Bug#986018: avahi-daemon: local DoS (daemon dies) on badly formatted hostname query to /run/avahi-daemon/socket

2021-04-17 Thread Thomas Kremer
On 16.04.2021 08:57, Salvatore Bonaccorso wrote: > This is now CVE-2021-3502. > > Have you reported the issue to upstream? No, I have not. Yours, Thomas Kremer -- OpenPGP Key ID: 0x6BFFE5CF3C7720398928CE741F2DAE97486A60BF

Bug#986018: avahi-daemon: local DoS (daemon dies) on badly formatted hostname query to /run/avahi-daemon/socket

2021-03-27 Thread Thomas Kremer
me results for these queries: "a.", ".a", "a..b", ".b.c", "a.b.." Note that every local user has access to the socket. Yours Thomas Kremer -- System Information: Debian Release: 10.8 APT prefers stable APT policy: (700, 'stable'), (500, 'oldoldsta

Bug#984938: avahi-daemon: local DoS by event-busy-loop from writing long lines to /run/avahi-daemon/socket

2021-03-10 Thread Thomas Kremer
e connection the moment the buffer fills up). [1] https://github.com/lathiat/avahi/blob/master/avahi-daemon/simple-protocol.c Yours Thomas Kremer -- System Information: Debian Release: 10.8 APT prefers stable APT policy: (700, 'stable'), (500, 'oldoldstable'), (500, 'oldstable'), (450, 'tes

Bug#886496: libopengl-perl: glutTimerFunc: Segmentation fault

2019-01-22 Thread Thomas Kremer
quilt rather than against it... Yours Thomas -- OpenPGP Key ID: 0x6BFFE5CF3C7720398928CE741F2DAE97486A60BF Description: Fix https://bugs.debian.org/886496 * Patched pogl_glut.xs to fix pointer truncation in glutTimerFunc (Closes: #886496) Author: Thomas Kremer Bug-Debian: https://bugs.d

Bug#876541: [PATCH] Patch for bug 876541

2018-01-31 Thread Thomas Kremer
-censored question about anonymous maintainer lists' reaction patterns] Yours Thomas Kremer -- OpenPGP Key ID: 0x6BFFE5CF3C7720398928CE741F2DAE97486A60BF --- /usr/share/xul-ext/sieve/chrome/chromeFiles/content/editor/SieveFilterEditor.js.orig 2015-08-09 21:40:50.0 +0200 +++ /usr/share/xul-ext

Bug#886496: libopengl-perl: glutTimerFunc: Segmentation fault

2018-01-06 Thread Thomas Kremer
dow("title"); glutTimerFunc(1000,sub{}); glutMainLoop();' Segmentation fault $ For my case, I have a workaround using glutIdleFunc() instead, but that's not a solution for everyone. Can you reproduce? Yours Thomas Kremer -- System Information: Debian Release: 9.3 APT prefers stable APT p

Bug#868190: gatling: -u is silently ignored if is a username rather than a numeric user id

2017-07-24 Thread Thomas Kremer
Hi, I tracked down the offending line that lead to the failure of reporting a name lookup failure in the chroot, see attached patch. I haven't had the time to test the patch though. The issue is already fixed in upstream's ver. 0.15. The name lookup failure itself is due to the username being

Bug#868190: gatling: -u is silently ignored if is a username rather than a numeric user id

2017-07-12 Thread Thomas Kremer
order: - Fixing manpage and /etc/default/gatling to match actual behaviour - making gatling throw an error if the uid is non-numeric - implementing actual user name lookup and then reverting the above two. Yours Thomas Kremer -- System Information: Debian Release: 8.8 APT prefers oldstable APT

Bug#754174: libqtcore4-perl: Memory leaks / no destructor invocation

2014-07-08 Thread Thomas Kremer
events, which reduced the problem but did not eliminate all memory leaks so far. I tried getting my hands on the source of 4.8.4-1+b1 to check if the problem has been fixed there, but apt refused to cooperate. Yours Thomas Kremer -- System Information: Debian Release: 7.5 APT prefers stable

Bug#688041: Please confirm

2012-10-12 Thread Thomas Kremer
Hi, Norbert. On 12.10.2012 03:06, Norbert Preining wrote: You don't see the conceptual difference between collection splitting and splitting a class of files (DocFiles) of packages. In other words: You insist, that debian packages must not correspond to TeX Live packages (which are part of a

Bug#688041: Please confirm

2012-10-11 Thread Thomas Kremer
On 11.10.2012 20:53, Frank Kuester wrote: Now, if you insist on keeping the debian package == Tex Live collection correspondence, We do not insist. We already have implemented docsplitting. Judging by his actions as well as his words, Norbert does insist. In his view, any change in

Bug#688041: Please confirm

2012-10-08 Thread Thomas Kremer
Hi Norbert, On 05.10.2012 11:36, Norbert Preining wrote: Bugs of this kind I normally close, if I don't because I ignored them at some point they may rot forever in the BTS (which I consider BTW anyway not very useful at all). That is life, I honestly don't care. Thank you for pointing out,

Bug#688041: Please confirm

2012-10-04 Thread Thomas Kremer
. There are undoubtedly many other packages that split the compiled output of their sources into smaller binary packages (e.g. when splitting into -data, -doc, -dev etc.) without needing written consent by upstream. [...] Yours Thomas Kremer -- To UNSUBSCRIBE, email to debian-bugs-dist-requ

Bug#688041: Please confirm

2012-10-03 Thread Thomas Kremer
Dear Maintainer, It's been two weeks now and there's no response yet. Did you read this bug report? In light of the several-years-ignored other bug reports in this package, I would greatly appreciate some feedback on the reception of this one. Thanks, Thomas Kremer -- To UNSUBSCRIBE, email

Bug#688041: texlive-fonts-extra: package size reached 400MB. Please split the package.

2012-09-18 Thread Thomas Kremer
to download and store 400 MB of data if he only needs one specific font. This would also reduce the lintian warnings about duplicate font files. Thanks, Thomas Kremer -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas

Bug#542353: [Patch] Re: Clive error: nothing to extract

2009-08-24 Thread Thomas Kremer
Hi Damyan, I've managed to make a chroot and install clive/sid (2.2.4-1). The video I've tested could be found without a problem. For the Lenny version, I haven't found any youtube link that worked without the patch, so basically every url is an example url. My test case was this one:

Bug#542353: [Patch] Re: Clive error: nothing to extract

2009-08-19 Thread Thomas Kremer
+0200 +++ clive-0.4.18/debian/changelog 2009-08-19 19:45:26.0 +0200 @@ -1,3 +1,9 @@ +clive (0.4.18-1fix1) unstable; urgency=low + + * Fixed youtube page style change. + + -- Thomas Kremer Wed, 19 Aug 2009 19:45:09 +0200 + clive (0.4.18-1) unstable; urgency=low * New upstream