source: rust-toml Version: 0.8.8-2 Severity: normal Tags: upstream -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Please update to at least v0.8.12. -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEn+Ppw2aRpp/1PMaELHwxRsGgASEFAmYmGgYACgkQLHwxRsGg

Bug#1069652: rust-tokio: please update to v1.37.0

2024-04-22 Thread Jonas Smedegaard
Source: rust-tokio Version: 1.35.1-1 Severity: normal Tags: upstream -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Please update to at least v1.37.0. -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEn+Ppw2aRpp/1PMaELHwxRsGgASEFAmYmGdEACgkQLHwxRsGg

Bug#1064293: less: CVE-2022-48624

2024-04-22 Thread Salvatore Bonaccorso
Hi, On Sat, Apr 20, 2024 at 07:54:13AM -0400, P. J. McDermott wrote: > On 2024-04-19 at 15:55, Salvatore Bonaccorso wrote: > > Hi, > > > > FWIW, I'm actually preparing a security update for the two CVEs and > > for bookworm I was first planning to do a 590-2.1 reaching unstable, > > and so then

Bug#1069651: rust-regex: please update to v1.10.4

2024-04-22 Thread Jonas Smedegaard
Source: rust-regex Version: 1.10.2-1 Severity: normal Tags: upstream -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Please update to at least v1.10.4. -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEn+Ppw2aRpp/1PMaELHwxRsGgASEFAmYmGXUACgkQLHwxRsGg

Bug#1069650: rust-rayon: please update to v1.10.0

2024-04-22 Thread Jonas Smedegaard
Source: rust-rayon Version: 1.8.1-1 Severity: normal Tags: upstream -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Please update to at least v1.10.0. -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEn+Ppw2aRpp/1PMaELHwxRsGgASEFAmYmGT4ACgkQLHwxRsGg

Bug#1069649: rust-nu-ansi-term: please upgrade to v0.50

2024-04-22 Thread Jonas Smedegaard
Source: rust-nu-ansi-term Version: 0.49.0-1 Severity: normal Tags: upstream -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Please upgrade to, or separately provide, branch v0.50. -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEn+Ppw2aRpp/1PMaELHwxRsGgASEFAmYmGQIACgkQLHwxRsGg

Bug#1069648: rust-ctrlc: please update to v3.4.4

2024-04-22 Thread Jonas Smedegaard
Source: rust-ctrlc Version: 3.4.2-1 Severity: normal Tags: upstream -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Please update to at least v3.4.4. -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEn+Ppw2aRpp/1PMaELHwxRsGgASEFAmYmGLMACgkQLHwxRsGg

Bug#1069646: python-glance-store - Build-depends on deprecated package: python3-boto

2024-04-22 Thread Bastian Blank
Package: python-glance-store Version: 4.7.0-2 Severity: serious python-glance-store build-depends on deprecated package python3-boto. See #1058652 Also it seems to not build at all: | dpkg-buildpackage: info: source package python-glance-store | dpkg-buildpackage: info: source version 4.7.0-2 |

Bug#1069647: rust-color-eyre: please update to at least v0.6.3

2024-04-22 Thread Jonas Smedegaard
Source: rust-color-eyre Version: 0.6.2-1 Severity: normal Tags: upstream -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Please update to at least v0.6.3. -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEn+Ppw2aRpp/1PMaELHwxRsGgASEFAmYmGIYACgkQLHwxRsGg

Bug#1069644: rust-async-trait: please update to v0.1.77

2024-04-22 Thread Jonas Smedegaard
Source: rust-async-trait Version: 0.1.77-1 Severity: normal Tags: upstream -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Please update to at least v0.1.77. -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEn+Ppw2aRpp/1PMaELHwxRsGgASEFAmYmF70ACgkQLHwxRsGg

Bug#1069645: rust-clap: please update to v4.5.4

2024-04-22 Thread Jonas Smedegaard
Source: rust-clap Version: 4.4.18-1 Severity: normal Tags: upstream -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Please update to at least v4.5.4. -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEn+Ppw2aRpp/1PMaELHwxRsGgASEFAmYmF+8ACgkQLHwxRsGg

Bug#1069643: dh_installman: doesn't honor nodoc build profile

2024-04-22 Thread Fab Stz
Package: debhelper Version: 13.15.3 Severity: normal Dear Maintainer, According to dh_installman, it should honor the nodoc build profile. However, it doesn't. As well as execute_before_dh_install. -- System Information: Debian Release: 12.5 APT prefers stable-updates APT policy: (991,

Bug#1068818: sngrep: CVE-2024-3119 CVE-2024-3120

2024-04-22 Thread Victor Seva
Hi, On 21/4/24 21:58, Moritz Muehlenhoff wrote: > Hi Victor, > diff looks fine, but I don't believe this really needs a DSA; it's rather > obscure attack vector. > I think addressing this via the next Bookworm point release is perfectly > fine, what do you think? Fine for me. No objections

Bug#1069641: right versions

2024-04-22 Thread Alexandre Rossi
Hi, With the right versions, sorry for the noise. nmu uwsgi-plugin-php_2.0.22+4+0.0.15+b2 . ANY . unstable . -m "rebuild against new uwsgi.h" nmu uwsgi-plugin-luajit_2.0.22+4+0.0.8+b2 . ANY . unstable . -m "rebuild against new uwsgi.h" nmu uwsgi-plugin-mongo_2.0.24+3+0.0.9+b3 . ANY . unstable

Bug#1069191: glibc: GLIBC-SA-2024-0004/CVE-2024-2961: ISO-2022-CN-EXT: fix out-of-bound writes when writing escape sequence

2024-04-22 Thread Charlemagne Lasse
Hi, Can this be backported to older Debian versions via the security repo? This bug can be used to execute code when using the PHP engine: * https://www.offensivecon.org/speakers/2024/charles-fol.html * https://www.openwall.com/lists/oss-security/2024/04/18/4

Bug#1069499: mtbl: FTBFS on armhf: dh_auto_test: error: make -j4 check "TESTSUITEFLAGS=-j4 --verbose" VERBOSE=1 returned exit code 2

2024-04-22 Thread Robert Edmonds
Lucas Nussbaum wrote: > Source: mtbl > Version: 1.3.0-1 > Severity: serious > Justification: FTBFS > Tags: trixie sid ftbfs > User: lu...@debian.org > Usertags: ftbfs-20240420 ftbfs-trixie ftbfs-t64-armhf > > Hi, > > During a rebuild of all packages in sid, your package failed to build > on

Bug#1069641: nmu: uwsgi-plugin-php_2.0.22+1+0.0.15+b1 uwsgi-plugin-luajit_2.0.22+1+0.0.8+b1 uwsgi-plugin-mongo_2.0.22+1+0.0.9+b1

2024-04-22 Thread Alexandre Rossi
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: binnmu X-Debbugs-Cc: uwsgi-plugin-...@packages.debian.org, d...@jones.dk Control: affects -1 + src:uwsgi-plugin-php Control: affects -1 + src:uwsgi-plugin-luajit Control: affects -1 +

Bug#1069302: libxerces-c-samples: k.zmi...@gmail.com

2024-04-22 Thread Konrad Zminda
Package: libxerces-c-samples Followup-For: Bug #1069302 X-Debbugs-Cc: k.zmi...@gmail.com Steps to reproduce the issue : get up-to-date debian bookworm, apt-get install apache2 libxerces-c-samples [ see full output of output from dpkg --list > packages.txt ] put attached schema.xsd in

Bug#1069417: upgrade procedure instructs users to run “apt update” but neglects upgrading

2024-04-22 Thread Holger Wansing
Control: tags -1 + patch Manny wrote: > The Bookworm release notes instruct users to “upgrade” to the latest point > release of Bullseye prior to upgrading to Bookworm: > > > https://www.debian.org/releases/stable/i386/release-notes/ch-upgrading.en.html#upgrade-to-latest-point-release > >

Bug#1053334: galera-4: FTBFS because of expired certificates

2024-04-22 Thread Otto Kekäläinen
I was able to reproduce this for Bookworm both locally and in CI at https://salsa.debian.org/mariadb-team/galera-4/-/jobs/5620032 After importing latest upstream build/test passes: https://salsa.debian.org/otto/galera/-/jobs/5624466 Stable upload request filed at

Bug#1069637: hd-idle: version 1.21+ds-1 hangs the upgrade process

2024-04-22 Thread Alex Mestiashvili
On 4/22/24 02:54, Arthur Marsh wrote: Package: hd-idle Version: 1.21+ds-1 Severity: normal Dear Maintainer, *** Reporter, please consider answering these questions, where appropriate *** * What led up to the situation? Setting up hd-idle (1.21+ds-1) ... Installing new version of config

Bug#1069640: lintian still links to lintian.debian.org but it is gone

2024-04-22 Thread Adam Baxter
Package: lintian Version: 2.117.0 Severity: normal X-Debbugs-Cc: deb...@voltagex.org Dear Maintainer, This is related to #1053710 (but apparently Affects: isn't the right tag here? There should be a Related: tag IMO) * What led up to the situation? Lintian produces messages like "E:

Bug#1069639: bookworm-pu: package galera-4 26.4.18-0+deb12u1

2024-04-22 Thread Otto Kekäläinen
Package: release.debian.org Severity: normal Tags: bookworm User: release.debian@packages.debian.org Usertags: pu X-Debbugs-Cc: mari...@packages.debian.org Control: affects -1 + src:galera-4 I propose that the latest minor maintenance version of Galera be included in the stable release update

<    1   2