Bug#508593: marked as done (CVE-2008-5432: Cross-site scripting (XSS) vulnerability via a Wiki page name)

2008-12-16 Thread Debian Bug Tracking System
Your message dated Tue, 16 Dec 2008 07:47:05 + with message-id e1lcue1-0001ue...@ries.debian.org and subject line Bug#508593: fixed in moodle 1.8.2.dfsg-1 has caused the Debian Bug report #508593, regarding CVE-2008-5432: Cross-site scripting (XSS) vulnerability via a Wiki page name to be

Bug#507947: marked as done (moodle: html2text.php is not DFSG-free)

2008-12-16 Thread Debian Bug Tracking System
Your message dated Tue, 16 Dec 2008 07:47:05 + with message-id e1lcue1-0001uc...@ries.debian.org and subject line Bug#507947: fixed in moodle 1.8.2.dfsg-1 has caused the Debian Bug report #507947, regarding moodle: html2text.php is not DFSG-free to be marked as done. This means that you

Bug#508890: texlive-fonts-extra: umrand nonfree

2008-12-16 Thread Norbert Preining
Package: texlive-fonts-extra Version: 2007.dfsg.11-1 Severity: serious Justification: nonfree license upstream: r11600 | karl | 2008-12-13 02:03:44 +0100 (Sat, 13 Dec 2008) | 1 line rm umrand, nonfree Changed paths: D /trunk/Master/texmf-dist/doc/fonts/umrand D

Bug#507242: amule-daemon: causes OOM's by leaking lots of memory [RC-LastCall]

2008-12-16 Thread Didier Raboud
Hi again Klaas, As reporter of bug 507242 [0], you have been pinged twice on the 3. and on the 9. of December, with no answer from you. As noone else could reproduce your bug (and raised his voice) and without answer from you for one week (until the 23. of December), I will either close this

Processed: (pas de sujet)

2008-12-16 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: reopen 494760 Bug#494760: kernel-patch-nfs-ngroups: Doesn't apply against Lenny kernel 'reopen' may be inappropriate when a bug has been closed with a version; you may need to use 'found' to remove fixed versions. Bug reopened, originator not

Bug#508907: merkaartor: crash with Object::connect: No such signal QWebFrame::loadDone(bool)

2008-12-16 Thread Jens Wilke
Package: merkaartor Version: 0.0.11~svn7913-2 Severity: grave Justification: renders package unusable crashes on zoom in this bug is fixed in 0.12-1 bugfix: http://www.mail-archive.com/merkaar...@openstreetmap.org/msg00295.html -- System Information: Debian Release: lenny/sid APT prefers

Bug#505440: marked as done (initramfs-tools: leaks environment)

2008-12-16 Thread Debian Bug Tracking System
Your message dated Tue, 16 Dec 2008 15:32:02 + with message-id e1lcbty-0004x8...@ries.debian.org and subject line Bug#505440: fixed in initramfs-tools 0.92m has caused the Debian Bug report #505440, regarding initramfs-tools: leaks environment to be marked as done. This means that you claim

Bug#426465: marked as done (/init exports MODPROBE_OPTIONS=-qb)

2008-12-16 Thread Debian Bug Tracking System
Your message dated Tue, 16 Dec 2008 15:32:02 + with message-id e1lcbty-0004wy...@ries.debian.org and subject line Bug#426465: fixed in initramfs-tools 0.92m has caused the Debian Bug report #426465, regarding /init exports MODPROBE_OPTIONS=-qb to be marked as done. This means that you claim

Bug#507059: marked as done (initramfs-tools: Wrong check for udevadm in functions)

2008-12-16 Thread Debian Bug Tracking System
Your message dated Tue, 16 Dec 2008 15:32:03 + with message-id e1lcbtz-0004xa...@ries.debian.org and subject line Bug#507059: fixed in initramfs-tools 0.92m has caused the Debian Bug report #507059, regarding initramfs-tools: Wrong check for udevadm in functions to be marked as done. This

Processed: severity of 508907 is serious

2008-12-16 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: severity 508907 serious Bug#508907: merkaartor: crash with Object::connect: No such signal QWebFrame::loadDone(bool) Severity set to `serious' from `grave' End of message, stopping processing here. Please contact me if you need assistance.

Bug#508788: screenruler + ruby vs experimental gtk?

2008-12-16 Thread Andreas Henriksson
Hello Sam! You have GTK+ packages from experimental installed, right? That's probably the culprit here... see #508272. -- Andreas Henriksson -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#508472: Newer upstream version released

2008-12-16 Thread Gunnar Wolf
retitle 508472 Please update to upstream version 5.14 thanks Version 5.14 was released. This fixes only a compatibility problem that should not bite Debian - However, if you are updating, well... Please update to the latest ;-) I see the other bug I filed on drupal6 was already closed - If you

Bug#508788: screenruler + ruby vs experimental gtk?

2008-12-16 Thread Sam Morris
On Tue, 2008-12-16 at 13:06 +0100, Andreas Henriksson wrote: Hello Sam! You have GTK+ packages from experimental installed, right? That's probably the culprit here... see #508272. Looks like it--thanks for the info. :) -- Sam Morris s...@robots.org.uk -- To UNSUBSCRIBE, email to

Processed: Re: Bug#507947 closed by Francois Marier franc...@debian.org (Bug#507947: fixed in moodle 1.8.2.dfsg-1)

2008-12-16 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: clone 507947 -1 Bug#507947: moodle: html2text.php is not DFSG-free Bug 507947 cloned as bug 508909. retitle -1 remote code execution via preg_replace in html2text.php Bug#508909: moodle: html2text.php is not DFSG-free Changed Bug title to

Bug#507947: closed by Francois Marier franc...@debian.org (Bug#507947: fixed in moodle 1.8.2.dfsg-1)

2008-12-16 Thread Raphael Geissert
clone 507947 -1 retitle -1 remote code execution via preg_replace in html2text.php tag -1 patch security thanks Hi Francois, [...] * Replace html2text with a GPL alternative (closes: #507947) I'm, so sorry, completely forgot to tell you about the recent issue we discovered in roundcube's

Processed: Re: Bug#508886: [fwbuilder] Does not honor custom install script

2008-12-16 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: severity 508886 normal Bug#508886: [fwbuilder] Does not honor custom install script Severity set to `normal' from `grave' thanks Stopping processing here. Please contact me if you need assistance. Debian bug tracking system administrator

Bug#498928: marked as done (SyntaxError: from __future__ imports must occur at the beginning of the file)

2008-12-16 Thread Debian Bug Tracking System
Your message dated Tue, 16 Dec 2008 14:32:03 + with message-id e1lcaxv-0001an...@ries.debian.org and subject line Bug#498928: fixed in python-soappy 0.12.0-4 has caused the Debian Bug report #498928, regarding SyntaxError: from __future__ imports must occur at the beginning of the file to be

Processed: tagging 508788

2008-12-16 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: # only happens together with gtk+ from exp. tags 508788 experimental Bug#508788: screenruler: Will not run There were no tags set. Tags added: experimental End of message, stopping processing here. Please contact me if you need assistance.

Processed: Re: Bug#508322: wodim: Cannot load media. Cannot init drive.

2008-12-16 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: severity 508322 normal Bug#508322: wodim: Cannot load media. Cannot init drive. Severity set to `normal' from `grave' thanks Stopping processing here. Please contact me if you need assistance. Debian bug tracking system administrator

Processed: notfound 508909 in 1.6.3-2, notfound 508909 in 1.8.2-2, bug 508909 is not forwarded ...

2008-12-16 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: notfound 508909 1.6.3-2 Bug#508909: remote code execution via preg_replace in html2text.php Bug no longer marked as found in version 1.6.3-2. (By the way, this Bug is currently marked as done.) notfound 508909 1.8.2-2 Bug#508909: remote code

Bug#508886: [fwbuilder] Does not honor custom install script

2008-12-16 Thread Christian Renner
Package: fwbuilder Version: 3.0.2-1 Severity: grave --- Please enter the report below this line. --- When a custom installer is configured in the firewall setting this is ignored and the build in installer is used. --- System information. --- Architecture: i386 Kernel: Linux

Bug#508788: Should only happen if you have GTK+ from experimental

2008-12-16 Thread Steve Cotton
(forgot to CC 508788-submit...@b.d.o) Hi Sam, The same missing symbol is reported in bug #508272 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508272 Quoting from there: This should only be a problem if you install GTK+ from experimental. Solution, don't! :) Please would you check if

Bug#508787: regarding rdesktop disk/share redirection regression.

2008-12-16 Thread Andreas Henriksson
Hello Andreas! Here's a shot in the dark, to try to narrow this down. Please ignore me if someone else contacts you about this issue. Based on your report that rdesktop disk/share redirection worked with etch and not in lenny, I made a diff and sorted out the very tiny changes that was not just

Bug#508443: 508443 also on 2.6.23/sparc64

2008-12-16 Thread Nelson A. de Oliveira
Hi Evgeni! On Tue, 16 Dec 2008 08:46:52 +0100 Evgeni Golov sarge...@die-welt.net wrote: I've a sparc running 2.6.23 (cant go to = 2.6.24 due to other bugs) and I can reproduce this bug. Attached you find a bt full, but it does not look very helpfull, can it be that the problem is in librsvg,

Bug#507721: [pkg-cryptsetup-devel] Bug#507721: cryptsetup: Sometimes initrd ends up missing conf/conf.d/cryptroot file in it

2008-12-16 Thread Jonas Meurer
On 16/12/2008 Christian Jaeger wrote: Christian Jaeger wrote: and if the missing recursion of get_lvm_deps() is really the reason, why does it only fail on some kernels for you? As I did say in my previous mails, I don't know. And I don't know whether it's got anything to do

Bug#503712: state of #503712

2008-12-16 Thread Niko Tyni
On Sun, Dec 14, 2008 at 10:50:44AM +0200, Eugene V. Lyubimkin wrote: Hello Niko, Jonas. Any news/decisions regarding this bug? Not to my knowledge, but I'm not a ghostscript maintainer. Things I can see that could get this forward: - testing if listing gs-common in

Bug#505237: marked as done (/etc/init.d/snmpd start reports error if already running)

2008-12-16 Thread Debian Bug Tracking System
Your message dated Tue, 16 Dec 2008 18:02:05 + with message-id e1lcefb-0006fk...@ries.debian.org and subject line Bug#505237: fixed in net-snmp 5.4.1~dfsg-12 has caused the Debian Bug report #505237, regarding /etc/init.d/snmpd start reports error if already running to be marked as done.

Bug#508788: Should only happen if you have GTK+ from experimental

2008-12-16 Thread Steve Cotton
The same missing symbol is reported in bug #508272 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508272 Quoting from there: This should only be a problem if you install GTK+ from experimental. Solution, don't! :) Please would you check if your version of the libgtk2.0-0 package is from

Processed: Newer upstream version released

2008-12-16 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: retitle 508472 Please update to upstream version 5.14 Bug#508472: drupal5: Please update to upstream version 5.13 Changed Bug title to `Please update to upstream version 5.14' from `drupal5: Please update to upstream version 5.13'. thanks

Bug#507721: [pkg-cryptsetup-devel] Bug#507721: cryptsetup: Sometimes initrd ends up missing conf/conf.d/cryptroot file in it

2008-12-16 Thread Christian Jaeger
Jonas Meurer wrote: Thanks for your great debugging work, Christian. I wouldn't have been able to track down this bug that soon without your invaluable help. Same goes to Ben Hutchings and Yves-Alexis Perez. You rock! Thanks for the credit. I've just prepared cryptsetup 1.0.6-7 with this

Bug#508133: [pkg-mad-maintainers] Bug#508133: audacity: munmap_chunk(): invalid pointer: 0x00000000026f4eb0

2008-12-16 Thread Kurt Roeckx
On Sat, Dec 13, 2008 at 04:30:52PM +0100, Kurt Roeckx wrote: tags 508133 + patch security thanks On Tue, Dec 09, 2008 at 06:59:08AM +0100, Max Kellermann wrote: It's a raw PCM file (16 bit stereo, 44.1 or 48 kHz). The crash is reproducible by invoking audacity libmad-crash-test.

Bug#508781: marked as done (mock: cannot find plugins)

2008-12-16 Thread Debian Bug Tracking System
Your message dated Tue, 16 Dec 2008 19:02:03 + with message-id e1lcfbd-0002fr...@ries.debian.org and subject line Bug#508781: fixed in mock 0.9.7-2.1 has caused the Debian Bug report #508781, regarding mock: cannot find plugins to be marked as done. This means that you claim that the problem

Processed: tagging as pending bugs that are closed by packages in NEW

2008-12-16 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: # Tue Dec 16 19:03:35 UTC 2008 # Tagging as pending bugs that are closed by packages in NEW # http://ftp-master.debian.org/new.html # # Source package in NEW: network-manager tags 503682 + pending Bug#503682: network-manager-gnome: partial

Bug#508938: Source changed between two revisions

2008-12-16 Thread Onkar Shinde
Package: libjboss-web-services-java Version: 0.0+svn5660+dak1-1 Severity: serious I am filing a bug (with minor changes) since I got no reply to my mail at [1]. I was recently checking if jbossas4 version from Debian unstable builds properly on Ubuntu so that I can drop changes made in last

Bug#508940: CVE-2008-5379: Symlink attack

2008-12-16 Thread Steffen Joeris
Package: netdisco-mibs-installer Severity: grave Tags: security Justification: user security hole Hi, the following CVE (Common Vulnerabilities Exposures) id was published for netdisco-mibs-installer. CVE-2008-5379[0]: | netdisco-mibs-installer 1.0 allows local users to overwrite arbitrary |

Bug#508943: [rsyslog] /var/lib/dpkg/info/rsyslog.postinst: 76: arith: syntax error: s+1

2008-12-16 Thread CSights
Package: rsyslog Version: 3.18.5-1 Severity: critical (critical b/c prevents installation) Hi, I get this error when installing rsyslog: Setting up rsyslog (3.18.5-1) ... /var/lib/dpkg/info/rsyslog.postinst: 76: arith: syntax error: s+1 dpkg: error processing rsyslog (--configure):

Bug#508565: Testing against 20061008-3

2008-12-16 Thread Asheesh Laroia
On Tue, 16 Dec 2008, Juan Carlos Suarez wrote: Dear Asheesh and Evgeni, I have tested the most recent version of f2c with my code. Unfortunately it still crashes showing the same error messages: Can you try downloading and compiling ftp://netlib.bell-labs.com:21/netlib/f2c/src.tar and

Bug#508943: [rsyslog] /var/lib/dpkg/info/rsyslog.postinst: 76: arith: syntax error: s+1

2008-12-16 Thread Michael Biebl
CSights wrote: Package: rsyslog Version: 3.18.5-1 Severity: critical (critical b/c prevents installation) Hi, I get this error when installing rsyslog: Setting up rsyslog (3.18.5-1) ... /var/lib/dpkg/info/rsyslog.postinst: 76: arith: syntax error: s+1 dpkg: error processing

Bug#508947: FTBFS: golly if libwxgtk2.6-dev is present

2008-12-16 Thread Sebastian Andrzej Siewior
Package: golly Version: 1.4-1 Severity: Serious golly fails to build from source if libwxbase2.6-dev is present. golly itself depends on libwxbase2.8-dev. Both packages packages provide a wx-config which is used to determine cflags. wx-config is managed by update-alternatives. I had 2.6 installed

Bug#508943: (no subject)

2008-12-16 Thread CSights
Hi Michael, What shell do you use (/bin/sh)? That computer is using the stable version of dash. So I guess older versions of dash give that error. Does the script need to be compatible with the older dash? Otherwise the problem is that I'm mixing stable and testing

Bug#508950: flashplugin-nonfree installs amd64 flash on my i386 box

2008-12-16 Thread Alexander Gerasiov
Package: flashplugin-nonfree Version: 1:2.1 Severity: serious Hi there. I have a i386 system installed on my adm64 capable PC. And I'm using amd64 kernel (because I like chroots :) ), but new flashplugin-nonfree installs amd64 version of plugin, not i386. g...@vice:~$ uname -a Linux vice

Bug#508950: Patch for #508950

2008-12-16 Thread Alexander Gerasiov
Package: flashplugin-nonfree Version: 1:2.1 Followup-For: Bug #508950 Here is this stupid patch :) -- System Information: Debian Release: lenny/sid APT prefers testing-proposed-updates APT policy: (700, 'testing-proposed-updates'), (700, 'testing'), (670, 'proposed-updates'), (670,

Processed: tagging 508950

2008-12-16 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: # Automatically generated email from bts, devscripts version 2.10.35lenny1 tags 508950 + patch Bug#508950: flashplugin-nonfree installs amd64 flash on my i386 box There were no tags set. Tags added: patch End of message, stopping processing

Bug#508962: boost1.37_1.37.0-2(mips/unstable): FTBFS

2008-12-16 Thread Thiemo Seufer
Package: boost1.37 Version: 1.37.0-2 Severity: serious There was an error while trying to autobuild your package: Automatic build of boost1.37_1.37.0-2 on ball by sbuild/mips 99.99 Build started at 20081216-2008 [...] ** Using build dependencies supplied by package: Build-Depends

Bug#504340: djvulibre-plugin #504340: upstream patch not successful in lenny?

2008-12-16 Thread Thomas Viehmann
Hi, regarding #504340 aka #507972, I am afraid that I have to report that applying the upstream patch (making the nsdjvu.c identical to unstable's) does not seem to solve the crash in testing's djvulibre-plugin. Unfortunately, I also don't seem to have the best of luck getting a stacktrace or

Bug#508943: marked as done ([rsyslog] /var/lib/dpkg/info/rsyslog.postinst: 76: arith: syntax error: s+1)

2008-12-16 Thread Debian Bug Tracking System
Your message dated Tue, 16 Dec 2008 23:47:13 + with message-id e1lcjdb-0005zl...@ries.debian.org and subject line Bug#508943: fixed in rsyslog 3.18.6-2 has caused the Debian Bug report #508943, regarding [rsyslog] /var/lib/dpkg/info/rsyslog.postinst: 76: arith: syntax error: s+1 to be marked

Processed: tagging 508032, tagging 508030

2008-12-16 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: tags 508032 security Bug#508032: CVE-2008-4311 vulnerability Tags were: security Bug#503532: send_requested_reply=true allows all non-reply messages Tags added: security tags 508030 security Bug#508030: CVE-2008-4310 denial of service flaw There

Bug#446405: ardour: libsndfile status update?

2008-12-16 Thread The Anarcat
Package: ardour Followup-For: Bug #446405 what's the status on the libsndfile upstream release here? it seems like sid has the latest libsndfile, is that okay now with Ardour? too bad this kept ardour out of lenny... -- System Information: Debian Release: lenny/sid APT prefers testing APT

Bug#400066: marked as done (lcdproc_0.5.1-2(powerpc/unstable): FTBFS: impossible constraint in asm)

2008-12-16 Thread Debian Bug Tracking System
Your message dated Wed, 17 Dec 2008 14:54:44 +1100 with message-id 1229486084.9977.25.ca...@jdesk.ivt.com.au and subject line Appears to have been fixed: relevant buildds (except S390) are reporting clean builds on 0.5.2-1.2+ has caused the Debian Bug report #400066, regarding

Bug#508962: [pkg-boost-devel] Bug#508962: boost1.37_1.37.0-2(mips/unstable): FTBFS

2008-12-16 Thread Steve M. Robbins
On Wed, Dec 17, 2008 at 12:27:55AM +0100, Thiemo Seufer wrote: Apparently the four failing targets are caused by an attempt to build long double support on architectures which don't have support for it. Yes. I had a patch to disable long double support, then removed it because I thought

Processed: bts

2008-12-16 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: close 508950 Bug#508950: flashplugin-nonfree installs amd64 flash on my i386 box 'close' is deprecated; see http://www.debian.org/Bugs/Developer#closing. Bug closed, send any further explanations to Alexander Gerasiov g...@cs.msu.su stop

Bug#454976: marked as done (gcc-snapshot: Unusable gcc: error while loading shared libraries: libmpfr.so.1)

2008-12-16 Thread Debian Bug Tracking System
Your message dated Wed, 17 Dec 2008 07:30:14 +0100 with message-id 18760.40054.246527.294...@gargle.gargle.howl and subject line Re: gcc-snapshot: missing dependency has caused the Debian Bug report #454667, regarding gcc-snapshot: Unusable gcc: error while loading shared libraries: libmpfr.so.1

Bug#454667: marked as done (gcc-snapshot: missing dependency)

2008-12-16 Thread Debian Bug Tracking System
Your message dated Wed, 17 Dec 2008 07:30:14 +0100 with message-id 18760.40054.246527.294...@gargle.gargle.howl and subject line Re: gcc-snapshot: missing dependency has caused the Debian Bug report #454667, regarding gcc-snapshot: missing dependency to be marked as done. This means that you