Processed: Re: lam4-dev: mpi alternative incompatible with current openmpi, mpich

2019-03-14 Thread Debian Bug Tracking System
Processing control commands: > tag -1 patch Bug #924452 [lam4-dev] lam4-dev: mpi alternative incompatible with current openmpi, mpich Added tag(s) patch. -- 924452: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=924452 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems

Bug#924452: lam4-dev: mpi alternative incompatible with current openmpi, mpich

2019-03-14 Thread Andreas Beckmann
Followup-For: Bug #924452 Control: tag -1 patch Hi, attached is my attempt to modernize the alternatives (and clean up some more bits). I've quickly tested upgrading in a chroot and it didn't explode immediately. Andreas diff -Nru lam-7.1.4/debian/changelog lam-7.1.4/debian/changelog ---

Bug#924397: corekeeper: insecure use of world-writable /var/crash

2019-03-14 Thread Paul Wise
On Thu, 2019-03-14 at 12:12 +0100, Jakub Wilk wrote: > As a data point, apport creates /var/crash as world-writable in postinst: Does apport use a core dump handler? If so it shouldn't need a world writable directory since the core dump handler runs as root. corekeeper and apport conflict so

Bug#924619: shim-signed,shim-helpers-amd64-signed: both ship /usr/lib/shim/fbx64.efi.signed

2019-03-14 Thread Andreas Beckmann
Package: shim-signed,shim-helpers-amd64-signed Severity: serious User: debian...@lists.debian.org Usertags: piuparts Control: found -1 1.28+nmu3+0.9+1474479173.6c180c6-1 Control: found -1 1+15+1533136590.3beb971+5 Hi, during a test with piuparts I noticed your package failed to install because

Processed: shim-signed,shim-helpers-amd64-signed: both ship /usr/lib/shim/fbx64.efi.signed

2019-03-14 Thread Debian Bug Tracking System
Processing control commands: > found -1 1.28+nmu3+0.9+1474479173.6c180c6-1 Bug #924619 [shim-signed,shim-helpers-amd64-signed] shim-signed,shim-helpers-amd64-signed: both ship /usr/lib/shim/fbx64.efi.signed There is no source info for the package 'shim-helpers-amd64-signed' at version

Bug#912549: icedtea-web FTBFS with OpenJDK 11

2019-03-14 Thread Matthias Klose
On 14.03.19 23:03, Emmanuel Bourg wrote: > > > On 13/03/2019 17:47, Matthias Klose wrote: > >> please look at the new upstream 1.7.2 and 1.8 releases. > > I got a quick look at these new versions released this week, IcedTea Web > 1.7.2 is rather close to the version in unstable since October

Bug#923891: Workaround Instructions

2019-03-14 Thread Soren Stoutner
As a temporary and messy workaround, you can download the upstream 4.0.1-1 release from http://www.redmine.org/releases/redmine-4.0.1.tar.gz. Then replace the contents of the following two directories with those from the tarball. /usr/share/redmine/app /usr/share/redmine/public I am all in

Bug#918309: marked as done (sphinxcontrib-programoutput: Please update to v0.13 that is compatible with Sphinx 1.8)

2019-03-14 Thread Debian Bug Tracking System
Your message dated Thu, 14 Mar 2019 23:04:30 + with message-id and subject line Bug#918309: fixed in sphinxcontrib-programoutput 0.11-3.1 has caused the Debian Bug report #918309, regarding sphinxcontrib-programoutput: Please update to v0.13 that is compatible with Sphinx 1.8 to be marked as

Processed: tagging 924615, found 924615 in 0~20181115.85588389-2

2019-03-14 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tags 924615 + upstream Bug #924615 [src:edk2] CVE-2018-12178 CVE-2018-12180 CVE-2018-12181 Added tag(s) upstream. > found 924615 0~20181115.85588389-2 Bug #924615 [src:edk2] CVE-2018-12178 CVE-2018-12180 CVE-2018-12181 Marked as found in versions

Processed: bug 924616 is forwarded to https://bugzilla.gnome.org/show_bug.cgi?id=796424

2019-03-14 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > forwarded 924616 https://bugzilla.gnome.org/show_bug.cgi?id=796424 Bug #924616 [src:evolution] CVE-2018-15587 Set Bug forwarded-to-address to 'https://bugzilla.gnome.org/show_bug.cgi?id=796424'. > thanks Stopping processing here. Please contact

Processed: found 924613 in 20140202+stable-3.1, fixed 924613 in 20180621~6979c25-1

2019-03-14 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > found 924613 20140202+stable-3.1 Bug #924613 [src:gnulib] CVE-2009-5155 Marked as found in versions gnulib/20140202+stable-3.1. > fixed 924613 20180621~6979c25-1 Bug #924613 [src:gnulib] CVE-2009-5155 Marked as fixed in versions

Processed: tagging 924610, found 924610 in 2.0.9+dfsg1-1, found 924610 in 2.0.5+dfsg1-2

2019-03-14 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tags 924610 + upstream Bug #924610 [src:libsdl2] libsdl2: Multiple security issues Added tag(s) upstream. > found 924610 2.0.9+dfsg1-1 Bug #924610 [src:libsdl2] libsdl2: Multiple security issues Marked as found in versions libsdl2/2.0.9+dfsg1-1.

Processed: found 924609 in 1.2.15+dfsg2-4, found 924609 in 1.2.15+dfsg1-4, tagging 924609

2019-03-14 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > found 924609 1.2.15+dfsg2-4 Bug #924609 [src:libsdl1.2] libsdl1.2: Multiple security issues Marked as found in versions libsdl1.2/1.2.15+dfsg2-4. > found 924609 1.2.15+dfsg1-4 Bug #924609 [src:libsdl1.2] libsdl1.2: Multiple security issues Marked

Bug#924616: CVE-2018-15587

2019-03-14 Thread Moritz Muehlenhoff
Source: evolution Severity: grave Tags: security https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-15587: https://bugzilla.gnome.org/show_bug.cgi?id=796424 https://gitlab.gnome.org/GNOME/evolution/commit/9c55a311325f5905d8b8403b96607e46cf343f21

Bug#924615: CVE-2018-12178 CVE-2018-12180 CVE-2018-12181

2019-03-14 Thread Moritz Muehlenhoff
Source: edk2 Severity: grave Tags: security Please see https://security-tracker.debian.org/tracker/CVE-2018-12178 https://security-tracker.debian.org/tracker/CVE-2018-12180 https://security-tracker.debian.org/tracker/CVE-2018-12181 Cheers, Moritz

Bug#912549: icedtea-web FTBFS with OpenJDK 11

2019-03-14 Thread Emmanuel Bourg
On 13/03/2019 17:47, Matthias Klose wrote: > please look at the new upstream 1.7.2 and 1.8 releases. I got a quick look at these new versions released this week, IcedTea Web 1.7.2 is rather close to the version in unstable since October and has a few extra Java 9+ fixes, it's probably worth

Bug#807666: reopen 807666, it should be fixed properly

2019-03-14 Thread Ana Guerrero Lopez
unarchive 807666 reopen 807666 notfixed 807666 mpich/3.2-1~exp1 found 807666 3.3-2 forwarded 807666 https://lists.mpich.org/pipermail/discuss/2019-March/011160.html kthxbye Hi, This bug wasn't closed properly. While a rebuild of the package with the new upload fixed the problem temporarily,

Processed: reopen 807666, it should be fixed properly

2019-03-14 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > unarchive 807666 Bug #807666 {Done: Anton Gladky } [src:mpich] mpich: overly restrictive GCC check Unarchived Bug 807666 > reopen 807666 Bug #807666 {Done: Anton Gladky } [src:mpich] mpich: overly restrictive GCC check 'reopen' may be

Bug#924613: CVE-2009-5155

2019-03-14 Thread Moritz Muehlenhoff
Source: gnulib Severity: grave Tags: security Please see https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-5155 Patch: http://git.savannah.gnu.org/cgit/gnulib.git/commit/?id=5513b40999149090987a0341c018d05d3eea1272 Cheers, Moritz

Bug#497471: sarge images have syslinux binaries without source

2019-03-14 Thread Daniel Baumann
reopen 497471 thanks it doesn't matter if debian supports sarge or not; the images with missing sources are still distributed from cdimage.debian.org: http://cdimage.debian.org/cdimage/archive/3.1_r0/i386/iso-cd/debian-31r0-i386-netinst.iso Regards, Daniel

Bug#924610: libsdl2: Multiple security issues

2019-03-14 Thread Moritz Muehlenhoff
Source: libsdl2 Severity: grave Tags: security Hi, a number of security issues were found in SDL, please see the following links for references. https://security-tracker.debian.org/tracker/CVE-2019-7638 https://security-tracker.debian.org/tracker/CVE-2019-7637

Processed: Re: Bug#924042: tomb: Multiple package relations for optionally used tools are missing (steghide, dcfldd, gettext-base, qrencode, unoconv, lsof, swish-e)

2019-03-14 Thread Debian Bug Tracking System
Processing control commands: > severity -1 important Bug #924042 [tomb] tomb: Multiple package relations for optionally used tools are missing (steghide, dcfldd, gettext-base, qrencode, unoconv, lsof, swish-e) Severity set to 'important' from 'serious' -- 924042:

Processed: Re: sarge images have syslinux binaries without source

2019-03-14 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > reopen 497471 Bug #497471 {Done: Demetris Demetriou } [cdimage.debian.org] sarge images have syslinux binaries without source Bug reopened Ignoring request to alter fixed versions of bug #497471 to the same values previously set > thanks

Bug#924042: tomb: Multiple package relations for optionally used tools are missing (steghide, dcfldd, gettext-base, qrencode, unoconv, lsof, swish-e)

2019-03-14 Thread Raphael Hertzog
Control: severity -1 important On Fri, 08 Mar 2019, Axel Beckert wrote: > tomb's exhume subcommand calls steghide: > > ~ → tomb exhume /tmp/example.jpg > tomb [E] Steghide not installed: cannot exhume keys from images. The failure mode is rather clean, I don't think the missing

Bug#924609: libsdl1.2: Multiple security issues

2019-03-14 Thread Moritz Muehlenhoff
Source: libsdl1.2 Severity: grave Tags: security Hi, a number of security issues were found in SDL, please see the following links for references. https://security-tracker.debian.org/tracker/CVE-2019-7638 https://security-tracker.debian.org/tracker/CVE-2019-7637

Processed: Re: Missing sources for d-i components/kernel of etch-n-half images

2019-03-14 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > reopen 507706 Bug #507706 {Done: Demetris Demetriou } [cdimage.debian.org] Missing sources for d-i components/kernel of etch-n-half images Bug reopened Ignoring request to alter fixed versions of bug #507706 to the same values previously set >

Bug#507706: Missing sources for d-i components/kernel of etch-n-half images

2019-03-14 Thread Daniel Baumann
reopen 507706 thanks doesn't matter if debian supports etch or not; the images with missing sources are still distributed from cdimage.debian.org: http://cdimage.debian.org/cdimage/archive/4.0_r4/i386/iso-cd/debian-40r4etchnhalf-i386-netinst.iso Regards, Daniel

Bug#924608: oggvideotools FTBFS in buster. Can't find file for test.

2019-03-14 Thread peter green
Package: oggvideotools Version: 0.9.1-4.1 Severity: serious Tags: patch oggvideotools FTBFS in buster. I first noticed this in raspbian, but it's also visible on the reproducible builds tests. http://buildd.raspbian.org/status/fetch.php?pkg=oggvideotools=armhf=0.9.1-4.1=1552572977

Bug#507706: marked as done (Missing sources for d-i components/kernel of etch-n-half images)

2019-03-14 Thread Debian Bug Tracking System
Your message dated Thu, 14 Mar 2019 23:24:37 +0200 with message-id <0bb66202-3882-6afd-57e1-a36ad1b17...@gmail.com> and subject line Re: Missing sources for d-i components/kernel of etch-n-half images has caused the Debian Bug report #507706, regarding Missing sources for d-i components/kernel of

Bug#497471: marked as done (sarge images have syslinux binaries without source)

2019-03-14 Thread Debian Bug Tracking System
Your message dated Thu, 14 Mar 2019 23:22:58 +0200 with message-id <3570d412-6ddb-d804-8cca-c5cdf1f83...@gmail.com> and subject line Re: sarge images have syslinux binaries without source has caused the Debian Bug report #497471, regarding sarge images have syslinux binaries without source to be

Processed: Decrease severity

2019-03-14 Thread Debian Bug Tracking System
Processing control commands: > severity -1 important Bug #924589 {Done: Xavier Guimard } [node-formidable] node-formidable: Unusable with Node.js >= 7 Severity set to 'important' from 'grave' -- 924589: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=924589 Debian Bug Tracking System Contact

Bug#924589: Decrease severity

2019-03-14 Thread Xavier
Control: severity -1 important Package seems usable with its 2 reverse dependencies: node-superagent which is a dependency of node-multiparty. Only node-multiparty package provides real test. I tested both build and autopkgtest with the 2 versions of node-formidable (old and upgraded) with

Bug#924605: Depend on icedtea-netx instead of icedtea-netx-common.

2019-03-14 Thread Matthias Klose
Package: src:sweethome3d-textures-editor Version: 1.6-1 Severity: serious Tags: sid buster patch Depend on icedtea-netx instead of icedtea-netx-common (nbs). Patch at http://launchpadlibrarian.net/415168607/sweethome3d-textures-editor_1.6-1_1.6-1ubuntu1.diff.gz

Bug#924604: Depend on icedtea-netx instead of icedtea-netx-common

2019-03-14 Thread Matthias Klose
Package: src:sweethome3d-furniture-editor Version: 1.24-1 Severity: serious Tags: sid buster patch Depend on icedtea-netx instead of icedtea-netx-common (nbs). Patch at http://launchpadlibrarian.net/415168474/sweethome3d-furniture-editor_1.24-1_1.24-1ubuntu1.diff.gz

Bug#923781: marked as done (python-tesserocr ftbfs)

2019-03-14 Thread Debian Bug Tracking System
Your message dated Thu, 14 Mar 2019 20:42:50 + with message-id and subject line Bug#923781: fixed in python-tesserocr 2.4.0-4 has caused the Debian Bug report #923781, regarding python-tesserocr ftbfs to be marked as done. This means that you claim that the problem has been dealt with. If

Bug#924589: marked as done (node-formidable: Unusable with Node.js >= 7)

2019-03-14 Thread Debian Bug Tracking System
Your message dated Thu, 14 Mar 2019 20:42:38 + with message-id and subject line Bug#924589: fixed in node-formidable 1.2.1-1 has caused the Debian Bug report #924589, regarding node-formidable: Unusable with Node.js >= 7 to be marked as done. This means that you claim that the problem has

Bug#924599: Bug #924599 in qtbase-opensource-src marked as pending

2019-03-14 Thread Dmitry Shachnev
Control: tag -1 pending Hello, Bug #924599 in qtbase-opensource-src reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at:

Processed: Bug #924599 in qtbase-opensource-src marked as pending

2019-03-14 Thread Debian Bug Tracking System
Processing control commands: > tag -1 pending Bug #924599 [src:qtbase-opensource-src] qtbase-opensource-src: Several copyright issues Added tag(s) pending. -- 924599: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=924599 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems

Bug#924599: qtbase-opensource-src: Several copyright issues

2019-03-14 Thread Dmitry Shachnev
Source: qtbase-opensource-src Version: 5.11.3+dfsg-5 Severity: serious While working on copyright update for Qt 5.12, I noticed the following copyright issues that are applicable to Qt 5.11 too. 1) src/3rdparty/gradle/gradle/wrapper/gradle-wrapper.jar — built file without source code; 2)

Bug#923889: marked as done (google-compute-image-packages - DoS via serial console write)

2019-03-14 Thread Debian Bug Tracking System
Your message dated Thu, 14 Mar 2019 19:34:02 + with message-id and subject line Bug#923889: fixed in google-compute-image-packages 20190124-3 has caused the Debian Bug report #923889, regarding google-compute-image-packages - DoS via serial console write to be marked as done. This means that

Bug#922306: linux: btrfs corruption (compressed data + hole data)

2019-03-14 Thread Salvatore Bonaccorso
Hi Christoph, On Thu, Mar 14, 2019 at 08:06:52PM +0100, Christoph Anton Mitterer wrote: > Hey Ben, Salvatore. > > Thanks for cherry-picking the bug for unstable. > > AFAIU stretch and jessie[-backports] should be affected as well. > Shouldn't it go there, too? Yes it needs to be adressed there

Bug#924579: marked as done (gitlab: upgrade (experimental) from 11.6 to 11.8 problems)

2019-03-14 Thread Debian Bug Tracking System
Your message dated Thu, 14 Mar 2019 23:51:53 +0500 with message-id <1552589513.1502...@j4v4m4n.in> and subject line Re: Bug#924579: gitlab: upgrade (experimental) from 11.6 to 11.8 problems has caused the Debian Bug report #924579, regarding gitlab: upgrade (experimental) from 11.6 to 11.8

Processed (with 5 errors): Re: Bug#924579: gitlab: upgrade (experimental) from 11.6 to 11.8 problems

2019-03-14 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > fixed 924579 11.8.2-1 Bug #924579 [gitlab] gitlab: upgrade (experimental) from 11.6 to 11.8 problems Marked as fixed in versions gitlab/11.8.2-1. > On Thu, Mar 14, 2019 at 9:14 PM, Dragos Jarca Unknown command or malformed arguments to command. >

Bug#922306: linux: btrfs corruption (compressed data + hole data)

2019-03-14 Thread Christoph Anton Mitterer
Hey Ben, Salvatore. Thanks for cherry-picking the bug for unstable. AFAIU stretch and jessie[-backports] should be affected as well. Shouldn't it go there, too? At least at the upstream mailing list it was said[0] the the bug was introduced around October 2008, which should be roughly kernel

Bug#924594: Build-depend on icedtea-netx instead of icedtea-netx-common

2019-03-14 Thread Matthias Klose
Package: src;sweethome3d Version: 6.1.2+dfsg-1 Severity: serious Tags: sid buster Build-depend on icedtea-netx instead of icedtea-netx-common (nbs). Patch at http://launchpadlibrarian.net/415155485/sweethome3d_6.1.2+dfsg-1_6.1.2+dfsg-1ubuntu1.diff.gz

Bug#924593: Build-depend on icedtea-netx instead of icedtea-netx-common

2019-03-14 Thread Matthias Klose
Package: src:geogebra Version: 4.0.34.0+dfsg1-6 Severity: serious Tags: sid buster Build-depend on icedtea-netx instead of icedtea-netx-common (nbs). Patch at http://launchpadlibrarian.net/415155213/geogebra_4.0.34.0+dfsg1-6_4.0.34.0+dfsg1-6ubuntu1.diff.gz However, the build fails then with:

Bug#912549: icedtea-web FTBFS with OpenJDK 11

2019-03-14 Thread Andreas Tille
On Wed, Mar 13, 2019 at 10:25:06PM +0100, Emmanuel Bourg wrote: > On 13/03/2019 21:30, Markus Koschany wrote: > > >> please look at the new upstream 1.7.2 and 1.8 releases. May be that's sensible for Buster+1 > > In https://bugs.debian.org/855686 Emmanuel wrote that icedtea-web will > > be

Bug#924591: fastboot format:ext4 misses /usr/lib/android-sdk/platform-tools/mke2fs

2019-03-14 Thread Jonas Meurer
Package: fastboot Version: 1:8.1.0+r23-4 Severity: serious Hello, after dist-upgrade to Buster, 'fastboot format:ext4' is broken. It tries to execute '/usr/lib/android-sdk/platform-tools/mke2fs' which doesn't exist and is not available in the Debian archive: $ fastboot format:ext4:0xcd3771e00

Bug#924589: node-formidable: Unusable with Node.js >= 7

2019-03-14 Thread Xavier Guimard
Package: node-formidable Version: 1.0.13-1 Severity: grave Tags: upstream Justification: renders package unusable node-formidable is unusable with Node.js >=7: Error [ERR_NO_LONGER_SUPPORTED]: Buffer.write(string, encoding, offset[, length]) is no longer supported at Buffer.write

Bug#923782: marked as done (Relax dependency on faraday to allow updating ruby-faraday)

2019-03-14 Thread Debian Bug Tracking System
Your message dated Thu, 14 Mar 2019 17:04:34 + with message-id and subject line Bug#923782: fixed in ruby-puppet-forge 2.2.9-3 has caused the Debian Bug report #923782, regarding Relax dependency on faraday to allow updating ruby-faraday to be marked as done. This means that you claim that

Bug#924579: gitlab: upgrade (experimental) from 11.6 to 11.8 problems

2019-03-14 Thread Dragos Jarca
Package: gitlab Version: 11.8.0-1 Severity: grave Tags: a11y Justification: renders package unusable Dear Maintainer, *** Reporter, please consider answering these questions, where appropriate *** * What led up to the situation? * What exactly did you do (or not do) that was effective (or

Bug#916163: marked as done (ppp FTBFS with glibc 2.28)

2019-03-14 Thread Debian Bug Tracking System
Your message dated Thu, 14 Mar 2019 15:34:10 + with message-id and subject line Bug#916163: fixed in ppp 2.4.7-2+4.1 has caused the Debian Bug report #916163, regarding ppp FTBFS with glibc 2.28 to be marked as done. This means that you claim that the problem has been dealt with. If this is

Bug#924346: marked as done (xmltooling: CVE-2019-9628: XML parser class fails to trap exceptions on malformed XML declaration)

2019-03-14 Thread Debian Bug Tracking System
Your message dated Thu, 14 Mar 2019 15:20:27 + with message-id and subject line Bug#924346: fixed in xmltooling 3.0.4-1 has caused the Debian Bug report #924346, regarding xmltooling: CVE-2019-9628: XML parser class fails to trap exceptions on malformed XML declaration to be marked as done.

Processed: found 924508 in 2:9.1.1-3

2019-03-14 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > found 924508 2:9.1.1-3 Bug #924508 {Done: Thomas Goirand } [src:neutron] neutron: CVE-2019-9735: it's possible to add a security group rule for VRRP with a dport Marked as found in versions neutron/2:9.1.1-3. > thanks Stopping processing here.

Bug#794466: Virtualbox might not be suitable for Stretch

2019-03-14 Thread Gianfranco Costamagna
As said on irc: 1) I don't want to ship the package in Buster if the security team can't handle security updates 2) I don't want security team to handle them, I'll in case provide them the stuff that can be sponsored (as we did in the past). In case the new micro releases are not ship anymore

Bug#923282: freezegun breaks cached-property autopkgtest

2019-03-14 Thread Paul Gevers
Hi Mathias, On 14-03-2019 12:48, Mathias Behrle wrote: >> Yes, please upload to unstable, with only the test disabled, and I'll >> take care of it. Thanks for understanding. > > You are welcome, thanks for the work of the release team. I just uploaded. I was more thinking of only disabling the

Bug#924447: marked as done (gitlab: CVE-2019-9170 CVE-2019-9171 CVE-2019-9172 CVE-2019-9174 CVE-2019-9175 CVE-2019-9176 CVE-2019-9178 CVE-2019-9179 CVE-2019-9217 CVE-2019-9219 CVE-2019-9220 CVE-2019-9

2019-03-14 Thread Debian Bug Tracking System
Your message dated Thu, 14 Mar 2019 12:49:51 + with message-id and subject line Bug#924447: fixed in gitlab 11.8.2-1 has caused the Debian Bug report #924447, regarding gitlab: CVE-2019-9170 CVE-2019-9171 CVE-2019-9172 CVE-2019-9174 CVE-2019-9175 CVE-2019-9176 CVE-2019-9178 CVE-2019-9179

Bug#924562: openvswitch-switch breaks networking.service due to dependency loop

2019-03-14 Thread Benjamin Drung
Package: openvswitch-switch Version: 2.10.0+2018.08.28+git.8ca7c82b7d+ds1-10 Priority: critical Hi, the fix for RC bug #878757 introduces a regression. openvswitch- switch.service specifies: [Unit] Description=Open vSwitch After=network.target openvswitch-nonetwork.service

Processed: Re: javahelper regressed building -doc packages

2019-03-14 Thread Debian Bug Tracking System
Processing control commands: > reassign 924328 javahelper Bug #924328 [src:android-platform-build] android-platform-build ftbfs, using new javahelper Bug reassigned from package 'src:android-platform-build' to 'javahelper'. No longer marked as found in versions

Bug#924339: javahelper regressed building -doc packages

2019-03-14 Thread Markus Koschany
Control: reassign 924328 javahelper Control: forcemerge 924339 924328 Control: affects 924328 src:android-platform-build Control: retitle 924328 javahelper: jh_build regressed for -doc packages This issue is caused by the fix for #887666 https://bugs.debian.org/887666 It is not related to the

Bug#923282: freezegun breaks cached-property autopkgtest

2019-03-14 Thread Mathias Behrle
* Paul Gevers: " Re: Bug#923282: freezegun breaks cached-property autopkgtest" (Thu, 14 Mar 2019 12:19:03 +0100): Hi Paul, > On 14-03-2019 12:16, Mathias Behrle wrote: > > I must admit that I find it a little bit strange to have no feedback at all > > from the freezegun maintainers about this

Bug#923282: freezegun breaks cached-property autopkgtest

2019-03-14 Thread Paul Gevers
Hi Mathias, On 14-03-2019 12:16, Mathias Behrle wrote: > I must admit that I find it a little bit strange to have no feedback at all > from the freezegun maintainers about this issue. Especially not for > https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=923282#34 > for the question, if not some

Bug#923282: freezegun breaks cached-property autopkgtest

2019-03-14 Thread Mathias Behrle
* Paul Gevers: " Re: Bug#923282: freezegun breaks cached-property autopkgtest" (Thu, 14 Mar 2019 11:55:47 +0100): Dear Paul, > Dear Mathias, > > On 13-03-2019 22:51, Mathias Behrle wrote: > >> Do I understand you correctly that there is no issue at all for the > >> package cached-property as

Bug#924397: corekeeper: insecure use of world-writable /var/crash

2019-03-14 Thread Jakub Wilk
As a data point, apport creates /var/crash as world-writable in postinst: if [ "$1" = configure ]; then # directory is required for package failures even if apport is disabled mkdir -p -m 1777 /var/crash fi And it chmods it in the init script: chmod 1777 /var/crash OTOH,

Bug#921114: AMD Radeon RX 580: no GL display, "amdgpu: The CS has been cancelled because the context is lost"

2019-03-14 Thread Simon McVittie
Control: severity -1 important On Thu, 14 Mar 2019 at 09:07:02 +, Simon McVittie wrote: > On Fri, 01 Feb 2019 at 18:16:41 +0100, Jean-Dominique Frattini wrote: > > since the latest update of xserver-xorg-video-amdgpu and > > firmware-amd-graphics [in buster], most GL applications do not

Processed: Re: Bug#921114: AMD Radeon RX 580: no GL display, "amdgpu: The CS has been cancelled because the context is lost"

2019-03-14 Thread Debian Bug Tracking System
Processing control commands: > severity -1 important Bug #921114 [firmware-amd-graphics] AMD Radeon RX 580: no GL display, "amdgpu: The CS has been cancelled because the context is lost" Bug #921004 [firmware-amd-graphics] AMD Radeon RX 580: no GL display, "amdgpu: The CS has been cancelled

Bug#922692: galax: FTBFS - ERROR: unable to find camomileLibrary.cmi in /usr/lib/ocaml/camomile

2019-03-14 Thread Ralf Treinen
This bug seems to be triggered by the update of libcamomile-ocaml-dev in sid to version 1.0.1-3. Buster, however, still has camomile 0.8.5-1. I just checked that galax 1.1-15 compiles fine on buster. Hence this bug does not concern the buster release. -Ralf. -- Ralf Treinen Institut de

Bug#924548: gnome-core: does not actually install a desktop environment on s390x

2019-03-14 Thread Simon McVittie
Package: gnome-core Version: 1:3.30+1 Severity: serious Justification: we should make a decision one way or another before release I recently changed gnome-core to install gnome-flashback instead of GNOME Shell on s390x, because: GNOME Shell is uninstallable on s390x, due to mozjs60 not being

Bug#924508: marked as done (neutron: CVE-2019-9735: it's possible to add a security group rule for VRRP with a dport)

2019-03-14 Thread Debian Bug Tracking System
Your message dated Thu, 14 Mar 2019 10:06:02 + with message-id and subject line Bug#924508: fixed in neutron 2:13.0.2-13 has caused the Debian Bug report #924508, regarding neutron: CVE-2019-9735: it's possible to add a security group rule for VRRP with a dport to be marked as done. This

Bug#924508: neutron: CVE-2019-9735: it's possible to add a security group rule for VRRP with a dport

2019-03-14 Thread Thomas Goirand
On 3/13/19 8:19 PM, Salvatore Bonaccorso wrote: > Source: neutron > Version: 2:13.0.2-10 > Severity: grave > Tags: security upstream > Justification: user security hole > Forwarded: https://bugs.launchpad.net/neutron/+bug/1818385 > > Hi, > > The following vulnerability was published for neutron.

Processed: not buster

2019-03-14 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tags 922692 - buster Bug #922692 [src:galax] galax: FTBFS - ERROR: unable to find camomileLibrary.cmi in /usr/lib/ocaml/camomile Removed tag(s) buster. > thanks Stopping processing here. Please contact me if you need assistance. -- 922692:

Bug#918339: marked as done (dovecot-mysql: dovecot/auth segfaults with double-free in mysql_close() / passdb_deinit())

2019-03-14 Thread Debian Bug Tracking System
Your message dated Thu, 14 Mar 2019 09:50:04 + with message-id and subject line Bug#918339: fixed in dovecot 1:2.3.4.1-2 has caused the Debian Bug report #918339, regarding dovecot-mysql: dovecot/auth segfaults with double-free in mysql_close() / passdb_deinit() to be marked as done. This

Bug#924508: Bug #924508 in neutron marked as pending

2019-03-14 Thread Thomas Goirand
Control: tag -1 pending Hello, Bug #924508 in neutron reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at:

Processed: Bug #924508 in neutron marked as pending

2019-03-14 Thread Debian Bug Tracking System
Processing control commands: > tag -1 pending Bug #924508 [src:neutron] neutron: CVE-2019-9735: it's possible to add a security group rule for VRRP with a dport Ignoring request to alter tags of bug #924508 to the same tags previously set -- 924508:

Bug#918339: dovecot: diff for NMU version 1:2.3.4.1-1.1

2019-03-14 Thread Laurent Bigonville
Le 14/03/19 à 10:35, Apollon Oikonomopoulos a écrit : Hi Laurent, On 13:26 Wed 13 Mar , Laurent Bigonville wrote: Control: tags 918339 + patch Control: tags 918339 + pending Dear maintainer, I've prepared an NMU for dovecot (versioned as 1:2.3.4.1-1.1) and uploaded it to DELAYED/3.

Bug#918339: dovecot: diff for NMU version 1:2.3.4.1-1.1

2019-03-14 Thread Apollon Oikonomopoulos
Hi Laurent, On 13:26 Wed 13 Mar , Laurent Bigonville wrote: > Control: tags 918339 + patch > Control: tags 918339 + pending > > > Dear maintainer, > > I've prepared an NMU for dovecot (versioned as 1:2.3.4.1-1.1) and > uploaded it to DELAYED/3. Please feel free to tell me if I > should

Processed: Re: Bug#921114: AMD Radeon RX 580: no GL display, "amdgpu: The CS has been cancelled because the context is lost"

2019-03-14 Thread Debian Bug Tracking System
Processing control commands: > reassign 921004 firmware-amd-graphics 20190114-1 Bug #921004 [firmware-amd-graphics] AMD Radeon RX 580: no GL display, "amdgpu: The CS has been cancelled because the context is lost" Bug #921114 [firmware-amd-graphics] AMD Radeon RX 580: no GL display, "amdgpu:

Processed: Re: Bug#921114: AMD Radeon RX 580: no GL display, "amdgpu: The CS has been cancelled because the context is lost"

2019-03-14 Thread Debian Bug Tracking System
Processing control commands: > reassign 921004 firmware-amd-graphics 20190114-1 Bug #921004 [firmware-amd-graphics] AMD Radeon RX 580: no GL display, "amdgpu: The CS has been cancelled because the context is lost" Bug #921114 [firmware-amd-graphics] AMD Radeon RX 580: no GL display, "amdgpu:

Bug#921114: AMD Radeon RX 580: no GL display, "amdgpu: The CS has been cancelled because the context is lost"

2019-03-14 Thread Simon McVittie
Control: reassign 921004 firmware-amd-graphics 20190114-1 Control: reassign 921145 firmware-amd-graphics 20190114-1 Control: forcemerge 921114 921004 921145 Control: retitle 921114 AMD Radeon RX 580: no GL display, "amdgpu: The CS has been cancelled because the context is lost" Control: tags

Processed: Re: Bug#921114: AMD Radeon RX 580: no GL display, "amdgpu: The CS has been cancelled because the context is lost"

2019-03-14 Thread Debian Bug Tracking System
Processing control commands: > reassign 921004 firmware-amd-graphics 20190114-1 Bug #921004 [xserver-xorg-video-amdgpu] amdgpu: The CS has been cancelled because the context is lost. Bug reassigned from package 'xserver-xorg-video-amdgpu' to 'firmware-amd-graphics'. Ignoring request to alter

Bug#924409: removing hiera from debian? or do not ship with buster

2019-03-14 Thread Apollon Oikonomopoulos
Control: severity -1 important Control: tags -1 - buster Control: retitle -1 hiera should be removed after Buster is released Hi, On 13:07 Tue 12 Mar , Antoine Beaupre wrote: > I see that Hiera in Puppet is at version 3.2.0 in buster. That's at > least two minor versions behind upstream,

Processed: Re: Bug#924409: removing hiera from debian? or do not ship with buster

2019-03-14 Thread Debian Bug Tracking System
Processing control commands: > severity -1 important Bug #924409 [hiera] removing hiera from debian? or do not ship with buster Severity set to 'important' from 'serious' > tags -1 - buster Bug #924409 [hiera] removing hiera from debian? or do not ship with buster Removed tag(s) buster. > retitle