Bug#1018941: cimg: CVE-2022-1325 - memory exhaustion from a malicious pandore or bmp file

2022-09-02 Thread Neil Williams
Source: cimg Version: 3.0.2+dfsg-1 Severity: important Tags: security upstream X-Debbugs-Cc: codeh...@debian.org, Debian Security Team Hi, The following vulnerability was published for cimg. CVE-2022-1325[0]: | A flaw was found in Clmg, where with the help of a maliciously crafted | pandore

Bug#1014391: scilab: CVE-2022-30045 incorrect memory handling in ezml support leading to a heap out-of-bounds read

2022-08-05 Thread Neil Williams
On Mon, 1 Aug 2022 18:25:04 +0200 Sylvestre Ledru wrote: > Hello, > > Le 05/07/2022 à 11:19, Neil Williams a écrit : > > Source: scilab > > Version: 6.1.1+dfsg2-3 > > Severity: important > > Tags: security > > X-Debbugs-Cc: codeh...@debian.org,

Bug#1003165: fixed in astrometry.net 0.89+dfsg-2

2022-08-01 Thread Neil Williams
solete field Name from debian/upstream/metadata > . >[ Ole Streicher ] >* Switch build depends on libnetpbm10-dev to libnetpbm-dev > (Closes: #1003165) 1003165 is the wrong bug number and a different package. The B-D bug in astrometry.net is 1016400. https://bugs.debian.org

Bug#1014391: scilab: CVE-2022-30045 incorrect memory handling in ezml support leading to a heap out-of-bounds read

2022-07-05 Thread Neil Williams
Source: scilab Version: 6.1.1+dfsg2-3 Severity: important Tags: security X-Debbugs-Cc: codeh...@debian.org, Debian Security Team Hi, The following vulnerability was published for scilab. CVE-2022-30045[0]: | An issue was discovered in libezxml.a in ezXML 0.8.6. The function | ezxml_decode()

Bug#1009191: cctbx: please re-enable building on riscv64

2022-04-30 Thread Neil Williams
eal-world usage of cctbx was manageable on any current RISCV64 hardware. > cctbx seems to build fine on riscv64 now. Can it be > re-enabled? Probably, yes. I won't have time to do an upload soon though. If someone else has time to do it as a team upload, go ahead. -- Neil Williams li...@cod

Bug#1010349: librecad: CVE-2021-21897 - heap-based buffer overflow loading a DXF file via embedded dxflib

2022-04-29 Thread Neil Williams
Source: librecad Version: 2.1.3-3 Severity: important Tags: security X-Debbugs-Cc: codeh...@debian.org, Debian Security Team Hi, The following vulnerability was published for librecad. CVE-2021-21897[0]: | A code execution vulnerability exists in the | DL_Dxf::handleLWPolylineData

Bug#1008520: cctbx hard-codes the python version in it's local patches

2022-03-29 Thread Neil Williams
it may be necessary to retain the current patch method and I don't see why that is against Policy. It's not pretty, I agree, but I have not (yet) found an alternative. -- Neil Williams = https://linux.codehelp.co.uk/ pgp9z_a7UMedA.pgp Description: OpenPGP digital signature -- debian-sc

Bug#1005747: freecad: CVE-2021-45844 - Improper sanitization in the invocation of ODA File Converter

2022-02-14 Thread Neil Williams
Source: freecad Version: 0.19.2+dfsg1-3 Severity: important Tags: security X-Debbugs-Cc: codeh...@debian.org, Debian Security Team Hi, The following vulnerability was published for freecad. CVE-2021-45844[0]: | Improper sanitization in the invocation of ODA File Converter from | FreeCAD 0.19

Bug#1004732: epics-base: Need to changes epics-base binary packages to broaden the support

2022-02-01 Thread Neil Williams
Source: epics-base Version: 7.0.3.1-3 Severity: important X-Debbugs-Cc: codeh...@debian.org Experimental Physics and Industrial Control System (EPICS) in Debian relates to the epics-base source package and the pyepics work that will result in new packages in Debian in due course. Currently,

Bug#1003165: scikit-learn in unstable FTBFS on arm64, armel, armhf, i386, ppc64el and s390x

2022-01-05 Thread Neil Williams
Source: scikit-learn Version: 0.23.2-5 Severity: serious Tags: ftbfs Justification: Fails to build from source X-Debbugs-Cc: codeh...@debian.org The new version of scikit-learn has not migrated to testing because it has not built on all required architectures. This is now affecting other packages

Bug#1000292: Why was libpython3.10-dev not available in the test build?

2021-11-24 Thread Neil Williams
this dependency for some reason. What was the setup of this test build? -- Neil Williams = http://www.linux.codehelp.co.uk/ pgprDszsn3oVy.pgp Description: OpenPGP digital signature -- debian-science-maintainers mailing list debian-science-maintainers@alioth-lists.debian.net https://alioth

Re: navarp_1.0.0-1_amd64.changes REJECTED

2021-11-17 Thread Neil Williams
A new upload of navarp 1.0.0-1 will be made. -- Neil Williams = https://linux.codehelp.co.uk/ pgppPxCzDUs4W.pgp Description: OpenPGP digital signature -- debian-science-maintainers mailing list debian-science-maintainers@alioth-lists.debian.net https://alioth-lists.debian.net/cgi-bin/

Bug#995226: nltk is vulnerable to Inefficient Regular Expression Complexity

2021-09-28 Thread Neil Williams
ixed upstream: https://github.com/nltk/nltk/commit/277711ab1dec729e626b27aab6fa35ea5efbd7e6 https://github.com/nltk/nltk/pull/2816 Current vulnerable version in unstable: https://sources.debian.org/src/nltk/3.5-1/nltk/corpus/reader/comparative_sents.py/#L48 -- Neil Williams = h