Bug#383296: manpages: nlmsg_pid/nl_pid is *not* the process ID

2007-04-25 Thread Martin Schulze
Herbert Xu wrote: On Tue, Sep 26, 2006 at 02:19:32PM +0200, Michael Kerrisk wrote: The man page netlink(7) refers to nlmsg_pid and nl_pid as process IDs. This is completely incorrect. Treating them as process IDs can lead to security holes. So please ask upstream to correct this as

Accepted manpages 2.44-1 (source all)

2007-04-22 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Format: 1.7 Date: Sun, 22 Apr 2007 18:38:34 +0200 Source: manpages Binary: manpages manpages-dev Architecture: source all Version: 2.44-1 Distribution: unstable Urgency: low Maintainer: Martin Schulze [EMAIL PROTECTED] Changed-By: Martin Schulze

Re: CD/DVD for Linuxtag? Linux Magazin spezial?

2007-04-21 Thread Martin Schulze
Marko Jung|LinuxTag wrote: Hi, Also sprach Thomas Lange am 17.04.2007: Are there any plans for creating a CD/DVD with etch for Linuxtag? Any plans for making a Linux Magazin Spezial Heft with Debian? LinuxTag is still looking for somebody who masters the official LinuxTag-DVD this

Re: stable / backports (Re: When Debian 4.1 will arrive... will anyone care?)

2007-04-20 Thread Martin Schulze
Craig Sanders wrote: i just don't see why people like to fool themselves that they're still running 'stable' when they install stuff from backports. they're not. Maybe the difference is that the overall system is still stable with all of its benefits, but with only a few packages pulled in from

Accepted sendfile 2.1b-4 (source i386)

2007-03-31 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Format: 1.7 Date: Sat, 31 Mar 2007 13:47:33 +0200 Source: sendfile Binary: sendfile Architecture: source i386 Version: 2.1b-4 Distribution: unstable Urgency: low Maintainer: Martin Schulze [EMAIL PROTECTED] Changed-By: Martin Schulze [EMAIL PROTECTED

Re: invalid link?

2007-03-31 Thread Martin Schulze
Klaus Ade Johnstad wrote: On the page http://packages.debian.org/experimental/editors/openoffice.org there is a link pointing to http://openoffice.debian.net/ which seems not to exist. That's from the packages' description - contact the maintainer. Regards, Joey -- It's

Re: I need a mentor for SoC

2007-03-29 Thread Martin Schulze
Runa Agate Sandvik wrote: Hi, I need a mentor for my Summer of Code proposal[1]. Please reply to this off list if you have any questions or want to help me out :) [1]: http://wiki.debian.org/SummerOfCode2007/WebCleanup I'm willing to co-mentor this, although you'll probably get a lot of

[Full-disclosure] [SECURITY] [DSA 1270-2] New OpenOffice.org packages fix several vulnerabilities

2007-03-28 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1270-2[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze March 28th, 2007

Re: Expulsion process: Sven Luther - Decision

2007-03-28 Thread Martin Schulze
Sven Luther wrote: Taking this to -project, since i am no more a DD. Not sure if all readers here have the original. Sven has not been expulsed and hence is still a DD. Regards, Joey -- Life is a lot easier when you have someone to share it with. -- Sean Perry -- To UNSUBSCRIBE,

[SECURITY] [DSA 1270-2] New OpenOffice.org packages fix several vulnerabilities

2007-03-28 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1270-2[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze March 28th, 2007

Re: SoC Project Debian Web Infrastructure Integration: Analysis and Design RFC

2007-03-27 Thread Martin Schulze
Leandro Doctors wrote: I am not the only one who thinks that there are problems regarding Debian's “web face”. This issue has been adressed by two candidates for this year's Could you name them? My contribution to that would be a set of **suggestions** about it (and how to implement it).

Re: Please remove live-package from Etch

2007-03-22 Thread Martin Schulze
Holger Levsen wrote: Holger (who's also a stable ion3 user. Or rather, have been.) Isn't that an oxymoron qua author? Regards, Joey -- The good thing about standards is that there are so many to choose from. -- Andrew S. Tanenbaum -- To UNSUBSCRIBE, email to

Re: Setting up a staging ground for etch release

2007-03-21 Thread Martin Schulze
Gustavo Franco wrote: *shrug* Parse error, as I said... Parse error, simple because you and I are not the target of the proposed feature. Hmm. That could have contributed to the parse error. to be saner, IMHO. Just ask on debian-user. Btw, I though we wrote a No. I'm asking on

Re: A contest for a new css

2007-03-21 Thread Martin Schulze
Bas Zoetekouw wrote: Actually, that's not a bad idea at all. There are lots of people in the past who have suggested that that would like to change the layout a bit, so why not give people a change to see what they come up with. However, if we want to create such a content, I think it is

Re: Setting up a staging ground for etch release

2007-03-21 Thread Martin Schulze
Gustavo Franco wrote: PS: There are indeed some information which are hard to find. But testing images are not affected! Now I'm understanding why more and more people start new Debian web pages with content that should be official instead cooperate with debian-www mailing list and add the

[Full-disclosure] [SECURITY] [DSA 1270-1] New OpenOffice.org packages fix several vulnerabilities

2007-03-20 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1270-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze March 20th, 2007

Re: SoC: website cleanup

2007-03-20 Thread Martin Schulze
Gustavo Franco wrote: This sounds more like debian-website-overthrow than debian-website-cleanup. I'd suggest maybe tidying up the design and navigation and merging/splitting some of the content as appropriate, but I'm not sure whether totally changing it all is a good idea. I think

[SECURITY] [DSA 1270-1] New OpenOffice.org packages fix several vulnerabilities

2007-03-20 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1270-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze March 20th, 2007

[SECURITY] [DSA 1269-1] New lookup-el packages fix insecure temporary file

2007-03-19 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1269-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze March 18th, 2007

[Full-disclosure] [SECURITY] [DSA 1269-1] New lookup-el packages fix insecure temporary file

2007-03-18 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1269-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze March 18th, 2007

Re: CVS webwml/english/mirror

2007-03-18 Thread Martin Schulze
CVS User nori wrote: Update of /cvs/webwml/webwml/english/mirror In directory gluck:/tmp/cvs-serv20775 Modified Files: submit.wml Log Message: Correct a place of a comma. --- /cvs/webwml/webwml/english/mirror/submit.wml 2007/02/18 23:41:52 1.58 +++

[Full-disclosure] [SECURITY] [DSA 1268-1] New libwpd packages fix arbitrary code execution

2007-03-17 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1268-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze March 17th, 2007

Accepted mailto 1.3.2-2 (source i386)

2007-03-17 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Format: 1.7 Date: Sat, 17 Mar 2007 12:55:10 +0100 Source: mailto Binary: mailto Architecture: source i386 Version: 1.3.2-2 Distribution: unstable Urgency: low Maintainer: Martin Schulze [EMAIL PROTECTED] Changed-By: Martin Schulze [EMAIL PROTECTED

Bug#415134: Mailto uses wrong hostname

2007-03-17 Thread Martin Schulze
Rob van der Putten wrote: Package: mailto Version: 1.2.6 Version: 1.3.2 Hi there Mailto uses gethostbyname() to get the hostname; /* Get the local hostname for later insertion */ gethostname(localhost, sizeof(localhost)); if ( index(localhost, '.')) {

Bug#415134: Mailto uses wrong hostname

2007-03-17 Thread Martin Schulze
Rob van der Putten wrote: Hi there On Sat, 17 Mar 2007, Martin Schulze wrote: Please be more verbose. Why should gethostname() not return the valid hostname of the host it runs on? If it doesn't return something useful, I'd expect /etc/hostname and thus the hostname setting

Re: Setting up a staging ground for etch release

2007-03-17 Thread Martin Schulze
Gustavo Franco wrote: On 3/16/07, Frank Lichtenheld [EMAIL PROTECTED] wrote: Hi. (...) On the other hand it would be nice to test something like that anyway so people can perhaps use this method for other tasks (redesign anyone ;) ?). Hi, Redesign and tests to move into svn? :-) I

Re: Setting up a staging ground for etch release

2007-03-17 Thread Martin Schulze
Gustavo Franco wrote: Re modern design and stuff: Please define problems with the current design and propose improvements. This has been asked all volunteers who wanted to apply a complete redesign of the web pages. The smaller the changes the easier they can be applied and the more likely

[SECURITY] [DSA 1268-1] New libwpd packages fix arbitrary code execution

2007-03-17 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1268-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze March 17th, 2007

Accepted manpages 2.43-0 (source all)

2007-03-16 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Format: 1.7 Date: Fri, 16 Mar 2007 14:39:47 +0100 Source: manpages Binary: manpages manpages-dev Architecture: source all Version: 2.43-0 Distribution: unstable Urgency: low Maintainer: Martin Schulze [EMAIL PROTECTED] Changed-By: Martin Schulze

Re: ajt's anti-rebuttal

2007-03-16 Thread Martin Schulze
Anthony Towns wrote: On Thu, Mar 15, 2007 at 06:35:59PM +0100, Andreas Barth wrote: * Anthony Towns (aj@azure.humbug.org.au) [070314 19:25]: Since then we've also had Debian Times established I don't see at all how this is realated to you being DPL - in fact, I would have prefered a more

Accepted manpages 2.42-1 (source all)

2007-03-14 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Format: 1.7 Date: Wed, 14 Mar 2007 10:10:09 +0100 Source: manpages Binary: manpages manpages-dev Architecture: source all Version: 2.42-1 Distribution: unstable Urgency: low Maintainer: Martin Schulze [EMAIL PROTECTED] Changed-By: Martin Schulze

Accepted manpages 2.41-1 (source all)

2007-03-12 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Format: 1.7 Date: Mon, 12 Mar 2007 19:50:07 +0100 Source: manpages Binary: manpages manpages-dev Architecture: source all Version: 2.41-1 Distribution: unstable Urgency: low Maintainer: Martin Schulze [EMAIL PROTECTED] Changed-By: Martin Schulze

Re: Cebit booth

2007-03-12 Thread Martin Schulze
Alexander Schmehl wrote: While we have the machines we need one monitor, keyboards, mouse, cable stuff. Whoever has some of that - please speak up. Somewhere from that area who has (one) TFT, a bit of mouse and keyboard and cable stuff he can give us for the booth? Well... since we

[Full-disclosure] [SECURITY] [DSA 1265-1] New Mozilla packages fix several vulnerabilities

2007-03-10 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1265-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze March 10th, 2007

Re: Debian Project Leader Elections 2007: Draft ballot

2007-03-10 Thread Martin Schulze
Marc Haber wrote: Or are we going to require an IQ test before people allowing to vote, understanding the ballot being one of the test? Seconded. Regards, Joey -- The MS-DOS filesystem is nice for removable media. -- H. Peter Anvin signature.asc Description: Digital signature

[SECURITY] [DSA 1265-1] New Mozilla packages fix several vulnerabilities

2007-03-10 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1265-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze March 10th, 2007

Bug#413797: OpenBSE inetd configure problem

2007-03-07 Thread Martin Schulze
Package: openbsd-inetd Version: 0.20050402-5 It seems that the postinst script of openbsd-inetd is not able to grok a situation in which the package is already installed and the server running. This is what I get: finlandia:~# apt-get dist-upgrade -y Reading package lists... Done Building

Re: Permission to upload a new hylafax package

2007-02-21 Thread Martin Schulze
Steve Langasek wrote: On Tue, Feb 20, 2007 at 02:55:41PM +0100, Giuseppe Sacco wrote: Hi all, hylafax 4.3.2 has just been released[1]. This is a minor update but fixes a few bug forwarded upstream and simplify the way Debian package may be done. The more important fix is that PAM will

Accepted libgsf 1.11.1-1sarge1 (source powerpc)

2007-02-17 Thread Martin Schulze
Urgency: high Maintainer: Martin Schulze [EMAIL PROTECTED] Changed-By: Martin Schulze [EMAIL PROTECTED] Description: libgsf-1 - Structured File Library - runtime version libgsf-1-dbg - Structured File Library - debugging files (basic version) libgsf-1-dev - Structured File Library - development

Re: BREAKING NEWS: Debian developers aren't trusted

2007-02-13 Thread Martin Schulze
Hamish Moffatt wrote: ] I am really upset by the way the ARM build daemons are managed. The ] packages are not uploaded regularly, with sometimes three days between ] two uploads. [...] ] ] All of that resulted in ARM being the slowest architecture to build ] packages. [...]

Re: BREAKING NEWS: Debian developers aren't trusted

2007-02-13 Thread Martin Schulze
Frank Küster wrote: I don't imagine Aurelien's any less upset, but as far as I can see, there aren't actual problems with the way arm's keeping up at present: Another problem is that the buildd email mailbox is apparently piped to /dev/null. FWIW, buildd mail is processed by a

Debian Weekly News - February 13th, 2007

2007-02-13 Thread Martin Schulze
page. Martin Schulze [21]proposed to alter the menu even more. 17. http://lists.debian.org/debian-www/2007/01/msg00116.html 18. http://www.debian.org/devel/website/stats/ 19. http://lists.debian.org/debian-www/2007/02/msg00020.html 20. http://www.debian.org/vote/ 21. http://lists.debian.org

Re: [GR] DD should be allowed to perform binary-only uploads

2007-02-12 Thread Martin Schulze
Wesley J. Landaker wrote: On Monday 12 February 2007 09:08, Stephen Gran wrote: [...] reproducibility will suffer. The fact that it failed to run the binary correctly in this failure instance is good. But another day, it may fail to correctly run gcc, and that would be bad if it exited 0

Accepted manpages 2.40-1 (source all)

2007-02-11 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Format: 1.7 Date: Sun, 11 Feb 2007 08:34:14 +0100 Source: manpages Binary: manpages manpages-dev Architecture: source all Version: 2.40-1 Distribution: unstable Urgency: low Maintainer: Martin Schulze [EMAIL PROTECTED] Changed-By: Martin Schulze

Re: [GR] DD should be allowed to perform binary-only uploads

2007-02-11 Thread Martin Schulze
Note that if you can get SPI to transfer the debian.org zone to other DNS servers than the current ones, you can NMU the infrastructure. Andreas Barth [EMAIL PROTECTED] wrote: I heavily disagree to that. The current servers are owned by Debian or sponsored to Debian by some people. So

Re: BREAKING NEWS: Debian developers aren't trusted

2007-02-11 Thread Martin Schulze
Francesco P. Lovergine wrote: On Sun, Feb 11, 2007 at 04:24:45AM +0200, Kalle Kivimaa wrote: Josselin Mouette [EMAIL PROTECTED] writes: Personally, I don't like either of the checks, but I've seen zero effort from Aurelian and friends to demonstrate they can be trusted, Quoting

Re: [GR] DD should be allowed to perform binary-only uploads

2007-02-11 Thread Martin Schulze
Julien BLACHE wrote: Note that if you can get SPI to transfer the debian.org zone to other DNS servers than the current ones, you can NMU the infrastructure. But (probably) only if it was at the request of the DPL. Could be at the request of the Project, via a GR I think, if the DPL

Re: [GR] DD should be allowed to perform binary-only uploads

2007-02-11 Thread Martin Schulze
Julien BLACHE wrote: Martin Schulze [EMAIL PROTECTED] wrote: Unlikely. SPI usually has a defined authorisationship with an associated project, this refers to people, not the project as a whole or their developers or their internal voting results. However, a GR should be able to kick

Bug#409907: Installing lpr over lprng doesn't work

2007-02-09 Thread Martin Schulze
Craig Small wrote: On Thu, Feb 08, 2007 at 09:36:43AM -0600, Adam Majer wrote: Martin Schulze wrote: I can't see a way of lprng postinst saying 'oh lpr is being installed' and not deleting the directory. I feared that... Maybe lprng postinst can check when it's going from rc

Bug#409907: Installing lpr over lprng doesn't work

2007-02-07 Thread Martin Schulze
Craig Small wrote: On Wed, Feb 07, 2007 at 07:36:47AM +0100, Martin Schulze wrote: Purge means purge, but it shouldnt purge files/directories now owned by another package. lpr/lprng are a special case I guess. Hmm, yes I see the problem now. So either lprng has to orphan the spool

Re: [SECURITY] [DSA 1258-1] New Mozilla Firefox packages fix several vulnerabilities

2007-02-07 Thread Martin Schulze
Alexander Sack wrote: On Wed, Feb 07, 2007 at 08:36:56AM +0100, Martin Schulze wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1258-1[EMAIL PROTECTED

[SECURITY] [DSA 1258-1] New Mozilla Firefox packages fix several vulnerabilities

2007-02-07 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1258-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze February 7th, 2007

[Full-disclosure] [SECURITY] [DSA 1258-1] New Mozilla Firefox packages fix several vulnerabilities

2007-02-06 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1258-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze February 7th, 2007

Bug#409907: Installing lpr over lprng doesn't work

2007-02-06 Thread Martin Schulze
Package: lpr, lprng Version: 2006.11.04, 3.8.28dfsg.1-1 Severity: important Installing lpr (by removing lprng) will leave you with no working lpr package since /var/spool/lpd is owned daemon.lp with mode 700. It should've been lp.lp with mode 2775. Purging lprng afterwards will remove

Bug#409907: Installing lpr over lprng doesn't work

2007-02-06 Thread Martin Schulze
Craig Small wrote: On Tue, Feb 06, 2007 at 10:19:51AM +0100, Martin Schulze wrote: 2. lprng.postrm should not remove /var/spool/lpd upon purge I cannot see the justification for this, purge means purge right? Purge means purge, but it shouldnt purge files/directories now owned by another

Bug#402592: foo

2007-02-04 Thread Martin Schulze
tags 402592 wontfix upstream severity normal thanks After being pestered about this bug I've contacted Werner on this regard. He told me that this can happen with all GNU utilities and is an inherent feature as they all operate without fixed limits whenever possible. For example, a user ID in

Bug#402592: foo

2007-02-04 Thread Martin Schulze
tags 402592 -wontfix pending thanks Martin Schulze wrote: After being pestered about this bug I've contacted Werner on this regard. He told me that this can happen with all GNU utilities and is an inherent feature as they all operate without fixed limits whenever possible. For example, a user

Re: Lenght of vote bar in http://www.debian.org/vote/

2007-02-04 Thread Martin Schulze
Manoj Srivastava wrote: As time and GR's pass, the length of the navigation bar for the vote pages keeps increasing. Considering that the list of votes is getting long, and that the most recent votes/elections are now at the bottom of the page, perhaps it is time to consider a

Re: Debian and software patents (Was: Re: how to donate free program for Debian?)

2007-02-02 Thread Martin Schulze
Daniel Ruoso wrote: Qua, 2007-01-31 às 09:21 +0100, Martin Schulze escreveu: I seem to recall Keving mentioning a patent minefield, which I would interpret not only as an area of computer science in which several patents exist but also that they are tried to be enforced

Re: Conflicting information on current Debian release

2007-02-02 Thread Martin Schulze
Steve Langasek wrote: On Fri, Feb 02, 2007 at 05:10:47PM -0500, Bob Kline wrote: The Debian home page (http://www.debian.org/) notes the announcement of the Upcoming Release of Debian GNU/Linux 4.0, and the page linked by that note says The Debian project confirms December 2006 as the

Bug#409147: glibc tzdata2005b out of date for 4 Canadian Provinces.

2007-01-31 Thread Martin Schulze
merge 409147 409148 thanks David Broome wrote: Package: glibc Version: glibc-2.3.2.ds1-22sarge4 Severity: critical Hello - tzdata in glibc for stable is based on tzdata2006b (from edits in 2.3.2.ds1-22sarge1), this does not have the correct PST changes for this year for 4 Canadian

Re: how to donate free program for Debian?

2007-01-31 Thread Martin Schulze
Manoj Srivastava wrote: On Tue, 30 Jan 2007 09:21:12 -0800, Kevin B McCarty [EMAIL PROTECTED] said: Cognaxon [EMAIL PROTECTED] wrote: Hello, we would like to donate our free small program called WSQ viewer (for Linux) to be distributed with Debian CD/DVD. The short description

Bug#409147: glibc tzdata2005b out of date for 4 Canadian Provinces.

2007-01-31 Thread Martin Schulze
merge 409147 409148 thanks David Broome wrote: Package: glibc Version: glibc-2.3.2.ds1-22sarge4 Severity: critical Hello - tzdata in glibc for stable is based on tzdata2006b (from edits in 2.3.2.ds1-22sarge1), this does not have the correct PST changes for this year for 4 Canadian

Bug#409147: glibc tzdata2005b out of date for 4 Canadian Provinces.

2007-01-31 Thread Martin Schulze
merge 409147 409148 thanks David Broome wrote: Package: glibc Version: glibc-2.3.2.ds1-22sarge4 Severity: critical Hello - tzdata in glibc for stable is based on tzdata2006b (from edits in 2.3.2.ds1-22sarge1), this does not have the correct PST changes for this year for 4 Canadian

Debian Weekly News - January 30th, 2007

2007-01-30 Thread Martin Schulze
been offline for more than ten days. Martin Schulze [47]added that the machine was being moved to a new location. Steve Langasek [48]answered that this requirement has been waived as a hard requirement for release qualification so that this particular outage doesn't affect the release status of alpha

[EMAIL PROTECTED]: [veterans] Call for Papers: LinuxTag May 30 - June 2, 2007 in Berlin, Germany]

2007-01-28 Thread Martin Schulze
FYI Gruesse, Joey - Forwarded message from Nils Magnus [EMAIL PROTECTED] - From: Nils Magnus [EMAIL PROTECTED] Organization: LinuxTag e. V. To: [EMAIL PROTECTED] Date: Mon, 29 Jan 2007 02:21:16 +0100 Cc: [EMAIL PROTECTED] Subject: [veterans] Call for Papers: LinuxTag May 30 -

Re: Debian, Iceweasle, Firefox!

2007-01-28 Thread Martin Schulze
Mike Hommey wrote: To be fair, it's not exactly true, because upgrading from firefox to iceweasel in debian means upgrading from version 1.0 or 1.5 to 2.0, and there are substancial changes that some people dislike, myself included. Which means Piotr is actually probably complaining about

[Full-disclosure] [SECURITY] [DSA 1252-1] New vlc packages fix arbitrary code execution

2007-01-27 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1252-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze January 27th, 2007

[Full-disclosure] [SECURITY] [DSA 1253-1] New Mozilla Firefox packages fix several vulnerabilities

2007-01-27 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1253-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze January 27th, 2006

Re: Social Committee proposal

2007-01-27 Thread Martin Schulze
Marc 'HE' Brockschmidt wrote: Heavens help us. And this is the example of the kind of person working on a social policy? To be fair, didn't Manoj deny wanting to work on it? Regards, Joey -- MIME - broken solution for a broken design. -- Ralf Baechle -- To

Re: something related to the soc-ctte

2007-01-27 Thread Martin Schulze
Sune Vuorela wrote: - I am not a DD, so my opinions don't count FWIW, that's wrong. Your opinions do count. Regards, Joey -- MIME - broken solution for a broken design. -- Ralf Baechle -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact

[SECURITY] [DSA 1252-1] New vlc packages fix arbitrary code execution

2007-01-27 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1252-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze January 27th, 2007

[SECURITY] [DSA 1253-1] New Mozilla Firefox packages fix several vulnerabilities

2007-01-27 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1253-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze January 27th, 2006

Re: [Pkg-mailman-hackers] Re: Planning for an upgrade path from etch to lenny for mailman

2007-01-24 Thread Martin Schulze
Thijs Kinkhorst wrote: On Tue, 2007-01-23 at 11:50 +0100, Martin Schulze wrote: Please keep in mind that the upgrade path from etch to lenny needs to work for etch r0 to lenny r0 as well. So I've understood, but cannot back this up with any documentation. Where is this documented? I'm

Re: Planning for an upgrade path from etch to lenny for mailman

2007-01-23 Thread Martin Schulze
Lionel Elie Mamane wrote: It has just come to my attention that there will be no upgrade path from the version of Mailman in etch at this time (2.1.9) to the version lenny will most probably have (2.2.x), but there will be an upgrade path from the yet-unreleased 2.1.y, y9, to 2.2.x, and an

Re: Erroneous upload of gnome-vfs2 2.16 to unstable

2007-01-21 Thread Martin Schulze
Loïc Minier wrote: I mistakingly uploaded gnome-vfs2 2.16 to unstable; it bumps shlibs and is incompatible with unstable's bonobo; it's not suitable for etch. First, sorry for this mistake. Second, here are the options: - upload bonobo 2.16 into unstable and upload updates via TPU

Re: Closing down obsolete lists

2007-01-21 Thread Martin Schulze
Martin Zobel-Helas wrote: Hi, as part of the spring cleaning effort of the listmasters, we would like to close down several unused, obsolete lists. Before doing so we would like to a) give you the chance to veto against it b) document our reasons and changes publicly The following

Re: Closing down obsolete lists

2007-01-21 Thread Martin Schulze
Loïc Minier wrote: Maybe I'm the only one wondering but: why aren't uploads announced to the *-changes lists anymore? Because it's -devel-changes? the -changes ones were meant for stable. (these logs may be missing as well, though). Regards, Joey -- The only stupid question is

Re: Erroneous upload of gnome-vfs2 2.16 to unstable

2007-01-21 Thread Martin Schulze
Loïc Minier wrote: I mistakingly uploaded gnome-vfs2 2.16 to unstable; it bumps shlibs and is incompatible with unstable's bonobo; it's not suitable for etch. First, sorry for this mistake. Second, here are the options: - upload bonobo 2.16 into unstable and upload updates via TPU

Re: why is alpha a release candidate?

2007-01-17 Thread Martin Schulze
Thomas Bushnell BSG wrote: So the release criteria require buildd redundancy. And yet, half the release candidate archs still don't have it. It gets marked in yellow on http://release.debian.org/etch_arch_qualify.html. Well, the one-and-only alpha buildd has been down for apparently ten

Bug#406602: Documentation improvement

2007-01-12 Thread Martin Schulze
Package: websec Version: 1.9.0-1 Severity: wishlist Tags: patch Hi, I was puzzled to have websec bail out on my configuration until I reached the examples section of url.list. On the top of the file the syntax was missing. Here's a patch to fix this. I'd be glad if you could add it to future

Bug#406605: Document source of fetching new versions

2007-01-12 Thread Martin Schulze
Package: websec Version: 1.9.0-1 Severity: wishlist Tags: patch Hi, I'd like the manpage to document when new versions are fetched. Since websec inspects the timestamp of an archived page and uses it in an additional HTML header line for if-modified-since this should be written down somewhere,

Bug#406607: Typo

2007-01-12 Thread Martin Schulze
Package: websec Version: 1.9.0-1 Tags: patch Hi, there's a typo in the webdiff.1 manpage. --- webdiff.1.orig 2007-01-12 10:46:03.0 +0100 +++ webdiff.1 2007-01-12 10:46:09.0 +0100 @@ -175,7 +175,7 @@ Don't ignore if token contains = given Debug messages .SH DESCRIPTION

Bug#406486: Reporting useless bugs

2007-01-12 Thread Martin Schulze
Thijs Kinkhorst wrote: Dear members of the security team(s), On Fri, 2007-01-12 at 11:08 -0300, Alex de Oliveira Silva wrote: Multiple vulnerabilities have been identified in phpMyAdmin, which may be exploited by attackers to execute arbitrary scripting code. These issues are due to

[Secure-testing-team] Re: Reporting useless bugs

2007-01-12 Thread Martin Schulze
Thijs Kinkhorst wrote: Dear members of the security team(s), On Fri, 2007-01-12 at 11:08 -0300, Alex de Oliveira Silva wrote: Multiple vulnerabilities have been identified in phpMyAdmin, which may be exploited by attackers to execute arbitrary scripting code. These issues are due to

Bug#405197: CVE name

2007-01-11 Thread Martin Schulze
Please use CVE-2006-5876. Regards, Joey -- GNU GPL: The source will be with you... always. Please always Cc to me when replying to me on the lists. -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Bug#405197: CVE name

2007-01-11 Thread Martin Schulze
Please use CVE-2006-5876. Regards, Joey -- GNU GPL: The source will be with you... always. Please always Cc to me when replying to me on the lists. -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Re: Debian at the 2nd Linux-Informationstage Oldenburg

2007-01-10 Thread Martin Schulze
Sebastian Feltel wrote: Hello, I just registered for an booth at the 2nd Linux-Informationstage Oldenburg (14.- 15. April 2007) [1] for debianforum.de. Are there any plans for an Debian booth too (Joey?)? Because this seems to be an rather small event maybe we could share an booth?

[Full-disclosure] [SECURITY] [DSA 1246-1] New OpenOffice.org packages fix arbitrary code execution

2007-01-08 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1246-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze January 8th, 2007

[SECURITY] [DSA 1246-1] New OpenOffice.org packages fix arbitrary code execution

2007-01-08 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1246-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze January 8th, 2007

Bug#404364: Various typos in manpages

2006-12-30 Thread Martin Schulze
Nicolas François wrote: The following list contain all the coded character sets known. This does not necessarily mean that all combinations of these names can be used for the FROM and TO command line parameters. One coded character set can be listed with several different names

Bug#404888: glib2.0: cannot go into testing; causes gnucash regrsession

2006-12-29 Thread Martin Schulze
Josselin Mouette wrote: Le jeudi 28 décembre 2006 à 17:29 -0800, Thomas Bushnell BSG a écrit : On Fri, 2006-12-29 at 01:56 +0100, Josselin Mouette wrote: Now, if you don't provide us with the necessary data, we won't be able to fix the regression it introduces in gnucash. There are

Bug#404888: glib2.0: cannot go into testing; causes gnucash regrsession

2006-12-29 Thread Martin Schulze
Josselin Mouette wrote: Le jeudi 28 décembre 2006 à 17:29 -0800, Thomas Bushnell BSG a écrit : On Fri, 2006-12-29 at 01:56 +0100, Josselin Mouette wrote: Now, if you don't provide us with the necessary data, we won't be able to fix the regression it introduces in gnucash. There are

SSH upgrade problem

2006-12-28 Thread Martin Schulze
I upgraded a machine from sarge to etch and the process broke over ssh :( Here's the log: Preconfiguring packages ... (Reading database ... 100606 files and directories currently installed.) Unpacking openssh-client (from .../openssh-client_1%3a4.3p2-7_i386.deb) ... Transferring ownership of

Re: SSH upgrade problem

2006-12-28 Thread Martin Schulze
Noah Meyerhans wrote: On Thu, Dec 28, 2006 at 06:11:28PM +0100, Martin Schulze wrote: I upgraded a machine from sarge to etch and the process broke over ssh :( I believe this was fixed by 1:4.3p2-8, which should be allowed to enter etch ASAP. Cool! Good to know that this problem

Re: Bug#404888: glib2.0: cannot go into testing; causes gnucash regrsession

2006-12-28 Thread Martin Schulze
Josselin Mouette wrote: Le jeudi 28 décembre 2006 à 17:29 -0800, Thomas Bushnell BSG a écrit : On Fri, 2006-12-29 at 01:56 +0100, Josselin Mouette wrote: Now, if you don't provide us with the necessary data, we won't be able to fix the regression it introduces in gnucash. There are

Bug#397875: CVE assignment

2006-12-27 Thread Martin Schulze
Please use CVE-2006-6318 when referring to this NULL pointer dereference. Regards, Joey -- If nothing changes, everything will remain the same. -- Barne's Law Please always Cc to me when replying to me on the lists. -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of

Bug#404598: SSL module only configured half

2006-12-26 Thread Martin Schulze
Package: apache2.2-common Version: 2.2.3-3.2 I guess that the file /etc/apache2/mods-available/ssl.conf is missing the statement Listen 443 to allow Apache 2 to actually listen to the SSL port as well. Regards, Joey -- A mathematician is a machine for converting coffee into theorems.

Debian Weekly News - December 26th, 2006

2006-12-26 Thread Martin Schulze
--- Debian Weekly News http://www.debian.org/News/weekly/2006/42/ Debian Weekly News - December 26th, 2006 --- Welcome to this year's 42nd issue of DWN,

Bug#403280: [EMAIL PROTECTED]: bad link]

2006-12-15 Thread Martin Schulze
Package: gnome-lokkit - Forwarded message from Bill Ries-Knight [EMAIL PROTECTED] - Date: Fri, 15 Dec 2006 08:55:27 -0800 From: Bill Ries-Knight [EMAIL PROTECTED] To: debian-www@lists.debian.org Subject: bad link X-Folder: debian-www@lists.debian.org on this page:

<    1   2   3   4   5   6   7   8   9   10   >