Bug#1014856: dogtag-pki: CVE-2019-10178

2022-07-13 Thread Moritz Mühlenhoff
Source: dogtag-pki X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerability was published for dogtag-pki. CVE-2019-10178[0]: | It was found that the Token Processing Service (TPS) did not properly | sanitize the Token IDs from the "Activity"

Bug#1014854: dogtag-pki: CVE-2020-1696

2022-07-13 Thread Moritz Mühlenhoff
Source: dogtag-pki X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerability was published for dogtag-pki. CVE-2020-1696[0]: | A flaw was found in the all pki-core 10.x.x versions, where Token | Processing Service (TPS) where it did not properly

Bug#1014855: dogtag-pki: CVE-2019-10180

2022-07-13 Thread Moritz Mühlenhoff
Source: dogtag-pki X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerability was published for dogtag-pki. CVE-2019-10180[0]: | A vulnerability was found in all pki-core 10.x.x version, where the | Token Processing Service (TPS) did not properly

Bug#1014846: rush: FTBFS on s390x

2022-07-13 Thread Bo YU
On Wed, Jul 13, 2022 at 08:47:41AM +0200, Bastian Germann wrote: Source: rush Severity: serious Version: 2.2-1 rush does not build on s390x due to a test error: 45: remopt FAILED (remopt.at:53) See

Bug#1012814: force merge duplicates

2022-07-13 Thread Christian Ehrhardt
forcemerge 1011633 1012814

Bug#1011633: Clear open-vm-tools duplicates - this is actually asking for 12.0.5

2022-07-13 Thread Christian Ehrhardt
retitle 1011633 Open-vm-tools 12.0.5 has been released

Bug#1012814: Duplicate

2022-07-13 Thread Christian Ehrhardt
Hi, thanks for your report - this is actually already covered by [1] which I just now realized had a bad title saying 12.0.0 instead of 12.0.5 - I fixed that by now. Therefore I'm merging this bug here with [1]. Current state is that it is already fixed in experimental and was just uploaded to

Bug#1004511: please remove luajit(2) on ppc64el now

2022-07-13 Thread Paul Gevers
reassign 1013808 ftp.debian.org retitle 1013808 RM: aegisub [ppc64el] -- RoQA; luajit2 segfaults reassign 1013814 ftp.debian.org retitle 1013814 RM: luakit [ppc64el] -- RoQA; luajit2 segfaults reassign 1013813 ftp.debian.org retitle 1013813 RM: uwsgi-plugin-luajit [ppc64el] -- RoQA; luajit2

Bug#1014852: gluegen2: ftbfs on riscv64("Requires '${compiler.cfg.id}'")

2022-07-13 Thread Bo YU
Source: gluegen2 Version: 2.3.2-8 Severity: normal Tags: ftbfs, patch User: debian-ri...@lists.debian.org Usertags: riscv64 X-Debbugs-Cc: debian-ri...@lists.debian.org Dear gluegen2 Maintainer, The package has a ftbfs on riscv64 due to: ``` ... BUILD FAILED /<>/make/build.xml:462: The following

Bug#1014851: Missing SLS mitigation (-mharden-sls) for x86

2022-07-13 Thread Ben Hutchings
Package: gcc-10 Version: 10.2.1-6 Severity: normal Tags: patch bullseye X-Debbugs-Cc: debian-ker...@lists.debian.org In an upcoming kernel update I would like to add mitigation of Straight Line Speculation (SLS) for amd64. This depends partly on compiler support, enabled with the -mharden-sls

Bug#993798: packaging issue

2022-07-13 Thread MyMisc
This is an packaging issue. Remove classpath in manifest from tagsoup.jar fix error. See https://github.com/AdoptOpenJDK/IcedTea-Web/issues/382 for explanation.

Bug#991011: please try new version grub-customizer 5.2.1-1

2022-07-13 Thread 肖盛文
control: tags -1 moreinfo Hi,   Please try new version grub-customizer 5.2.1-1, Can the appearance change now? Your feedback is welcome! https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=991011 -- 肖盛文 xiao sheng wen https://www.atzlinux.com 《铜豌豆 Linux》基于 Debian 的 Linux 中文 桌面 操作系统 Debian QA

Bug#948712: [Pkg-raspi-maintainers] Bug#948712: Pinebook Pro also uses this chip

2022-07-13 Thread Ben Hutchings
On Tue, 2022-07-12 at 20:18 +0200, Adam Borowski wrote: > On Tue, Jul 12, 2022 at 12:45:11PM +0200, Diederik de Haas wrote: > > On dinsdag 12 juli 2022 01:47:21 CEST Adam Borowski wrote: > > > Pinebook Pro also wants this firmware, and it's definitely not a raspi, > > > and it doesn't have

Bug#1014850: O: python-imaplib2 -- Threaded Python IMAP4 client (Python 3)

2022-07-13 Thread Ilias Tsitsimpis
Package: wnpp Severity: normal X-Debbugs-Cc: Sudip Mukherjee , Ulises Vitulli Control: affects -1 src:python-imaplib2 I intend to orphan the python-imaplib2 package. Since this package is used by OfflineIMAP, I have reached out to Sudip Mukherjee (CC-ed) who is willing to adopt this package

Bug#1014847: mirror submission for fastmirror.pp.ua

2022-07-13 Thread Marco d'Itri
On Jul 13, Ivan Barabash wrote: > Site: fastmirror.pp.ua I do not think that it is appropriate to list a mirror which has IPv6 connectivity from a tunnel broker. -- ciao, Marco signature.asc Description: PGP signature

Bug#1014849: Newer jimtcl (>= 0.81) requires fix to scripts

2022-07-13 Thread NIIBE Yutaka
Package: openocd Version: 0.11.0-1+b1 Severity: serious Hello, After I upgraded to libjim0.81, OpenOCD started to emit errors like: == Error executing event examine-end on target stm32f0x.cpu: /usr/bin/../share/openocd/scripts/mem_helper.tcl:37: Error: wrong # args: should be

Bug#1014848: git: CVE-2022-29187

2022-07-13 Thread Salvatore Bonaccorso
Source: git Version: 1:2.36.1-1 Severity: important Tags: security upstream X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerability was published for git. CVE-2022-29187[0]: | Git is a distributed revision control system. Git prior to versions | 2.37.1, 2.36.2,

Bug#1014847: mirror submission for fastmirror.pp.ua

2022-07-13 Thread Ivan Barabash
Package: mirrors Severity: wishlist User: mirr...@packages.debian.org Usertags: mirror-submission Submission-Type: new Site: fastmirror.pp.ua Type: leaf Archive-architecture: amd64 arm64 armel armhf i386 mips mips64el mipsel ppc64el s390x Archive-http: /debian/ Archive-rsync: debian/ Maintainer:

Bug#1014846: rush: FTBFS on s390x

2022-07-13 Thread Bastian Germann
Source: rush Severity: serious Version: 2.2-1 rush does not build on s390x due to a test error: 45: remopt FAILED (remopt.at:53) See https://buildd.debian.org/status/fetch.php?pkg=rush=s390x=2.2-1=1657661702=0 This keeps the package from migrating to

Bug#1014845: node-moment: CVE-2022-31129

2022-07-13 Thread Salvatore Bonaccorso
Source: node-moment Version: 2.29.3+ds-1 Severity: grave Tags: security upstream X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerability was published for node-moment. CVE-2022-31129[0]: | moment is a JavaScript date library for parsing, validating, |

Bug#1011629: minidlna: can't access localhost:8200 - DNS rebinding attack suspected

2022-07-13 Thread Marcos Raúl Carot
Thanks for that. Just tried and it works with only IP:8200 I was using localhost:8200 Cheers, Marcos On Wed, 13 Jul 2022 at 10:54, Oliver Freyermuth wrote: > On Fri, 8 Jul 2022 21:50:32 +0800 =?UTF-8?Q?Marcos_Ra=C3=BAl_Carot?= < > marcos.ca...@gmail.com> wrote: > > Oh, so there is no way now

Bug#1014844: python-lsp-server: breaks spyder 5.3.1 and needs to be held until spyder 5.3.2 is released

2022-07-13 Thread Julian Gilbey
Source: python-lsp-server Version: 1.5.0-1 Severity: serious This package is incompatible with the currently released version of spyder (5.3.1). As explained by upstream in https://github.com/spyder-ide/spyder/issues/17550#issuecomment-1079828357 the releases of PyLSP and Spyder are performed by

<    1   2