Re: [Bug 235135] Re: [MASTER] Please backport flashplugin-nonfree version 10 beta and asound-plugins from Intrepid so we can drop libflashsupport and the crashes it causes

2008-07-10 Thread John Vivirito
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Scott Kitterman wrote: > Ack for Hardy from ubuntu-backporters for: > > flashplugin-nonfree (10.0.1.218+10.0.0.525ubuntu1 > libflashsupport (1.9-0ubuntu2) > > ** Changed in: hardy-backports >Importance: Undecided => Wishlist >Status: Tria

[Bug 247442] [NEW] Please backport erlang-manpages

2008-07-10 Thread Francois-Denis Gonthier
Public bug reported: Version 1:12.b.3-1 is in Intrepid. Should be a simple rebuild. ** Affects: hardy-backports Importance: Undecided Status: New -- Please backport erlang-manpages https://bugs.launchpad.net/bugs/247442 You received this bug notification because you are a member

[Bug 247443] [NEW] Please backport erlang-doc-html

2008-07-10 Thread Francois-Denis Gonthier
Public bug reported: Version 1:12.b.3-1 is in Intrepid. Should need a simple rebuild. ** Affects: hardy-backports Importance: Undecided Status: New -- Please backport erlang-doc-html https://bugs.launchpad.net/bugs/247443 You received this bug notification because you are a membe

[Bug 247428] [NEW] Please backport erlang

2008-07-10 Thread Francois-Denis Gonthier
Public bug reported: Bug 176154 reports this as a simple rebuild. ** Affects: hardy-backports Importance: Undecided Status: New -- Please backport erlang https://bugs.launchpad.net/bugs/247428 You received this bug notification because you are a member of Ubuntu Backports Testing

[Bug 227464] Re: Please roll out security fixes from PHP 5.2.6

2008-07-10 Thread Tormod Volden
I agree with spinkham. It is a shame that a security issue in a main package (and php5 is pretty prominent when it comes to servers) has a tested debdiff sitting untouched for 5 weeks. Can't blame Kees and his two other colleagues - they have certainly been busy - but yes, there are only 3 (three)

Re: [Bug 227464] Re: Please roll out security fixes from PHP 5.2.6

2008-07-10 Thread Kees Cook
Sorry for the delays in getting this update published. The Ubuntu Security Team has been very busy lately. As an explaination, most of the vulnerabilities are hard to exploit, so this has been lower on the list of things to do. All that said, now that Bind and the latest cycles of kernel updates

[Bug 246238] Re: warsow 0.42 backported to Hardy, but warsow-data 0.42 not backported

2008-07-10 Thread Aïssi Dylan
I built warsow-data_0.42-1 with a pbuilder, it installs fine, and works correctly. -- warsow 0.42 backported to Hardy, but warsow-data 0.42 not backported https://bugs.launchpad.net/bugs/246238 You received this bug notification because you are a member of Ubuntu Backports Testing Team, which is

[Bug 246238] Re: warsow 0.42 backported to Hardy, but warsow-data 0.42 not backported

2008-07-10 Thread Scott Kitterman
Only a bug in hardy-backports, not in warsow-data. ** Changed in: warsow-data (Ubuntu) Status: Confirmed => Invalid -- warsow 0.42 backported to Hardy, but warsow-data 0.42 not backported https://bugs.launchpad.net/bugs/246238 You received this bug notification because you are a member of

[Bug 246238] Re: warsow 0.42 backported to Hardy, but warsow-data 0.42 not backported

2008-07-10 Thread Scott Kitterman
Someone please test warsow-data for backporting and then I can approve it. Please specify the exact version you test. ** Changed in: hardy-backports Status: Confirmed => Incomplete -- warsow 0.42 backported to Hardy, but warsow-data 0.42 not backported https://bugs.launchpad.net/bugs/246

[Bug 227464] Re: Please roll out security fixes from PHP 5.2.6

2008-07-10 Thread spinkham
This has been addressed in Intrepid by updating to PHP 5 here: https://launchpad.net/ubuntu/intrepid/+source/php5/5.2.6-1ubuntu1 Minimal patch above in this post https://bugs.launchpad.net/ubuntu/+source/php5/+bug/227464/comments/15 Re: test cases: I've not yet seen widely published exploit code,

[Bug 227464] Re: Please roll out security fixes from PHP 5.2.6

2008-07-10 Thread spinkham
This has been addressed in Intrepid buy updating to PHP 5 here: https://launchpad.net/ubuntu/intrepid/+source/php5/5.2.6-1ubuntu1 Minimal patch above in this post https://bugs.launchpad.net/ubuntu/+source/php5/+bug/227464/comments/15 Re: test cases: I've not yet seen widely published exploit code

[Bug 245903] Re: alien-arena in hardy-backports cannot be installed

2008-07-10 Thread Aïssi Dylan
There is same bug with warsow and warsow-data https://bugs.launchpad.net/hardy-backports/+bug/246238 -- alien-arena in hardy-backports cannot be installed https://bugs.launchpad.net/bugs/245903 You received this bug notification because you are a member of Ubuntu Backports Testing Team, which is

[Bug 227464] Re: Please roll out security fixes from PHP 5.2.6

2008-07-10 Thread spinkham
Impact: Fixed possible stack buffer overflow in FastCGI SAPI Impact:Potential DOS and remote code execution if using FastCGI Updated PCRE to deal with issues fixed in USN-581-1 Impact:potential DOS and code execution Fixes CVE-2008-0599 Impact:Potential DOS and remote code execu

[Bug 227464] Re: Please roll out security fixes from PHP 5.2.6

2008-07-10 Thread spinkham
Sorry, my listing of cURL exploit is not quite accurate, here's an updated version with that and some other fixes (let that be a lesson for you, not to post hastefully and in anger ;-) Impact: Fixed possible stack buffer overflow in FastCGI SAPI Impact:Potential DOS and remote code executio

[Bug 246238] Re: warsow 0.42 backported to Hardy, but warsow-data 0.42 not backported

2008-07-10 Thread Aïssi Dylan
** Changed in: hardy-backports Status: New => Confirmed -- warsow 0.42 backported to Hardy, but warsow-data 0.42 not backported https://bugs.launchpad.net/bugs/246238 You received this bug notification because you are a member of Ubuntu Backports Testing Team, which is subscribed to Hardy

[Bug 227464] Re: Please roll out security fixes from PHP 5.2.6

2008-07-10 Thread spinkham
I'm sorry for whining to the people who are subscribed to and care about this bug, but over 2 months since the release of a package with 3 claimed remotely exploitable code injection bugs makes me VERY hesitant to ever recommend Ubuntu for server use ever again. By this time even the slow moving

Re: [Bug 227464] Re: Please roll out security fixes from PHP 5.2.6

2008-07-10 Thread Andrew Cholakian
Well this sounds like it meets the first criteria: "Bugs which may, under realistic circumstances, directly cause a *security vulnerability*. These are done by the security team and are documented at SecurityUpdateProcedures ." So what stage is

[Bug 245240] Re: Please backport amule 2.2.1 from intrepid

2008-07-10 Thread Fabio Pedretti
Closing as Invalid, as this will be managed as a SRU: https://bugs.launchpad.net/ubuntu/+source/amule/+bug/244670 ** Changed in: hardy-backports Status: New => Invalid -- Please backport amule 2.2.1 from intrepid https://bugs.launchpad.net/bugs/245240 You received this bug notification be

[Bug 246238] Re: warsow 0.42 backported to Hardy, but warsow-data 0.42 not backported

2008-07-10 Thread Alexander Schulze
** Also affects: hardy-backports Importance: Undecided Status: New -- warsow 0.42 backported to Hardy, but warsow-data 0.42 not backported https://bugs.launchpad.net/bugs/246238 You received this bug notification because you are a member of Ubuntu Backports Testing Team, which is subscr

Re: [Bug 227464] Re: Please roll out security fixes from PHP 5.2.6

2008-07-10 Thread Dustin Kirkland
On Thu, Jul 10, 2008 at 10:14 AM, Andrew Cholakian <[EMAIL PROTECTED]> wrote: > Agreed spinkham, debian got the release out fast, what's going on here? The Stable Release Update process for an Long Term Support release such as Hardy involves a bit a work and justification on our end in order to ro

[Bug 227464] Re: Please roll out security fixes from PHP 5.2.6

2008-07-10 Thread Andrew Cholakian
Agreed spinkham, debian got the release out fast, what's going on here? -- Please roll out security fixes from PHP 5.2.6 https://bugs.launchpad.net/bugs/227464 You received this bug notification because you are a member of Ubuntu Backports Testing Team, which is subscribed to Hardy Backports. --

[Bug 227464] Re: Please roll out security fixes from PHP 5.2.6

2008-07-10 Thread spinkham
Another month has passed, no release for Hardy. I'm not savvy enough with the Ubuntu release procedures to even know who to contact about this. Could someone tell me what it would take to get these bugs fixed in the current stable, advertised for server use Ubuntu? There are 3 remote code execut

[Bug 235135] Re: [MASTER] Please backport flashplugin-nonfree version 10 beta and asound-plugins from Intrepid so we can drop libflashsupport and the crashes it causes

2008-07-10 Thread Scott Kitterman
Ack for Hardy from ubuntu-backporters for: flashplugin-nonfree (10.0.1.218+10.0.0.525ubuntu1 libflashsupport (1.9-0ubuntu2) ** Changed in: hardy-backports Importance: Undecided => Wishlist Status: Triaged => In Progress -- [MASTER] Please backport flashplugin-nonfree version 10 beta a

[Bug 245903] Re: alien-arena in hardy-backports cannot be installed

2008-07-10 Thread Scott Kitterman
ack from ubuntu-backporters ** Changed in: hardy-backports Importance: Undecided => Wishlist Status: Triaged => In Progress -- alien-arena in hardy-backports cannot be installed https://bugs.launchpad.net/bugs/245903 You received this bug notification because you are a member of Ubuntu

[Bug 200954] Re: Get Alien Arena 2008 (v7.0) into hardy

2008-07-10 Thread John Vivirito
the data bug number is at https://bugs.edge.launchpad.net/ubuntu/+source /alien-arena/+bug/245903 -- Get Alien Arena 2008 (v7.0) into hardy https://bugs.launchpad.net/bugs/200954 You received this bug notification because you are a member of Ubuntu Backports Testing Team, which is subscribed to H

Re: [Bug 200954] Re: Get Alien Arena 2008 (v7.0) into hardy

2008-07-10 Thread John Vivirito
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Scott Kitterman wrote: > John Vivirito: Is there another bug for the data package? > There is i will get the bug number and post it here, just let me get through the rest of my email - -- Sincerely Yours, John Vivirito https://launchpad.net/~gno