Bug#742990: News?

2014-05-06 Thread Frank Habermann
Hi, Frank, are you still active or should someone take over ? I'm asking because gitpkg is much less used than git-buildpackage and it might be easier to use Bastien's solution if we switch to git-buildpackage. From my side any help is welcome and somebody could take over. I am very busy at

Bug#641808: On ckeditor package

2014-01-29 Thread Frank Habermann
Hi, sorry for late reply. Lot of private stuff Feel free to upload an NMU package. I will try to fix the other bugs as soon as possible. regards, Frank -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact

Bug#706696: dojo: Please upgrade to new upstream version

2013-10-25 Thread Frank Habermann
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hello David, there is a new upstream version 1.8.3 of dojotoolkit available 1.9.1 is now available, and the version currently in the archive FTBFSes (#724124). I’d be happy to help maintaining this package (because the upcoming owncloud package

Bug#708319: Update to 1.7.1

2013-05-28 Thread Frank Habermann
close 708319 thanks Hi, version 1.7.1 was successfully uploaded. Frank -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#696483: Fix for CVE-2012-5657

2013-01-07 Thread Frank Habermann
Hi, i have prepared a package for squeeze: http://debian.lordlamer.de/zendframework/1.10.6squeeze1/zendframework_1.10.6-1squeeze2.dsc I also tested it and fixes the problem. I will contact security team now. regards, Frank signature.asc Description: This is a digitally signed message part.

Bug#696483: Uploaded to DELAYED/7

2012-12-29 Thread Frank Habermann
Hi, I've uploaded a NMU with the patch above to DELAYED/7. Thanks for your patch and the work and sorry for delayed answer. Christmas holidays and family ;) Now, i am sitting on a patch for stable/squeeze. regards, Frank -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org

Bug#688946: zendframework: CVE-2012-4451

2012-10-18 Thread Frank Habermann
close #688946 Hi, Remember Debian is in freeze, so please only apply the isolated securitx fix and request an unblock by filing a bug against release.debian.org I contacted upstream to clarify this. Zendframework Version 1 is not affected by this. So no fix is needed here! regards, Frank

Bug#686616: unblock: zendframework 1.11.13-1

2012-09-03 Thread Frank Habermann
Package: release.debian.org Severity: high User: release.debian@packages.debian.org Usertags: freeze-exception Hi, please unblock zendframework 1.11.13-1. Zendframework 1.11.13-1 fixes XML eXternal Entity (XXE) and XML Entity Expansion (XEE) vulnerabilities in Zend_Dom, Zend_Feed,

Bug#683418: [Debian RT] CVE-2012-4000: XSS vulnerability in fckeditor

2012-08-03 Thread Frank Habermann
Hi, I will create fixed packages tomorrow. Please try to isolate fixes from the other upstream changes (if any), since we are in freeze. For Squeeze, please build in a clean chroot and with -sa. I uploaded a fixed version to unstable. A fixed version for squeeze can be found here:

Bug#683418: [Debian RT] CVE-2012-4000: XSS vulnerability in fckeditor

2012-08-02 Thread Frank Habermann
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, upstream has released a fixed version. The spellchecker versions in perl and cfm contains also this vulnerability. I will create fixed packages tomorrow. I will try to contact upstream to find a solution. And can you check if ckeditor is

Bug#683418: [Debian RT] CVE-2012-4000: XSS vulnerability in fckeditor

2012-08-01 Thread Frank Habermann
Hi, I will try to contact upstream to find a solution. upstream is working on a solution and will give me feedback tomorrow. And can you check if ckeditor is affected too? I checked it and it was not affected. regards, Frank signature.asc Description: This is a digitally signed message

Bug#683418: [Debian RT] CVE-2012-4000: XSS vulnerability in fckeditor

2012-07-31 Thread Frank Habermann
Hi, an XSS vulnerability was found in fckeditor before 2.6.7. Please try to fix the problem using an isolated fix since we are in freeze. More info can be found at http://disse.cting.org/2012/06/22/fckeditor-reflected-xss-vulnerability/ Thanks for the advice. I found no official solution at

Bug#413062: tinymce: please bundle the compressor(s)

2012-04-17 Thread Frank Habermann
tags 413062 confirmed thanks Hi, i will add this as soon as possible. Frank signature.asc Description: This is a digitally signed message part.

Bug#413066: packaging tinymce locales?

2012-04-17 Thread Frank Habermann
tags 413066 confirmed thanks Bug is confirmed and will be done as soon as possible. signature.asc Description: This is a digitally signed message part.

Bug#666167: ckeditor: missing adapters/jquery.js file

2012-04-17 Thread Frank Habermann
tags 666167 confirmed thanks Hi, i will add this as soon as possible. Frank signature.asc Description: This is a digitally signed message part.

Bug#641808: ckeditor: Includes a copy of YUI which is packaged in debian

2012-04-17 Thread Frank Habermann
tags 641808 confirmed thanks Hi, i will fix this as soon as possible. Hopefully in the next version. Frank signature.asc Description: This is a digitally signed message part.

Bug#664082: fckeditor shoud not depends on an httpd server

2012-04-17 Thread Frank Habermann
tags 664082 confirmed thanks Hi, i will fix this in the next version. Frank signature.asc Description: This is a digitally signed message part.

Bug#638792: libjs-scriptaculous 1.9.0 breaks libjs-protaculous

2012-04-17 Thread Frank Habermann
tags 638792 confirmed thanks Hi, i will add this in the next version. But i think for package libjs-protoaculous the best would be if the files would be created at build time not at install time. So you did not have problems at installation time. Frank signature.asc Description: This is a

Bug#669168: debian-maintainers: Please add Frank Habermann as a Debian Maintainer

2012-04-17 Thread Frank Habermann
Package: debian-maintainers Severity: normal thanks Hi, Please add my key 01ED3AC7 to the DM keyring. Jetring changeset is attached. regards, Frank Habermann Comment: Add Frank Habermann lordla...@lordlamer.de as a Debian Maintainer Date: Tue, 17 Apr 2012 23:34:18 +0200 Action: import Data

Bug#591206: License updated (flvplayer)

2010-12-02 Thread Frank Habermann
Hi, sorry for late replay. Lot of private work ;) From my side it was all ok. Thanks for the work! regards, Frank Am 30.11.2010 16:25, schrieb Didier 'OdyX' Raboud: Le Tuesday 23 November 2010 13:15:50 Frank Habermann, vous avez écrit : I have contacted moxiecode. The answer

Bug#591206: License updated (flvplayer)

2010-11-23 Thread Frank Habermann
Hi, $ find . -name *swf* ./jscripts/tiny_mce/plugins/media/img/flv_player.swf ./examples/media/sample.swf How important are those files? Could those be replaced or removed without affecting application functionality? I found nothing about using the flv_player.swf in sources. Seems to be

Bug#591206: License updated (flvplayer)

2010-11-22 Thread Frank Habermann
Hi, $ find . -name *swf* ./jscripts/tiny_mce/plugins/media/img/flv_player.swf ./examples/media/sample.swf How important are those files? Could those be replaced or removed without affecting application functionality? I found nothing about using the flv_player.swf in sources. Seems to be

Bug#592385: zendframework: Unable to translate error messages because resources files are not shipped

2010-08-09 Thread Frank Habermann
Hi, Could you please provide resources files in the Debian package? I will add the stuff as soon as possible! regards, Frank signature.asc Description: This is a digitally signed message part.

Bug#413066: Packaging TinyMCE locales

2010-07-28 Thread Frank Habermann
Hi, sounds good for me. If you could help and post a patch it would be fine. Thanks and regards Frank signature.asc Description: This is a digitally signed message part.

Bug#566871: libjs-prototype: Using /javascript/ as the default alias easily breaks web

2010-03-25 Thread Frank Habermann
close #566871 thanks Could be closed because the bug is not in prototype package. Frank -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#480676: tinymce: please consider defining web server config in this package

2010-03-25 Thread Frank Habermann
close #480676 thanks Bug could be closed because the user should place the config in the vhost part and not in a global part of apache. Frank -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#511767: tinymce: please consider defining web server config in this package

2010-03-25 Thread Frank Habermann
close #511767 thanks Bug could be closed because version 3.3.2 will come to unstable next. Frank -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#538722: CVE-2009-2265: fckeditor is embedded in etch version

2010-03-25 Thread Frank Habermann
close #538722 thanks fixed in lenny, and testing/unstable; etch is unsupported, closing. Frank -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#555230: knowledgeroot: embeds prototype.js

2009-11-28 Thread Frank Habermann
reopen 555230 thanks The previous close is wrong. The version is still affected. regards, Frank -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#555229: knowledgeroot: CVE-2007-2383 and CVE-2008-7720 prototypejs vulnerabilities

2009-11-28 Thread Frank Habermann
reopen 555229 thanks The previous close is wrong. The version is still affected. regards, Frank -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#538722: knowledgeroot: embeds prototype.js

2009-11-28 Thread Frank Habermann
reopen 538722 thanks The previous close is wrong. The version is still affected. regards, Frank -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#544793: Acknowledgement (zf.sh and zf.php unavailable)

2009-09-06 Thread Frank Habermann
For Debian i think we could be even smarter. :-) Yes. The package in Ubuntu does not look so good i think. We could have zendframework (as it is now) or libphp-zendframework (for coherence with other php library), then zendframework-doc or libphp-zendframework-doc for the documentation and

Bug#536051: CVE-2009-2265, CVE-2009-2324: input sanitization errors

2009-07-07 Thread Frank Habermann
Hi, i contacted the security team ~6 hours ago with that. Frank -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#489806: tinymce: new upstream version

2008-07-07 Thread Frank Habermann
Package: tinymce Version: 3.0.8-1 Severity: normal A new upstream version 3.1.0.1 is available. Thanks Frank Habermann -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Bug#471641: Needs to use fckeditor

2008-03-19 Thread Frank Habermann
Package: egroupware-core Severity: serious Your package includes a copy of FCKEditor, which also is packaged as fckeditor in the archive. You need to fix your package to use the system-wide editor. Otherwise it requires too much overhead whenever a vulnerability in FCKEditor is found. Frank

Bug#469570: please update to new upstream version

2008-03-05 Thread Frank Habermann
Package: tinymce Please update this package to the new upstream version (3.0.3 at the moment). Frank Habermann -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Bug#467363: Needs to use fckeditor

2008-02-24 Thread Frank Habermann
Package: moinmoin-common Severity: serious Your package includes a copy of FCKEditor, which also is packaged as fckeditor in the archive. You need to fix your package to use the system-wide editor. Otherwise it requires too much overhead whenever a vulnerability in FCKEditor is found. Frank

Bug#467362: Needs to use fckeditor

2008-02-24 Thread Frank Habermann
Package: karrigell-doc Severity: serious Your package includes a copy of FCKEditor, which also is packaged as fckeditor in the archive. You need to fix your package to use the system-wide editor. Otherwise it requires too much overhead whenever a vulnerability in FCKEditor is found. Frank

Bug#431025: Bug#431026: Bug#433141: Bug#431025: Bug#431026: [PEAR-DEV] Quality assurancepropositionfor HTMLSax3

2007-11-13 Thread Frank Habermann
Hi, A debian package php-xml-htmlsafe3 has just entered debian Where can i find the package? I did not found it. Frank -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Bug#431026: Bug#433141: Bug#431025: Bug#431026: [PEAR-DEV] Quality assurancepropositionfor HTMLSax3

2007-11-02 Thread Frank Habermann
Hi, FYI: Harry is adding LGPL to HTMLSax and HTMLSax3. So it will be ok for debian or not? regards, Frank -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Bug#431025: Bug#431026: [PEAR-DEV] Quality assurance proposition for HTMLSax3

2007-10-30 Thread Frank Habermann
Hi all, good news from Harry, he has fixed the licence problem with HtmlSax and HTMLSax3 in CVS of pear. You can see it here: http://cvs.php.net/viewvc.cgi/pear/XML_HTMLSax/ regards, Frank -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL

Bug#447592: fckeditor

2007-10-24 Thread Frank Habermann
Hello, FYI: i am working on a package. I hope to upload it to unstable these days. regards, Frank -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Bug#444928: CVE-2007-5156 remote php file inclusion vulnerability in fckeditor

2007-10-08 Thread Frank Habermann
Hi, thanks for the link! Sorry for my mistake. I have tested it again and it works now. I dont know why my first test does not work. But that does not matter now. I hope to fix this tomorrow for stable and for unstable. Thanks. Frank pgpUoF7bZhps0.pgp Description: PGP signature

Bug#444928: CVE-2007-5156 remote php file inclusion vulnerability in fckeditor

2007-10-07 Thread Frank Habermann
is a apache configuration problem. So also here is not a problem in Knowledgeroot. Thanks for the report. Frank Habermann pgpnSY4dxLTy4.pgp Description: PGP signature

Bug#431026: Quality assurance proposition for HTMLSax3

2007-10-03 Thread Frank Habermann
Hi, i have talked with Lukas on the pear-dev list about that problem and he want to talk with Harry next week as you see here [0]. I hope he can clear this problem that we have a solution as fast as possible. Frank Habermann [0]: http://news.php.net/php.pear.dev/48218 -- To UNSUBSCRIBE

Bug#431026: Bug#433141: Clarifications on issues for this bug

2007-09-01 Thread Frank Habermann
Hi, Am Mittwoch, 18. Juli 2007 15:22 schrieb Michael Schultheiss: I spoke with the upstream Gallery developers and they're working on getting this module relicensed under BSD or some other GPL compatible license. Have you any feedback from the developers for this problem? regards, Frank

Bug#415784: recommends also postgresql-7.4 if you have postgresql-8.1

2007-03-21 Thread Frank Habermann
Package: phppgadmin Version: 4.0.1-3.1 When you install phppgadmin in etch/testing it need postgresql-7.4. This is a bad solution if you have installed postgresql-8.1. So you should change that you have recommends to postgresq 7.4 and 8.1 and not only to 7.4. Frank Habermann

Bug#398200: knowledgeroot: Upgrade overwrites config.inc.php without warning

2006-11-15 Thread Frank Habermann
Hi, i have fixed this in version 0.9.7.3-2. The config is now placed in /etc/knowledgeroot/ I will wait for your feedback and will close the bugreport if all is fine. regards, Frank -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL

Bug#398200: knowledgeroot: Upgrade overwrites config.inc.php without warning

2006-11-12 Thread Frank Habermann
Hi, thanks for the information. I will fix this! regards, Frank Habermann pgpWrwpJddmHA.pgp Description: PGP signature

Bug#381912: knowledgeroot: embedded FCKeditor and TinyMCE may have unfixed security

2006-08-09 Thread Frank Habermann
Hello, we have checked that bugs. All bugs are fixed in our fckeditor and in tinymce! Thanks for inform us! regards, Frank Habermann -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]