[Secure-testing-team] Bug#608286: CVE-2010-4312: does not use HTTPOnly for session cookies by default

2010-12-29 Thread Giuseppe Iuculano
Package: tomcat6 Severity: serious Tags: security -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, the following CVE (Common Vulnerabilities Exposures) id was published for tomcat6. CVE-2010-4312[0]: | The default configuration of Apache Tomcat 6.x does not include the | HTTPOnly flag in a

[Secure-testing-team] Bug#608288: CVE-2010-4254

2010-12-29 Thread Giuseppe Iuculano
Package: moon Severity: serious Tags: security -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, the following CVE (Common Vulnerabilities Exposures) id was published for moon. CVE-2010-4254[0]: | Mono, when Moonlight before 2.3.0.1 or 2.99.x before 2.99.0.10 is | used, does not properly

[Secure-testing-team] Bug#608289: CVE-2010-3905

2010-12-29 Thread Giuseppe Iuculano
Package: eucalyptus Severity: serious Tags: security -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, the following CVE (Common Vulnerabilities Exposures) id was published for eucalyptus. CVE-2010-3905[0]: | The password reset feature in the administrator interface for | Eucalyptus 2.0.0 and

[Secure-testing-team] Bug#608290: CVE-2010-4480 CVE-2010-4481

2010-12-29 Thread Giuseppe Iuculano
Package: phpmyadmin Severity: serious Tags: security -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, the following CVE (Common Vulnerabilities Exposures) ids were published for phpmyadmin. CVE-2010-4480[0]: | error.php in PhpMyAdmin 3.3.8.1, and other versions before | 3.4.0-beta1, allows

[SECURITY] [DSA 2138-1] Security update for wordpress

2010-12-29 Thread Giuseppe Iuculano
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-2138-1 secur...@debian.org http://www.debian.org/security/Giuseppe Iuculano December 29, 2010

Bug#608273: CVE-2010-3853: pam_namespace executes namespace.init with service's environment

2010-12-29 Thread Giuseppe Iuculano
Package: pam Severity: serious Tags: security patch -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Tomas Mraz pointed out that pam_namespace PAM module executes external namespace.init script with an environment settings inherited form the program or service that has pam_namespace configured.

Bug#608286: CVE-2010-4312: does not use HTTPOnly for session cookies by default

2010-12-29 Thread Giuseppe Iuculano
Package: tomcat6 Severity: serious Tags: security -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, the following CVE (Common Vulnerabilities Exposures) id was published for tomcat6. CVE-2010-4312[0]: | The default configuration of Apache Tomcat 6.x does not include the | HTTPOnly flag in a

Bug#608288: CVE-2010-4254

2010-12-29 Thread Giuseppe Iuculano
Package: moon Severity: serious Tags: security -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, the following CVE (Common Vulnerabilities Exposures) id was published for moon. CVE-2010-4254[0]: | Mono, when Moonlight before 2.3.0.1 or 2.99.x before 2.99.0.10 is | used, does not properly

Bug#608289: CVE-2010-3905

2010-12-29 Thread Giuseppe Iuculano
Package: eucalyptus Severity: serious Tags: security -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, the following CVE (Common Vulnerabilities Exposures) id was published for eucalyptus. CVE-2010-3905[0]: | The password reset feature in the administrator interface for | Eucalyptus 2.0.0 and

Bug#608290: CVE-2010-4480 CVE-2010-4481

2010-12-29 Thread Giuseppe Iuculano
Package: phpmyadmin Severity: serious Tags: security -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, the following CVE (Common Vulnerabilities Exposures) ids were published for phpmyadmin. CVE-2010-4480[0]: | error.php in PhpMyAdmin 3.3.8.1, and other versions before | 3.4.0-beta1, allows

Accepted wordpress 2.5.1-11+lenny4 (source all)

2010-12-29 Thread Giuseppe Iuculano
-By: Giuseppe Iuculano iucul...@debian.org Description: wordpress - weblog manager Closes: 605603 Changes: wordpress (2.5.1-11+lenny4) stable-security; urgency=high . * [6f61bff] Fix CVE-2010-4257: SQL injection vulnerability in the do_trackbacks function (Closes: #605603) Checksums-Sha1

Re: Bug#604016: Please support 3w-sas controllers

2010-12-29 Thread Giuseppe Iuculano
On 12/23/2010 11:23 AM, Florian Weimer wrote: The attached patch was tested with a 9750 controller and a 9500S controller. Basic SMART functionality still works. smartmontools 5.39.1+svn3124-2 uploaded with your patch, thanks. Cheers, Giuseppe. signature.asc Description: OpenPGP digital

Accepted wordpress 3.0.3.dfsg-1 (source all)

2010-12-28 Thread Giuseppe Iuculano
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Format: 1.8 Date: Tue, 28 Dec 2010 17:22:34 +0100 Source: wordpress Binary: wordpress wordpress-l10n Architecture: source all Version: 3.0.3.dfsg-1 Distribution: unstable Urgency: high Maintainer: Giuseppe Iuculano iucul...@debian.org Changed

Bug#607608: unblock: wordpress/3.0.3-1

2010-12-28 Thread Giuseppe Iuculano
-- Giuseppe Iuculano iucul...@debian.org Tue, 28 Dec 2010 17:22:34 +0100 signature.asc Description: OpenPGP digital signature

Bug#607608: unblock: wordpress/3.0.3-1

2010-12-28 Thread Giuseppe Iuculano
-- Giuseppe Iuculano iucul...@debian.org Tue, 28 Dec 2010 17:22:34 +0100 signature.asc Description: OpenPGP digital signature

Accepted smartmontools 5.39.1+svn3124-2 (source i386)

2010-12-26 Thread Giuseppe Iuculano
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Format: 1.8 Date: Sun, 26 Dec 2010 12:26:16 +0100 Source: smartmontools Binary: smartmontools Architecture: source i386 Version: 5.39.1+svn3124-2 Distribution: unstable Urgency: low Maintainer: Giuseppe Iuculano iucul...@debian.org Changed

[Secure-testing-commits] r15747 - data/CVE

2010-12-24 Thread Giuseppe Iuculano
Author: iuculano Date: 2010-12-24 12:25:55 + (Fri, 24 Dec 2010) New Revision: 15747 Modified: data/CVE/list Log: chromium/webkit issues Modified: data/CVE/list === --- data/CVE/list 2010-12-23 21:14:45 UTC (rev 15746)

Bug#607608: unblock: wordpress/3.0.3-1

2010-12-24 Thread Giuseppe Iuculano
On 12/21/2010 05:27 PM, Julien Cristau wrote: I still don't know what you mean. Surely the lyrics is essentially data, so whether it's GPL-compatible is irrelevant? And if it's non-free, you're still shipping the old lyrics (twice now, since it's both in the upstream source and the debian

Bug#607922: CVE-2010-4494: memory corruption (double-free) in XPath processing code

2010-12-24 Thread Giuseppe Iuculano
Package: libxml2 Severity: serious Tags: security patch -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, the following CVE (Common Vulnerabilities Exposures) id was published for libxml2. CVE-2010-4494[0]: | Double free vulnerability in Google Chrome before 8.0.552.215 allows | remote

[Secure-testing-team] Bug#607922: CVE-2010-4494: memory corruption (double-free) in XPath processing code

2010-12-24 Thread Giuseppe Iuculano
Package: libxml2 Severity: serious Tags: security patch -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, the following CVE (Common Vulnerabilities Exposures) id was published for libxml2. CVE-2010-4494[0]: | Double free vulnerability in Google Chrome before 8.0.552.215 allows | remote

Bug#607922: CVE-2010-4494: memory corruption (double-free) in XPath processing code

2010-12-24 Thread Giuseppe Iuculano
Package: libxml2 Severity: serious Tags: security patch -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, the following CVE (Common Vulnerabilities Exposures) id was published for libxml2. CVE-2010-4494[0]: | Double free vulnerability in Google Chrome before 8.0.552.215 allows | remote

Bug#607608: unblock: wordpress/3.0.3-1

2010-12-24 Thread Giuseppe Iuculano
On 12/21/2010 05:27 PM, Julien Cristau wrote: I still don't know what you mean. Surely the lyrics is essentially data, so whether it's GPL-compatible is irrelevant? And if it's non-free, you're still shipping the old lyrics (twice now, since it's both in the upstream source and the debian

Bug#607608: unblock: wordpress/3.0.3-1

2010-12-21 Thread Giuseppe Iuculano
On 12/20/2010 05:38 PM, Julien Cristau wrote: What is GPL-compliant lyrics supposed to mean? Either they're free, and there's no need to replace them, GPL or not. Or they're not free, and we need to not ship them, in which case a patch is not enough. I just don't get what the GPL has to do

Bug#607738: unblock: chromium-browser/6.0.472.63~r59945-4

2010-12-21 Thread Giuseppe Iuculano
Out-of-bounds read in CSS parsing. Credit to Chris Rohlf. - High Stale pointers in cursor handling. Credit to Sławomir Błażek and Sergey Glazunov. -- Giuseppe Iuculano iucul...@debian.org Sat, 18 Dec 2010 17:39:19 +0100 chromium-browser (6.0.472.63~r59945-3) unstable; urgency=high

Bug#607608: unblock: wordpress/3.0.3-1

2010-12-21 Thread Giuseppe Iuculano
On 12/20/2010 05:38 PM, Julien Cristau wrote: What is GPL-compliant lyrics supposed to mean? Either they're free, and there's no need to replace them, GPL or not. Or they're not free, and we need to not ship them, in which case a patch is not enough. I just don't get what the GPL has to do

Bug#607738: unblock: chromium-browser/6.0.472.63~r59945-4

2010-12-21 Thread Giuseppe Iuculano
Out-of-bounds read in CSS parsing. Credit to Chris Rohlf. - High Stale pointers in cursor handling. Credit to Sławomir Błażek and Sergey Glazunov. -- Giuseppe Iuculano iucul...@debian.org Sat, 18 Dec 2010 17:39:19 +0100 chromium-browser (6.0.472.63~r59945-3) unstable; urgency=high

Bug#607608: unblock: wordpress/3.0.3-1

2010-12-20 Thread Giuseppe Iuculano
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: freeze-exception -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Please unblock package wordpress, 3.0.3 is a security release. unblock wordpress/3.0.3-1 Cheers, Giuseppe. -BEGIN PGP

Bug#607608: unblock: wordpress/3.0.3-1

2010-12-20 Thread Giuseppe Iuculano
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: freeze-exception -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Please unblock package wordpress, 3.0.3 is a security release. unblock wordpress/3.0.3-1 Cheers, Giuseppe. -BEGIN PGP

Accepted chromium-browser 6.0.472.63~r59945-4 (source all amd64)

2010-12-19 Thread Giuseppe Iuculano
: unstable Urgency: high Maintainer: Debian Chromium Maintainers pkg-chromium-ma...@lists.alioth.debian.org Changed-By: Giuseppe Iuculano iucul...@debian.org Description: chromium-browser - Chromium browser chromium-browser-dbg - chromium-browser debug symbols chromium-browser-inspector - page

Accepted wordpress 3.0.3-1 (source all)

2010-12-17 Thread Giuseppe Iuculano
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Format: 1.8 Date: Fri, 17 Dec 2010 11:03:55 +0100 Source: wordpress Binary: wordpress wordpress-l10n Architecture: source all Version: 3.0.3-1 Distribution: unstable Urgency: high Maintainer: Giuseppe Iuculano iucul...@debian.org Changed-By: Giuseppe

Bug#607240: [f29b6ac] Fix for Bug#607240 committed to git

2010-12-17 Thread Giuseppe Iuculano
tags 607240 + pending thanks Hello, The following change has been committed for this bug by Giuseppe Iuculano iucul...@debian.org on Fri, 17 Dec 2010 10:59:01 +0100. The fix will be in the next upload. = Use GPL

Bug#607240: [f29b6ac] Fix for Bug#607240 committed to git

2010-12-17 Thread Giuseppe Iuculano
tags 607240 + pending thanks Hello, The following change has been committed for this bug by Giuseppe Iuculano iucul...@debian.org on Fri, 17 Dec 2010 10:59:01 +0100. The fix will be in the next upload. = Use GPL

Accepted chromium-browser 6.0.472.63~r59945-3 (source all amd64)

2010-12-08 Thread Giuseppe Iuculano
: unstable Urgency: high Maintainer: Debian Chromium Maintainers pkg-chromium-ma...@lists.alioth.debian.org Changed-By: Giuseppe Iuculano iucul...@debian.org Description: chromium-browser - Chromium browser chromium-browser-dbg - chromium-browser debug symbols chromium-browser-inspector - page

Accepted wordpress 3.0.2-1 (source all)

2010-12-07 Thread Giuseppe Iuculano
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Format: 1.8 Date: Tue, 07 Dec 2010 08:43:38 +0100 Source: wordpress Binary: wordpress wordpress-l10n Architecture: source all Version: 3.0.2-1 Distribution: unstable Urgency: high Maintainer: Giuseppe Iuculano iucul...@debian.org Changed-By: Giuseppe

Bug#602732: [612c23f] Fix for Bug#602732 committed to git

2010-12-06 Thread Giuseppe Iuculano
tags 602732 + pending thanks Hello, The following change has been committed for this bug by Giuseppe Iuculano iucul...@debian.org on Mon, 6 Dec 2010 16:51:02 +0100. The fix will be in the next upload. = Remove

Bug#602732: [612c23f] Fix for Bug#602732 committed to git

2010-12-06 Thread Giuseppe Iuculano
tags 602732 + pending thanks Hello, The following change has been committed for this bug by Giuseppe Iuculano iucul...@debian.org on Mon, 6 Dec 2010 16:51:02 +0100. The fix will be in the next upload. = Remove

[Full-disclosure] [SECURITY] [DSA-2128-1] New libxml2 packages fix potential code execution

2010-12-01 Thread Giuseppe Iuculano
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-2128-1 secur...@debian.org http://www.debian.org/security/Giuseppe Iuculano December 01, 2010

[SECURITY] [DSA-2128-1] New libxml2 packages fix potential code execution

2010-12-01 Thread Giuseppe Iuculano
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-2128-1 secur...@debian.org http://www.debian.org/security/Giuseppe Iuculano December 01, 2010

Accepted dmraid 1.0.0.rc16-4 (source i386)

2010-11-22 Thread Giuseppe Iuculano
: Giuseppe Iuculano iucul...@debian.org Changed-By: Giuseppe Iuculano iucul...@debian.org Description: dmraid - Device-Mapper Software RAID support tool dmraid-udeb - Device-Mapper Software RAID support tool (udeb) (udeb) libdmraid-dev - Device-Mapper Software RAID support tool - header files

Bug#604016: Please support 3w-sas controllers

2010-11-22 Thread Giuseppe Iuculano
Release Team, Would this be an acceptable change for a freeze exception? On 11/19/2010 01:11 PM, Florian Weimer wrote: Package: smartmontools Version: 5.39.1+svn3124-1 3w-sas is part of squeeze's kernel (for the 9750 cards), so it would be nice to have support in smartmontools as well.

Re: Bug#604016: Please support 3w-sas controllers

2010-11-22 Thread Giuseppe Iuculano
Release Team, Would this be an acceptable change for a freeze exception? On 11/19/2010 01:11 PM, Florian Weimer wrote: Package: smartmontools Version: 5.39.1+svn3124-1 3w-sas is part of squeeze's kernel (for the 9750 cards), so it would be nice to have support in smartmontools as well.

Accepted chromium-browser 9.0.587.0~r66374-1 (source all i386)

2010-11-20 Thread Giuseppe Iuculano
: experimental Urgency: low Maintainer: Debian Chromium Maintainers pkg-chromium-ma...@lists.alioth.debian.org Changed-By: Giuseppe Iuculano iucul...@debian.org Description: chromium-browser - Chromium browser chromium-browser-dbg - chromium-browser debug symbols chromium-browser-inspector - page

Accepted chromium-browser 9.0.576.0~r65344-1 (source all i386)

2010-11-17 Thread Giuseppe Iuculano
: experimental Urgency: low Maintainer: Debian Chromium Maintainers pkg-chromium-ma...@lists.alioth.debian.org Changed-By: Giuseppe Iuculano iucul...@debian.org Description: chromium-browser - Chromium browser chromium-browser-dbg - chromium-browser debug symbols chromium-browser-inspector - page

[Secure-testing-commits] r15581 - data/CVE

2010-11-14 Thread Giuseppe Iuculano
Author: iuculano Date: 2010-11-14 10:50:36 + (Sun, 14 Nov 2010) New Revision: 15581 Modified: data/CVE/list Log: chromium/webkit issues Modified: data/CVE/list === --- data/CVE/list 2010-11-13 21:14:28 UTC (rev 15580)

Bug#583826: RFH: chromium-browser -- Chromium browser

2010-11-14 Thread Giuseppe Iuculano
Hi Daniel! Sorry for the late reply. On 11/05/2010 03:23 AM, Daniel Takashi wrote: I want to help the project too, if it still needed. You are welcome, please join[1] the alioth group. [1]https://alioth.debian.org/projects/pkg-chromium/ Cheers, Giuseppe. signature.asc Description: OpenPGP

Bug#583826: RFH: chromium-browser -- Chromium browser

2010-11-14 Thread Giuseppe Iuculano
Hi Daniel! Sorry for the late reply. On 11/05/2010 03:23 AM, Daniel Takashi wrote: I want to help the project too, if it still needed. You are welcome, please join[1] the alioth group. [1]https://alioth.debian.org/projects/pkg-chromium/ Cheers, Giuseppe. signature.asc Description: OpenPGP

[Secure-testing-commits] r15573 - data/CVE

2010-11-09 Thread Giuseppe Iuculano
Author: iuculano Date: 2010-11-09 18:32:00 + (Tue, 09 Nov 2010) New Revision: 15573 Modified: data/CVE/list Log: Old webkit issues are fixed in chromium Modified: data/CVE/list === --- data/CVE/list 2010-11-09 03:49:27

Bug#602355: [Pkg-chromium-maint] Bug#602355: chromium-browser: Error when both html5 enabled and signed-in at youtube

2010-11-09 Thread Giuseppe Iuculano
tags 602355 experimental thanks On 11/09/2010 04:13 AM, Jonathan Nieder wrote: Could you indicate what version of google-chrome-stable you used (from about:version)? Hopefully this has just been recently fixed upstream and we can just sync with that or cherry-pick a relevant patch. The

Bug#602355: [Pkg-chromium-maint] Bug#602355: chromium-browser: Error when both html5 enabled and signed-in at youtube

2010-11-09 Thread Giuseppe Iuculano
On 11/09/2010 05:09 PM, Jonathan Nieder wrote: Doesn't debbugs version tracking take care of that already? Yes but the tag comes in handy when you upload a new experimental version and have to check if some bugs were fixed in that suite. Cheers, Giuseppe. signature.asc Description: OpenPGP

Bug#602686: unblock: chromium-browser/6.0.472.63~r59945-2

2010-11-07 Thread Giuseppe Iuculano
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: freeze-exception -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Please unblock package chromium-browser chromium-browser (6.0.472.63~r59945-2) unstable; urgency=high * Added the missing

Bug#602693: Memory corruption in libvpx

2010-11-07 Thread Giuseppe Iuculano
Package: libvpx Version: 0.9.1-1 Severity: serious Tags: security patch -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, Christoph Diehl discovered a memory corruption in libvpx. (see the chromium blog post[0], [$1000] [60055] High Memory corruption in libvpx. Credit to Christoph Diehl.)

Bug#602693: Memory corruption in libvpx

2010-11-07 Thread Giuseppe Iuculano
On 11/07/2010 10:27 AM, Giuseppe Iuculano wrote: Patch: https://review.webmproject.org/#change,928 Please also apply the following regression patch: http://review.webmproject.org/#change,1098 Cheers, Giuseppe. signature.asc Description: OpenPGP digital signature

[Secure-testing-team] Bug#602693: Memory corruption in libvpx

2010-11-07 Thread Giuseppe Iuculano
Package: libvpx Version: 0.9.1-1 Severity: serious Tags: security patch -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, Christoph Diehl discovered a memory corruption in libvpx. (see the chromium blog post[0], [$1000] [60055] High Memory corruption in libvpx. Credit to Christoph Diehl.)

Bug#602693: Memory corruption in libvpx

2010-11-07 Thread Giuseppe Iuculano
Package: libvpx Version: 0.9.1-1 Severity: serious Tags: security patch -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, Christoph Diehl discovered a memory corruption in libvpx. (see the chromium blog post[0], [$1000] [60055] High Memory corruption in libvpx. Credit to Christoph Diehl.)

Bug#602693: Memory corruption in libvpx

2010-11-07 Thread Giuseppe Iuculano
On 11/07/2010 10:27 AM, Giuseppe Iuculano wrote: Patch: https://review.webmproject.org/#change,928 Please also apply the following regression patch: http://review.webmproject.org/#change,1098 Cheers, Giuseppe. signature.asc Description: OpenPGP digital signature

Bug#602686: unblock: chromium-browser/6.0.472.63~r59945-2

2010-11-07 Thread Giuseppe Iuculano
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: freeze-exception -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Please unblock package chromium-browser chromium-browser (6.0.472.63~r59945-2) unstable; urgency=high * Added the missing

Bug#602609: CVE-2010-4008: does not well process a malformed XPATH

2010-11-06 Thread Giuseppe Iuculano
Package: libxml2 Version: 2.7.7.dfsg-4 Severity: serious Tags: security -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, it was discovered that libxml2 does not well process a malformed XPATH, causing crash and allowing arbitrary code execution. Patch:

Bug#602609: Acknowledgement (CVE-2010-4008: does not well process a malformed XPATH)

2010-11-06 Thread Giuseppe Iuculano
fixed 602609 2.7.8.dfsg-1 thanks It was fixed in 2.7.8 Cheers, Giuseppe signature.asc Description: OpenPGP digital signature

[Secure-testing-team] Bug#602609: CVE-2010-4008: does not well process a malformed XPATH

2010-11-06 Thread Giuseppe Iuculano
Package: libxml2 Version: 2.7.7.dfsg-4 Severity: serious Tags: security -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, it was discovered that libxml2 does not well process a malformed XPATH, causing crash and allowing arbitrary code execution. Patch:

Bug#602609: CVE-2010-4008: does not well process a malformed XPATH

2010-11-06 Thread Giuseppe Iuculano
Package: libxml2 Version: 2.7.7.dfsg-4 Severity: serious Tags: security -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, it was discovered that libxml2 does not well process a malformed XPATH, causing crash and allowing arbitrary code execution. Patch:

Bug#602609: Acknowledgement (CVE-2010-4008: does not well process a malformed XPATH)

2010-11-06 Thread Giuseppe Iuculano
fixed 602609 2.7.8.dfsg-1 thanks It was fixed in 2.7.8 Cheers, Giuseppe signature.asc Description: OpenPGP digital signature

Accepted chromium-browser 6.0.472.63~r59945-2 (source all amd64)

2010-11-05 Thread Giuseppe Iuculano
: unstable Urgency: high Maintainer: Debian Chromium Maintainers pkg-chromium-ma...@lists.alioth.debian.org Changed-By: Giuseppe Iuculano iucul...@debian.org Description: chromium-browser - Chromium browser chromium-browser-dbg - chromium-browser debug symbols chromium-browser-inspector - page

Bug#601398: unblock: chromium-browser/6.0.472.63~r59945-1

2010-10-25 Thread Giuseppe Iuculano
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: freeze-exception -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Please unblock package chromium-browser * New stable microrelease. * Allow to choose whether links are opened in a new link or

Bug#601398: unblock: chromium-browser/6.0.472.63~r59945-1

2010-10-25 Thread Giuseppe Iuculano
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: freeze-exception -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Please unblock package chromium-browser * New stable microrelease. * Allow to choose whether links are opened in a new link or

Accepted chromium-browser 6.0.472.63~r59945-1 (source all amd64)

2010-10-20 Thread Giuseppe Iuculano
: unstable Urgency: high Maintainer: Debian Chromium Maintainers pkg-chromium-ma...@lists.alioth.debian.org Changed-By: Giuseppe Iuculano iucul...@debian.org Description: chromium-browser - Chromium browser chromium-browser-dbg - chromium-browser debug symbols chromium-browser-inspector - page

[Secure-testing-commits] r15441 - data/CVE

2010-10-08 Thread Giuseppe Iuculano
Author: iuculano Date: 2010-10-08 08:02:08 + (Fri, 08 Oct 2010) New Revision: 15441 Modified: data/CVE/list Log: chromium/webkit issues Modified: data/CVE/list === --- data/CVE/list 2010-10-07 21:14:44 UTC (rev 15440)

Re: RFS: bareftp (NMU, RC bugfix)

2010-10-07 Thread Giuseppe Iuculano
On 10/06/2010 08:23 PM, gustavo panizzo gfa wrote: The upload would fix these bugs: 598284 security related bug, CVE-2010-3350 I've uploaded your package, thanks for your work. Cheers, Giuseppe. signature.asc Description: OpenPGP digital signature

[Secure-testing-commits] r15436 - data/CVE

2010-10-07 Thread Giuseppe Iuculano
Author: iuculano Date: 2010-10-07 10:30:39 + (Thu, 07 Oct 2010) New Revision: 15436 Modified: data/CVE/list Log: CVE-2010-3350 fixed in sid Modified: data/CVE/list === --- data/CVE/list 2010-10-07 07:08:10 UTC (rev

Bug#581391: [Pkg-chromium-maint] Bug#581391: Workaround

2010-10-07 Thread Giuseppe Iuculano
On 10/06/2010 04:00 PM, Sam Morris wrote: Just realised there is an obvious workaround for this problem: set a custom command 'chromium-browser --new-window' as the preferred web browser. I bet I should play with /usr/share/gnome-control-center/default-apps/chromium-browser.xml, tab-command

Accepted chromium-browser 7.0.544.0~r61416-1 (source all i386)

2010-10-06 Thread Giuseppe Iuculano
: experimental Urgency: low Maintainer: Debian Chromium Maintainers pkg-chromium-ma...@lists.alioth.debian.org Changed-By: Giuseppe Iuculano iucul...@debian.org Description: chromium-browser - Chromium browser chromium-browser-dbg - chromium-browser debug symbols chromium-browser-inspector - page

Re: [Bug 655539] [NEW] BIND9 can't read /etc/smbind/smbind.conf

2010-10-06 Thread Giuseppe Iuculano
On 10/06/2010 09:28 AM, Lazy wrote: Oct 6 10:26:19 lucid-lynx named[2866]: /etc/bind/named.conf.local:9: open: /etc/smbind/smbind.conf: permission denied As write in /usr/share/doc/smbind/README.Debian, probably you want run: /usr/share/doc/smbind/README.Debian Cheers, Giuseppe -- BIND9

[Secure-testing-commits] r15416 - in data: . CVE

2010-10-04 Thread Giuseppe Iuculano
Author: iuculano Date: 2010-10-04 10:02:06 + (Mon, 04 Oct 2010) New Revision: 15416 Modified: data/CVE/list data/embedded-code-copies Log: CVE-2010-3071 fixed in squeeze criticalmass embeds curl Modified: data/CVE/list ===

Bug#598570: [Pkg-chromium-maint] Bug#598570: chromium-browser: segfaults at startup

2010-10-04 Thread Giuseppe Iuculano
On 10/04/2010 01:54 PM, Laurent Fousse wrote: LD_LIBRARY_PATH=/usr/lib/chromium-browser:/usr/lib/xulrunner-1.9.1:/usr/lib/chromium-browser #

Bug#598570: [Pkg-chromium-maint] Bug#598570: chromium-browser: segfaults at startup

2010-10-04 Thread Giuseppe Iuculano
On 10/04/2010 11:16 AM, Laurent Fousse wrote: Same problem. New script attached. Regards, Laurent. could you try also chromium-browser --disable-plugins please? Cheers, Giuseppe. signature.asc Description: OpenPGP digital signature

Bug#599061: Please update the package to dynamically link to the system curl

2010-10-04 Thread Giuseppe Iuculano
Package: criticalmass Version: 1:1.0.0-1.4 Severity: important -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 This package statically links against the curl system copy. This can lead to problems in case of security issues, please update the package to dynamically link to the system curl.

Bug#598570: [Pkg-chromium-maint] Bug#598570: chromium-browser: segfaults at startup

2010-10-04 Thread Giuseppe Iuculano
On 10/04/2010 01:29 PM, Laurent Fousse wrote: * Giuseppe Iuculano [Mon, Oct 04, 2010 at 11:39:46AM +0200]: On 10/04/2010 11:16 AM, Laurent Fousse wrote: # Env: # LD_LIBRARY_PATH=/usr/lib/chromium-browser:/usr/lib/xulrunner-1.9.1:/kora/home/casys/lfousse/local_amd64/lib:/usr/local/cuda

Bug#598570: [Pkg-chromium-maint] Bug#598570: chromium-browser: segfaults at startup

2010-10-04 Thread Giuseppe Iuculano
On 10/04/2010 11:21 AM, Laurent Fousse wrote: * Giuseppe Iuculano [Mon, Oct 04, 2010 at 11:19:31AM +0200]: On 10/04/2010 11:16 AM, Laurent Fousse wrote: Same problem. New script attached. Regards, Laurent. could you try also chromium-browser --disable-plugins please? Still the same

Bug#598570: [Pkg-chromium-maint] Bug#598570: chromium-browser: segfaults at startup

2010-10-04 Thread Giuseppe Iuculano
On 10/04/2010 11:16 AM, Laurent Fousse wrote: # Env: # LD_LIBRARY_PATH=/usr/lib/chromium-browser:/usr/lib/xulrunner-1.9.1:/kora/home/casys/lfousse/local_amd64/lib:/usr/local/cuda/lib64 #

Bug#598570: [Pkg-chromium-maint] Bug#598570: chromium-browser: segfaults at startup

2010-10-03 Thread Giuseppe Iuculano
On 09/30/2010 03:32 PM, Laurent Fousse wrote: Does this happen also with chromium-browser --temp-profile ? Yes. Laurent. Please run the debugger again with run --single-process Cheers, Giuseppe. signature.asc Description: OpenPGP digital signature

Bug#595476: [Pkg-chromium-maint] Bug#595476: Some tabs just spin forever, and those URLs can never be loaded without restarting the browser

2010-10-03 Thread Giuseppe Iuculano
Ciao Enrico, thanks for the bug report. On 09/04/2010 11:49 AM, Enrico Zini wrote: I am sorry this bug report is not very precise, but it is a very annoying issue that I haven't managed to pinpoint in a deterministic way. Sometimes, chromium decides that it does not want to load a URL. In

Bug#598570: [Pkg-chromium-maint] Bug#598570: chromium-browser: segfaults at startup

2010-09-30 Thread Giuseppe Iuculano
On 09/30/2010 09:57 AM, Laurent Fousse wrote: I can't run chromium-browser, it just segfaults at startup: lfou...@bourrasque:~% chromium-browser zsh: segmentation fault chromium-browser Does this happen also with chromium-browser --temp-profile ? Cheers, Giuseppe. signature.asc

Accepted couchdb 0.11.0-2.1 (source i386)

2010-09-26 Thread Giuseppe Iuculano
-By: Giuseppe Iuculano iucul...@debian.org Description: couchdb- RESTful document oriented database Closes: 570013 Changes: couchdb (0.11.0-2.1) unstable; urgency=high . * Non-maintainer upload by the Security Team. * CVE-2010-2234: fix Cross-site request forgery vulnerability

Bug#498693: [60136ec] Fix for Bug#498693 committed to git

2010-09-26 Thread Giuseppe Iuculano
On 09/24/2010 02:36 PM, Luís Picciochi Oliveira wrote: - On my diff, I moved the /usr/share/amule/skins directory from the amule package to amule-common. You seem to have copied it instead, so now it is provided by both packages, although amule depends on amule-common (and this directory will

Bug#570013: couchdb: diff for NMU version 0.11.0-2.1

2010-09-26 Thread Giuseppe Iuculano
/changelog @@ -1,3 +1,11 @@ +couchdb (0.11.0-2.1) unstable; urgency=high + + * Non-maintainer upload by the Security Team. + * CVE-2010-2234: fix Cross-site request forgery vulnerability +(Closes: #570013) + + -- Giuseppe Iuculano iucul...@debian.org Sun, 26 Sep 2010 11:09:53 +0200 + couchdb

[Secure-testing-commits] r15368 - data/CVE

2010-09-23 Thread Giuseppe Iuculano
Author: iuculano Date: 2010-09-23 16:28:14 + (Thu, 23 Sep 2010) New Revision: 15368 Modified: data/CVE/list Log: chromium/webkit issues Modified: data/CVE/list === --- data/CVE/list 2010-09-23 12:11:39 UTC (rev 15367)

[Secure-testing-commits] r15369 - data/CVE

2010-09-23 Thread Giuseppe Iuculano
Author: iuculano Date: 2010-09-23 16:46:04 + (Thu, 23 Sep 2010) New Revision: 15369 Modified: data/CVE/list Log: CVE-2010-3476 fixed in otrs2 2.4.8+dfsg1-1 NFUs Modified: data/CVE/list === --- data/CVE/list 2010-09-23

Bug#597856: CVE-2010-3412: memory overrun issue in CPU profiler

2010-09-23 Thread Giuseppe Iuculano
Package: libv8 Severity: serious Tags: security patch -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, the following CVE (Common Vulnerabilities Exposures) id was published for libv8. CVE-2010-3412[0]: | Race condition in the console implementation in Google Chrome before | 6.0.472.59 has

Bug#597856: CVE-2010-3412: memory overrun issue in CPU profiler

2010-09-23 Thread Giuseppe Iuculano
On 09/23/2010 06:18 PM, Jérémy Lal wrote: Thank you Giuseppe, i'll fix this tonight. You are welcome. Feel free to ping me if you need a sponsor. Cheers, Giuseppe. signature.asc Description: OpenPGP digital signature

[Secure-testing-team] Bug#597856: CVE-2010-3412: memory overrun issue in CPU profiler

2010-09-23 Thread Giuseppe Iuculano
Package: libv8 Severity: serious Tags: security patch -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, the following CVE (Common Vulnerabilities Exposures) id was published for libv8. CVE-2010-3412[0]: | Race condition in the console implementation in Google Chrome before | 6.0.472.59 has

Bug#597856: CVE-2010-3412: memory overrun issue in CPU profiler

2010-09-23 Thread Giuseppe Iuculano
Package: libv8 Severity: serious Tags: security patch -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, the following CVE (Common Vulnerabilities Exposures) id was published for libv8. CVE-2010-3412[0]: | Race condition in the console implementation in Google Chrome before | 6.0.472.59 has

Bug#597856: CVE-2010-3412: memory overrun issue in CPU profiler

2010-09-23 Thread Giuseppe Iuculano
On 09/23/2010 06:18 PM, Jérémy Lal wrote: Thank you Giuseppe, i'll fix this tonight. You are welcome. Feel free to ping me if you need a sponsor. Cheers, Giuseppe. signature.asc Description: OpenPGP digital signature

[Secure-testing-commits] r15347 - data/CVE

2010-09-19 Thread Giuseppe Iuculano
Author: iuculano Date: 2010-09-19 08:51:46 + (Sun, 19 Sep 2010) New Revision: 15347 Modified: data/CVE/list Log: changeset for CVE-2010-1807 Modified: data/CVE/list === --- data/CVE/list 2010-09-18 14:32:25 UTC (rev

[Secure-testing-commits] r15346 - data/CVE

2010-09-18 Thread Giuseppe Iuculano
Author: iuculano Date: 2010-09-18 14:32:25 + (Sat, 18 Sep 2010) New Revision: 15346 Modified: data/CVE/list Log: CVE-2010-2790 fixed some details for CVE-2010-1807 Modified: data/CVE/list === --- data/CVE/list

Accepted chromium-browser 6.0.472.62~r59676-1 (source all amd64)

2010-09-18 Thread Giuseppe Iuculano
: unstable Urgency: low Maintainer: Debian Chromium Maintainers pkg-chromium-ma...@lists.alioth.debian.org Changed-By: Giuseppe Iuculano iucul...@debian.org Description: chromium-browser - Chromium browser chromium-browser-dbg - chromium-browser debug symbols chromium-browser-inspector - page inspector

Bug#580681: [Pkg-chromium-maint] Bug#580681:

2010-09-18 Thread Giuseppe Iuculano
tags 580681 moreinfo thanks On 06/01/2010 10:38 AM, Luk Bettale wrote: I have the same bug to. The bug only appears when the gtk-key-theme-name is set to Emacs AND when my keyboard layout is set to 'fr (oss)'. The space bar does work well when the layout is 'us (alt-intl)' or 'fr (latin9)'

Bug#594734: [Pkg-chromium-maint] Bug#594734: elinks works, but chromium-browser does not start

2010-09-18 Thread Giuseppe Iuculano
tags 594734 moreinfo thanks On 08/28/2010 10:19 PM, yellow wrote: I am running linux on a HPC mini and the internet browser chromium is not working. I get a first popup window, and cannot click into to say start. Could you say me if this is happening with chromium 6 please? Cheers,

[Secure-testing-commits] r15334 - data/CVE

2010-09-16 Thread Giuseppe Iuculano
Author: iuculano Date: 2010-09-16 15:13:01 + (Thu, 16 Sep 2010) New Revision: 15334 Modified: data/CVE/list Log: CVE-2010-3081 kernel: 64-bit Compatibility Mode Stack Pointer Underflow Modified: data/CVE/list === ---

[Secure-testing-commits] r15329 - data/CVE

2010-09-15 Thread Giuseppe Iuculano
Author: iuculano Date: 2010-09-15 13:49:22 + (Wed, 15 Sep 2010) New Revision: 15329 Modified: data/CVE/list Log: apple/webkit duplicates Modified: data/CVE/list === --- data/CVE/list 2010-09-15 13:37:20 UTC (rev 15328)

Accepted chromium-browser 6.0.472.59~r59126-1 (source all amd64)

2010-09-15 Thread Giuseppe Iuculano
: unstable Urgency: low Maintainer: Debian Chromium Maintainers pkg-chromium-ma...@lists.alioth.debian.org Changed-By: Giuseppe Iuculano iucul...@debian.org Description: chromium-browser - Chromium browser chromium-browser-dbg - chromium-browser debug symbols chromium-browser-inspector - page inspector

Re: chromium not in Squeeze: a bit of communication needed?

2010-09-15 Thread Giuseppe Iuculano
On 09/15/2010 08:23 PM, Mehdi Dogguy wrote: I think it's easy to see if we will have to accept a new major release of Chromium in Squeeze (after its release): Would you be able to backport any fix from 6.x to 3.x? If they keep releasing every 3 months, you'll have to deal with a more distant

<    1   2   3   4   5   6   7   8   9   10   >