[Full-disclosure] [SECURITY] [DSA 1191-1] New Mozilla Thunderbird packages fix several vulnerabilities

2006-10-05 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1191-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze October 5th, 2006

Accepted gui-apt-key 0.1-1 (source all)

2006-10-05 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Format: 1.7 Date: Thu, 5 Oct 2006 18:53:25 +0200 Source: gui-apt-key Binary: gui-apt-key Architecture: source all Version: 0.1-1 Distribution: unstable Urgency: low Maintainer: Martin Schulze [EMAIL PROTECTED] Changed-By: Martin Schulze [EMAIL

Accepted gui-apt-key 0.1-2 (source all)

2006-10-05 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Format: 1.7 Date: Thu, 5 Oct 2006 20:24:03 +0200 Source: gui-apt-key Binary: gui-apt-key Architecture: source all Version: 0.1-2 Distribution: unstable Urgency: low Maintainer: Martin Schulze [EMAIL PROTECTED] Changed-By: Martin Schulze [EMAIL

Re: DSA 1184 corrections

2006-10-05 Thread Martin Schulze
Jens Seidel wrote: Hi, I applied the following patch to CVS and hope I did it right. But I have one problem understanding the text: Index: dsa-1184.wml === RCS file: /cvs/webwml/webwml/english/security/2006/dsa-1184.wml,v

Re: Reorganising Talk Pages

2006-10-05 Thread Martin Schulze
Martin Schulze wrote: Hi, in my opinion, the web pages about speakers[1] and talks[2] given at various conferences could use an overhaul. From several occasions there also exist video or audio recordings which would be useful for a web visitor, especially after the particular event is over

Re: Reorg of talks and events pages in w.d.o

2006-10-05 Thread Martin Schulze
[This mail may be considered public, feel free to quote or bounce it to debian-www.] Javier Fernandez-Sanguino wrote: I was thinking that maybe the events / speakers page should be ordered based on: - topic level (introduction, users, developers): so that users can easily find which talks

Re: DSA 1184 corrections

2006-10-05 Thread Martin Schulze
Jens Seidel wrote: On Thu, Oct 05, 2006 at 09:06:41AM +0200, Martin Schulze wrote: Jens Seidel wrote: I applied the following patch to CVS and hope I did it right. But I have one problem understanding the text: Index: dsa-1184.wml

[SECURITY] [DSA 1191-1] New Mozilla Thunderbird packages fix several vulnerabilities

2006-10-05 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1191-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze October 5th, 2006

[Full-disclosure] [SECURITY] [DSA 1188-1] New mailman packages fix several problems

2006-10-04 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1188-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze October 4th, 2006

Reorganising Talk Pages

2006-10-04 Thread Martin Schulze
Hi, in my opinion, the web pages about speakers[1] and talks[2] given at various conferences could use an overhaul. From several occasions there also exist video or audio recordings which would be useful for a web visitor, especially after the particular event is over. 1.

[SECURITY] [DSA 1188-1] New mailman packages fix several problems

2006-10-04 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1188-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze October 4th, 2006

Re: Summary? (Or: my vote is for sale!)

2006-10-03 Thread Martin Schulze
Sven Luther wrote: Jurij, i still think your draft is lightyears more clear and to the point than most GRs out there. One comment. As BLOB stands for Binary Large OBject, binary blob is somewhat strange. Regards, Joey -- Given enough thrust pigs will fly, but it's not necessarily a

Call for Translations

2006-10-03 Thread Martin Schulze
Hi, I'd be glad to add translations from the start, hence I'd appreciate any translated pot files sent back to me. German is already done, naturally. I'm attaching the POT file with untranslated strings. Regards, Joey -- Given enough thrust pigs will fly, but it's not necessarily a

Re: CLI Tool fuer automatischen Zeilenumbruch gesucht

2006-09-30 Thread Martin Schulze
Martin Grandrath wrote: ich bin auf der Suche nach einer Moeglichkeit, Mails mit ueberlangen Zeilen mittels einer pipe (aus mutt heraus) zu reformatieren. man fold Zitate und URLs sollten dabei unangetastet bleiben. Das ist schon wieder schwieriger und erfordert erheblich mehr Logik vom

Re: wie ermitteln ob /dev/tty beschrieben werden kann

2006-09-30 Thread Martin Schulze
Frank Dietrich wrote: wie kann ich auf einfachem Weg feststellen ob ein Prozess etwas auf einer Konsole ausgeben kann? Nutze ein Skript in der Art. --- testmoi.sh --- #!/bin/sh # stdout und stderr in Datei umleiten exec /tmp/logfile 21 # alle Ausgaben auch auf der Konsole anzeigen

Re: [Fwd: Re: Rechtsform debian Deutschland]

2006-09-30 Thread Martin Schulze
Max Muxe wrote: in einer Diskussion über Rechtsformen des open-news-network.org sehe ich mit der Behauptung konfrontiert, dass der deutsche Teil von Debian eine GbR sei. Warum die Frage, weil die Idee hinter ONNO [...] Ich würde eher sagen, daß Debian in Deutschland keinen Status hat.

Re: DVD-Datei ansehen

2006-09-30 Thread Martin Schulze
Rüdiger Noack wrote: Moin Ich habe von einem Freund eine selbsterstellte Urlaubs-DVD als Datei bekommen. Obwohl ich keinen DVD-Brenner besitze, würde ich mir den Film gern ansehen. Kann mir jemand sagen, wie ich das realisieren kann unter sarge? Fuer normale DVDs eignen sich ogle und

Bug#388537: DSA-1172 upgrade sets incorrect permissions on rndc.key

2006-09-30 Thread Martin Schulze
retitle 388537 bind9 upgrade sets incorrect permissions on rndc.key thanks dude Matt Brown wrote: Package: bind9 Version: 1:9.2.4-1sarge1 Hi, After applying the security update from DSA-1172 to two Sarge systems that I run the permissions of /etc/bind/rndc.key are set to bind:bind 0640.

Re: Practical Linux in Gie ßen

2006-09-30 Thread Martin Schulze
Alexander Schmehl wrote: Are there interested people from the Debian community who would like to run the booth? It's a one-day regional event, so not too much preparation is needed. The german skolelinux-team will be there, too. If no one would volunteer for an own one man booth,

Accepted sysklogd 1.4.1-20 (source i386)

2006-09-28 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Format: 1.7 Date: Thu, 28 Sep 2006 20:46:41 +0200 Source: sysklogd Binary: sysklogd klogd Architecture: source i386 Version: 1.4.1-20 Distribution: unstable Urgency: low Maintainer: Martin Schulze [EMAIL PROTECTED] Changed-By: Martin Schulze [EMAIL

[Full-disclosure] [SECURITY] [DSA 1184-2] New Linux 2.6.8 packages fix several vulnerabilities

2006-09-26 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1184-2[EMAIL PROTECTED] http://www.debian.org/security/ Dann Frazier September 26th, 2006

Bug#389586: Reference to php4

2006-09-26 Thread Martin Schulze
Package: php5-xcache Version: 1.0-4 Severity: minor Hi, /usr/share/doc/php5-xcache/README.Debian says [..] You can find a sample file about what to append at /usr/share/doc/php4-xcache/examples/php.ini. [..] Other pieces contain references to php4 instead of php5 as well. You may want to

Bug#366454: Config is in source

2006-09-26 Thread Martin Schulze
Hi, the well documented configuration file is still there. However it's only available in the source archive. After fetching and unpacking the source you'll find the documentation in config/gdm.conf.in. Regards, Joey -- Still can't talk about what I can't talk about. Sorry. --

Bug#366454: Config is in source

2006-09-26 Thread Martin Schulze
Martin Schulze wrote: the well documented configuration file is still there. However it's only available in the source archive. After fetching and unpacking the source you'll find the documentation in config/gdm.conf.in. Philipp Kern pointed me to /usr/share/gdm/defaults.conf which

[SECURITY] [DSA 1184-2] New Linux 2.6.8 packages fix several vulnerabilities

2006-09-26 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1184-2[EMAIL PROTECTED] http://www.debian.org/security/ Dann Frazier September 26th, 2006

[Full-disclosure] [SECURITY] [DSA 1183-1] New Linux 2.4.27 packages fix several vulnerabilities

2006-09-25 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1183-1[EMAIL PROTECTED] http://www.debian.org/security/ Dann Frazier September 25th, 2006

[Full-disclosure] [SECURITY] [DSA 1184-1] New Linux 2.6.8 packages fix several vulnerabilities

2006-09-25 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1184-1[EMAIL PROTECTED] http://www.debian.org/security/ Dann Frazier September 25th, 2006

Re: Proposal: Recall the Project Leader

2006-09-25 Thread Martin Schulze
Martin Schulze wrote: On Thu, Sep 21, 2006 at 07:10:25PM +0200, Pierre Habouzit wrote: I'd say that I'm not more comfortable with Steve McIntyre beeing involved and a DPL-assistant (or whatever name his position has) either, so if Aj stops beeing involved with dunc-tank, (1

[SECURITY] [DSA 1183-1] New Linux 2.4.27 packages fix several vulnerabilities

2006-09-25 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1183-1[EMAIL PROTECTED] http://www.debian.org/security/ Dann Frazier September 25th, 2006

[SECURITY] [DSA 1184-1] New Linux 2.6.8 packages fix several vulnerabilities

2006-09-25 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1184-1[EMAIL PROTECTED] http://www.debian.org/security/ Dann Frazier September 25th, 2006

Re: Proposal: Recall the Project Leader

2006-09-23 Thread Martin Schulze
Michael Banck wrote: On Thu, Sep 21, 2006 at 12:05:39AM +0200, Denis Barbier wrote: Again, the question is: is this organisation sufficiently outside of Debian when the DPL is intimately involved. In my opinion, the answer is obviously no, meaning that this quarantine will not work and

Re: Proposal: Recall the Project Leader

2006-09-23 Thread Martin Schulze
John Goerzen wrote: * Debian itself donated $1000 to the Gnome project to fund its development due to a dispute with KDE over Qt licensing. I don't recall this coming with strings such as can't be spent on programmer time. So there is even precedent for the project doing this sort of

Re: Proposal: Recall the Project Leader

2006-09-23 Thread Martin Schulze
Matthew R. Dempsky wrote: On Wed, Sep 20, 2006 at 07:43:22PM +0200, Denis Barbier wrote: Anthony Towns ends up his announce[1] about dunc-tank.org with these two paragraphs: A question that has been raised is whether the organisation can be sufficiently outside of Debian when

Re: Proposal: Recall the Project Leader

2006-09-23 Thread Martin Schulze
Pierre Habouzit wrote: Le jeu 21 septembre 2006 20:44, Graham Wilson a écrit : On Thu, Sep 21, 2006 at 07:10:25PM +0200, Pierre Habouzit wrote: I'd say that I'm not more comfortable with Steve McIntyre beeing involved and a DPL-assistant (or whatever name his position has) either, so

Re: Proposal: Recall the Project Leader

2006-09-23 Thread Martin Schulze
martin f krafft wrote: also sprach Martin Schulze [EMAIL PROTECTED] [2006.09.23.2110 +0200]: It's not about a timely release, it's about Debian directly or indirectly paying *some* developers for the work they signed up to. No, it's about a timely release and enabling two people of core

Bug#387091: gdrae: Description improvement

2006-09-21 Thread Martin Schulze
Jens Seidel wrote: On Tue, Sep 12, 2006 at 09:41:49AM +0200, Martin Schulze wrote: Package: gdrae Version: current Severity: minor - Description: A Real Academia Espanola dictinoary interface + Description: Real Academia Espanola dictionary interface I found this description also

Re: Can't write to /tmp on cvs.debian.org

2006-09-20 Thread Martin Schulze
Matt Taggart wrote: Peter Karlsson writes... I'm getting error messages from the cvs server on cvs.debian.org saying that it cannot write to the /tmp directory. It seems there are too many files on the file system, there are no inodes left in /tmp I checked haydn and /tmp has

Re: Proposal: Recall the Project Leader

2006-09-20 Thread Martin Schulze
Seconded. Regards, Joey Denis Barbier wrote: Hi, Anthony Towns ends up his announce[1] about dunc-tank.org with these two paragraphs: The first article[2] on the topic's already been published; with one somewhat inaccuracy - this is not a Debian project, and is

[Full-disclosure] [SECURITY] [DSA 1179-1] New alsaplayer packages fix denial of service

2006-09-19 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1179-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze September 19th, 2006

[Full-disclosure] [SECURITY] [DSA 1180-1] New bomberclone packages fix several vulnerabilities

2006-09-19 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1180-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze September 19th, 2006

Re: The Sourceless software in the kernel source GR

2006-09-19 Thread Martin Schulze
On Mon, 18 Sep 2006 18:46:50 -0700, Don Armstrong [EMAIL PROTECTED] said: But just like the groundwork and foundation of a structure, the non-actionable content of a resolutions can contain information on how the actionable content is to be interpreted. As such, it is part of the

Re: Fw: Kurdish Linux debian

2006-09-19 Thread Martin Schulze
Michelle Konzack wrote: Am 2006-09-17 21:20:06, schrieb Lior Kaplan: AFAIK. Erdal Ronahi is already did some translations of the debian installer to Kurdish [1]. some translations? - This guy is heavy... I read his name and see his translations over many Mailinglists and the BTS.

[SECURITY] [DSA 1179-1] New alsaplayer packages fix denial of service

2006-09-19 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1179-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze September 19th, 2006

[SECURITY] [DSA 1180-1] New bomberclone packages fix several vulnerabilities

2006-09-19 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1180-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze September 19th, 2006

Re: m68k not a release arch for etch; status in testing, future plans?

2006-09-19 Thread Martin Schulze
Wouter Verhelst wrote: I think the best way forward at this point in time is to create our own release, as you suggest, very much like what amd64 did for sarge. On the August 16 birthday party in Breda, I discussed this with Jeroen Van Wolffelaar who told me that in theory, it should not be

Re: m68k not a release arch for etch; status in testing, future plans?

2006-09-19 Thread Martin Schulze
Wouter Verhelst wrote: I think the best way forward at this point in time is to create our own release, as you suggest, very much like what amd64 did for sarge. On the August 16 birthday party in Breda, I discussed this with Jeroen Van Wolffelaar who told me that in theory, it should not be

Accepted sysklogd 1.4.1-19 (source i386)

2006-09-18 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Format: 1.7 Date: Mon, 18 Sep 2006 13:15:59 +0200 Source: sysklogd Binary: sysklogd klogd Architecture: source i386 Version: 1.4.1-19 Distribution: unstable Urgency: low Maintainer: Martin Schulze [EMAIL PROTECTED] Changed-By: Martin Schulze [EMAIL

Bug#315605: sysklogd: UTF-8 log messages are mangled horribly

2006-09-18 Thread Martin Schulze
Roger Leigh wrote: When a program using a UTF-8 locale logs a UTF-8 string using syslog(3), syslog mangles the string. For example: Jun 23 21:34:24 hardknott schroot[10687]: [sid chroot] rleigh\u\206\222rleigh Running login shell: /bin/bash [sid chroot] rleigh???rleigh Running login

Bug#388044: savelog documentation fix

2006-09-18 Thread Martin Schulze
Package: debianutils Version: 2.17.1 Severity: wishlist Tags: patch Please apply the attached patch to the next upload. It fixes a documentation gap since -m/-g/-u implies -t so that new files are indeed created. Regards, Joey -- There are lies, statistics and benchmarks. Please

Practical Linux in Gießen

2006-09-18 Thread Martin Schulze
Moin! We have been invited to maintain a booth at the Practical Linux exhibition in Gießen. It'll take place on October 21st in Gießen, Germany. Are there interested people from the Debian community who would like to run the booth? It's a one-day regional event, so not too much preparation is

Re: m68k not a release arch for etch; status in testing, future plans?

2006-09-18 Thread Martin Schulze
Frans Pop wrote: On Monday 18 September 2006 09:18, Frans Pop wrote: * Installation Guide Add note in the introduction that m68k is not officially supported. Otherwise the same as d-i: continue building and uploading into unstable. I'd suggest to just keep the development version

Re: Preparation of the next stable Debian GNU/Linux update (I)

2006-09-16 Thread Martin Schulze
Matthijs Mohlmann wrote: Hi, What about #375494 and #377047, those are security bugs in the current stable distribution (Sarge) and according to the Security Team it didn't warrant an upload. Although it has a CVE so I think it's worth an upload to stable. The first one doesn't look like a

Re: Preparation of the next stable Debian GNU/Linux update (I)

2006-09-16 Thread Martin Schulze
Holger Levsen wrote: On Saturday 16 September 2006 08:50, Martin Schulze wrote: The first one doesn't look like a real security problem. Please explain why you think that putting arbitrary long strings into fixed sized buffers is not a security problem, preferedly in the bugreport. Please

[Full-disclosure] [SECURITY] [DSA 1177-1] New usermin packages fix denial of service

2006-09-15 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1177-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze September 15th, 2006

Re: Proposal: Apologize for releasing etch with sourceless/non-free firmware

2006-09-15 Thread Martin Schulze
Lionel Elie Mamane wrote: On Fri, Aug 25, 2006 at 11:03:47AM +0100, Daniel Ruoso wrote: I propose the following option to the GR: PROPOSAL The Debian Project reaffirms its commitment of providing a 100% free operating system, and reaffirms the decisions taken by GR 2004-03, but some

[SECURITY] [DSA 1160-2] New Mozilla packages fix several vulnerabilities

2006-09-15 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1160-2[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze September 15th, 2006

[SECURITY] [DSA 1177-1] New usermin packages fix denial of service

2006-09-15 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1177-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze September 15th, 2006

Re: Sarge - Etch upgrade issue

2006-09-15 Thread Martin Schulze
Alexander Schmehl wrote: * Steve Langasek [EMAIL PROTECTED] [060908 01:46]: 1) sarge: 1.1) apt-get dist-upgrade - upgrading to etch [..] Yes, I can see that apt Recommends: debian-archive-keyring and Suggests: gnupg. Given that apt should be doing secure archives by default now, the

[Full-disclosure] [SECURITY] [DSA 1160-2] New Mozilla packages fix several vulnerabilities

2006-09-14 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1160-2[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze September 15th, 2006

Re: Obsolete info on www.debian.org/misc/related_links

2006-09-14 Thread Martin Schulze
Don Wright wrote: Page: http://www.debian.org/misc/related_links Section: Linux User Groups The first user group link (GLUE) now redirects to Linux Journal. Their closest match seems to be under Community where they list your second entry, Linux User Groups WorldWide. That one still

[Full-disclosure] [SECURITY] [DSA 1161-2] New Mozilla Firefox packages fix several vulnerabilities

2006-09-13 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1161-2[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze September 13th, 2006

[Full-disclosure] [SECURITY] [DSA 1175-1] New isakmpd packages fix replay protection bypass

2006-09-13 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1175-1[EMAIL PROTECTED] http://www.debian.org/security/ Noah Meyerhans September 13th, 2006

Bug#385040: pcmanfm: Description improvement

2006-09-13 Thread Martin Schulze
Andrew Lee wrote: Dear Joey and Tetralet, I found this in the prepared upload: Description: Extremely fast and lightweight file manager for the X Window System - According to developers-reference 6.2.2, it says the synopsis shoud not starts with a capital letter. Ugh! Stupid! Stupid!

Re: Firmware Social Contract: GR proposal

2006-09-13 Thread Martin Schulze
Anthony Towns wrote: The Debian Project resolves that: (a) The Social Contract shall be reverted to its original form, as at http://www.debian.org/social_contract.1.0 ARGS. This is certainly one of the worst GR proposals I've seen. Not seconded, of course. I believe it would

Re: Firmware Social Contract: GR proposal

2006-09-13 Thread Martin Schulze
Josselin Mouette wrote: Le mardi 05 septembre 2006 à 19:07 -0700, Thomas Bushnell BSG a écrit : For me the key question is whether the d-i team is actually doing the work or not. Are they? If the answer is yes, then I might vote for a delay. If the answer is no, then I see no reason that

Re: Firmware Social Contract: GR proposal

2006-09-13 Thread Martin Schulze
Anthony Towns wrote: 1. I'm utterly frustrated with your ways. The mail on d-d-a could not have any other answer that please release etch in time, that's something a perfect moron could have predicted without a doubt. 26% of the people on the forums said supporting hardware

[SECURITY] [DSA 1175-1] New isakmpd packages fix replay protection bypass

2006-09-13 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1175-1[EMAIL PROTECTED] http://www.debian.org/security/ Noah Meyerhans September 13th, 2006

[SECURITY] [DSA 1161-2] New Mozilla Firefox packages fix several vulnerabilities

2006-09-13 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1161-2[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze September 13th, 2006

Bug#387089: Certificate links must not be removed

2006-09-12 Thread Martin Schulze
Package: ca-certificates Version: 20050804 Severity: important Upon upgrade of this package it seems that all symlinks to certificates in /etc/ssl/certs are removed. However, recreated are only those to certificates provided by this package. (or all symlinks to certs not from this package are

Bug#387091: gdrae: Description improvement

2006-09-12 Thread Martin Schulze
Package: gdrae Version: current Severity: minor - Description: A Real Academia Espanola dictinoary interface + Description: Real Academia Espanola dictionary interface Regards, Joey -- GNU does not eliminate all the world's problems, only some of them.

Bug#387092: obexfs: Description improvement

2006-09-12 Thread Martin Schulze
Package: obexfs Version: current Severity: minor - Description: Mount filesystem of ObexFTP capabable devices + Description: Mount filesystem of ObexFTP capable devices Regards, Joey -- GNU does not eliminate all the world's problems, only some of them.

Bug#387160: Beautify queuegraph

2006-09-12 Thread Martin Schulze
Package: queuegraph Version: 1.1.0-1 Severity: wishlist Since this package is somewhat derived from mailgraph it would be nice if the titles would be displayed similarily. The attached fix does this. Regards, Joey -- GNU does not eliminate all the world's problems, only some of them.

Re: Meeting Minutes from the latest SRM meeting

2006-09-12 Thread Martin Schulze
Martin Zobel-Helas wrote: - Time based release: We spoke about the idea of a time based release for r4. Anthony and Julien think it is a too short time frame, but we should try this experiment, and the speak with cd-vendors after r4, so we get better impression. Release

[SECURITY] [DSA 1159-2] New Mozilla Thunderbird packages fix several problems

2006-09-11 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1159-2[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze September 8th, 2006

[Full-disclosure] [SECURITY] [DSA 1172-1] New bind9 packages fix denial of service

2006-09-09 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1172-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze September 9th, 2006

[SECURITY] [DSA 1172-1] New bind9 packages fix denial of service

2006-09-09 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1172-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze September 9th, 2006

[Full-disclosure] [SECURITY] [DSA 1159-2] New Mozilla Thunderbird packages fix several problems

2006-09-07 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1159-2[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze September 8th, 2006

Re: Sarge - Etch upgrade issue

2006-09-07 Thread Martin Schulze
Ingo Juergensmann wrote: Joey asked me to forward this to here, so here it is: When upgrading sarge to etch, apt-get complains about untrusted source of packages because gnupg isn't installed during apt-get dist-upgrade. After manually installing gnupg apt-get update everything seems

Bug#358575: mailman 2.1.5-8sarge3: screwup between security and maintainer upload

2006-09-06 Thread Martin Schulze
Lionel Elie Mamane wrote: let a be an architecture in sarge. Then one of the following holds for mailman in sarge r3: - it is affected by a security problem. - it has a severity critical bug. Mailman in sid: - may or may not suffer of a security problem A security problem in

Re: New website layout / design contest?

2006-09-06 Thread Martin Schulze
Christoph Haas wrote: On Tuesday 05 September 2006 04:16, Matej Cepl wrote: Paul Belanger wrote: After all, the point of any distribution is to sell it to a user. It is not. For example, Debian Developers usually don't care how many users is Debian sold to. And that is a good thing.

[SECURITY] [DSA 1170-1] New fastjar packages fix directory traversal

2006-09-06 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1170-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze September 6th, 2006

Bug#358575: mailman 2.1.5-8sarge3: screwup between security and maintainer upload

2006-09-06 Thread Martin Schulze
Lionel Elie Mamane wrote: let a be an architecture in sarge. Then one of the following holds for mailman in sarge r3: - it is affected by a security problem. - it has a severity critical bug. Mailman in sid: - may or may not suffer of a security problem A security problem in

Re: Secure APT Key Management

2006-09-06 Thread Martin Schulze
Andreas Barth wrote: Hi, I try to summarize the results of the discussion from start of August, in hope that we can finish this off, and test-run this first for the next stable point release. From the security team, some input on their preference would be welcome. The idea is to have

Re: mailman 2.1.5-8sarge3: screwup between security and maintainer upload

2006-09-06 Thread Martin Schulze
Lionel Elie Mamane wrote: let a be an architecture in sarge. Then one of the following holds for mailman in sarge r3: - it is affected by a security problem. - it has a severity critical bug. Mailman in sid: - may or may not suffer of a security problem A security problem in

[Full-disclosure] [SECURITY] [DSA 1169-1] New MySQL 4.1 packages fix several vulnerabilities

2006-09-05 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1169-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze September 5th, 2006

Re: Fwd: Re: Possible hacked box

2006-09-05 Thread Martin Schulze
David Martínez Moreno wrote: Hello, Debian admins. A user has contacted us about a 'user connecting to IRC from haydn.d.o'. Probably it has been forwarded to you, but no one has noted it in the debian-www list, so I prefer two warnings instead of none. Please talk to the Alioth

Debian Weekly News - September 5th, 2006

2006-09-05 Thread Martin Schulze
--- Debian Weekly News http://www.debian.org/News/weekly/2006/36/ Debian Weekly News - September 5th, 2006 --- Welcome to this year's 36th issue of DWN,

[SECURITY] [DSA 1169-1] New MySQL 4.1 packages fix several vulnerabilities

2006-09-05 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1169-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze September 5th, 2006

Bug#386010: r2e run consumes max CPU

2006-09-04 Thread Martin Schulze
Package: python2.4 Version: 2.4.3-8 When I add the feed for www.bildblog.de to rss2email, i.e. http://feeds.feedburner.com/Bildblog r2e run does not terminate anymore bug consumes loads of memory. This seems to be problem of the python2.4 package since r2e uses python-feedparser which uses

[Full-disclosure] [SECURITY] [DSA 1165-1] New capi4hylafax packages fix arbitrary command execution

2006-09-01 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1165-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze September 1st, 2006

Re: Broken links for debian manual

2006-09-01 Thread Martin Schulze
Hi! Osamu Aoki wrote: On Mon, Aug 28, 2006 at 10:18:28PM -0700, Matt Kraai wrote: On Mon, Aug 28, 2006 at 11:09:09PM +0200, Stephan Fuhrmann wrote: this one http://www.debian.org/doc/user-manuals#quick-reference seems to be broken on all web servers (404, not found) for all languages

Bug#384832: Broken links for debian manual

2006-09-01 Thread Martin Schulze
Hi! Osamu Aoki wrote: On Mon, Aug 28, 2006 at 10:18:28PM -0700, Matt Kraai wrote: On Mon, Aug 28, 2006 at 11:09:09PM +0200, Stephan Fuhrmann wrote: this one http://www.debian.org/doc/user-manuals#quick-reference seems to be broken on all web servers (404, not found) for all languages

Re: Broken links for debian manual

2006-09-01 Thread Martin Schulze
Hi! Osamu Aoki wrote: On Mon, Aug 28, 2006 at 10:18:28PM -0700, Matt Kraai wrote: On Mon, Aug 28, 2006 at 11:09:09PM +0200, Stephan Fuhrmann wrote: this one http://www.debian.org/doc/user-manuals#quick-reference seems to be broken on all web servers (404, not found) for all languages

Re: Broken links for debian manual

2006-08-31 Thread Martin Schulze
Stephan Fuhrmann wrote: Hi there, this one http://www.debian.org/doc/user-manuals#quick-reference seems to be broken on all web servers (404, not found) for all languages i tried in HTML form: * http://www.debian.org/doc/manuals/reference/reference.en.html *

Re: Broken links for debian manual

2006-08-31 Thread Martin Schulze
Jens Seidel wrote: Stephan Fuhrmann wrote: this one http://www.debian.org/doc/user-manuals#quick-reference seems to be broken on all web servers (404, not found) for all languages i tried in HTML form: * http://www.debian.org/doc/manuals/reference/reference.en.html *

Re: typo? in english/security/2006/dsa-1163.wml

2006-08-31 Thread Martin Schulze
SUGIYAMA Tomoaki wrote: Hello, Though I don't understand well, I think that the following may be a typo on line 5 in english/security/2006/dsa-1163.wml file. a remove server - a remote server (?) Oh well... sure... go ahead. Regards, Joey -- Everybody talks about it, but

[SECURITY] [DSA 1164-1] New sendmail packages fix denial of service

2006-08-31 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1164-1[EMAIL PROTECTED] http://www.debian.org/security/ Noah Meyerhans August 31st, 2006

Accepted libextractor 0.4.2-2sarge5 (source powerpc)

2006-08-31 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Format: 1.7 Date: Fri, 26 May 2006 10:50:37 +0200 Source: libextractor Binary: extract libextractor1-dev libextractor1 Architecture: source powerpc Version: 0.4.2-2sarge5 Distribution: stable-security Urgency: high Maintainer: Martin Schulze [EMAIL

Accepted heartbeat 1.2.3-9sarge6 (source all powerpc)

2006-08-31 Thread Martin Schulze
-security Urgency: high Maintainer: Martin Schulze [EMAIL PROTECTED] Changed-By: Martin Schulze [EMAIL PROTECTED] Description: heartbeat - Subsystem for High-Availability Linux heartbeat-dev - Subsystem for High-Availability Linux - development files ldirectord - Monitors virtual services provided

Accepted gnupg2 1.9.15-6sarge2 (source powerpc)

2006-08-31 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Format: 1.7 Date: Thu, 3 Aug 2006 10:40:19 +0200 Source: gnupg2 Binary: gnupg2 gpgsm gnupg-agent Architecture: source powerpc Version: 1.9.15-6sarge2 Distribution: stable-security Urgency: high Maintainer: Martin Schulze [EMAIL PROTECTED] Changed

<    2   3   4   5   6   7   8   9   10   11   >