Bug#787259: Acknowledgement (start error with pbuilder-satisfydepends-gdebi)

2019-05-01 Thread Thorsten Glaser
François Poirotte dixit: > this and I'm not sure how this could be fixed (does the Debian policy even > state what the character encoding should be for the control file?) It requires UTF-8 encoding, has been doing so since a couple of years. Can you try rebuilding without your local hack, but wi

Bug#928292: stretch-pu: package signing-party/2.5-1

2019-05-01 Thread Guilhem Moulin
Package: release.debian.org Severity: normal Tags: stretch User: release.debian@packages.debian.org Usertags: pu Hi there, CVE-2019-11627 was recently published for signing-party's gpg-key2ps(1). Unsafe shell call enabling shell injection via a User ID. See also #928256. However the Se

Bug#711853: insserv: Design bug: rcN.d unstable and not, maintainable

2019-05-01 Thread Alessandro Vesely
On Thu 25/Apr/2019 16:12:42 +0200 Dmitry Bogatov wrote: > [2019-04-22 19:07] Alessandro Vesely > >> The point is building every time from scratch, rigidly enjoining specs, >> like it or lump it, versus an incremental, tolerant, minimal changes >> operation. > > What is the point of "incremental,

Bug#928288: knack: please make the build reproducible

2019-05-01 Thread Luca Boccassi
On Wed, 2019-05-01 at 06:18 -0400, Chris Lamb wrote: > [adding > reproducible-bui...@lists.alioth.debian.org > to CC] > > Hi Luca, > > > Also the reprotest on the Gitlab CI didn't flag it as those builds > > are > > run with "nocheck": > > That's... unfortunate. :) Indeed, there are a non-triv

Bug#928291: unblock: signing-party/2.10-1

2019-05-01 Thread Guilhem Moulin
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock Hi there, gpg-key2ps(1) from signing-party 2.9-1 is vulnerable to CVE-2018-15599: unsafe shell call enabling shell injection via a User ID. Debdiff between 2.9-1 and 2.10-1 attached. (Whi

Bug#926547: insserv: tests/run-tests are not used

2019-05-01 Thread Dmitry Bogatov
[2019-04-28 21:05] Jesse Smith > > I have been looking into the issues with the insserv test scripts. There > are a few problems here, in brief: > [...] > > In other words, I think there is some difference in expectations between > what I think insserv should be doing and what the scripts we inh

Bug#921688: electrum being actively used for phishing

2019-05-01 Thread Laurent Bigonville
On Tue, 30 Apr 2019 10:59:16 -0400 Sam Hartman wrote: > > I realize that we normally don't care about packages only in sid, but > the version of electrum in sid is apparently only useful to funnel your > bitcoin to attackers. > The issue is that versions prior to 3.3 are vulnerable to mallware, a

Bug#928290: Acknowledgement (unblock: debian-edu-doc/2.10.16)

2019-05-01 Thread Holger Levsen
Hi, attached is the debdiff for this unblock request. -- tschau, Holger --- holger@(debian|reproducible-builds|layer-acht).org PGP fingerprint: B8BF 5413 7B09 D35C F026 FE9D 091A B856 069A

Bug#928288: knack: please make the build reproducible

2019-05-01 Thread Chris Lamb
[adding reproducible-bui...@lists.alioth.debian.org to CC] Hi Luca, > Also the reprotest on the Gitlab CI didn't flag it as those builds are > run with "nocheck": That's... unfortunate. :) Indeed, there are a non-trivial number of packages that are non-determinstic due to their tests. Could you

Bug#928290: unblock: debian-edu-doc/2.10.16

2019-05-01 Thread Holger Levsen
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock Please unblock debian-edu-doc, it's a documentation only change: debian-edu-doc (2.10.16) unstable; urgency=medium * Update Debian Edu Buster and Stretch manuals from the wiki. * Updat

Bug#928288: knack: please make the build reproducible

2019-05-01 Thread Luca Boccassi
On Wed, 2019-05-01 at 05:32 -0400, Chris Lamb wrote: > Source: knack > Version: 0.6.1-1 > Severity: wishlist > Tags: patch > User: > reproducible-bui...@lists.alioth.debian.org > > Usertags: randoness > X-Debbugs-Cc: > reproducible-b...@lists.alioth.debian.org > > > Hi, > > Whilst working on

Bug#613832:

2019-05-01 Thread Mrs Jemilah
Happy New month and good news greetings my dear. I have been expecting to receive your reply on my previous two emails i sent to you last month, Regarding the welfare of the less privileges . Did you receive my two email? Please am surprise that you did not respond. Urgently get back to me.

Bug#787259: Acknowledgement (start error with pbuilder-satisfydepends-gdebi)

2019-05-01 Thread François Poirotte
On Wed, 06 Jul 2016 15:30:26 +0200 Leopold Palomo-Avellaneda wrote:> On Fri, 27 May 2016 20:33:54 + Mattia Rizzolo wrote: > > The question then is why this line could produce the error is some packages > and in other no. > > Leopold > > Hi, I just stumbled across this issue when tryin

Bug#928289: git-flow: empty defaults

2019-05-01 Thread Alessandro -oggei- Ogier
Package: git-flow Version: 1.12.0-1 Severity: normal Dear Maintainer, version 1.12 lost defaults: ## 1.12 behaviour $ mkdir repo && ( cd repo && git init && git flow init -d ) Initialized empty Git repository in /tmp/repo/.git/ Using default branch names. No branches exist yet. Base branc

Bug#928288: knack: please make the build reproducible

2019-05-01 Thread Chris Lamb
Source: knack Version: 0.6.1-1 Severity: wishlist Tags: patch User: reproducible-bui...@lists.alioth.debian.org Usertags: randoness X-Debbugs-Cc: reproducible-b...@lists.alioth.debian.org Hi, Whilst working on the Reproducible Builds effort [0], we noticed that knack could not be built reproducib

Bug#928287: ITP: python-qutip -- python package for simulating the dynamics of open quantum systems

2019-05-01 Thread Drew Parsons
Package: wnpp Severity: wishlist Owner: Drew Parsons * Package name: python-qutip Version : 4.3.1 Upstream Author : Paul D. Nation and Robert J. Johansson * URL : http://qutip.org/ * License : BSD Programming Lang: Python Description : python package fo

Bug#928286: libpam-sss: passwd change does not prompt for new passwd unless using pam_sss.so prompt_always

2019-05-01 Thread J. Pfennig
Package: libpam-sss Version: 1.16.3-3.1 Severity: normal Dear Maintainer, problem: changing SAMBA AD DC passwd using SSSD with AD providers When user runs 'passwd' the old pw is prompted for and validated but not prompt for a new pw is shows. SSSD log and source code indicate that pam_s

Bug#927824: Grisbi 1.2.1-1 always crashes when creating a new transaction

2019-05-01 Thread Jérôme de Bretagne
Thanks Ludovic, the updated version has been unblocked and has now migrated to testing, this fixes the issue. Le mer. 24 avr. 2019 à 17:10, Ludovic Rousseau a écrit : > > Le 24/04/2019 à 15:51, Ludovic Rousseau a écrit : > > debian-release will not accept to migrate 1.2.2 into testing. > > Maybe

Bug#928240: etw: Segmentation fault at start

2019-05-01 Thread Steinar H. Gunderson
On Wed, May 01, 2019 at 01:11:32AM +0200, Markus Koschany wrote: > Thanks for providing a solution and a way forward. Could you provide a > trivial fix/patch as well? I'm willing to test it and ask the release > team for an unblock. I currently don't understand the underlying issue > and why it was

Bug#928168: ntp: Wrong path in apparmor profile for samba

2019-05-01 Thread L. van Belle
Hai, We got reports on the samba list of this. See: https://www.spinics.net/lists/samba/msg156739.html And i verified the user his problem and also noticed the wrong path also, and reported it as fix with the change. You said you did follow the wiki, which part? Is windows in you test case s

Bug#850627: Note

2019-05-01 Thread Dominik Stadler
Bug #914217 would fix this one via update to the latest version from Git, see Changelog at https://github.com/afrantzis/bless/blob/master/NEWS

Bug#914217: Update

2019-05-01 Thread Dominik Stadler
This would also fix bugs #767216 and #850627 and maybe one or two more.

Bug#928285: rtc.debian.org: uses resiprocate which is no longer in Debian

2019-05-01 Thread Jonas Smedegaard
Package: rtc.debian.org Severity: important -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Paul Wise warns¹ that the rtc.debian.org service uses resiprocate which is no longer in Debian. - Jonas ¹ https://lists.debian.org/caktje6g05y7wxuvryw3rqh4eaytrbfs5j78r1l8rkpqf-mb...@mail.gmail.com -

Bug#928284: libxalan2-java: Breaks JOSM with javaws: Provider org.apache.xerces.jaxp.validation.XMLSchemaFactory not found

2019-05-01 Thread Jörn Heissler
Source: libxalan2-java Severity: normal Hello, when libxalan2-java is installed, I cannot run JOSM (https://josm.openstreetmap.de/) through javaws anymore. Reproduce: * apt install icedtea-netx libxalan2-java * Click https://josm.openstreetmap.de/download/josm.jnlp in your browser * Alternative

Bug#928283: lintian: false positive pkg-js-tools-test-is-missing for openjk: assumes variables contain --with=nodejs

2019-05-01 Thread Simon McVittie
Package: lintian Version: 2.13.0 Severity: normal lintian emits pkg-js-tools-test-is-missing for the openjk source package in contrib. I believe this is because it uses a variable in the dh invocation, to disable one binary package (which is not considered ready by upstream) unless built for expe

Bug#928282: filezilla: CVE-2019-5429

2019-05-01 Thread Salvatore Bonaccorso
Source: filezilla Version: 3.39.0-2 Severity: grave Tags: security upstream Hi, The following vulnerability was published for filezilla. CVE-2019-5429[0]: | Untrusted search path in FileZilla before 3.41.0-rc1 allows an | attacker to gain privileges via a malicious 'fzsftp' binary in the | user'

Bug#928281: unblock: lemonldap-ng/2.0.2+ds-7 (pre-approval)

2019-05-01 Thread Xavier Guimard
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock Please unblock package lemonldap-ng Hi all, upstream authors of lemonldap-ng have updated language translations. I imported updated translation files in a patch. Do you think it is opportu

<    1   2