Bug#527007: gstreamer0.10: FTBFS: subst in debian patch misformed

2009-05-05 Thread Sebastian Dröge
Am Montag, den 04.05.2009, 18:29 -0400 schrieb Arnaud Soyez (Weboide):
 Package: libgstreamer0.10-0
 Version: 0.10.22-3
 Severity: grave
 File: gstreamer0.10
 Tags: patch
 Justification: renders package unusable
 
 
 In Ubuntu Karmic, this package FTBFS.
 As a reference, see these build logs [1]  [2].
 
 The problem comes from the patch named
 90_dont-link-gstcheck-with-check.patch:
 The subst function doesn't handle commas in its parameters and needs a
 new variable containing a comma as a workaround (for more information,
 see gnumake's manual [3]).
 
 I provided this debdiff [4] for Ubuntu but we would appreciate if this
 fix can be introduced in Debian.

Thanks, I'll include this patch with the next upload in the next days :)


signature.asc
Description: Dies ist ein digital signierter Nachrichtenteil
___
Pkg-gstreamer-maintainers mailing list
Pkg-gstreamer-maintainers@lists.alioth.debian.org
http://lists.alioth.debian.org/mailman/listinfo/pkg-gstreamer-maintainers

Bug#527075: gst-plugins-bad0.10: CVE-2009-1438 integer overflow in embedded libmodplug

2009-05-05 Thread Nico Golde
Package: gst-plugins-bad0.10
Severity: grave
Tags: security patch

Hi,
the following CVE (Common Vulnerabilities  Exposures) id was
published for gst-plugins-bad0.10.

CVE-2009-1438[0]:
| Integer overflow in the CSoundFile::ReadMed function
| (src/load_med.cpp) in libmodplug before 0.8.6, as used in
| gstreamer-plugins and other products, allows context-dependent
| attackers to execute arbitrary code via a MED file with a crafted (1)
| song comment or (2) song name, which triggers a heap-based buffer
| overflow.

Since you embedd this package in your sources
The upstream patch is available on:
http://modplug-xmms.cvs.sourceforge.net/viewvc/modplug-xmms/libmodplug/src/load_med.cpp?r1=1.1r2=1.2view=patch
  

If you fix the vulnerability please also make sure to include the
CVE id in your changelog entry.

For further information see:

[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1438
http://security-tracker.debian.net/tracker/CVE-2009-1438

-- 
Nico Golde - http://www.ngolde.de - n...@jabber.ccc.de - GPG: 0x73647CFF
For security reasons, all text in this mail is double-rot13 encrypted.


pgpDqkify61Qx.pgp
Description: PGP signature
___
Pkg-gstreamer-maintainers mailing list
Pkg-gstreamer-maintainers@lists.alioth.debian.org
http://lists.alioth.debian.org/mailman/listinfo/pkg-gstreamer-maintainers

Mail delivery failed: returning message to sender

2009-05-05 Thread Mail Delivery System
This message was created automatically by mail delivery software.

A message that you sent could not be delivered to one or more of its
recipients. This is a permanent error. The following address(es) failed:

  pkg-gstreamer-maintainers@lists.alioth.debian.org
(generated from gst-plugins...@packages.debian.org)
SMTP error from remote mail server after end of data:
host lists.alioth.debian.org [217.196.43.134]:
550-Blacklisted URL in message. (pejjenif.cn) in [jp] [ob]. See
550 http://www.surbl.org/lists.html.

-- This is a copy of the message, including all the headers. --

Return-path: gst-plugins...@packages.debian.org
Received: from [219.241.123.163]
by powell.debian.org with esmtp (Exim 4.69)
(envelope-from gst-plugins...@packages.debian.org)
id 1M1MF7-0003dZ-VU
for gst-plugins...@packages.debian.org; Tue, 05 May 2009 15:07:38 +
X-Mailer: QUALCOMM Windows Eudora Version 7.1.0.9
Date:   Wed, 6 May 2009 00:07:34 +0900
To: gst-plugins...@packages.debian.org
From:   Jolanda Brucato gst-plugins...@packages.debian.org
Subject: The enlargement you needed
Mime-Version: 1.0
Content-Type: multipart/alternative;
boundary==_35158685==.ALT
X-Greylist: delayed 1565 seconds by postgrey-1.31 at powell; Tue, 05 May 2009 
15:07:37 UTC

--=_35158685==.ALT
Content-Type: text/plain; charset=us-ascii; format=flowed

Boost your tool performance http://www.pejjenif.cn/
--=_35158685==.ALT
Content-Type: text/html; charset=us-ascii

html
body
bBoost your tool performance/b
a href=http://www.pejjenif.cn/; 
eudora=autourlhttp://www.pejjenif.cn//a/body
/html

--=_35158685==.ALT--

___
Pkg-gstreamer-maintainers mailing list
Pkg-gstreamer-maintainers@lists.alioth.debian.org
http://lists.alioth.debian.org/mailman/listinfo/pkg-gstreamer-maintainers


Erotic Masssage

2009-05-05 Thread Heinzman Tilus
inline: image/png___
Pkg-gstreamer-maintainers mailing list
Pkg-gstreamer-maintainers@lists.alioth.debian.org
http://lists.alioth.debian.org/mailman/listinfo/pkg-gstreamer-maintainers

Bug#527158: gstreamer0.10-plugins-good: should warn if the tag encoding is wrong

2009-05-05 Thread Tino Keitel
Package: gstreamer0.10-plugins-good
Version: 0.10.14-2
Severity: normal

I noticed that rhythmbox shows correctly decoded tags for for local files,
but not for files provided by a mt-daapd server.  While analyzing this
issue, I saw that most of the tags in my MP3 collection contained garbage:
the text had a wrong encoding.  Very often, UTF8 text was put into ID3 v2.3
tags.  However, ID3 v2.3 doesn't support UTF8, only v2.4 does.

For local files, the broken encoding was magically and silently fixed, I
suspect the id3demux plugin is the culprit.  This behaviour looks
userfriendly at the first place, but the user also doesn't notice that his
files contain garbage in the tags (like with german umlauts, or other
non-ASCII characters), so there should be at least some warning that broken
text in ID3 tags was corrected.  This way, the user knows that there is
something wrong.

In my case, I installed mt-daapd, which handles the ID3 tags and the defined
charset according to the specification, and I ended up with broken tags in a
lot of files.

Regards,
Tino
-- System Information:
Debian Release: squeeze/sid
  APT prefers unstable
  APT policy: (500, 'unstable'), (500, 'testing'), (1, 'experimental')
Architecture: amd64 (x86_64)

Kernel: Linux 2.6.30-rc4-00187-gb4348f3 (SMP w/2 CPU cores)
Locale: LANG=C, LC_CTYPE=de_DE.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash

Versions of packages gstreamer0.10-plugins-good depends on:
ii  gconf2   2.26.0-1GNOME configuration database syste
ii  gstreamer0.1 0.10.22-5   GStreamer plugins from the base 
ii  libaa1   1.4p5-38ascii art library
ii  libavc1394-0 0.5.3-1+b2  control IEEE 1394 audio/video devi
ii  libbz2-1.0   1.0.5-1 high-quality block-sorting file co
ii  libc62.9-10  GNU C Library: Shared libraries
ii  libcaca0 0.99.beta16-1   colour ASCII art library
ii  libcairo21.8.6-2+b1  The Cairo 2D vector graphics libra
ii  libdbus-1-3  1.2.12-1simple interprocess messaging syst
ii  libdv4   1.0.0-2 software library for DV format dig
ii  libflac8 1.2.1-1.2   Free Lossless Audio Codec - runtim
ii  libgcc1  1:4.4.0-3   GCC support library
ii  libgconf2-4  2.26.0-1GNOME configuration database syste
ii  libglib2.0-0 2.20.1-2The GLib library of C routines
ii  libgstreamer 0.10.22-5   GStreamer libraries from the base
ii  libgstreamer 0.10.22-3   Core GStreamer libraries and eleme
ii  libgtk2.0-0  2.16.1-2The GTK+ graphical user interface 
ii  libhal1  0.5.12~git20090406.46dc48-2 Hardware Abstraction Layer - share
ii  libiec61883- 1.2.0-0.1   an partial implementation of IEC 6
ii  libjpeg626b-14   The Independent JPEG Group's JPEG 
ii  liboil0.30.3.15-1Library of Optimized Inner Loops
ii  libpng12-0   1.2.35-1PNG library - runtime
ii  libraw1394-1 2.0.2-2 library for direct access to IEEE 
ii  libshout32.2.2-5 MP3/Ogg Vorbis broadcast streaming
ii  libsoup2.4-1 2.26.1-1an HTTP library implementation in 
ii  libspeex11.2~rc1-1   The Speex codec runtime library
ii  libstdc++6   4.4.0-3 The GNU Standard C++ Library v3
ii  libtag1c2a   1.5-6   TagLib Audio Meta-Data Library
ii  libv4l-0 0.5.9-1 Collection of video4linux support 
ii  libwavpack1  4.50.1-1an audio codec (lossy and lossless
ii  libx11-6 2:1.2.1-1   X11 client-side library
ii  libxdamage1  1:1.1.1-4   X11 damaged region extension libra
ii  libxext6 2:1.0.4-1   X11 miscellaneous extension librar
ii  libxfixes3   1:4.0.3-2   X11 miscellaneous 'fixes' extensio
ii  libxml2  2.7.3.dfsg-1GNOME XML library
ii  zlib1g   1:1.2.3.3.dfsg-13   compression library - runtime

Versions of packages gstreamer0.10-plugins-good recommends:
ii  gstreamer0.10-x   0.10.22-5  GStreamer plugins for X11 and Pang

gstreamer0.10-plugins-good suggests no packages.

-- no debconf information



___
Pkg-gstreamer-maintainers mailing list
Pkg-gstreamer-maintainers@lists.alioth.debian.org
http://lists.alioth.debian.org/mailman/listinfo/pkg-gstreamer-maintainers