Processed: doxygen: cascade of FTBFS

2019-02-08 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org:

> retitle 921779 cascade of FTBFS
Bug #921779 [src:doxygen] doxygen: FTBFS (LaTeX error)
Changed Bug title to 'cascade of FTBFS' from 'doxygen: FTBFS (LaTeX error)'.
> affects 921779 primesieve bliss librostlab-blast doxygen
Bug #921779 [src:doxygen] cascade of FTBFS
Added indication that 921779 affects primesieve, bliss, librostlab-blast, and 
doxygen
> reassign 921802 doxygen
Bug #921802 [src:primesieve] primesieve: FTBFS (LaTeX error)
Bug reassigned from package 'src:primesieve' to 'doxygen'.
No longer marked as found in versions primesieve/7.3+ds-1.
Ignoring request to alter fixed versions of bug #921802 to the same values 
previously set
> reassign 921776 doxygen
Bug #921776 [src:bliss] bliss: FTBFS (LaTeX error)
Bug reassigned from package 'src:bliss' to 'doxygen'.
No longer marked as found in versions bliss/0.73-2.
Ignoring request to alter fixed versions of bug #921776 to the same values 
previously set
> reassign 921789 doxygen
Bug #921789 [src:librostlab-blast] librostlab-blast: FTBFS (LaTeX error)
Bug reassigned from package 'src:librostlab-blast' to 'doxygen'.
No longer marked as found in versions librostlab-blast/1.0.1-9.
Ignoring request to alter fixed versions of bug #921789 to the same values 
previously set
> thanks
Stopping processing here.

Please contact me if you need assistance.
-- 
921776: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=921776
921779: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=921779
921789: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=921789
921802: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=921802
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems



Bug#921779: doxygen: FTBFS (LaTeX error)

2019-02-08 Thread Jerome BENOIT
Dear All,

I think there is a major issue with doxygen:
#921802 , #921776, #921789, and certainly other seem affected by a recent bug 
that affect doxygen.

For #921776, I cannot compose the PDF in a Sid environment, but I can compose 
it on my Stretch box.

Jerome

-- 
Jerome BENOIT | calculus+at-rezozer^dot*net
https://qa.debian.org/developer.php?login=calcu...@rezozer.net
AE28 AE15 710D FF1D 87E5  A762 3F92 19A6 7F36 C68B



signature.asc
Description: OpenPGP digital signature


php-cas is marked for autoremoval from testing

2019-02-08 Thread Debian testing autoremoval watch
php-cas 1.3.3-4 is marked for autoremoval from testing on 2019-03-11

It is affected by these RC bugs:
868466: php-cas: CVE-2017-171



Bug#921779: doxygen: FTBFS (LaTeX error)

2019-02-08 Thread Santiago Vila
Package: src:doxygen
Version: 1.8.13-10
Severity: serious
Tags: ftbfs

Dear maintainer:

I tried to build this package in buster but it failed:


[...]
 debian/rules build-indep
dh_testdir
/usr/bin/make -C jquery install
make[1]: Entering directory '/<>/jquery'
java -jar /usr/share/yui-compressor/yui-compressor.jar jquery-1.7.1.js > 
jquery-1.7.1-min.js
java -jar /usr/share/yui-compressor/yui-compressor.jar jquery.ui-1.8.18.core.js 
> jquery.ui-1.8.18.core-min.js
java -jar /usr/share/yui-compressor/yui-compressor.jar 
jquery.ui-1.8.18.widget.js > jquery.ui-1.8.18.widget-min.js
java -jar /usr/share/yui-compressor/yui-compressor.jar 
jquery.ui-1.8.18.mouse.js > jquery.ui-1.8.18.mouse-min.js
java -jar /usr/share/yui-compressor/yui-compressor.jar 
jquery.ui-1.8.18.resizable.js > jquery.ui-1.8.18.resizable-min.js
java -jar /usr/share/yui-compressor/yui-compressor.jar 
jquery.ba-1.3-hashchange.js > jquery.ba-1.3-hashchange-min.js
java -jar /usr/share/yui-compressor/yui-compressor.jar jquery.scrollTo-1.4.2.js 
> jquery.scrollTo-1.4.2-min.js
java -jar /usr/share/yui-compressor/yui-compressor.jar jquery.powertip-1.2.0.js 
> jquery.powertip-1.2.0-min.js
java -jar /usr/share/yui-compressor/yui-compressor.jar 
jquery.ui-0.2.3.touch-punch.js > jquery.ui-0.2.3.touch-punch-min.js
java -jar /usr/share/yui-compressor/yui-compressor.jar 
jquery.smartmenus-1.0.0.js > jquery.smartmenus-1.0.0-min.js

[... snipped ...]

[100%] Generating trouble.doc
cd /<>/build/doc && /usr/bin/cmake -E copy 
/<>/doc/trouble.doc /<>/build/doc/
[100%] Generating xmlcmds.doc
cd /<>/build/doc && /usr/bin/cmake -E copy 
/<>/doc/xmlcmds.doc /<>/build/doc/
[100%] Generating Latex and HTML documentation.
cd /<>/build/doc && /<>/build/bin/doxygen
This is pdfTeX, Version 3.14159265-2.6-1.40.19 (TeX Live 2019/dev/Debian) 
(preloaded format=latex)
 restricted \write18 enabled.
entering extended mode
(./_formulas.tex
LaTeX2e <2018-12-01>

make[4]: Leaving directory '/<>/build'
[100%] Built target run_doxygen
/usr/bin/make -f doc/CMakeFiles/doxygen_pdf.dir/build.make 
doc/CMakeFiles/doxygen_pdf.dir/depend
make[4]: Entering directory '/<>/build'
cd /<>/build && /usr/bin/cmake -E cmake_depends "Unix Makefiles" 
/<> /<>/doc /<>/build 
/<>/build/doc 
/<>/build/doc/CMakeFiles/doxygen_pdf.dir/DependInfo.cmake --color=
Dependee 
"/<>/build/doc/CMakeFiles/doxygen_pdf.dir/DependInfo.cmake" is 
newer than depender 
"/<>/build/doc/CMakeFiles/doxygen_pdf.dir/depend.internal".
Dependee 
"/<>/build/doc/CMakeFiles/CMakeDirectoryInformation.cmake" is 
newer than depender 
"/<>/build/doc/CMakeFiles/doxygen_pdf.dir/depend.internal".
Scanning dependencies of target doxygen_pdf
make[4]: Leaving directory '/<>/build'
/usr/bin/make -f doc/CMakeFiles/doxygen_pdf.dir/build.make 
doc/CMakeFiles/doxygen_pdf.dir/build
make[4]: Entering directory '/<>/build'
[100%] Generating Doxygen Manual PDF.
cd /<>/build/latex && /usr/bin/cmake -E remove refman.tex
cd /<>/build/latex && /usr/bin/cmake -E copy 
/<>/build/doc/doxygen_manual.tex .
cd /<>/build/latex && /usr/bin/cmake -E copy 
/<>/build/doc/manual.sty .
cd /<>/build/latex && /usr/bin/epstopdf 
/<>/doc/doxygen_logo.eps --outfile=doxygen_logo.pdf
cd /<>/build/latex && /usr/bin/pdflatex -shell-escape 
doxygen_manual.tex
This is pdfTeX, Version 3.14159265-2.6-1.40.19 (TeX Live 2019/dev/Debian) 
(preloaded format=pdflatex)
 \write18 enabled.
entering extended mode
(./doxygen_manual.tex
LaTeX2e <2018-12-01>

make[4]: *** [doc/CMakeFiles/doxygen_pdf.dir/build.make:62: 
doc/CMakeFiles/doxygen_pdf] Error 1
make[4]: Leaving directory '/<>/build'
make[3]: *** [CMakeFiles/Makefile2:445: doc/CMakeFiles/doxygen_pdf.dir/all] 
Error 2
make[3]: Leaving directory '/<>/build'
make[2]: *** [CMakeFiles/Makefile2:484: doc/CMakeFiles/docs.dir/rule] Error 2
make[2]: Leaving directory '/<>/build'
make[1]: *** [Makefile:301: docs] Error 2
make[1]: Leaving directory '/<>/build'
make: *** [debian/rules:60: build-stamp] Error 2
dpkg-buildpackage: error: debian/rules build-indep subprocess returned exit 
status 2


(The above is just how the build ends and not necessarily the most relevant 
part)

The build was made in my autobuilder with "dpkg-buildpackage -A"
and it also fails here:

https://tests.reproducible-builds.org/debian/rb-pkg/unstable/amd64/doxygen.html

where you can get a full build log if you need it.

If this is really a bug in one of the build-depends, please use reassign and 
affects,
so that this is still visible in the BTS web page for this package.

Thanks.



Bug#868466: php-cas: CVE-2017-1000071

2019-02-08 Thread Moritz Mühlenhoff
On Sat, Jul 15, 2017 at 09:06:41PM +0200, Salvatore Bonaccorso wrote:
> Source: php-cas
> Version: 1.3.3-1
> Severity: important
> Tags: security upstream
> Forwarded: https://github.com/Jasig/phpCAS/issues/228
> 
> Hi,
> 
> the following vulnerability was published for php-cas.
> 
> CVE-2017-171[0]:
> | Jasig phpCAS version 1.3.4 is vulnerable to an authentication bypass
> | in the validateCAS20 function when configured to authenticate against
> | an old CAS server.
> 
> If you fix the vulnerability please also make sure to include the
> CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

Fixed in 
https://github.com/apereo/phpCAS/commit/c9ba00327fd0ac8faecc62ce150c1986022856cd

Cheers,
Moritz



Processed: severity of 868466 is grave

2019-02-08 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org:

> severity 868466 grave
Bug #868466 [src:php-cas] php-cas: CVE-2017-171
Severity set to 'grave' from 'important'
> thanks
Stopping processing here.

Please contact me if you need assistance.
-- 
868466: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=868466
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems