Re: Bug#703290: davical: possible code insertion or XSS

2013-03-19 Thread Thijs Kinkhorst
On Tue, March 19, 2013 01:37, Christoph Anton Mitterer wrote: severity 703290 important stop On Tue, 2013-03-19 at 10:20 +1300, Andrew McMillan wrote: Is there any way to do an XSS exploit in 12 characters? If not, then I don't think this is 'grave'. Unless someone from the security or

Bug#703409: unblock: ruby-actionpack-2.3/2.3.14-5, ruby-actionpack-3.2/3.2.6-6, ruby-activerecord-2.3/2.3.14-6, ruby-activerecord-3.2/3.2.6-5, ruby-activesupport-2.3/2.3.14-7, ruby-activesupport-3.2/3

2013-03-19 Thread Ondřej Surý
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock Please unblock package ruby-activesupport-3.2 http://weblog.rubyonrails.org/2013/3/18/SEC-ANN-Rails-3-2-13-3-1-12-and-2-3-18-have-been-released/ Rails versions 3.2.13, 3.1.12, and 2.3.18

Bug#698117: unblock: rebuildd/0.4.2

2013-03-19 Thread Neil McGovern
tags 698117 moreinfo user debian-rele...@packages.debian.org usertags 671635 wheezy-will-remove thanks On Mon, Mar 04, 2013 at 02:51:36PM +0100, Raphael Hertzog wrote: The time spent by the RM and the maintainer to prepare and accept the tpu upload is higher than adding a simple unblock

Bug#699171: Pre-Approval: capi4hylafax/1:01.03.00.99.svn.300-19

2013-03-19 Thread Julien Cristau
On Mon, Mar 18, 2013 at 22:22:03 +0100, Joachim Wiedorn wrote: Hello Julien, Julien Cristau wrote on 2013-03-18 20:42: The debdiff and the above is rather short on explanations (and I'd rather not read the whole bug log for 661482)... Care to explain why these directories must be

Processed: Re: Bug#698117: unblock: rebuildd/0.4.2

2013-03-19 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: tags 698117 moreinfo Bug #698117 [release.debian.org] unblock: rebuildd/0.4.2 Added tag(s) moreinfo. user debian-rele...@packages.debian.org Setting user to debian-rele...@packages.debian.org (was ne...@debian.org). usertags 671635

Re: Bug#678979: request freeze exception for slony1-2

2013-03-19 Thread Neil McGovern
user debian-rele...@packages.debian.org usertags 678979 wheezy-will-remove thanks On Sat, Mar 16, 2013 at 12:44:15PM -0400, Peter Eisentraut wrote: On Sat, 2013-03-16 at 11:38 +, Adam D. Barratt wrote: On Sun, 2012-10-07 at 14:30 +0200, Mehdi Dogguy wrote: On 21/09/2012 04:58, Peter

Bug#703378: unblock: hsqldb/1.8.0.10+dfsg-1

2013-03-19 Thread Jonathan Wiltshire
On 2013-03-18 22:33, Rene Engelhard wrote: Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock Please unblock package hsqldb Changes: hsqldb (1.8.0.10+dfsg-1) unstable; urgency=low . * remove lib/servlet.jar and make the build

Bug#703378: unblock: hsqldb/1.8.0.10+dfsg-1

2013-03-19 Thread Rene Engelhard
Hi, On Tue, Mar 19, 2013 at 10:13:00AM +, Jonathan Wiltshire wrote: Please unblock package hsqldb Changes: hsqldb (1.8.0.10+dfsg-1) unstable; urgency=low . * remove lib/servlet.jar and make the build actually use /usr/share/java/servlet-api-2.5.jar... Whilst the diff is

Re: Bug#703290: davical: possible code insertion or XSS

2013-03-19 Thread Jonathan Wiltshire
On 2013-03-19 07:40, Thijs Kinkhorst wrote: On Tue, March 19, 2013 01:37, Christoph Anton Mitterer wrote: severity 703290 important stop On Tue, 2013-03-19 at 10:20 +1300, Andrew McMillan wrote: Is there any way to do an XSS exploit in 12 characters? If not, then I don't think this is

Re: Bug#703290: davical: possible code insertion or XSS

2013-03-19 Thread Thijs Kinkhorst
severity 703294 important thanks On Tue, March 19, 2013 11:20, Jonathan Wiltshire wrote: Agreed that it's not grave until we have a concrete vulnerability at hand. The code could/should definitely be more robust, but there's not yet an acute issue. Is it fair to apply this line of reasoning

Bug#703418: unblock: nvidia-settings-legacy-173xx/173.14.35-2

2013-03-19 Thread Andreas Beckmann
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock Please unblock package nvidia-settings-legacy-173xx nvidia-settings-legacy-173xx was created at a time when the 96xx legacy driver was not functional due to missing Xorg support. This has

Bug#697589: unblock: gnome-menus/3.4.2-7

2013-03-19 Thread intrigeri
Control: tag -1 - moreinfo Hi, Jonathan Wiltshire wrote (19 Feb 2013 20:01:45 GMT) : Do you have any comment on Bill's reply? Assuming Jonathan's question was specifically about Bill stating that it was rather unusual for GNOME users to run update-menus as user, then I believe it was answered

Processed: Re: Bug#697589: unblock: gnome-menus/3.4.2-7

2013-03-19 Thread Debian Bug Tracking System
Processing control commands: tag -1 - moreinfo Bug #697589 [release.debian.org] unblock: gnome-menus/3.4.2-7 Bug #697219 [release.debian.org] unblock: gnome-menus/3.4.2-6 Removed tag(s) moreinfo. Removed tag(s) moreinfo. -- 697219: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=697219

Processed: Re: Bug#702390: unblock: rsyslog/5.8.11-3

2013-03-19 Thread Debian Bug Tracking System
Processing control commands: tag -1 + moreinfo Bug #702390 [release.debian.org] unblock: rsyslog/5.8.11-3 Added tag(s) moreinfo. -- 702390: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=702390 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems -- To UNSUBSCRIBE, email

Bug#702390: unblock: rsyslog/5.8.11-3

2013-03-19 Thread intrigeri
Control: tag -1 + moreinfo Hi, Michael Biebl wrote (05 Mar 2013 23:16:56 GMT) : It has a one-line fix to future-proof rsyslog's systemd service file to work with newer systemd versions. +rsyslog (5.8.11-3) unstable; urgency=low + + * debian/patches/04-systemd_journal.patch: The journal

Bug#703241: Acknowledgement (unblock: intel-microcode/1.20130222.1)

2013-03-19 Thread intrigeri
Hi, (disclaimer: I'm not part of the release team.) Henrique de Moraes Holschuh wrote (18 Mar 2013 00:48:39 GMT) : diffstat from debdiff: changelog |4 debian/changelog | 10 microcode-20120606.v2.dat |31086 --

Bug#702390: unblock: rsyslog/5.8.11-3

2013-03-19 Thread Michael Biebl
On 19.03.2013 12:58, intrigeri wrote: Control: tag -1 + moreinfo Hi, Michael Biebl wrote (05 Mar 2013 23:16:56 GMT) : It has a one-line fix to future-proof rsyslog's systemd service file to work with newer systemd versions. +rsyslog (5.8.11-3) unstable; urgency=low + + *

Bug#702933: unblock: duplicity/0.6.20-3

2013-03-19 Thread intrigeri
Control: tag -1 + moreinfo Hi Alexander, (disclaimer: I'm not part of the release team, just trying to help a bit with the pile of unblock requests.) Alexander Zangerl wrote (13 Mar 2013 03:05:26 GMT) : dear release team, duplicity's version in testing (0.6.18.-3) suffers from bug #702563,

Processed: Re: Bug#702933: unblock: duplicity/0.6.20-3

2013-03-19 Thread Debian Bug Tracking System
Processing control commands: tag -1 + moreinfo Bug #702933 [release.debian.org] unblock: duplicity/0.6.20-3 Added tag(s) moreinfo. -- 702933: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=702933 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems -- To UNSUBSCRIBE,

Bug#698778: preapproval of expect/5.45-3

2013-03-19 Thread intrigeri
Control: tag -1 + moreinfo Hi Sergei, (disclaimer: I'm not part of the release team.) Sergei Golovan wrote (26 Jan 2013 06:07:52 GMT) : On Sat, Jan 26, 2013 at 12:15 AM, Julien Cristau jcris...@debian.org wrote: Anything like that needs to get tons of testing to ensure it doesn't have

Processed: Re: Bug#698778: preapproval of expect/5.45-3

2013-03-19 Thread Debian Bug Tracking System
Processing control commands: tag -1 + moreinfo Bug #698778 [release.debian.org] preapproval of expect/5.45-3 Added tag(s) moreinfo. -- 698778: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=698778 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems -- To UNSUBSCRIBE,

Bug#703378: unblock: hsqldb/1.8.0.10+dfsg-1

2013-03-19 Thread Jonathan Wiltshire
On 2013-03-19 10:23, Rene Engelhard wrote: Hi, On Tue, Mar 19, 2013 at 10:13:00AM +, Jonathan Wiltshire wrote: Please unblock package hsqldb Changes: hsqldb (1.8.0.10+dfsg-1) unstable; urgency=low . * remove lib/servlet.jar and make the build actually use

Bug#703378: unblock: hsqldb/1.8.0.10+dfsg-1

2013-03-19 Thread Rene Engelhard
Hi, On Tue, Mar 19, 2013 at 12:35:32PM +, Jonathan Wiltshire wrote: So, I'm fine with the diff you sent in principle, but the actual diff from testing-sid is rather larger: argh. damn. I forgot that this diverged because hsqldb didn't migrate in time due to (afair) archive issues...

Bug#703378: unblock: hsqldb/1.8.0.10+dfsg-1

2013-03-19 Thread Rene Engelhard
retitle 703378 pre-approval: hsqldb/1.8.0.10+dfsg-0+deb7u1 thanks Hi, On Tue, Mar 19, 2013 at 01:43:16PM +0100, Rene Engelhard wrote: argh. damn. I forgot that this diverged because hsqldb didn't migrate in time due to (afair) archive issues... [...] I would believe that you wouldn't accept

Processed: Re: Bug#703378: unblock: hsqldb/1.8.0.10+dfsg-1

2013-03-19 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: retitle 703378 pre-approval: hsqldb/1.8.0.10+dfsg-0+deb7u1 Bug #703378 [release.debian.org] unblock: hsqldb/1.8.0.10+dfsg-1 Changed Bug title to 'pre-approval: hsqldb/1.8.0.10+dfsg-0+deb7u1' from 'unblock: hsqldb/1.8.0.10+dfsg-1' thanks Stopping

Bug#703362: unblock: openssl/1.0.1e-2

2013-03-19 Thread Adam D. Barratt
Control: tags -1 + confirmed d-i On 18.03.2013 19:58, Kurt Roeckx wrote: Please unblock openssl/1.0.1e-2, it fixes a bunch of issues fixed in upstream git since the 1.0.1e release. Unblocked, but needs a udeb ack. Regards, Adam -- To UNSUBSCRIBE, email to

Processed: Re: Bug#703362: unblock: openssl/1.0.1e-2

2013-03-19 Thread Debian Bug Tracking System
Processing control commands: tags -1 + confirmed d-i Bug #703362 [release.debian.org] unblock: openssl/1.0.1e-2 Added tag(s) d-i and confirmed. -- 703362: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=703362 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems -- To

Bug#703391: marked as done (unblock: clamav/0.97.7+dfsg-1)

2013-03-19 Thread Debian Bug Tracking System
Your message dated Tue, 19 Mar 2013 13:08:45 + with message-id 7f5859097fe21e121fec5f99f89be...@mail.adsl.funky-badger.org and subject line Re: Bug#703391: unblock: clamav/0.97.7+dfsg-1 has caused the Debian Bug report #703391, regarding unblock: clamav/0.97.7+dfsg-1 to be marked as done.

Bug#703409: marked as done (unblock: ruby-actionpack-2.3/2.3.14-5, ruby-actionpack-3.2/3.2.6-6, ruby-activerecord-2.3/2.3.14-6, ruby-activerecord-3.2/3.2.6-5, ruby-activesupport-2.3/2.3.14-7, ruby-act

2013-03-19 Thread Debian Bug Tracking System
Your message dated Tue, 19 Mar 2013 13:12:54 + with message-id 8507df7ae96260b98424cddc0d5b5...@mail.adsl.funky-badger.org and subject line Re: Bug#703409: unblock: ruby-actionpack-2.3/2.3.14-5, ruby-actionpack-3.2/3.2.6-6, ruby-activerecord-2.3/2.3.14-6, ruby-activerecord-3.2/3.2.6-5,

Bug#702390: marked as done (unblock: rsyslog/5.8.11-3)

2013-03-19 Thread Debian Bug Tracking System
Your message dated Tue, 19 Mar 2013 13:15:44 + with message-id cdcb7631967661ef2a7b56feba8c8...@mail.adsl.funky-badger.org and subject line Re: Bug#702390: unblock: rsyslog/5.8.11-3 has caused the Debian Bug report #702390, regarding unblock: rsyslog/5.8.11-3 to be marked as done. This means

Bug#703241: marked as done (unblock: intel-microcode/1.20130222.1)

2013-03-19 Thread Debian Bug Tracking System
Your message dated Tue, 19 Mar 2013 13:14:03 + with message-id 8c35432fe80ae16ef31a63cb5f493...@mail.adsl.funky-badger.org and subject line Re: Bug#703241: unblock: intel-microcode/1.20130222.1 has caused the Debian Bug report #703241, regarding unblock: intel-microcode/1.20130222.1 to be

Bug#685230: marked as done (unblock hylafax 3:6.0.6-4)

2013-03-19 Thread Debian Bug Tracking System
Your message dated Tue, 19 Mar 2013 13:16:50 + with message-id 32a6fd01f3dec66dcd22b8e0f9b5a...@mail.adsl.funky-badger.org and subject line Re: Bug#685230: unblock hylafax 3:6.0.6-4 has caused the Debian Bug report #685230, regarding unblock hylafax 3:6.0.6-4 to be marked as done. This means

Bug#703378: unblock: hsqldb/1.8.0.10+dfsg-1

2013-03-19 Thread Rene Engelhard
Hi, On Tue, Mar 19, 2013 at 01:52:38PM +0100, Rene Engelhard wrote: 13:46 _rene_ and will upload 1.8.0.10+dfsg-0+deb7u1 or something like that... Done. Regards, Rene -- To UNSUBSCRIBE, email to debian-release-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact

Processed: tagging 703378

2013-03-19 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: tags 703378 + pending Bug #703378 [release.debian.org] pre-approval: hsqldb/1.8.0.10+dfsg-0+deb7u1 Added tag(s) pending. thanks Stopping processing here. Please contact me if you need assistance. -- 703378:

Bug#703378: marked as done (pre-approval: hsqldb/1.8.0.10+dfsg-0+deb7u1)

2013-03-19 Thread Debian Bug Tracking System
Your message dated Tue, 19 Mar 2013 15:18:30 + with message-id 861a1b767934686fc7f8d29ebceae...@hogwarts.powdarrmonkey.net and subject line Re: Bug#703378: unblock: hsqldb/1.8.0.10+dfsg-1 has caused the Debian Bug report #703378, regarding pre-approval: hsqldb/1.8.0.10+dfsg-0+deb7u1 to be

Bug#703338: marked as done (unblock: firebird2.5/2.5.2~svn+54698.ds4-2)

2013-03-19 Thread Debian Bug Tracking System
Your message dated Tue, 19 Mar 2013 15:30:18 + with message-id d318fa5c998f9176cd486306ceca5...@mail.adsl.funky-badger.org and subject line Re: Bug#703338: unblock: firebird2.5/2.5.2~svn+54698.ds4-2 has caused the Debian Bug report #703338, regarding unblock: firebird2.5/2.5.2~svn+54698.ds4-2

Bug#698778: preapproval of expect/5.45-3

2013-03-19 Thread Julien Cristau
On Tue, Mar 19, 2013 at 13:36:31 +0100, intrigeri wrote: I suggest preparing and proposing a Jenkins dist-upgrade job (either as a patch against an existing appropriate job, or as a new job) to Holger (Cc'd), so that we have an easy way to verify that the Squeeze to Wheezy upgrade is indeed

Bug#698778: preapproval of expect/5.45-3

2013-03-19 Thread intrigeri
Hi, Julien Cristau wrote (19 Mar 2013 18:38:10 GMT) : Does this test random combinations of installed packages? What I suggested does not, but one could imagine and implement a more involved test case. Cheers, -- intrigeri | GnuPG key @

Re: Fixing lucky 13 CVE-2013-0169 in gnutls28

2013-03-19 Thread Andreas Metzler
On 2013-03-18 Julien Cristau jcris...@debian.org wrote: On Sun, Mar 17, 2013 at 19:26:10 +0100, Andreas Metzler wrote: On 2013-03-17 Julien Cristau jcris...@debian.org wrote: On Sun, Mar 17, 2013 at 16:00:29 +0100, Andreas Metzler wrote: [...] 2. If armel armhf mipsel break due to

Re: Fixing lucky 13 CVE-2013-0169 in gnutls28

2013-03-19 Thread Julien Cristau
On Tue, Mar 19, 2013 at 20:06:38 +0100, Andreas Metzler wrote: Find attached a proposed patch. Forgot the attachment? Cheers, Julien signature.asc Description: Digital signature

Re: Fixing lucky 13 CVE-2013-0169 in gnutls28

2013-03-19 Thread Andreas Metzler
On 2013-03-19 Andreas Metzler ametz...@downhill.at.eu.org wrote: Find attached a proposed patch. diff -Nru gnutls26-2.12.20/debian/changelog gnutls26-2.12.20/debian/changelog --- gnutls26-2.12.20/debian/changelog 2013-02-04 19:44:26.0 +0100 +++ gnutls26-2.12.20/debian/changelog

Bug#700205: unblock: libquvi-scripts/0.4.11-2 (pre-upload approval)

2013-03-19 Thread Julien Cristau
On Sat, Feb 9, 2013 at 22:45:16 +0100, Ansgar Burchardt wrote: I would like to update libquvi-scripts in wheezy to 0.4.11-2 (identical to -1 already in experimental). It includes fixes for various sites, see NEWS in the attached diff. There's also support for a few new sites which is not

Bug#699171: Pre-Approval: capi4hylafax/1:01.03.00.99.svn.300-19

2013-03-19 Thread Joachim Wiedorn
Hello Julien, Julien Cristau wrote on 2013-03-19 10:36: I don't understand. dpkg won't try to remove a directory owned by two packages if you remove one of them. It isn't done by dpkg but by postrm of hylafax-server package in this way: [ -d /var/spool/hylafax/etc ] rm -rf

Bug#699915: tpu: lcdf-typetools/2.92+dfsg1-1.1

2013-03-19 Thread Michael Stapelberg
Hi Adam, Adam D. Barratt a...@adam-barratt.org.uk writes: Ping? As discussed in IRC, I uploaded 2.92+dfsg1-0.1~deb7u1 to testing-proposed-updates. Sorry for taking so long to react on this one. -- Best regards, Michael -- To UNSUBSCRIBE, email to debian-release-requ...@lists.debian.org

Bug#703458: pu: package clamav/0.97.7+dfsg-1~squeeze1

2013-03-19 Thread Scott Kitterman
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: pu I'd like to upload clamav 0.97.7 for all the same reasons (and with the same diff modulo a slightly different debian/changelog entry) as I wanted it in Wheezy (See #703391: unblock:

Bug#703467: pu: package graphviz/2.26.3-5+b1

2013-03-19 Thread David Claughton
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: pu Hi Stable Release Team, Bug #702436 has recently been reported against graphviz, which advises that graphviz is being linked with an ancient shipped version of libltdl instead of the system

Bug#699109: unblock (pre-approval): initramfs-tools-tcos/0.89.91

2013-03-19 Thread Jonathan Wiltshire
user release.debian@packages.debian.org usertag 699109 + wheezy-will-remove usertag 694870 + wheezy-will-remove thanks On Fri, Mar 01, 2013 at 02:14:58PM +0100, Julien Cristau wrote: On Mon, Jan 28, 2013 at 09:22:35 +, Manuel A. Fernandez Montecelo wrote: 2013/1/27 Julien Cristau