Bug#289623: marked as done (openoffice.org-thesaurus-it: should depend on openoffice.org)

2005-01-23 Thread Debian Bug Tracking System
Your message dated Sun, 23 Jan 2005 03:32:25 -0500
with message-id <[EMAIL PROTECTED]>
and subject line Bug#289623: fixed in openoffice.org-thesaurus-it 0+20041114.2
has caused the attached Bug report to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what I am
talking about this indicates a serious mail system misconfiguration
somewhere.  Please contact me immediately.)

Debian bug tracking system administrator
(administrator, Debian Bugs database)

--
Received: (at submit) by bugs.debian.org; 10 Jan 2005 04:57:51 +
>From [EMAIL PROTECTED] Sun Jan 09 20:57:51 2005
Return-path: <[EMAIL PROTECTED]>
Received: from mail.gmx.de (mail.gmx.net) [213.165.64.20] 
by spohr.debian.org with smtp (Exim 3.35 1 (Debian))
id 1Cnrcl-0001gG-00; Sun, 09 Jan 2005 20:57:51 -0800
Received: (qmail invoked by alias); 10 Jan 2005 04:57:19 -
Received: from dsl-082-083-172-207.arcor-ip.net (EHLO localhost) (82.83.172.207)
  by mail.gmx.net (mp009) with SMTP; 10 Jan 2005 05:57:19 +0100
X-Authenticated: #1545045
Received: by localhost (Postfix, from userid 1000)
id 3FE391BB44; Mon, 10 Jan 2005 05:57:19 +0100 (CET)
Date: Mon, 10 Jan 2005 05:57:19 +0100
From: Rene Engelhard <[EMAIL PROTECTED]>
To: Debian Bug Tracking System <[EMAIL PROTECTED]>
Subject: openoffice.org-thesaurus-it: should depend on openoffice.org
Message-ID: <[EMAIL PROTECTED]>
Mime-Version: 1.0
Content-Type: multipart/signed; micalg=pgp-sha1;
protocol="application/pgp-signature"; boundary="gE7i1rD7pdK0Ng3j"
Content-Disposition: inline
X-Reportbug-Version: 3.2
X-PGP-Key: 248AEB73
X-PGP-Fingerprint: 41FA F208 28D4 7CA5 19BB  7AD9 F859 90B0 248A EB73
User-Agent: Mutt/1.5.6+20040907i
X-Y-GMX-Trusted: 0
Delivered-To: [EMAIL PROTECTED]
X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2005_01_02 
(1.212-2003-09-23-exp) on spohr.debian.org
X-Spam-Status: No, hits=-3.0 required=4.0 tests=BAYES_00 autolearn=no 
version=2.60-bugs.debian.org_2005_01_02
X-Spam-Level: 


--gE7i1rD7pdK0Ng3j
Content-Type: multipart/mixed; boundary="ABTtc+pdwF7KHXCz"
Content-Disposition: inline


--ABTtc+pdwF7KHXCz
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline

Package: openoffice.org-thesaurus-it
Severity: serious
Tags: patch sarge sid

Hi,

openoffice.org-thesaurus-it is a thesaurus for OpenOffice.org so it
should depend on OpenOffice.org. That the myspell policy says otherwiese
is because anything using libmyspell can use those dictionaries and ther
already are 3 things using it: OpenOffice.org, Mozilla and libenchant
which can use libmyspell3. There also is a unneeded Depends: line in
control.

Attched patch fixes this.

Regards,

Rene

BTW: You probably should make openoffice.org-thesaurus-it a non-native
package...

-- System Information:
Debian Release: 3.1
  APT prefers testing
  APT policy: (500, 'testing')
Architecture: i386 (i686)
Kernel: Linux 2.6.10
Locale: [EMAIL PROTECTED], [EMAIL PROTECTED] (charmap=ISO-8859-15)

Versions of packages openoffice.org-thesaurus-it depends on:
ii  dictionaries-common [openo 0.22.40sarge7 Common utilities for spelling dict

--ABTtc+pdwF7KHXCz
Content-Type: text/plain; charset=us-ascii
Content-Disposition: attachment; filename="openoffice.org-thesaurus-it.patch"
Content-Transfer-Encoding: quoted-printable

--- control.old 2004-12-24 19:18:14.0 +0100
+++ control 2005-01-10 05:49:59.0 +0100
@@ -7,10 +7,8 @@
=20
 Package: openoffice.org-thesaurus-it
 Architecture: any
-Depends: ${shlibs:Depends}
 Provides: openoffice.org-thesaurus
-Depends: dictionaries-common (>=3D 0.10) | openoffice.org-updatedicts
-Suggests: openoffice.org (>=3D 1.0.3-3)
+Depends: openoffice.org (>=3D 1.0.2), dictionaries-common (>=3D 0.10) | op=
enoffice.org-updatedicts
 Conflicts: openoffice.org (<=3D 1.0.3-2)
 Description: Italian Thesaurus for OpenOffice.org
  This package contains an Italian thesaurus for use with the

--ABTtc+pdwF7KHXCz--

--gE7i1rD7pdK0Ng3j
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature
Content-Disposition: inline

-BEGIN PGP SIGNATURE-
Version: GnuPG v1.2.4 (GNU/Linux)

iD8DBQFB4gsu+FmQsCSK63MRAnO8AJ9CaCa5gtLtsMb0lYr1b1iJ4T9eHwCfUOhy
DXXDAfzP+jhHOfLC6sAjTVw=
=d0kw
-END PGP SIGNATURE-

--gE7i1rD7pdK0Ng3j--

---
Received: (at 289623-close) by bugs.debian.org; 23 Jan 2005 08:35:44 +
>From [EMAIL PROTECTED] Sun Jan 23 00:35:44 2005
Return-path: <[EMAIL PROTECTED]>
Received: from newraff.debian.org [208.185.25.31] (mail)
by spohr.debian.org with esmtp (Exim 3.35 1 (Debian))
id 1CsdDj-0004XR-00; Sun, 23 Jan 2005 00:35:43 -0800
Received: from katie by newraff.debian.org with local (Exim 3.35 

Processed: Re: kipina_0.1.1-1(ia64/unstable): FTBFS: "Scan failed"

2005-01-23 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]:

> # not an arch regression, therefore not RC
> severity 291786 important
Bug#291786: kipina_0.1.1-1(ia64/unstable): FTBFS: "Scan failed"
Severity set to `important'.

> thanks
Stopping processing here.

Please contact me if you need assistance.

Debian bug tracking system administrator
(administrator, Debian Bugs database)


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]



Bug#287166: meld: traceback when comparing 2 directories

2005-01-23 Thread Steve Langasek
merge 290811 287166
thanks

This bug is most likely a release-critical regression in glade2, not a bug
in meld.  I've asked Jordi Mallach to take a look at this on the glade end.

-- 
Steve Langasek
postmodern programmer


signature.asc
Description: Digital signature


Processed: mrph

2005-01-23 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]:

> forwarded 290811 http://bugzilla.gnome.org/show_bug.cgi?id=163322';
Bug#290811: meld crashes on start
Noted your statement that Bug has been forwarded to 
http://bugzilla.gnome.org/show_bug.cgi?id=163322';.

> merge 290811 287166
Bug#287166: meld: traceback when comparing 2 directories
Bug#290811: meld crashes on start
Mismatch - only Bugs in same state can be merged:
Values for `forwarded addr' don't match:
 #287166 has `http://bugzilla.gnome.org/show_bug.cgi?id=163322';
 #290811 has `http://bugzilla.gnome.org/show_bug.cgi?id=163322';'

> thanks
Stopping processing here.

Please contact me if you need assistance.

Debian bug tracking system administrator
(administrator, Debian Bugs database)


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]



Bug#291784: zopeinterface_3.0.0-2(hppa/unstable): FTBFS: missing build-depends?

2005-01-23 Thread Steve Langasek
This bug seems to be due to changes in cdbs, which in newer versions
recognizes the existence of python2.4.  Because you pull the list of python
versions from cdbs, despite only actually building packages for two of these
versions; and because you don't build-depend on python2.4-dev, and don't
ignore errors from this command in debian/rules, this package now FTBFS on
all architectures.

-- 
Steve Langasek
postmodern programmer


signature.asc
Description: Digital signature


Processed: fails to configure because gs-common is not configured

2005-01-23 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]:

> reassign 290597 gs-common
Bug#290597: fails to configure because gs-common is not configured
Bug reassigned from package `gs-gpl' to `gs-common'.

> thanks
Stopping processing here.

Please contact me if you need assistance.

Debian bug tracking system administrator
(administrator, Debian Bugs database)


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]



Bug#287899: vdr: run as non-root user

2005-01-23 Thread Steve Langasek
Thomas,

This RC bug has been tagged "pending" for almost a month now.  What's the
status of this upload?

-- 
Steve Langasek
postmodern programmer


signature.asc
Description: Digital signature


Bug#290597: fails to configure because gs-common is not configured

2005-01-23 Thread Steve Langasek
reassign 290597 gs-common
thanks

Matt,

All of the high-level apt tools should be capable of breaking this kind of
dependency loop between gs-gpl and gs-common, so the most apparent reason
for this kind of failure would be that gs-common could not be configured for
reasons other than this dependency loop.  I think we really need to see the
output of trying to install gs-common on this system in order to debug this.

Thanks,
-- 
Steve Langasek
postmodern programmer


signature.asc
Description: Digital signature


Processed: Re: xscreensaver-gl: GLKnots crashes my whole X-Window system

2005-01-23 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]:

> severity 290809 minor
Bug#290809: xscreensaver-gl: GLKnots crashes my whole X-Window system
Severity set to `minor'.

> thanks
Stopping processing here.

Please contact me if you need assistance.

Debian bug tracking system administrator
(administrator, Debian Bugs database)


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]



Processed: reducing severity

2005-01-23 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]:

> severity 290905 important
Bug#290905: rsync fails with error when rsyncing to a remote host (file server) 
running rsyncd
Severity set to `important'.

> thanks
Stopping processing here.

Please contact me if you need assistance.

Debian bug tracking system administrator
(administrator, Debian Bugs database)


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]




Bug#290809: xscreensaver-gl: GLKnots crashes my whole X-Window system

2005-01-23 Thread Steve Langasek
severity 290809 minor
thanks

If an X application crashes the X server, that's an X server bug, not a bug
in the X client.  As I understand it, the X server you're using did not come
from Debian, which means the bug is not in a Debian package.  I'm
downgrading the severity of this bug accordingly, and leaving it open in
case the xscreensaver-gl maintainer wishes to help debug this further.  For
my part, I think the bug should just be closed.

-- 
Steve Langasek
postmodern programmer


signature.asc
Description: Digital signature


Bug#290905: More questions

2005-01-23 Thread Goswin von Brederlow
Hi,

some more questions about your setup:

Your config says:
| [mirror]
| path = /root/backup_server/backup
| use chroot = no
| max connections = 4
| auth users = root
| hosts allow = backup_server
| secrets file = /etc/.rs_sec
| uid = root
| gid = root

and to the question if it is writeable you said:

| $ ls -l /root/venus
| drwxr-xr-x  3 root root 4096 2005-01-03 09:46 backup

That is a different path.

Also what user did you set in inetd.conf for rsyncd?

MfG
Goswin


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]



Bug#290905: reducing severity

2005-01-23 Thread Goswin von Brederlow
severity 290905 important
thanks

Hi,

rsync and rsyncd seems to work for most people, even 50% for the
reportee so I agree with Steve Langasek (on irc) that this is not a
grave bug and should not stop sarge.

MfG
Goswin



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]



Bug#284783: kernel-image-2.6.9-1-686-smp: Kernel oops possibly related to kswapd

2005-01-23 Thread maximilian attems
On Wed, 08 Dec 2004, Sean O'Dubhghaill wrote:
> Under normal use (running kde, konqueor etc) my kernel oops causing the
> machine to freeze requiring a hard reset. From looking at the oops
> message (which is attached) i suspect it has something to do with
> kswapd.

can you still reproduce it?

does it happen with the newer kernel-image 2.6.10 from unstable?

thanks for your repsonse, dmesg of affected kernel may help.

maks


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]



Processed: tags 289796 pending

2005-01-23 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]:

> package courier-filter-perl
Ignoring bugs not assigned to: courier-filter-perl

> tags 289796 pending
Bug#289796: courier-filter-perl: Perl 5.8 dependency not represented in package
There were no tags set.
Tags added: pending

> thanks
Stopping processing here.

Please contact me if you need assistance.

Debian bug tracking system administrator
(administrator, Debian Bugs database)


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]



Bug#291600: FTBFS: Attempts to use 'apt-get source'

2005-01-23 Thread Rene Mayrhofer
On Friday 21 January 2005 19:37, Stephen Quinney wrote:
> Upon investigation I found that debian/rules is calling two scripts:
> build-discover (which attempts to download the source for curl, expat
> and discover) and build-paste (which attempts to grab the source for
> coreutils). This is total and utter madness, I've never come across
> anything so odd before in my experience of Debian packaging.
There is absolutely _no_ reason to be rude about this. If you think that it is 
odd, then ok. But insulting me personally is unprofessional and certainly 
counterproductive. Just because it doesn't work like you would've done it is 
no indicator for "total and utter madness". 

 It might have helped if you had asked for the reasons for this special 
construction, which I have not done just for the fun of it But I 
understand that flaming is easier, takes less of your seemingly valuable time 
and maybe gets you a few additional ego points then thinking about the issue 
and writing a constructive email with real suggestions for improving it.

Btw, this is already documented in the changelog.

> You must not assume even the existence of a network connection from a
> buildd never mind the ability to run apt-get. It must be possible to
> build a package inside a self-contained chroot. You should also note
> that there is a high chance that the apt source urls will not be
> listed in typical chroots.
In all of the build environments that I have access to, they are. I agree that 
some might not have this possibility, but then you could work with a local 
package mirror.

> I am absolutely certain that you really do not need to download the
> source code for each of these packages and then build them. There must
> be a better way to achieve what you are trying to do here.
OK, send me patches if you have a better solution. I will look at them and 
decide if they have other problems.

In case you care about the reasoning for my decisions: it is all about 
maintainability and size: I do not want to:
a) duplicate the complete sources in my package, because it would simply be a 
waste of space and bandwidth.
b) extract only those source files that are really necessary and create a new 
build system for them, because that would mean a lot of effort for tracking 
upstream changes for no benefit (and for building the uclibc-linked discover 
binary, nearly all of the source files are necessary anyways).
c) ship pre-compiled binaries in the source package, like it was done in the 
version before this "odd" construction.

If you have a solution that does not need to download the source packages at 
build time (which is no problem for reasonable development environments) and 
does not have the problems listed above, then you are welcome to send me 
patches. I am not completely happy with the current solution and would like 
to do something about it. And since you are "absolutely certain" that there 
is such a solution, I am already delighted to get the chance to improve my 
package. 

PS: A second outright insulting email (aka. flame) will simply be ignored, 
because my time is also valuable. If you would like to resolve this in a 
constructive manner, then I am, as always, open to any suggestion.

Rene


pgpjPqweqclrX.pgp
Description: PGP signature


Bug#291807: evolution: lots body in pgp signed messages

2005-01-23 Thread Miguel Gea Milvaques
Package: evolution
Version: 2.0.3-1.1
Severity: grave
Justification: causes non-serious data loss

When I receive a message signed with gpg, it lost the body part of
message. I've tried with another mail client ant the problem disapears
:(

-- System Information:
Debian Release: 3.1
  APT prefers unstable
  APT policy: (500, 'unstable')
Architecture: i386 (i686)
Kernel: Linux 2.6.10
Locale: LANG=ca_ES.UTF-8, LC_CTYPE=ca_ES.UTF-8 (charmap=UTF-8)

Versions of packages evolution depends on:
ii  evolution-data-server1.0.3-2 evolution database backend server
ii  gconf2   2.8.1-4 GNOME configuration database syste
ii  gnome-icon-theme 2.8.0-1 GNOME Desktop icon theme
ii  gtkhtml3.2   3.2.4-1 HTML rendering/editing library - b
ii  libart-2.0-2 2.3.16-6Library of functions for 2D graphi
ii  libatk1.0-0  1.8.0-4 The ATK accessibility toolkit
ii  libaudiofile00.2.6-5 Open-source version of SGI's audio
ii  libbonobo2-0 2.8.0-4 Bonobo CORBA interfaces library
ii  libbonoboui2-0   2.8.0-2 The Bonobo UI library
ii  libc62.3.2.ds1-20GNU C Library: Shared libraries an
ii  libcompfaceg11989.11.11-24   Compress/decompress images for mai
ii  libdb4.2 4.2.52-17   Berkeley v4.2 Database Libraries [
ii  libebook81.0.3-2 Client library for evolution addre
ii  libecal6 1.0.3-2 Client library for evolution calen
ii  libedataserver3  1.0.3-2 Utily library for evolution data s
ii  libegroupwise6   1.0.3-2 Client library for accessing group
ii  libesd0  0.2.35-2Enlightened Sound Daemon - Shared 
ii  libfontconfig1   2.2.3-4 generic font configuration library
ii  libfreetype6 2.1.7-2.3   FreeType 2 font engine, shared lib
ii  libgail-common   1.8.2-1 GNOME Accessibility Implementation
ii  libgail171.8.2-1 GNOME Accessibility Implementation
ii  libgal2.2-1  2.2.4-1 G App Libs (run time library)
ii  libgal2.2-common 2.2.4-1 G App Libs (common files)
ii  libgconf2-4  2.8.1-4 GNOME configuration database syste
ii  libgcrypt11  1.2.0-11LGPL Crypto library - runtime libr
ii  libglade2-0  1:2.4.1-1   Library to load .glade files at ru
ii  libglib2.0-0 2.6.1-2 The GLib library of C routines
ii  libgnome-keyring00.4.1-1 GNOME keyring services library
ii  libgnome-pilot2  2.0.12-1.1  Support libraries for gnome-pilot
ii  libgnome2-0  2.8.0-6 The GNOME 2 library - runtime file
ii  libgnomecanvas2-02.8.0-1 A powerful object-oriented display
ii  libgnomeprint2.2-0   2.8.2-1 The GNOME 2.2 print architecture -
ii  libgnomeprintui2.2-0 2.8.2-1 The GNOME 2.2 print architecture U
ii  libgnomeui-0 2.8.0-3 The GNOME 2 libraries (User Interf
ii  libgnomevfs2-0   2.8.3-6 The GNOME virtual file-system libr
ii  libgnutls11  1.0.16-13   GNU TLS library - runtime library
ii  libgpg-error01.0-1   library for common error values an
ii  libgtk2.0-0  2.4.14-2The GTK+ graphical user interface 
ii  libgtkhtml3.2-11 3.2.4-1 HTML rendering/editing library - r
ii  libice6  4.3.0.dfsg.1-10 Inter-Client Exchange library
ii  libjpeg626b-9The Independent JPEG Group's JPEG 
ii  libldap2 2.1.30-3OpenLDAP libraries
ii  libnspr4 2:1.7.5-1   Netscape Portable Runtime Library
ii  libnss3  2:1.7.5-1   Network Security Service Libraries
ii  liborbit21:2.10.2-1.1libraries for ORBit2 - a CORBA ORB
ii  libpango1.0-01.6.0-3 Layout and rendering of internatio
ii  libpisock8   0.11.8-10   Library for communicating with a P
ii  libpisync0   0.11.8-10   Synchronization library for PalmOS
ii  libpopt0 1.7-5   lib for parsing cmdline parameters
ii  libsm6   4.3.0.dfsg.1-10 X Window System Session Management
ii  libsoup2.2-7 2.2.1-1 an HTTP library implementation in 
ii  libtasn1-2   0.2.10-4Manage ASN.1 structures (runtime)
ii  libx11-6 4.3.0.dfsg.1-10 X Window System protocol client li
ii  libxml2  2.6.11-5GNOME XML library
ii  xlibs4.3.0.dfsg.1-10 X Keyboard Extension (XKB) configu
ii  zlib1g   1:1.2.2-4   compression library - runtime

-- no debconf information


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [

Processed: your mail

2005-01-23 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]:

> tags 291782 pending
Bug#291782: bible-kjv_4.17(hppa/unstable): FTBFS: compile errors (implicit 
definition)
There were no tags set.
Tags added: pending

> quit
Stopping processing here.

Please contact me if you need assistance.

Debian bug tracking system administrator
(administrator, Debian Bugs database)


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]



Processed: Re: gtk2-engines-gtk-qt: Crashes firefox and galeon

2005-01-23 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]:

> severity 290960 important
Bug#290960: gtk2-engines-gtk-qt: Crashes firefox and galeon
Severity set to `important'.

> thanks
Stopping processing here.

Please contact me if you need assistance.

Debian bug tracking system administrator
(administrator, Debian Bugs database)


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]



Bug#290960: gtk2-engines-gtk-qt: Crashes firefox and galeon

2005-01-23 Thread Steve Langasek
severity 290960 important
thanks

I also have not been able to reproduce this bug here.  Since it's not
reproducible with a default config, and may even be specific to a single Qt
theme, I think it's reasonable to not consider this bug release-critical, at
least until there's more information about how to reproduce it.

Thanks,
-- 
Steve Langasek
postmodern programmer


signature.asc
Description: Digital signature


Bug#291782: (no subject)

2005-01-23 Thread Matthew Vernon
tags 291782 pending
quit
Thanks for this report. I've gone away and built this package with a newer 
gcc &c, and the package will be uploaded later today.

Regards,
Matthew
--
Rapun.sel - outermost outpost of the Pick Empire
http://www.pick.ucam.org

--
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]


Bug#290773: phpgroupware: forum, polls, preferences, projects, tts, wiki: HTML and SQL insertio

2005-01-23 Thread Steve Langasek
Hi Thomas,

> I have an upload of 005 ready but needed to figure out which changes 
> were security related.

I hope this doesn't mean that you're waiting to figure out which changes
were security related before uploading?

-- 
Steve Langasek
postmodern programmer


signature.asc
Description: Digital signature


Bug#287899: vdr: run as non-root user

2005-01-23 Thread Thomas Schmidt
Hi

* Steve Langasek schrieb am 23.01.05, um 10:44 Uhr:
> This RC bug has been tagged "pending" for almost a month now.  What's the
> status of this upload?

Sorry that the new package has not been uploaded yet, it was ready to
be uploaded last week, but my sponsor suggested another change on the
package, which i am testing now. I am very sure that the package which
will fix this bug will be uploaded during next week.


Regards,
Thomas

-- 
Thomas Schmidt
[EMAIL PROTECTED]


signature.asc
Description: Digital signature


Processed: Bug 280573: Quake II Server Multiple Remote Vulnerabilities

2005-01-23 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]:

> package quake2
Ignoring bugs not assigned to: quake2

> tags 280573 patch
Bug#280573: ID Software Quake II Server Multiple Remote Vulnerabilities
Tags were: security
Tags added: patch

> thanks
Stopping processing here.

Please contact me if you need assistance.

Debian bug tracking system administrator
(administrator, Debian Bugs database)


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]



Bug#280573: Bug 280573: Quake II Server Multiple Remote Vulnerabilities

2005-01-23 Thread Stefan Fritsch
package quake2
tags 280573 patch
thanks

I am not a Debian developer, so I cannot make a NMU. I have made a 
patch however. Does this help? If you don't have time to apply it, 
please tell me as soon as possible, then I will try to find someone 
else to do a NMU. I would really like quake2 to be in sarge.

Cheers,
Stefan
diff -urN quake2-0.3/debian/changelog quake2-0.3.n/debian/changelog
--- quake2-0.3/debian/changelog	2005-01-23 13:37:26.0 +0100
+++ quake2-0.3.n/debian/changelog	2005-01-23 13:27:38.0 +0100
@@ -1,3 +1,12 @@
+quake2 (1:0.3-2) unstable; urgency=high
+
+  *** Change by Stefan Fritsch <[EMAIL PROTECTED]>
+  
+  * Add warnings about security problems
+(allows downgrading of RC bug #280573)
+
+ -- Jamie Wilkinson <[EMAIL PROTECTED]>  Sun, 23 Jan 2005 12:31:57 +0100
+
 quake2 (1:0.3-1) unstable; urgency=low
 
   * The "I bought my laptop for this bug" release.
diff -urN quake2-0.3/debian/control quake2-0.3.n/debian/control
--- quake2-0.3/debian/control	2005-01-23 13:37:26.0 +0100
+++ quake2-0.3.n/debian/control	2005-01-23 13:27:38.0 +0100
@@ -21,3 +21,6 @@
  .
  This game currently supports software rendering with X11, SDL, or SVGAlib,
  or hardware accelerated rendering with OpenGL (directly or via SDL).
+ .
+ NOTE: The network part of Quake II has several unfixed security problems.
+ It should not be used in untrusted networks.
diff -urN quake2-0.3/debian/NEWS quake2-0.3.n/debian/NEWS
--- quake2-0.3/debian/NEWS	1970-01-01 01:00:00.0 +0100
+++ quake2-0.3.n/debian/NEWS	2005-01-23 13:27:38.0 +0100
@@ -0,0 +1,14 @@
+quake2 (1:0.3-2) unstable; urgency=high
+
+   The network part of Quake II (especially the server part) contains
+   several unfixed security issues. Therefore, Quake II should not be
+   used over untrusted networks (like the internet). The version
+   included in Debian is intended only for local play.   
+   
+   See [1] for details. A (hopefully) secure version of the server is
+   available at [2].
+
+   [1] http://archives.neohapsis.com/archives/bugtraq/2004-10/0299.html
+   [2] http://www.r1ch.net/stuff/r1q2/
+
+ -- Jamie Wilkinson <[EMAIL PROTECTED]>  Sun, 23 Jan 2005 12:31:57 +0100
diff -urN quake2-0.3/debian/quake2.6 quake2-0.3.n/debian/quake2.6
--- quake2-0.3/debian/quake2.6	2005-01-23 13:37:26.0 +0100
+++ quake2-0.3.n/debian/quake2.6	2005-01-23 13:27:38.0 +0100
@@ -12,6 +12,9 @@
 .br
 This manual page was written for the Debian GNU/Linux distribution
 because the original program does not have a manual page.
+.sp 1
+\fBWARNING:\fP The network part of Quake 2 has several unfixed security
+problems. You should not use Quake 2 in untrusted networks.
 .PP
 .\" TeX users may be more comfortable with the \fB\fP and
 .\" \fI\fP escape sequences to invode bold face and italics, 
@@ -63,6 +66,9 @@
 The model viewer in Multiplayer->player setup displays the skins incorrectly.
 .sp 1
 If you upgrade this package, your savegames will not work, due to the way savegames are made.
+.sp 1
+There are several unfixed security issues in the network code. Do not use in
+untrusted networks.
 .SH AUTHOR
 .B quake2
 was originally written by iD Software.
diff -urN quake2-0.3/debian/rules quake2-0.3.n/debian/rules
--- quake2-0.3/debian/rules	2005-01-23 13:37:26.0 +0100
+++ quake2-0.3.n/debian/rules	2005-01-23 13:27:38.0 +0100
@@ -58,6 +58,8 @@
 	$(MAKE) install DESTDIR=$(CURDIR)/debian/quake2
 	install -p -m 644 debian/quake2.xpm debian/quake2/usr/share/pixmaps/
 	install -p -m 644 debian/quake2ctf.xpm debian/quake2/usr/share/pixmaps/
+	mv debian/quake2/usr/games/quake2 debian/quake2/usr/games/quake2.real
+	install -p quake2.wrapper debian/quake2/usr/games/quake2
 
 # Build architecture-independent files here.
 # Pass -i to all debhelper commands in this target to reduce clutter.
diff -urN quake2-0.3/quake2.wrapper quake2-0.3.n/quake2.wrapper
--- quake2-0.3/quake2.wrapper	1970-01-01 01:00:00.0 +0100
+++ quake2-0.3.n/quake2.wrapper	2005-01-23 13:27:38.0 +0100
@@ -0,0 +1,10 @@
+#!/bin/bash
+cat <<_EOF_
+* WARNING *
+   The network part of Quake II (especially the server part) contains
+   several unfixed security issues. Therefore, Quake II should not be
+   used over untrusted networks (like the internet). The version
+   included in Debian is intended only for local play.   
+***
+_EOF_
+/usr/games/quake2.real "$@"


Bug#291355: marked as done (gaim-gnome: installation fails, depends on uninstalable libpanel-applet0)

2005-01-23 Thread Debian Bug Tracking System
Your message dated Sun, 23 Jan 2005 12:38:49 +
with message-id <[EMAIL PROTECTED]>
and subject line Bug#291355: Fwd: Re: Bug#291355: gaim-gnome: installation 
fails,depends on uninstalable libpanel-applet0
has caused the attached Bug report to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what I am
talking about this indicates a serious mail system misconfiguration
somewhere.  Please contact me immediately.)

Debian bug tracking system administrator
(administrator, Debian Bugs database)

--
Received: (at submit) by bugs.debian.org; 20 Jan 2005 09:04:29 +
>From [EMAIL PROTECTED] Thu Jan 20 01:04:29 2005
Return-path: <[EMAIL PROTECTED]>
Received: from mail.marquard.pl [62.29.141.5] 
by spohr.debian.org with smtp (Exim 3.35 1 (Debian))
id 1CrYEv-000247-00; Thu, 20 Jan 2005 01:04:29 -0800
Received: (qmail 19953 invoked from network); 20 Jan 2005 09:04:19 -
Received: from unknown (HELO localhost) (62.29.141.2)
  by mail.marquard.pl with SMTP; 20 Jan 2005 09:04:19 -
Received: from julian by localhost with local (Exim 4.43)
id 1CrYEm-000147-QS; Thu, 20 Jan 2005 10:04:20 +0100
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: julian kania <[EMAIL PROTECTED]>
To: Debian Bug Tracking System <[EMAIL PROTECTED]>
Subject: gaim-gnome: installation fails, depends on uninstalable 
libpanel-applet0
X-Mailer: reportbug 3.5
Date: Thu, 20 Jan 2005 10:04:20 +0100
Message-Id: <[EMAIL PROTECTED]>
Delivered-To: [EMAIL PROTECTED]
X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2005_01_02 
(1.212-2003-09-23-exp) on spohr.debian.org
X-Spam-Status: No, hits=-5.3 required=4.0 tests=BAYES_00,HAS_PACKAGE,
SUBJ_HAS_UNIQ_ID autolearn=no version=2.60-bugs.debian.org_2005_01_02
X-Spam-Level: 

Package: gaim-gnome
Version: 1:0.58-2.4
Severity: grave
Justification: renders package unusable


# LANG=en; apt-get install gaim-gnome
Reading Package Lists... Done
Building Dependency Tree... Done
Some packages could not be installed. This may mean that you have
requested an impossible situation or if you are using the unstable
distribution that some required packages have not yet been created
or been moved out of Incoming.

Since you only requested a single operation it is extremely likely that
the package is simply not installable and a bug report against
that package should be filed.
The following information may help to resolve the situation:

The following packages have unmet dependencies:
  gaim-gnome: Depends: libpanel-applet0 (>= 1.4.0.2-3) but it is not installable



-- System Information:
Debian Release: 3.1
  APT prefers unstable
  APT policy: (990, 'unstable')
Architecture: i386 (i686)
Kernel: Linux 2.6.6-1-686
Locale: LANG=pl_PL, LC_CTYPE=pl_PL (charmap=ISO-8859-2)

---
Received: (at 291355-done) by bugs.debian.org; 23 Jan 2005 12:38:41 +
>From [EMAIL PROTECTED] Sun Jan 23 04:38:41 2005
Return-path: <[EMAIL PROTECTED]>
Received: from ppsw-4.csi.cam.ac.uk [131.111.8.134] 
by spohr.debian.org with esmtp (Exim 3.35 1 (Debian))
id 1Csh0r-0004Wk-00; Sun, 23 Jan 2005 04:38:41 -0800
Received: from quadrant.corpus.cam.ac.uk ([131.111.235.202]:32896)
by ppsw-4.csi.cam.ac.uk (ppsw.cam.ac.uk [131.111.8.134]:25)
with esmtp id 1Csh0m-0006eL-Dh (Exim 4.44)
(return-path <[EMAIL PROTECTED]>); Sun, 23 Jan 2005 12:38:36 +
Message-ID: <[EMAIL PROTECTED]>
Date: Sun, 23 Jan 2005 12:38:49 +
From: Robert McQueen <[EMAIL PROTECTED]>
User-Agent: Debian Thunderbird 1.0 (X11/20050116)
X-Accept-Language: en-us, en
MIME-Version: 1.0
To: "Adam D. Barratt" <[EMAIL PROTECTED]>
CC: [EMAIL PROTECTED], Luke Schierer <[EMAIL PROTECTED]>, 
 julian <[EMAIL PROTECTED]>
Subject: Re: Bug#291355: Fwd: Re: Bug#291355: gaim-gnome: installation fails,
depends on uninstalable libpanel-applet0
References: <[EMAIL PROTECTED]> <[EMAIL PROTECTED]>
In-Reply-To: <[EMAIL PROTECTED]>
X-Enigmail-Version: 0.90.0.0
X-Enigmail-Supports: pgp-inline, pgp-mime
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
X-Cam-ScannerInfo: http://www.cam.ac.uk/cs/email/scanner/
X-Cam-AntiVirus: No virus found
X-Cam-SpamDetails: Not scanned
Delivered-To: [EMAIL PROTECTED]
X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2005_01_02 
(1.212-2003-09-23-exp) on spohr.debian.org
X-Spam-Status: No, hits=-2.1 required=4.0 tests=BAYES_00,FROM_ENDS_IN_NUMS,
HAS_BUG_NUMBER,SUBJ_HAS_UNIQ_ID autolearn=no 
version=2.60-bugs.debian.org_2005_01_02
X-Spam-Level: 

Adam D. Barratt wrote:
> Either the submitter has stable sources in their sources.list, or is using a
> very badly broken mirr

Bug#291718: marked as done (gforge: [security] GForge 3.x directory traversal vulnerability)

2005-01-23 Thread Debian Bug Tracking System
Your message dated Sun, 23 Jan 2005 07:47:07 -0500
with message-id <[EMAIL PROTECTED]>
and subject line Bug#291718: fixed in gforge 3.1-26
has caused the attached Bug report to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what I am
talking about this indicates a serious mail system misconfiguration
somewhere.  Please contact me immediately.)

Debian bug tracking system administrator
(administrator, Debian Bugs database)

--
Received: (at submit) by bugs.debian.org; 22 Jan 2005 17:52:30 +
>From [EMAIL PROTECTED] Sat Jan 22 09:52:29 2005
Return-path: <[EMAIL PROTECTED]>
Received: from c201166.ppp.asahi-net.or.jp (grapefruit) [210.155.201.166] 
by spohr.debian.org with esmtp (Exim 3.35 1 (Debian))
id 1CsPQz-0008WT-00; Sat, 22 Jan 2005 09:52:29 -0800
Received: by grapefruit (Postfix, from userid 1000)
id D6A80402F; Sun, 23 Jan 2005 02:56:08 +0900 (JST)
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: Hideki Yamane <[EMAIL PROTECTED]>
To: Debian Bug Tracking System <[EMAIL PROTECTED]>
Subject: gforge: [security] GForge 3.x directory traversal vulnerability
X-Mailer: reportbug 3.6
Date: Sun, 23 Jan 2005 02:56:07 +0900
Message-Id: <[EMAIL PROTECTED]>
Delivered-To: [EMAIL PROTECTED]
X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2005_01_02 
(1.212-2003-09-23-exp) on spohr.debian.org
X-Spam-Status: No, hits=-8.0 required=4.0 tests=BAYES_00,HAS_PACKAGE 
autolearn=no version=2.60-bugs.debian.org_2005_01_02
X-Spam-Level: 

Package: gforge
Severity: grave
Tags: security
Justification: user security hole

-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

Dear gforge maintainer,

 GForge 3.x has directory traversal vulnerabilities because of lack
 about sanitisation in some scripts.

 You can see detail about vulnerability with PoC and workaround
 in this advisory 
 http://www.securityfocus.com/archive/1/387850/2005-01-19/2005-01-25/0


- --
Regards,

 Hideki Yamane henrich @ samba.gr.jp/iijmio-mail.jp


-BEGIN PGP SIGNATURE-
Version: GnuPG v1.2.5 (GNU/Linux)

iD8DBQFB8pO2Iu0hy8THJksRAhE8AJ4gntmdUoj0zApRAK6YfGvhsx7UtgCfXutm
xg2AiEbs1UB7saoWJlNdBgA=
=yAVX
-END PGP SIGNATURE-

---
Received: (at 291718-close) by bugs.debian.org; 23 Jan 2005 12:53:05 +
>From [EMAIL PROTECTED] Sun Jan 23 04:53:05 2005
Return-path: <[EMAIL PROTECTED]>
Received: from newraff.debian.org [208.185.25.31] (mail)
by spohr.debian.org with esmtp (Exim 3.35 1 (Debian))
id 1CshEn-0006a6-00; Sun, 23 Jan 2005 04:53:05 -0800
Received: from katie by newraff.debian.org with local (Exim 3.35 1 (Debian))
id 1Csh91-0004Xw-00; Sun, 23 Jan 2005 07:47:07 -0500
From: Roland Mas <[EMAIL PROTECTED]>
To: [EMAIL PROTECTED]
X-Katie: $Revision: 1.55 $
Subject: Bug#291718: fixed in gforge 3.1-26
Message-Id: <[EMAIL PROTECTED]>
Sender: Archive Administrator <[EMAIL PROTECTED]>
Date: Sun, 23 Jan 2005 07:47:07 -0500
Delivered-To: [EMAIL PROTECTED]
X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2005_01_02 
(1.212-2003-09-23-exp) on spohr.debian.org
X-Spam-Status: No, hits=-6.0 required=4.0 tests=BAYES_00,HAS_BUG_NUMBER 
autolearn=no version=2.60-bugs.debian.org_2005_01_02
X-Spam-Level: 

Source: gforge
Source-Version: 3.1-26

We believe that the bug you reported is fixed in the latest version of
gforge, which is due to be installed in the Debian FTP archive:

gforge-common_3.1-26_all.deb
  to pool/main/g/gforge/gforge-common_3.1-26_all.deb
gforge-cvs_3.1-26_all.deb
  to pool/main/g/gforge/gforge-cvs_3.1-26_all.deb
gforge-db-postgresql_3.1-26_all.deb
  to pool/main/g/gforge/gforge-db-postgresql_3.1-26_all.deb
gforge-dns-bind9_3.1-26_all.deb
  to pool/main/g/gforge/gforge-dns-bind9_3.1-26_all.deb
gforge-ftp-proftpd_3.1-26_all.deb
  to pool/main/g/gforge/gforge-ftp-proftpd_3.1-26_all.deb
gforge-ldap-openldap_3.1-26_all.deb
  to pool/main/g/gforge/gforge-ldap-openldap_3.1-26_all.deb
gforge-lists-mailman_3.1-26_all.deb
  to pool/main/g/gforge/gforge-lists-mailman_3.1-26_all.deb
gforge-mta-exim4_3.1-26_all.deb
  to pool/main/g/gforge/gforge-mta-exim4_3.1-26_all.deb
gforge-mta-exim_3.1-26_all.deb
  to pool/main/g/gforge/gforge-mta-exim_3.1-26_all.deb
gforge-mta-postfix_3.1-26_all.deb
  to pool/main/g/gforge/gforge-mta-postfix_3.1-26_all.deb
gforge-shell-ldap_3.1-26_all.deb
  to pool/main/g/gforge/gforge-shell-ldap_3.1-26_all.deb
gforge-sourceforge-transition_3.1-26_all.deb
  to pool/main/g/gforge/gforge-sourceforge-transition_3.1-26_all.deb
gforge-web-apache_3.1-26_all.deb
  to pool/main/g/gforge/gforge-web-apache_3.1-26_all.deb
gforge_3.1-26.diff.gz
  to pool/main/g/gforge/gforge_3.1-26.diff.gz
gforge_3.1-26.dsc
  to

Processed: Re: Bug#287107: kfish: query over licensing of fish images

2005-01-23 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]:

> tags 287107 +pending
Bug#287107: kfish:  query over licensing of fish images
Tags were: unreproducible
Tags added: pending

> Thanks Mate :)
Stopping processing here.

Please contact me if you need assistance.

Debian bug tracking system administrator
(administrator, Debian Bugs database)


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]



Bug#287107: kfish: query over licensing of fish images

2005-01-23 Thread Helen Faulkner
tags 287107 +pending
Thanks Mate :)
I have repackaged kfish, naming the correct author for the one 
problematic image that does turn out to be DFSG-free, and substituting 
the other images with DFSG-free ones (from kaquarium).

The new version will be uploaded when my sponsor is able to do that.
Thanks,
Helen Faulkner
--
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]


Bug#291254: Doesn't work with the latest kernel-source-2.6.8

2005-01-23 Thread Aurelien Jarno
On Fri, Jan 21, 2005 at 03:02:07AM -0500, Kyle McMartin wrote:
> Thanks, I've already fixed this in my working tree, but I've been working
> fairly heavily with Bdale and others to make sure the next upload works
> well for everyone, so I've not yet uploaded it yet.
> 
> I expect to have fixed things up in a short while.
> 
> If you're really desperate for punishment, you can fetch the latest
> debs from http://parisc-linux.org/~kyle/debian-kernel/2005-01-18/.

I have just tested them, they works well. Thanks!

Bye,
Aurélien

-- 
  .''`.  Aurelien Jarno   GPG: 1024D/F1BCDB73
 : :' :  Debian GNU/Linux developer | Electrical Engineer
 `. `'   [EMAIL PROTECTED] | [EMAIL PROTECTED]
   `-people.debian.org/~aurel32 | www.aurel32.net


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]



Processed: Re: Bug#290811: I can reproduce it now

2005-01-23 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]:

> Reassign 290811 libglade2-0
Bug#290811: meld crashes on start
Bug reassigned from package `meld' to `libglade2-0'.

> Retitle 290811 Upgrading to 2.4.1-1 version causes meld to crash.
Bug#290811: meld crashes on start
Changed Bug title.

> thanks
Stopping processing here.

Please contact me if you need assistance.

Debian bug tracking system administrator
(administrator, Debian Bugs database)


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]



Bug#290811: I can reproduce it now

2005-01-23 Thread Margarita Manterola
Reassign 290811 libglade2-0
Retitle 290811 Upgrading to 2.4.1-1 version causes meld to crash.
thanks

Hola Bas Zoetekouw!

> > The dependency tree is:
> > meld depends on python-gtk2, which depends on python2.3-gtk2 which depends
> > on " libgtk2.0-0 (>= 2.4.4) ".  libgtk2.0-0 is presently at 2.4.14, I'm
> > guessing that Bas might have a version that is in the middle of the two,
> > and that for some reason has this "non-deprecated vs deprecated" issue.
> Nopes, this is an up-to-date sid system, with the latest gnome and gtk
> libraries.

Ok, based on this information, I kept investigating and found out that
after upgrading libglade2-0 to version 2.4.1-1, I can reproduce the bug,
though with the previous version (2.4.0-1) it did not occur.

Thus, I'm reassigning this bug to libglade.  I'll keep working on this,
hoping to find a solution.

-- 
 Bezos, (o.
 Marga. (/)_


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]



Bug#291827: /usr/share/doc/gaim is empty

2005-01-23 Thread Angel Abad (Indio)
Package: gaim
Version: 1:1.1.2-1
Severity: serious
Justification: 12


The /usr/share/doc/gaim directory is empty, please fill it, show:

# dpkg -L gaim
/.
/usr
/usr/lib
/usr/lib/menu
/usr/lib/menu/gaim
/usr/lib/gaim
/usr/lib/gaim/autorecon.so
/usr/lib/gaim/docklet.so
/usr/lib/gaim/extplacement.so
/usr/lib/gaim/gaim-remote.so
/usr/lib/gaim/gestures.so
/usr/lib/gaim/gevolution.so
/usr/lib/gaim/history.so
/usr/lib/gaim/iconaway.so
/usr/lib/gaim/idle.so
/usr/lib/gaim/libgg.so
/usr/lib/gaim/libirc.so
/usr/lib/gaim/libjabber.so
/usr/lib/gaim/libmsn.so
/usr/lib/gaim/libnapster.so
/usr/lib/gaim/libnovell.so
/usr/lib/gaim/liboscar.so
/usr/lib/gaim/libyahoo.so
/usr/lib/gaim/libzephyr.so
/usr/lib/gaim/notify.so
/usr/lib/gaim/relnot.so
/usr/lib/gaim/spellchk.so
/usr/lib/gaim/ssl-gnutls.so
/usr/lib/gaim/ssl-nss.so
/usr/lib/gaim/ssl.so
/usr/lib/gaim/statenotify.so
/usr/lib/gaim/tcl.so
/usr/lib/gaim/ticker.so
/usr/lib/gaim/timestamp.so
/usr/lib/libgaim-remote.so.0.0.0
/usr/bin
/usr/bin/gaim
/usr/bin/gaim-remote
/usr/share
/usr/share/doc
/usr/lib/libgaim-remote.so.0
/usr/share/doc/gaim

Bye,

-- System Information:
Debian Release: 3.1
  APT prefers unstable
  APT policy: (500, 'unstable')
Architecture: i386 (i686)
Kernel: Linux 2.6.10
Locale: [EMAIL PROTECTED], [EMAIL PROTECTED] (charmap=ISO-8859-15)

Versions of packages gaim depends on:
ii  gaim-data1:1.1.2-1   multi-protocol instant messaging c
ii  libao2   0.8.5-1 Cross Platform Audio Output Librar
ii  libaspell15  0.50.5-5The GNU Aspell spell-checker runti
ii  libatk1.0-0  1.8.0-4 The ATK accessibility toolkit
ii  libaudiofile00.2.6-5 Open-source version of SGI's audio
ii  libc62.3.2.ds1-20GNU C Library: Shared libraries an
ii  libgcrypt11  1.2.0-11LGPL Crypto library - runtime libr
ii  libglib2.0-0 2.6.1-2 The GLib library of C routines
ii  libgnutls11  1.0.16-13   GNU TLS library - runtime library
ii  libgtk2.0-0  2.4.14-2The GTK+ graphical user interface 
ii  libgtkspell0 2.0.8-1 a spell-checking addon for GTK's T
ii  libice6  4.3.0.dfsg.1-10 Inter-Client Exchange library
ii  libpango1.0-01.6.0-3 Layout and rendering of internatio
ii  libsm6   4.3.0.dfsg.1-10 X Window System Session Management
ii  libstartup-notification0 0.7-1   library for program launch feedbac
ii  libx11-6 4.3.0.dfsg.1-10 X Window System protocol client li
ii  libxext6 4.3.0.dfsg.1-10 X Window System miscellaneous exte
ii  xlibs4.3.0.dfsg.1-10 X Keyboard Extension (XKB) configu

-- no debconf information



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]



Bug#291827: /usr/share/doc/gaim is empty

2005-01-23 Thread Robert McQueen
Angel Abad (Indio) wrote:
The /usr/share/doc/gaim directory is empty, please fill it, show:
# dpkg -L gaim
/usr/share/doc/gaim
This is correct, the package contains a symlink from gaim to gaim-data. 
The error is that I forgot that dpkg won't replace a symlink with a 
directory, or vice versa, because of undefined behaviour when the 
directory has contents. I've added a preinst that rmdir's the 
/usr/share/doc/gaim directory, and will upload now.

Bye,
Regards,
Rob
--
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]


Bug#291782: marked as done (bible-kjv_4.17(hppa/unstable): FTBFS: compile errors (implicit definition))

2005-01-23 Thread Debian Bug Tracking System
Your message dated Sun, 23 Jan 2005 09:47:02 -0500
with message-id <[EMAIL PROTECTED]>
and subject line Bug#291782: fixed in bible-kjv 4.18
has caused the attached Bug report to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what I am
talking about this indicates a serious mail system misconfiguration
somewhere.  Please contact me immediately.)

Debian bug tracking system administrator
(administrator, Debian Bugs database)

--
Received: (at submit) by bugs.debian.org; 23 Jan 2005 05:43:13 +
>From [EMAIL PROTECTED] Sat Jan 22 21:43:13 2005
Return-path: <[EMAIL PROTECTED]>
Received: from mmjgroup.com [192.34.35.33] 
by spohr.debian.org with esmtp (Exim 3.35 1 (Debian))
id 1CsaWn-Lt-00; Sat, 22 Jan 2005 21:43:13 -0800
Received: from mix.mmjgroup.com (mix.mmjgroup.com [192.34.35.16])
by mmjgroup.com (Postfix) with ESMTP id DEA1316DE8
for <[EMAIL PROTECTED]>; Sat, 22 Jan 2005 22:43:12 -0700 (MST)
Received: by mix.mmjgroup.com (Postfix, from userid 1000)
id EFEBE8F31F; Sat, 22 Jan 2005 22:43:13 -0700 (MST)
Date: Sat, 22 Jan 2005 22:43:13 -0700
From: [EMAIL PROTECTED]
To: [EMAIL PROTECTED]
Subject: bible-kjv_4.17(hppa/unstable): FTBFS: compile errors (implicit 
definition)
Message-ID: <[EMAIL PROTECTED]>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
User-Agent: Mutt/1.5.6+20040907i
Delivered-To: [EMAIL PROTECTED]
X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2005_01_02 
(1.212-2003-09-23-exp) on spohr.debian.org
X-Spam-Status: No, hits=-6.4 required=4.0 tests=BAYES_00,HAS_PACKAGE,
NO_REAL_NAME autolearn=no version=2.60-bugs.debian.org_2005_01_02
X-Spam-Level: 

Package: bible-kjv
Version: 4.17
Severity: serious

There was an error while trying to autobuild your package:

> Automatic build of bible-kjv_4.17 on sarti by sbuild/hppa 1.170.5
> Build started at 20050123-0028

[...]

> ** Using build dependencies supplied by package:
> Build-Depends: libreadline4-dev

[...]

> rm -rf debian/tmp debian/files* bible debian/bible-kjv-text \
>   debian/randverse debian/substvars randverse
>  debian/rules build
> test -f bible.c -a -f debian/rules
> /usr/bin/make all
> make[1]: Entering directory `/build/buildd/bible-kjv-4.17'
> cc -Wall -Wformat -Werror -Wshadow -W -Wmissing-declarations 
> -Wmissing-prototypes -Wstrict-prototypes -Wcast-align -Wcast-qual 
> -Wbad-function-cast -Wpointer-arith -g2 -ggdb -DDESTLIB=\"/usr/lib\"   -c -o 
> bible.o bible.c
> ./makeindex2 bible.rawtext
> cc -Wall -Wformat -Werror -Wshadow -W -Wmissing-declarations 
> -Wmissing-prototypes -Wstrict-prototypes -Wcast-align -Wcast-qual 
> -Wbad-function-cast -Wpointer-arith -g2 -ggdb -DDESTLIB=\"/usr/lib\"   -c -o 
> brl-index.o brl-index.c
> cc -Wall -Wformat -Werror -Wshadow -W -Wmissing-declarations 
> -Wmissing-prototypes -Wstrict-prototypes -Wcast-align -Wcast-qual 
> -Wbad-function-cast -Wpointer-arith -g2 -ggdb -DDESTLIB=\"/usr/lib\"   -c -o 
> brl.o brl.c
> brl.c: In function `get_book':
> brl.c:585: warning: implicit declaration of function `exit'
> make[1]: *** [brl.o] Error 1
> make[1]: Leaving directory `/build/buildd/bible-kjv-4.17'
> make: *** [build] Error 2

A full build log can be found at:
http://buildd.debian.org/build.php?arch=hppa&pkg=bible-kjv&ver=4.17


---
Received: (at 291782-close) by bugs.debian.org; 23 Jan 2005 14:53:08 +
>From [EMAIL PROTECTED] Sun Jan 23 06:53:08 2005
Return-path: <[EMAIL PROTECTED]>
Received: from newraff.debian.org [208.185.25.31] (mail)
by spohr.debian.org with esmtp (Exim 3.35 1 (Debian))
id 1Csj6y-0002Rt-00; Sun, 23 Jan 2005 06:53:08 -0800
Received: from katie by newraff.debian.org with local (Exim 3.35 1 (Debian))
id 1Csj14-0007tE-00; Sun, 23 Jan 2005 09:47:02 -0500
From: Matthew Vernon <[EMAIL PROTECTED]>
To: [EMAIL PROTECTED]
X-Katie: $Revision: 1.55 $
Subject: Bug#291782: fixed in bible-kjv 4.18
Message-Id: <[EMAIL PROTECTED]>
Sender: Archive Administrator <[EMAIL PROTECTED]>
Date: Sun, 23 Jan 2005 09:47:02 -0500
Delivered-To: [EMAIL PROTECTED]
X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2005_01_02 
(1.212-2003-09-23-exp) on spohr.debian.org
X-Spam-Status: No, hits=-6.0 required=4.0 tests=BAYES_00,HAS_BUG_NUMBER 
autolearn=no version=2.60-bugs.debian.org_2005_01_02
X-Spam-Level: 

Source: bible-kjv
Source-Version: 4.18

We believe that the bug you reported is fixed in the latest version of
bible-kjv, which is due to be installed in the

Bug#289865: libmd5-perl fails to build on arm processor

2005-01-23 Thread Steve Langasek
Hi Jay,

> Is this bug safe to reassign / kill?

I think you're safe to kill it, yes, unless there's evidence that
Digest::MD5 is universally broken on arm.  That seems unlikely to me, as I
would expect that module to be exercised in the building of other packages,
if nothing else.  (I know there are a number of tests as part of the perl
package's own testsuite.)

Cheers,
-- 
Steve Langasek
postmodern programmer


signature.asc
Description: Digital signature


Bug#291380: marked as done ([msutton@iDefense.com: iDEFENSE Security Advisory 01.19.05: MySQL MaxDB Web Agent Multiple Denial of Service Vulnerabilities])

2005-01-23 Thread Debian Bug Tracking System
Your message dated Sun, 23 Jan 2005 07:12:21 -0800
with message-id <[EMAIL PROTECTED]>
and subject line [EMAIL PROTECTED]: iDEFENSE Security Advisory 01.19.05: MySQL 
MaxDB Web Agent Multiple Denial of Service Vulnerabilities]
has caused the attached Bug report to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what I am
talking about this indicates a serious mail system misconfiguration
somewhere.  Please contact me immediately.)

Debian bug tracking system administrator
(administrator, Debian Bugs database)

--
Received: (at submit) by bugs.debian.org; 20 Jan 2005 12:07:32 +
>From [EMAIL PROTECTED] Thu Jan 20 04:07:32 2005
Return-path: <[EMAIL PROTECTED]>
Received: from luonnotar.infodrom.org [195.124.48.78] 
by spohr.debian.org with esmtp (Exim 3.35 1 (Debian))
id 1Crb64-0001oX-00; Thu, 20 Jan 2005 04:07:32 -0800
Received: by luonnotar.infodrom.org (Postfix, from userid 10)
id 98BC3366B7F; Thu, 20 Jan 2005 13:07:34 +0100 (CET)
Received: at Infodrom Oldenburg (/\##/\ Smail-3.2.0.102 1998-Aug-2 #2)
from infodrom.org by finlandia.Infodrom.North.DE
via smail from stdin
id <[EMAIL PROTECTED]>
for [EMAIL PROTECTED]; Thu, 20 Jan 2005 13:01:19 +0100 (CET) 
Date: Thu, 20 Jan 2005 13:01:19 +0100
From: Martin Schulze <[EMAIL PROTECTED]>
To: [EMAIL PROTECTED]
Subject: [EMAIL PROTECTED]: iDEFENSE Security Advisory 01.19.05: MySQL MaxDB 
Web Agent Multiple Denial of Service Vulnerabilities]
Message-ID: <[EMAIL PROTECTED]>
Mime-Version: 1.0
Content-Type: text/plain; charset=iso-8859-1
Content-Disposition: inline
User-Agent: Mutt/1.5.6+20040907i
Delivered-To: [EMAIL PROTECTED]
X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2005_01_02 
(1.212-2003-09-23-exp) on spohr.debian.org
X-Spam-Status: No, hits=-5.0 required=4.0 tests=HAS_PACKAGE autolearn=no 
version=2.60-bugs.debian.org_2005_01_02
X-Spam-Level: 

Package: maxdb
Severity: grave
Tags: sarge security
# sid is already fixed, so this is a reminder.

Two CVE ids have been assigned to this advisory:


Candidate: CAN-2005-0081
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0081

Reference: IDEFENSE:20050119 MySQL MaxDB Web Agent Multiple Denial of Service 
Vulnerabilities
Reference: 
URL:http://www.idefense.com/application/poi/display?id=187&type=vulnerabilities

MySQL MaxDB 7.5.0.0, and other versions before 7.5.0.21, allows remote
attackers to cause a denial of service (crash) via an HTTP request
with invalid headers.


Candidate: CAN-2005-0082
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0082

Reference: IDEFENSE:20050119 MySQL MaxDB Web Agent Multiple Denial of Service 
Vulnerabilities
Reference: 
URL:http://www.idefense.com/application/poi/display?id=187&type=vulnerabilities

The sapdbwa_GetUserData function in MySQL MaxDB 7.5.0.0, and other
versions before 7.5.0.21, allows remote attackers to cause a denial of
service (crash) via invalid parameters to the WebDAV handler code,
which triggers a null dereference that causes the SAP DB Web Agent to
crash.

Please mention them in the changelog (or add them to the changelog
later with your next upload).

Regards,

Joey


- Forwarded message from Michael Sutton <[EMAIL PROTECTED]> -

Subject: iDEFENSE Security Advisory 01.19.05: MySQL MaxDB Web Agent Multiple 
Denial of Service Vulnerabilities
Date: Wed, 19 Jan 2005 16:03:46 -0500
From: Michael Sutton <[EMAIL PROTECTED]>
To: bugtraq@securityfocus.com, [EMAIL PROTECTED]
X-Folder: [EMAIL PROTECTED]

MySQL MaxDB Web Agent Multiple Denial of Service Vulnerabilities

iDEFENSE Security Advisory 01.19.05
www.idefense.com/application/poi/display?id=187&type=vulnerabilities
January 19, 2005

I. BACKGROUND

MaxDB by MySQL is a re-branded and enhanced version of SAP DB, SAP AG's
open source database. MaxDB is a heavy-duty, SAP-certified open source
database that offers high availability, scalability and a comprehensive
feature set. MaxDB complements the MySQL database server, targeted for
large mySAP ERP environments and other applications that require maximum
enterprise-level database functionality. Further details are available
at:

   http://www.mysql.com/products/maxdb/

II. DESCRIPTION

Two remotely exploitable denial of service conditions have been found to
exist in MySQL MaxDB and SAP DB Web Agent products.

The first vulnerability specifically exists due to a null pointer
dereference in the sapdbwa_GetUserData() function. A remote attacker can
request the webdav handler code with invalid parameters to cause a null
pointer dereference resulting in a crash of SAP DB Web Agent.

The second vulnerability is due to insufficient handling of malformed
HTTP headers. A remote attacker can submit a HTTP

Bug#291827: /usr/share/doc/gaim is empty

2005-01-23 Thread Angel Abad (Ikusnet SLL)
Thank you for a rapid solution.

Bye.

Angel Abad (Ikusnet SLL)
[EMAIL PROTECTED]

Mil maneras de sentir y una de decir que no!



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]



Bug#289646: kbabel: crash with some .po file

2005-01-23 Thread Frans Pop
I've also been having crashes using kbabel in Sarge (see #289646). I've 
had crashes with several po files now.

The behavior is somewhat eratic: when I first had the crash, I could 
always reproduce it, now I find that sometimes the crash does not happen.
Very likely my crashes are related to this BR.

The tag 'sid' for this bug is probably _not_ correct!

||/ Name  Version
+++-=-===
ii  kbabel3.3.1-2
ii  kdelibs   3.3.1-4
ii  kdelibs4  3.3.1-4


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]



Bug#291827: marked as done (/usr/share/doc/gaim is empty)

2005-01-23 Thread Debian Bug Tracking System
Your message dated Sun, 23 Jan 2005 10:17:05 -0500
with message-id <[EMAIL PROTECTED]>
and subject line Bug#291827: fixed in gaim 1:1.1.2-2
has caused the attached Bug report to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what I am
talking about this indicates a serious mail system misconfiguration
somewhere.  Please contact me immediately.)

Debian bug tracking system administrator
(administrator, Debian Bugs database)

--
Received: (at submit) by bugs.debian.org; 23 Jan 2005 13:50:13 +
>From [EMAIL PROTECTED] Sun Jan 23 05:50:05 2005
Return-path: <[EMAIL PROTECTED]>
Received: from (mail.pastelero.net) [217.76.134.161] 
by spohr.debian.org with esmtp (Exim 3.35 1 (Debian))
id 1Csi7v-0006Po-00; Sun, 23 Jan 2005 05:50:03 -0800
Received: from mail.pastelero.net (localhost [127.0.0.1])
by mail.pastelero.net (Postfix) with ESMTP id 6FA0D1A0007;
Sun, 23 Jan 2005 15:33:52 +0100 (CET)
Received: from goa.atxeta (173.Red-213-98-156.pooles.rima-tde.net 
[213.98.156.173])
by mail.pastelero.net (Postfix) with ESMTP id E0B2B1A0003;
Sun, 23 Jan 2005 15:33:51 +0100 (CET)
Received: by goa.atxeta (Postfix, from userid 1000)
id A06BF4BF3E; Sun, 23 Jan 2005 14:49:18 +0100 (CET)
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: "Angel Abad (Indio)" <[EMAIL PROTECTED]>
To: Debian Bug Tracking System <[EMAIL PROTECTED]>
Subject: /usr/share/doc/gaim is empty
X-Mailer: reportbug 3.6
Date: Sun, 23 Jan 2005 14:49:18 +0100
Message-Id: <[EMAIL PROTECTED]>
X-Virus-Scanned: ClamAV using ClamSMTP
Delivered-To: [EMAIL PROTECTED]
X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2005_01_02 
(1.212-2003-09-23-exp) on spohr.debian.org
X-Spam-Status: No, hits=-8.0 required=4.0 tests=BAYES_00,HAS_PACKAGE 
autolearn=no version=2.60-bugs.debian.org_2005_01_02
X-Spam-Level: 

Package: gaim
Version: 1:1.1.2-1
Severity: serious
Justification: 12


The /usr/share/doc/gaim directory is empty, please fill it, show:

# dpkg -L gaim
/.
/usr
/usr/lib
/usr/lib/menu
/usr/lib/menu/gaim
/usr/lib/gaim
/usr/lib/gaim/autorecon.so
/usr/lib/gaim/docklet.so
/usr/lib/gaim/extplacement.so
/usr/lib/gaim/gaim-remote.so
/usr/lib/gaim/gestures.so
/usr/lib/gaim/gevolution.so
/usr/lib/gaim/history.so
/usr/lib/gaim/iconaway.so
/usr/lib/gaim/idle.so
/usr/lib/gaim/libgg.so
/usr/lib/gaim/libirc.so
/usr/lib/gaim/libjabber.so
/usr/lib/gaim/libmsn.so
/usr/lib/gaim/libnapster.so
/usr/lib/gaim/libnovell.so
/usr/lib/gaim/liboscar.so
/usr/lib/gaim/libyahoo.so
/usr/lib/gaim/libzephyr.so
/usr/lib/gaim/notify.so
/usr/lib/gaim/relnot.so
/usr/lib/gaim/spellchk.so
/usr/lib/gaim/ssl-gnutls.so
/usr/lib/gaim/ssl-nss.so
/usr/lib/gaim/ssl.so
/usr/lib/gaim/statenotify.so
/usr/lib/gaim/tcl.so
/usr/lib/gaim/ticker.so
/usr/lib/gaim/timestamp.so
/usr/lib/libgaim-remote.so.0.0.0
/usr/bin
/usr/bin/gaim
/usr/bin/gaim-remote
/usr/share
/usr/share/doc
/usr/lib/libgaim-remote.so.0
/usr/share/doc/gaim

Bye,

-- System Information:
Debian Release: 3.1
  APT prefers unstable
  APT policy: (500, 'unstable')
Architecture: i386 (i686)
Kernel: Linux 2.6.10
Locale: [EMAIL PROTECTED], [EMAIL PROTECTED] (charmap=ISO-8859-15)

Versions of packages gaim depends on:
ii  gaim-data1:1.1.2-1   multi-protocol instant messaging c
ii  libao2   0.8.5-1 Cross Platform Audio Output Librar
ii  libaspell15  0.50.5-5The GNU Aspell spell-checker runti
ii  libatk1.0-0  1.8.0-4 The ATK accessibility toolkit
ii  libaudiofile00.2.6-5 Open-source version of SGI's audio
ii  libc62.3.2.ds1-20GNU C Library: Shared libraries an
ii  libgcrypt11  1.2.0-11LGPL Crypto library - runtime libr
ii  libglib2.0-0 2.6.1-2 The GLib library of C routines
ii  libgnutls11  1.0.16-13   GNU TLS library - runtime library
ii  libgtk2.0-0  2.4.14-2The GTK+ graphical user interface 
ii  libgtkspell0 2.0.8-1 a spell-checking addon for GTK's T
ii  libice6  4.3.0.dfsg.1-10 Inter-Client Exchange library
ii  libpango1.0-01.6.0-3 Layout and rendering of internatio
ii  libsm6   4.3.0.dfsg.1-10 X Window System Session Management
ii  libstartup-notification0 0.7-1   library for program launch feedbac
ii  libx11-6 4.3.0.dfsg.1-10 X Window System protocol client li
ii  libxext6 4.3.0.dfsg.1-10 X Window System miscellaneous exte
ii  xlibs4.3.0.dfsg.1-10 X Keyboard Extension (XKB) configu

-- no debconf information


-

Processed: Patch that fixes the problem in libglade

2005-01-23 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]:

> Merge 288445 287167 290811
Bug#287167: libglade errors on startup
Bug#288445: libglade2-0 upgrade breaks synaptic toolbar
Mismatch - only Bugs in same state can be merged:
Values for `package' don't match:
 #287167 has `meld';
 #288445 has `synaptic'
Values for `forwarded addr' don't match:
 #287167 has `http://bugzilla.gnome.org/show_bug.cgi?id=163322';
 #288445 has `'
Values for `severity' don't match:
 #287167 has `grave';
 #288445 has `important'

> Tags 290811 +patch
Bug#290811: Upgrading to 2.4.1-1 version causes meld to crash.
There were no tags set.
Tags added: patch

> thanks
Stopping processing here.

Please contact me if you need assistance.

Debian bug tracking system administrator
(administrator, Debian Bugs database)


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]



Bug#287167: Patch that fixes the problem in libglade

2005-01-23 Thread Margarita Manterola
Merge 288445 287167 290811
Tags 290811 +patch
thanks

I'm attaching a patch that fixes these bugs.

They were all the same bug: libglade2 made an important update in the code
of glade-gtk.c that started using the new toolbar api.  This change
rendered programs that used both glade and the toolbar api directly
unusable.

Upstream report: http://bugzilla.gnome.org/show_bug.cgi?id=163322

The patch I'm attaching was made with interdiff. It is indended to make the
less damage possible.  I only regressed those changes that affected the way
meld and synaptic behaved (I don't know if there are other programs
affected by this bug).

With these changes, the two programs behave properly, almost no warnings
issued on the console. I hope you find this patch worthy of applying.

-- 
 Bezitos,
 Maggie.
diff -u libglade2-2.4.1/debian/changelog libglade2-2.4.1/debian/changelog
--- libglade2-2.4.1/debian/changelog
+++ libglade2-2.4.1/debian/changelog
@@ -1,3 +1,9 @@
+libglade2 (1:2.4.1-1.1) unstable; urgency=low
+
+  * Undo the update of the API, so that synaptic and meld keep working.
+
+ -- Margarita Manterola <[EMAIL PROTECTED]>  Sun, 23 Jan 2005 11:49:01 -0300
+
 libglade2 (1:2.4.1-1) unstable; urgency=low
 
   * GNOME team upload.
only in patch2:
unchanged:
--- libglade2-2.4.1.orig/glade/glade-gtk.c
+++ libglade2-2.4.1/glade/glade-gtk.c
@@ -868,71 +868,46 @@
if (iconw)
gtk_widget_show (iconw);
 
-   if (new_group) {
-   GtkWidget *toolitem = GTK_WIDGET (gtk_tool_item_new ());
-
-   gtk_container_add (GTK_CONTAINER (parent), toolitem);
-   gtk_widget_show (toolitem);
-   }
+   if (new_group)
+   gtk_toolbar_append_space (GTK_TOOLBAR (parent));
 
/* FIXME: these should be translated */
if (!strcmp (childinfo->child->classname, "toggle")) {
-   child = g_object_new (GTK_TYPE_TOGGLE_TOOL_BUTTON,
- "label", label,
- "stock_id", stock,
- NULL);
-   gtk_toggle_tool_button_set_active
-   (GTK_TOGGLE_TOOL_BUTTON (child), active);
+   child = gtk_toolbar_append_element (
+   GTK_TOOLBAR (parent),
+   GTK_TOOLBAR_CHILD_TOGGLEBUTTON, NULL,
+   label, tooltip, NULL, iconw, NULL, NULL);
+   gtk_toggle_button_set_active(
+   GTK_TOGGLE_BUTTON (child), active);
} else if (!strcmp (childinfo->child->classname, "radio")) {
-   child = g_object_new (GTK_TYPE_RADIO_TOOL_BUTTON,
- "label", label,
- "stock_id", stock,
- NULL);
+   child = gtk_toolbar_append_element (
+   GTK_TOOLBAR (parent),
+   GTK_TOOLBAR_CHILD_RADIOBUTTON, NULL,
+   label, tooltip, NULL, iconw, NULL, NULL);
+
if (group_name) {
g_object_set (G_OBJECT (child),
  "group", glade_xml_get_widget (xml, 
group_name),
  NULL);
}
-   gtk_toggle_tool_button_set_active
-   (GTK_TOGGLE_TOOL_BUTTON (child), active);
-   } else {
-   child = g_object_new (GTK_TYPE_TOOL_BUTTON,
- "label", label,
- "stock_id", stock,
- NULL);
-   }
-   if (iconw)
-   gtk_tool_button_set_icon_widget (GTK_TOOL_BUTTON (child),
-iconw);
+   } else
+   child = gtk_toolbar_append_item (
+   GTK_TOOLBAR (parent),
+   label, tooltip, NULL, iconw, NULL, NULL);

/* GTK+ doesn't support use_underline directly, so we have to hack
   it. */
if (use_underline) {
-   GtkWidget *labelw = gtk_tool_button_get_label_widget 
(GTK_TOOL_BUTTON (child));
-   gtk_label_set_use_underline (GTK_LABEL (labelw), TRUE);
+   GList *elem = g_list_last (GTK_TOOLBAR (parent)->children);
+   GtkToolbarChild *toolbar_child = elem->data;
+   gtk_label_set_use_underline (GTK_LABEL (toolbar_child->label),
+TRUE);
}
 
-   if (tooltip) {
-   gtk_tool_item_set_tooltip (GTK_TOOL_ITEM (child),
-  xml->priv->tooltips,
-  tooltip, NULL);
-   
-   }
-
-   gtk_container_add (GTK_CONTAINER (parent), child);
-
glade_xml_set_common_params (xml, child, childinfo->child);
} else {
child = glade_xml_

Processed: Re: Bug#289646: kbabel: crash with some .po file

2005-01-23 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]:

> tag 289646 - sid
Bug#289646: kbabel: crash with some .po file
Tags were: sid
Tags removed: sid

> thanks dude
Stopping processing here.

Please contact me if you need assistance.

Debian bug tracking system administrator
(administrator, Debian Bugs database)


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]



Bug#289646: kbabel: crash with some .po file

2005-01-23 Thread Adeodato Simó
tag 289646 - sid
thanks dude

> The tag 'sid' for this bug is probably _not_ correct!

  Yeah, I forgot to remove it after Riku's mail. In the future, please
  feel free to do control@ handling yourself when you're confident :-)
  (At least in KDE land.)

  Cheers (and congrats for your AM ;-),

-- 
Adeodato Simó
EM: asp16 [ykwim] alu.ua.es | PK: DA6AE621
 
The pure and simple truth is rarely pure and never simple.
-- Oscar Wilde



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]



Bug#281655: info2www: Cross-site scripting vulnerability

2005-01-23 Thread Uwe Hermann
Hi,

sorry, the mail about this bug somehow got lost in my inbox...

(CC to debian-devel, any help with this issue is welcome)


On Wed, Nov 17, 2004 at 03:45:55AM +0100, Nicolas Gregoire wrote:
> Package: info2www
> Version: 1.2.2.9-22
> Severity: normal
> Tags: security
> 
> There's a XSS vulnerabilty in the info2www CGI.
> 
> The following URL will display the document location using Javascript :
> /cgi-bin/info2www?(coreutils)

Bug#290685: vcdimager: FTBFS on a sid system

2005-01-23 Thread Ludovic Rousseau
Hi,

The correct english error message from apt-get is:
  $ LANG=C sudo apt-get install vcdimager
  Reading Package Lists... Done
  Building Dependency Tree... Done
  Some packages could not be installed. This may mean that you have
  requested an impossible situation or if you are using the unstable
  distribution that some required packages have not yet been created
  or been moved out of Incoming.
  
  Since you only requested a single operation it is extremely likely that
  the package is simply not installable and a bug report against
  that package should be filed.
  The following information may help to resolve the situation:
  
  The following packages have unmet dependencies:
vcdimager: Depends: libcdio0 but it is not installable
   Depends: libiso9660-0 (> 0.67) but it is not installable
   Depends: libvcdinfo0 but it is not going to be installed
  E: Broken packages


I tried to recompile the package in a sid chroot to solve the dependency
problem and get:

mkdir .libs
 i386-linux-gcc -DHAVE_CONFIG_H -I. -I. -I.. -I../include/ -I../lib/ -g -Wall 
-O2 -Wall -Wchar-subscripts -Wmissing-prototypes -Wmissing-declarations 
-Wunused -Wpointer-arith -Wwrite-strings -Wnested-externs -Wno-sign-compare -MT 
info.lo -MD -MP -MF .deps/info.Tpo -c info.c  -fPIC -DPIC -o .libs/info.o
info.c: In function `_init_segments':
info.c:113: warning: assignment from incompatible pointer type
info.c: In function `vcdinfo_get_track_msf':
info.c:1314: warning: `from_bcd8' is deprecated (declared at 
/usr/include/cdio/util.h:115)
info.c:1315: warning: `from_bcd8' is deprecated (declared at 
/usr/include/cdio/util.h:115)
info.c:1316: warning: `from_bcd8' is deprecated (declared at 
/usr/include/cdio/util.h:115)
info.c: In function `vcdinfo_open':
info.c:1809: error: too many arguments to function `iso9660_fs_stat'
info.c:1817: error: too many arguments to function `iso9660_fs_stat'
info.c:1839: error: too many arguments to function `iso9660_fs_stat'
info.c:1855: error: too many arguments to function `iso9660_fs_stat'
info.c:1880: error: too many arguments to function `iso9660_fs_stat'
info.c:1886: error: too many arguments to function `iso9660_fs_stat'
info.c:1895: error: too many arguments to function `iso9660_fs_stat'
info.c:1934: error: too many arguments to function `iso9660_fs_stat'
make[3]: *** [info.lo] Erreur 1
make[3]: Leaving directory
`/imports/acer/home/NoBackup/Debian/vcdimager/vcdimager-0.7.20/lib'
make[2]: *** [all-recursive] Erreur 1
make[2]: Leaving directory
`/imports/acer/home/NoBackup/Debian/vcdimager/vcdimager-0.7.20'
make[1]: *** [all] Erreur 2
make[1]: Leaving directory
`/imports/acer/home/NoBackup/Debian/vcdimager/vcdimager-0.7.20'
make: *** [build-stamp] Erreur 2
debuild: fatal error at line 764:
dpkg-buildpackage failed!

The function iso9660_fs_stat() is used as:
  statbuf = iso9660_fs_stat (obj->img, "MPEGAV", true);
but the prototype in /usr/include/cdio/iso9660.h is now defined as
  iso9660_stat_t *iso9660_fs_stat (CdIo *p_cdio, const char pathname[]);


The code available in CVS [1] correct this compilation bug (in version
1.18 of lib/info.c) but a new upstream release is not ready yet.

The package should not/can not enter sarge for now.

[1] http://savannah.gnu.org/cgi-bin/viewcvs/vcdimager/vcdimager

-- 
 Dr. Ludovic Rousseau[EMAIL PROTECTED]
 -- Normaliser Unix c'est comme pasteuriser le camembert, L.R. --


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]



Bug#291265: marked as done ([Fixed in CVS] Silent data loss when saving in a directory with iso8859-1 name)

2005-01-23 Thread Debian Bug Tracking System
Your message dated Sun, 23 Jan 2005 11:17:44 -0500
with message-id <[EMAIL PROTECTED]>
and subject line Bug#291265: fixed in gnumeric 1.4.2-2
has caused the attached Bug report to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what I am
talking about this indicates a serious mail system misconfiguration
somewhere.  Please contact me immediately.)

Debian bug tracking system administrator
(administrator, Debian Bugs database)

--
Received: (at submit) by bugs.debian.org; 19 Jan 2005 18:50:11 +
>From [EMAIL PROTECTED] Wed Jan 19 10:50:11 2005
Return-path: <[EMAIL PROTECTED]>
Received: from postfix3-1.free.fr [213.228.0.44] 
by spohr.debian.org with esmtp (Exim 3.35 1 (Debian))
id 1CrKuA-0001Un-00; Wed, 19 Jan 2005 10:50:11 -0800
Received: from simone (unknown [82.233.190.178])
by postfix3-1.free.fr (Postfix) with ESMTP id CA552173511;
Wed, 19 Jan 2005 19:50:07 +0100 (CET)
Received: from nicolas by simone with local (Exim 4.34)
id 1CrKuJ-pJ-7J; Wed, 19 Jan 2005 19:50:19 +0100
MIME-Version: 1.0
Content-Type: text/plain; charset="ISO-8859-15"
From: Nicolas Boulenguez <[EMAIL PROTECTED]>
To: Debian Bug Tracking System <[EMAIL PROTECTED]>
Subject: gnumeric: Silent data loss when saving in a directory with iso8859-1 
name
X-Mailer: reportbug 3.2
Date: Wed, 19 Jan 2005 19:50:19 +0100
Message-Id: <[EMAIL PROTECTED]>
Content-Transfer-Encoding: quoted-printable
Delivered-To: [EMAIL PROTECTED]
X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2005_01_02 
(1.212-2003-09-23-exp) on spohr.debian.org
X-Spam-Status: No, hits=-8.0 required=4.0 tests=BAYES_00,HAS_PACKAGE 
autolearn=no version=2.60-bugs.debian.org_2005_01_02
X-Spam-Level: 

Package: gnumeric
Version: 1.4.1-1
Severity: critical
Justification: causes serious data loss


Hello.

Save a file, say "Book1.gnumeric", in a directory named "=E9". In the
window dedicated to "save", it is named "\351" (iso8859-1, octal) in
the saving dialog. Nothing seems unusual, I heard that gnome uses
UTF8. Except the file has a size of 0, and the data is lost.

It does not lose data, but it seems related:
- The same works correctly if I create the directory with gnumeric (it
uses an unicode filename, with ugly two-letters results).
- Loading a file with an "=E9" in its name crashes gnumeric.

Maybe it is not worth the mess, because UTF8 is the future and few
users use the command line and gnumeric. But a "save your data
elsewhere" message would be nice.


PS: Do not cry for my data, I printed before s(h)aving them
accidently.

-- System Information:
Debian Release: 3.1
  APT prefers testing
  APT policy: (500, 'testing')
Architecture: i386 (i686)
Kernel: Linux 2.6.9.20041229
Locale: [EMAIL PROTECTED], [EMAIL PROTECTED] (charmap=3DISO-8859-15)

Versions of packages gnumeric depends on:
ii  gconf2   2.8.1-4 GNOME configuration database=
 syste
ii  gnumeric-common  1.4.1-1 Common files for Gnumeric, t=
he GNO
ii  gsfonts  8.14+v8.11-0.1  Fonts for the Ghostscript in=
terpre
ii  libart-2.0-2 2.3.16-6Library of functions for 2D =
graphi
ii  libatk1.0-0  1.8.0-4 The ATK accessibility toolki=
t
ii  libbonobo2-0 2.8.0-4 Bonobo CORBA interfaces libr=
ary
ii  libbonoboui2-0   2.8.0-2 The Bonobo UI library
ii  libc62.3.2.ds1-20GNU C Library: Shared librar=
ies an
ii  libgconf2-4  2.8.1-4 GNOME configuration database=
 syste
ii  libglade2-0  1:2.4.1-1   Library to load .glade files=
 at ru
ii  libglib2.0-0 2.4.8-1 The GLib library of C routin=
es
ii  libgnome2-0  2.8.0-6 The GNOME 2 library - runtim=
e file
ii  libgnomecanvas2-02.8.0-1 A powerful object-oriented d=
isplay
ii  libgnomeprint2.2-0   2.8.2-1 The GNOME 2.2 print architec=
ture -
ii  libgnomeprintui2.2-0 2.8.1-1 The GNOME 2.2 print architec=
ture U
ii  libgnomeui-0 2.8.0-3 The GNOME 2 libraries (User =
Interf
ii  libgnomevfs2-0   2.8.3-8 The GNOME virtual file-syste=
m libr
ii  libgsf-1 1.11.1-1Structured File Library - ru=
ntime=20
ii  libgsf-gnome-1   1.11.1-1Structured File Library - ru=
ntime=20
ii  libgtk2.0-0  2.4.14-2The GTK+ graphical user inte=
rface=20
ii  libice6  4.3.0.dfsg.1-10 Inter-Client Exchange librar=
y
ii  liborbit21:2.10.2-1.1libraries for ORBit2 - a COR=
BA ORB
ii  libpango1.0-01.6.0-3 Layout and rendering of inte=
rnatio
ii  libpopt0 1.7-5   lib for 

Bug#284783: kernel-image-2.6.9-1-686-smp: Kernel oops possibly related to kswapd

2005-01-23 Thread Sean O'Dubhghaill
Hi maks

I'm now running 2.6.10 (not from unstable though it's vanilla with ac1 
patches) and I haven't had a single kernel opps since. I've attached a dmesg 
from the kernel i'm currently running. If you would like I can switch back to 
an older kernel to test it/get a dmesg etc.

thanks,
sean
Linux version 2.6.10-ac1 ([EMAIL PROTECTED]) (gcc version 3.3.5 (Debian 
1:3.3.5-5)) #1 SMP Thu Dec 30 13:15:25 GMT 2004
BIOS-provided physical RAM map:
 BIOS-e820:  - 0009fc00 (usable)
 BIOS-e820: 0009fc00 - 000a (reserved)
 BIOS-e820: 000f - 0010 (reserved)
 BIOS-e820: 0010 - 1fff (usable)
 BIOS-e820: 1fff - 1fff8000 (ACPI data)
 BIOS-e820: 1fff8000 - 2000 (ACPI NVS)
 BIOS-e820: fec0 - fec01000 (reserved)
 BIOS-e820: fee0 - fee01000 (reserved)
 BIOS-e820: fffc - 0001 (reserved)
511MB LOWMEM available.
found SMP MP-table at 000fbe00
On node 0 totalpages: 131056
  DMA zone: 4096 pages, LIFO batch:1
  Normal zone: 126960 pages, LIFO batch:16
  HighMem zone: 0 pages, LIFO batch:1
DMI 2.3 present.
ACPI: RSDP (v000 AMI   ) @ 0x000fa950
ACPI: RSDT (v001 AMIINT AMIINI09 0x0010 MSFT 0x0097) @ 0x1fff
ACPI: FADT (v001 AMIINT AMIINI09 0x0011 MSFT 0x0097) @ 0x1fff0030
ACPI: MADT (v001 AMIINT AMIINI09 0x0011 MSFT 0x0097) @ 0x1fff00c0
ACPI: DSDT (v001VIA APOLLO-P 0x1000 MSFT 0x010d) @ 0x
ACPI: PM-Timer IO Port: 0x808
ACPI: Local APIC address 0xfee0
ACPI: LAPIC (acpi_id[0x01] lapic_id[0x00] enabled)
Processor #0 6:8 APIC version 17
ACPI: LAPIC (acpi_id[0x02] lapic_id[0x01] enabled)
Processor #1 6:8 APIC version 17
ACPI: IOAPIC (id[0x02] address[0xfec0] gsi_base[0])
IOAPIC[0]: apic_id 2, version 17, address 0xfec0, GSI 0-23
ACPI: INT_SRC_OVR (bus 0 bus_irq 0 global_irq 2 dfl dfl)
ACPI: INT_SRC_OVR (bus 0 bus_irq 9 global_irq 9 low level)
ACPI: IRQ0 used by override.
ACPI: IRQ2 used by override.
ACPI: IRQ9 used by override.
Enabling APIC mode:  Flat.  Using 1 I/O APICs
Using ACPI (MADT) for SMP configuration information
Built 1 zonelists
Kernel command line: root=/dev/hda3 ro
mapped APIC to d000 (fee0)
mapped IOAPIC to c000 (fec0)
Initializing CPU#0
PID hash table entries: 2048 (order: 11, 32768 bytes)
Detected 996.900 MHz processor.
Using pmtmr for high-res timesource
Console: colour VGA+ 80x25
Dentry cache hash table entries: 131072 (order: 7, 524288 bytes)
Inode-cache hash table entries: 65536 (order: 6, 262144 bytes)
Memory: 515248k/524224k available (2211k kernel code, 8500k reserved, 832k 
data, 216k init, 0k highmem)
Checking if this processor honours the WP bit even in supervisor mode... Ok.
Calibrating delay loop... 1974.27 BogoMIPS (lpj=987136)
Mount-cache hash table entries: 512 (order: 0, 4096 bytes)
CPU: After generic identify, caps: 0387fbff   
CPU: After vendor identify, caps:  0387fbff   
CPU: L1 I cache: 16K, L1 D cache: 16K
CPU: L2 cache: 256K
CPU serial number disabled.
CPU: After all inits, caps:0383fbff   0040
Intel machine check architecture supported.
Intel machine check reporting enabled on CPU#0.
Enabling fast FPU save and restore... done.
Enabling unmasked SIMD FPU exception support... done.
Checking 'hlt' instruction... OK.
CPU0: Intel Pentium III (Coppermine) stepping 0a
per-CPU timeslice cutoff: 731.68 usecs.
task migration cache decay timeout: 1 msecs.
Booting processor 1/1 eip 3000
Initializing CPU#1
Calibrating delay loop... 1990.65 BogoMIPS (lpj=995328)
CPU: After generic identify, caps: 0387fbff   
CPU: After vendor identify, caps:  0387fbff   
CPU: L1 I cache: 16K, L1 D cache: 16K
CPU: L2 cache: 256K
CPU serial number disabled.
CPU: After all inits, caps:0383fbff   0040
Intel machine check architecture supported.
Intel machine check reporting enabled on CPU#1.
CPU1: Intel Pentium III (Coppermine) stepping 0a
Total of 2 processors activated (3964.92 BogoMIPS).
ENABLING IO-APIC IRQs
..TIMER: vector=0x31 pin1=2 pin2=-1
checking TSC synchronization across 2 CPUs: passed.
Brought up 2 CPUs
CPU0:
 domain 0: span 3
  groups: 1 2
CPU1:
 domain 0: span 3
  groups: 2 1
NET: Registered protocol family 16
PCI: PCI BIOS revision 2.10 entry at 0xfdb21, last bus=1
PCI: Using configuration type 1
mtrr: v2.0 (20020519)
mtrr: your CPUs had inconsistent variable MTRR settings
mtrr: probably your BIOS does not setup all CPUs.
mtrr: corrected configuration.
ACPI: Subsystem revision 20041105
ACPI: Interpreter enabled
ACPI: Using IOAPIC for interrupt routing
ACPI: PCI Root Bridge [PCI0] (00:00)
PCI: Probing PCI hardware (bus 00)
ACPI: PCI Interrupt Routing Table [\_SB_.PCI0._PRT]
ACPI: Power Resource [URP1] (off)
ACPI: Power Resource [URP2] (off)
ACPI: Power Resource [FDDP

Processed: merging hwtools

2005-01-23 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]:

> severity 291504 serious
Bug#291504: hwtools: man page buffer.1.gz conflicts with the one from the 
buffer package
Severity set to `serious'.

> severity 291138 serious
Bug#291138: hwtools: uninstallable
Severity set to `serious'.

> merge 291504 291138
Bug#291138: hwtools: uninstallable
Bug#291504: hwtools: man page buffer.1.gz conflicts with the one from the 
buffer package
Merged 291138 291504.

> thanks
Stopping processing here.

Please contact me if you need assistance.

Debian bug tracking system administrator
(administrator, Debian Bugs database)


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]



Bug#291846: Bugs not fixed from 2.6.8

2005-01-23 Thread Peter Walser
Package: kernel-image-2.6.8-2-686
Version:  2.6.8-12
Severity:  grave

hi

Has someone looked at the bugs in kernel-image-2.6.8-1-386 and 
kernel-image-2.6.8-1-686?

Grave functionality bugs - outstanding (1 bug)
Important bugs - outstanding (5 bugs)
Normal bugs - outstanding (9 bugs)
Wishlist items - outstanding (1 bug)
Grave functionality bugs - resolved (2 bugs)

Critical bugs - outstanding (1 bug)
Important bugs - outstanding (8 bugs)
Normal bugs - outstanding (21 bugs)
Minor bugs - outstanding (2 bugs)
Wishlist items - outstanding (1 bug)
Normal bugs - resolved (1 bug)

At least not all bugs are tested, if they are still present and the  
people are not informed to test with the newer version 
kernel-image-2.6.8-2-686.
My bug #282800 is still not fixed and you shouldn't go out with this 
2.6.8. In Kernel 2.6.10 this bug is fixed.


Peter


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]



Bug#281655: info2www: Cross-site scripting vulnerability

2005-01-23 Thread Justin Pryzby
On Sun, Jan 23, 2005 at 05:12:15PM +0100, Uwe Hermann wrote:
> Hi,
> 
> sorry, the mail about this bug somehow got lost in my inbox...
> 
> (CC to debian-devel, any help with this issue is welcome)
> 
> 
> On Wed, Nov 17, 2004 at 03:45:55AM +0100, Nicolas Gregoire wrote:
> > Package: info2www
> > Version: 1.2.2.9-22
> > Severity: normal
> > Tags: security
> > 
> > There's a XSS vulnerabilty in the info2www CGI.
> > 
> > The following URL will display the document location using Javascript :
> > /cgi-bin/info2www?(coreutils)alert(document.location)