Bug#630597: qa.debian.org: rmadison lacks experimental/main/debian-installer?

2011-07-04 Thread Raphael Geissert
the problem lies in UDD's config. I was looking at an old config file. Summarising for debian-admin: no action is need, my bad, sorry for the noise. I will commit the necessary changes in a moment, but somebody from the udd group needs to update udd.d.o's subversion. Cheers, --

Bug#630597: qa.debian.org: rmadison lacks experimental/main/debian-installer?

2011-07-04 Thread Raphael Geissert
info as it is available in the mirror it is configured to use. CC'ing debian- admin for that bit, but I guess they'll ping debian-mirrors for the final tweak. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist

Bug#631909: xserver-xorg-input-synaptics: high CPU usage by syndaemon after suspend to ram

2011-06-28 Thread Raphael Geissert
restart it, everything goes back to usual. Please let me know if you need more info. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Conta

Bug#631908: boinc-client: looks for virtualbox-related binaries, for an unknown reason

2011-06-28 Thread Raphael Geissert
) put simply, that it should use it. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#631907: libc6-dev: should add breaks for gcc without multiarch support

2011-06-28 Thread Raphael Geissert
c-4.6 to 4.6.0-10 (with multiarch support): $ make t CC=gcc-4.6 gcc-4.6 t.c -o t $ ./t 'lo world Please add Breaks, as appropriate. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#631906: gcc-4.4: cannot find -lgcc_s after upgrade to 4.4.6-6

2011-06-28 Thread Raphael Geissert
c/i486-linux-gnu/4.4.6/../../../libgcc_s.a", O_RDONLY|O_LARGEFILE) = -1 ENOENT open("/usr/i486-linux-gnu/lib32/libgcc_s.so", O_RDONLY|O_LARGEFILE) = -1 ENOENT open("/usr/i486-linux-gnu/lib32/libgcc_s.a", O_RDONLY|O_LARGEFILE) = -1 ENOENT But gcc-4.4 ships libgcc_s.so in /

Bug#631905: pybootchartgui: output file's extension is always png, in spite of using format

2011-06-28 Thread Raphael Geissert
d 0 logger processes bootchart written to 'bootchart.png' $ file bootchart.png bootchart.png: SVG Scalable Vector Graphics image Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.o

Bug#631904: pybootchartgui: supported file formats are not documented

2011-06-28 Thread Raphael Geissert
Package: pybootchartgui Version: 0.14.0-3 Severity: wishlist Hi, Unless I'm missing something, the supported output file formats are not documented anywhere. Please do :) According to the code it supports png, svg, and pdf. Cheers, -- Raphael Geissert - Debian Developer www.debia

Bug#631903: O: kcheckgmail -- a Gmail notifier-like new email notifier for KDE

2011-06-28 Thread Raphael Geissert
h him. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#625681: ufw: errors when DEFAULT_FORWARD_POLICY = REJECT

2011-05-04 Thread Raphael Geissert
Error occurred at line: 2 > Try `iptables-restore -h' or 'iptables-restore --help' for more information. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#625280: boinc-client: doesn't handle EPERM correctly

2011-05-02 Thread Raphael Geissert
ng to create a directory for every value of $n. Not only this is useless, but it also leads to high CPU usage because of the, apparently endless, loop. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist

Bug#620222: security.debian.org: One server unreachable in IPv6

2011-03-31 Thread Raphael Geissert
8:c:a003::1)  1.566 ms >  4  zr-fra1-te0-7-0-1.x-win.dfn.de (2001:638:c:c043::2)  11.052 ms >  5  GiE1-2.ffmxs10.kl90.ffm.spxs.net (2001:7f8::306f:0:2)  10.573 ms >  6  2001:a78:bb:2::1a (2001:a78:bb:2::1a)  11.072 ms >  7  GiE1-1.ffmxs11.ix.ffm.spxs.net (2001:7f8::306f:0:1)  16.

Bug#619224: xserver-xorg-video-intel: tiling splash screen with kde and composition enabled

2011-03-22 Thread Raphael Geissert
g/howto/report-bugs.html reportbug tends to leak^Wshare too much info, sorry. I'm attaching it now. I can provide you with the EDID if you want/need, or other info that may help you. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net X server symlink status: --

Bug#619224: xserver-xorg-video-intel: tiling splash screen with kde and composition enabled

2011-03-21 Thread Raphael Geissert
On Monday 21 March 2011 22:35:07 Raphael Geissert wrote: > With linux 2.6.38 enabling KMS on the i915 driver, when logging into a kde > session the splash screen starts tiling when it should be replaced by the > wallpaper. After some seconds the display "stabilises" but wh

Bug#619225: file: new version available with security-relevant fixes

2011-03-21 Thread Raphael Geissert
rmine whether we need to backport fixes to old/stable. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#619224: xserver-xorg-video-intel: tiling splash screen with kde and composition enabled

2011-03-21 Thread Raphael Geissert
t" the machine with kexec and KMS enabled the display gets garbled until after udev is done doing its stuff after rebooting. This is on a 945GME. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@list

Bug#619223: mozplugger: insecure handling of mozdebug file

2011-03-21 Thread Raphael Geissert
, but it should be fixed nevertheless. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#619072: apt-get lies when using --dry-run and 'source' command together

2011-03-20 Thread Raphael Geissert
s for real execution. Keep also in mind that locking is deactivated, so don't depend on the relevance to the real current situation! Reading package lists... Done Building dependency tree Reading state information... Done Need to get 58.2 kB of source archives. Fetch source foo Chee

Bug#619036: [php-maint] Bug#619036: php5: Build-Depends uninstallable

2011-03-20 Thread Raphael Geissert
former maintainer of db uploaded the latest version and orphaned the packages. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#618489: [debian/debian-lenny] Fix CVE-2011-0441: arbitrary files removal via cronjob (Closes #618489)

2011-03-19 Thread Raphael Geissert
tag 618489 pending thanks Date: Fri Mar 18 18:33:09 2011 -0600 Author: Raphael Geissert Commit ID: 236533b4fe16ea4109a651a1ce9b8d7334b86980 Commit URL: http://git.debian.org/?p=pkg-php/php.git;a=commitdiff;h=236533b4fe16ea4109a651a1ce9b8d7334b86980 Patch URL: http://git.debian.org/?p=pkg-php

Bug#618489: [php-maint] Bug#618489: Bug#618489: Bug#618489: Bug#618489: php5-common: priviledge escalation in /etc/cron.d/php5

2011-03-17 Thread Raphael Geissert
gument to do make those changes with the risk of breaking setups, I'm going to release the DSA without them. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsub

Bug#615770: [php-maint] Bug#615770: Bug#615770: [Pkg-php-commits] [php/debian-sid] Fix FTBFS with gold or ld --no-add-needed (Closes: #615770) (Patch courtesy of Adrian Lang)

2011-03-17 Thread Raphael Geissert
ngely I start to side with people who say that Ubuntu doesn't cooperate > with the rest of the world, but it is just probably on the per-maintainer > basis:-/. Sadly, that's true. -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBS

Bug#615770: [Pkg-php-commits] [php/debian-sid] Fix FTBFS with gold or ld --no-add-needed (Closes: #615770) (Patch courtesy of Adrian Lang)

2011-03-17 Thread Raphael Geissert
) > + > ++ PHP_ADD_LIBRARY(crypto) > ++ > + if test "$PHP_KERBEROS" != "no"; then > + PHP_SETUP_KERBEROS(OPENSSL_SHARED_LIBADD) > + fi The patch is incomplete. Ubuntu already has a patch that only needs a minor cleanup (it patches a generated file.)

Bug#618489: [php-maint] Bug#618489: Bug#618489: Bug#618489: Bug#618489: php5-common: priviledge escalation in /etc/cron.d/php5

2011-03-17 Thread Raphael Geissert
per-user directory. > Another reason for using -delete (you're using GNU syntax > anyway) is that files are removed just after their time stamp is > checked. And it avoids extra forks, yes. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- T

Bug#618489: [php-maint] Bug#618489: Bug#618489: php5-common: priviledge escalation in /etc/cron.d/php5

2011-03-16 Thread Raphael Geissert
ke /var/lib/php5 uid: root, gid: www-data, and remove the world-rw mode. Why would we want to allow anyone else to use that dir anyway? perhaps I'm missing some bits of history. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIB

Bug#589384: [php-maint] Bug#589384: libapache2-mod-php5: Even with new SetHandler config, php is still activated because of mime type

2011-03-11 Thread Raphael Geissert
ed this report. I don't think we should have to deal with side effects of changes in mime-support. I'm therefore reassigning this report; all the x-httpd-* entries seem incorrect to me. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To

Bug#616436: Lintian complains about PHP license 2.01 even for PEAR packages

2011-03-04 Thread Raphael Geissert
Refer to http://ftp-master.debian.org/REJECT-FAQ.html for details. > N: > N:Severity: serious, Certainty: possible > > even if PEAR packages are really to be considered part of PHP. No, PEAR modules are not part of PHP, the interpreter. The tag's description could be cleare

Bug#616323: [php-maint] Bug#616323: segfaults when serving HTTP requests (including non-PHP ones) on kfreebsd-i386

2011-03-03 Thread Raphael Geissert
;m not even sure it's a bug in php (perhaps it's just exposing a bug elsewhere.) PHP itself does work as the test suite passes (well, not at 100% but that's not something kfreebsd-specific). Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To U

Bug#615471: php5-auth-pam: (not so) new upstream release available

2011-02-26 Thread Raphael Geissert
Package: php5-auth-pam Version: 0.4-10 Severity: wishlist Hi, There have been a few releases since the Debian package was first uploaded, please update it. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ

Bug#614888: RM: pixelpost -- RoQA; unused, unmaintained, multiple security issues

2011-02-23 Thread Raphael Geissert
ckage/pixelpost Thanks in advance. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net signature.asc Description: This is a digitally signed message part.

Bug#614887: don't display the full CVE description in package report

2011-02-23 Thread Raphael Geissert
ample) then put it behind some js. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#603012: [php-maint] Bug#603012: php5-cgi: CRYPT_SALT_LENGTH constant is not defined

2011-02-23 Thread Raphael Geissert
here doesn't seem to be a way to determine the limit at built-time (at least crypt(3) doesn't mention any defined constant). Worst case would be to hardcode it to 16 bytes and add a test that makes sure that's in fact the limit. Cheers, -- Raphael Geissert - Debian Developer www.

Bug#614737: [t/runtests] runtests doesn't fail if a a thread dies (e.g. because of die())

2011-02-22 Thread Raphael Geissert
rt it if it died. The latter should really be done only after refactoring the code. (I'm personally inclined to leaving this bug unfixed until the make bug is fixed. This bug doesn't affect tests that fail, only tests that fail to build.) Cheers, -- Raphael Geissert - Debian Developer www

Bug#614701: make: read jobs pipe: No such file or directory

2011-02-22 Thread Raphael Geissert
looks worrisome though. In the same testsuite run I got hit twice, so I guess there's not-so-difficult some way to reproduce it. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a su

Bug#614518: arpon: weak permissions in log file

2011-02-21 Thread Raphael Geissert
heers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#614413: re buildd's resolver and package's build deps

2011-02-21 Thread Raphael Geissert
id. If the package fails to build because the dependencies were resolved in a non- standard way then an RC bug should be filed and fixed. I abhor the idea of uselessly tightening dependencies. Regards, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIB

Bug#593603: lintian: debian-watch-file-should-use-sf-redirector triggered even with SourceForge files page

2011-02-19 Thread Raphael Geissert
's web pages are constantly modified. I am going to update the tag's description to reflect that. Regards, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#563773: lintian: false positive if a patch in debian/patches is a symlink

2011-02-19 Thread Raphael Geissert
tag 563773 - moreinfo thanks Raphael Geissert wrote: > I'm for now tagging it with 'moreinfo' because it needs to be discussed > with the dpkg folks (whether symlinks outside the debian tarball are > supported). I had forgotten about this report, sorry. I talked to Rapha

Bug#598546: lintian: unsubstituted #!perl

2011-02-19 Thread Raphael Geissert
27;t there's a bug) > It could pick up gzipped examples like > > /usr/share/doc/libbit-vector-perl/examples/SetObject.pl.gz > > too, if it doesn't already. That would require #42936 (which I have not yet decided how to best fix.) Cheers, -- Raphael Geissert - Debi

Bug#598546: lintian: unsubstituted #!perl

2011-02-18 Thread Raphael Geissert
t-vector-perl/examples/primes.pl (#!perl != > /usr/bin/perl) [1]http://lintian.debian.org/tags/wrong-path-for-interpreter.html [2]http://lintian.debian.org/tags/example-wrong-path-for-interpreter.html Or am I missing something? Cheers, -- Raphael Geissert - Debian Developer www.debian.org - g

Bug#614027: arpon: leaves stderr pointing to /dev/pts/ fd

2011-02-18 Thread Raphael Geissert
the log file if specified, or to /dev/null otherwise. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#597990: missing error from command line, found at lintian.d.o

2011-02-18 Thread Raphael Geissert
setgid directory +./usr/bin/^@ setgid directory And after wtfing for a while as to why the dirs were setgid: $ stat -c %A /org/lintian.debian.org/ drwxrwsr-x Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUB

Bug#613982: [php-maint] Bug#613982: Bug#613982: printf generates scientific notation inaccurately

2011-02-18 Thread Raphael Geissert
ctually been fixed > in that version. Right, I knew I had seen a commit related to the printf precision not long ago. 5.3.5-1 was just accepted from the NEW queue, so I'm closing this report. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSC

Bug#613982: [php-maint] Bug#613982: printf generates scientific notation inaccurately

2011-02-18 Thread Raphael Geissert
precision up to 318. You can workaround it by using number_format btw (which internally uses the same formatter as *printf, without the arbitrary limit). P.S. would be great if you could report it upstream. It would save us some time. Cheers, -- Raphael Geissert - Debian Developer www.d

Bug#587358: [hardening-discuss] Bug#587358: hardening-wrapper: should -Werror=format and -Werror=format-security be set too?

2011-02-18 Thread Raphael Geissert
On Sunday 13 February 2011 19:21:38 Kees Cook wrote: > On Sun, Feb 13, 2011 at 06:44:01PM -0600, Raphael Geissert wrote: > > I think now would be a great moment to make this change, don't you think? > > The problem is sorting out how to support the older gcc binaries that

Bug#613308: cppcheck: still FTBFS where char is unsigned by default

2011-02-16 Thread Raphael Geissert
ecking behaviour on those architectures, nothing to change re signedness. @Reijo: yes, I took a better look this time and I think the other commit fixes the arch-specific case. Btw, you may want to subscribe to the 'buildd' keyword on the PTS so that you get notified automatically. Ch

Bug#613556: Why dash's local variable inherits its value from outter env?

2011-02-15 Thread Raphael Geissert
st initialize it to the empty value. E.g. local x= Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#613327: lintian: check for missing build deps based on 'dh --with' calls

2011-02-13 Thread Raphael Geissert
. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#587925: Bug#613002: lintian: Please convert SGML to DocBook XML

2011-02-13 Thread Raphael Geissert
ad. If you can guide me (or even better: provide a patch :) to finally make the switch I would be happy to include it. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of &

Bug#507303: security-tracker: please provide a per-maintainer report

2011-02-13 Thread Raphael Geissert
emented that way either. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#613314: centerim: browser setting should default to sensible-browser

2011-02-13 Thread Raphael Geissert
Package: centerim Version: 4.22.10-1 Severity: wishlist Hi, The browser setting in centerim defaults to mozilla, but in Debian it should better default to sensible-browser. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian

Bug#587358: hardening-wrapper: should -Werror=format and -Werror=format-security be set too?

2011-02-13 Thread Raphael Geissert
Hi Kees, I think now would be a great moment to make this change, don't you think? Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble?

Bug#597963: uscan: incorrect parsing of ftp listing

2011-02-13 Thread Raphael Geissert
e. Agreed. I should review the code one of this days, but uscan shouldn't allow a regex to swallow some html (XSS anyone?). Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subjec

Bug#613308: cppcheck: FTBFS in multiple architetures

2011-02-13 Thread Raphael Geissert
: https://github.com/danmar/cppcheck/commit/d8119cd57a6547648b3df5c66d483d25ad33bb82 https://github.com/danmar/cppcheck/commit/b3e19c24d384465b38eec44ee19e4cff0a932939 Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net signature.asc Description: This is a digitally

Bug#613006: apt-file: missing relationship with dpkg-dev and gcc

2011-02-11 Thread Raphael Geissert
Package: apt-file Version: 2.4.0 Severity: minor Hi, rapt-file calls dpkg-architecture (from dpkg-dev) which in turns calls gcc. apt-file should at the very least suggest both packages. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email

Bug#613005: rapt-file is not documented

2011-02-11 Thread Raphael Geissert
Package: apt-file Version: 2.4.0 Severity: minor Hi, There's no manpage for rap-file and even its output is not equivalent to apt- file's. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.

Bug#612841: udd: package info from security mirror horribly out of date, still

2011-02-10 Thread Raphael Geissert
updated, but I don't know what else, if anything was done. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#601602: [php-maint] Bug#601602: still broken?!!

2011-02-06 Thread Raphael Geissert
ines from php.conf, reloaded apache and still have issues then it's a configuration problem elsewhere. The report should probably be closed too. Regards, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debia

Bug#611217: CVE-2011-0413: crash after DHCPv6 decline message

2011-01-26 Thread Raphael Geissert
On Wednesday 26 January 2011 15:24:19 Raphael Geissert wrote: > Hi Ari, Andrew, of course :) (Thanks to adsb for pointing it out) Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org wit

Bug#611217: CVE-2011-0413: crash after DHCPv6 decline message

2011-01-26 Thread Raphael Geissert
which applies almost cleanly in 4.1.1-P1 (3 lines diff between hunks.) I have not tested it, though. [0]http://security-tracker.debian.org/tracker/CVE-2011-0413 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0413 [1]http://www.isc.org/software/dhcp/advisories/cve-2011-0413 Cheers, -- Rapha

Bug#611163: make generated HTML CSS-friendlier

2011-01-26 Thread Raphael Geissert
Package: security-tracker Severity: wishlist In order to apply some CSS the generated code needs to be friendlier, for example: * include ids in the tags * use divs instead of tables Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to

Bug#611162: link to package's changelog entry of fixed version

2011-01-26 Thread Raphael Geissert
1.2.3-1 Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#611161: provide report of RESERVED issues that have information

2011-01-26 Thread Raphael Geissert
Package: security-tracker Severity: wishlist Hi, It would be great to have a report like the one generated by bin/reserved-but- public. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with

Bug#611066: UDD: please import Packages and Sources from archived releases

2011-01-25 Thread Raphael Geissert
Package: qa.debian.org User: qa.debian@packages.debian.org Usertags: udd Severity: wishlist Hi, It would be nice to have the list of packages and sources from archived releases in a some sort of archived_{packages,sources} tables. Thanks in advance. Cheers, -- Raphael Geissert - Debian

Bug#610935: [php-maint] Bug#610935: Bug#610935: Bug#610935: Bug#610935: [php5-intl] Conflicts with php5-idn 1.2b-6

2011-01-24 Thread Raphael Geissert
On Monday 24 January 2011 02:29:45 Ondřej Surý wrote: > On Mon, Jan 24, 2011 at 09:20, Raphael Geissert wrote: > > php5-idn should be dropped from the archive. I don't know of any > > application that uses any of the functions from idn that are not > > provided by in

Bug#610935: [php-maint] Bug#610935: Bug#610935: [php5-intl] Conflicts with php5-idn 1.2b-6

2011-01-24 Thread Raphael Geissert
I'll Conflict php5-intl with php5-idn I never added the conflict because it is supposed to be handled by the extensions manager, and the latest policy explicitly adds a note that such kind of "soft" conflicts are not reason enough to add Conflicts. Cheers, -- Raphael Geis

Bug#605390: mirror submission for mirror.fcaglp.unlp.edu.ar

2011-01-15 Thread Raphael Geissert
; please refer to the following page for the details: http://www.debian.org/mirror/official#process Thanks for mirroring Debian. Regards, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subje

Bug#598233: mirror submission for mirrors.ece.ubc.ca

2011-01-15 Thread Raphael Geissert
Hi, Looks like the mirror is ready to be accepted. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#589499: mirror submission for mirrors.dnepr.com

2011-01-15 Thread Raphael Geissert
Hi, It seems like you are using anonftpsync now, thanks. Could you please tell us how much bandwidth it has available? Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of

Bug#609800: qa.debian.org: please add NEW queue info to madison.php

2011-01-12 Thread Raphael Geissert
all change needs to be made to UDD and the rest is a snap. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#609315: [php-maint] Bug#609315: php5: Upstream bug CVE-2010-4645 / bug #53632, critical: conversion string>double might hang PHP interpreter

2011-01-08 Thread Raphael Geissert
o this bug. I'd > recommend getting in touch with the people from PHP (Pajoye). It can not be reproduced in lenny. The only indication I have for now as to why it can't be reproduced is because the version of gcc in lenny doesn't optimise zend_strotod by making use of the x87 uni

Bug#609283: tokyotyrant: 005-change-default-port can break applications

2011-01-07 Thread Raphael Geissert
those applications should be modified to also pass a port explicitly, maybe the built-in default should be reconsidered (defaulting to 127.0.0.0 isn't too bad either.) Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs

Bug#609071: [php-maint] Bug#609071: Class 'SQLiteDatabase' not found

2011-01-06 Thread Raphael Geissert
> Other php scripts work fine, it's only the sqlite that has an error. Please make sure the extension is actually enabled in the configuration file used by your setup. A simple call to phpinfo() should do it. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net --

Bug#513663: [general] need infrastructure to check related packages

2011-01-06 Thread Raphael Geissert
o be called with 'remove-' Deciding what collection scripts need to depend on the unpack level 1 replacement might be tricky, though. Basically they all depend on it. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bu

Bug#600783: [php-maint] Bug#600783: Confirm

2011-01-04 Thread Raphael Geissert
you please provide a complete backtrace and more details about the test conditions? You can find instructions to generate the backtrace at: http://bugs.php.net/bugs-generating-backtrace.php Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email

Bug#608926: [php-maint] Bug#608926: php5-ffmpeg: Loop while using the extension with FLV files

2011-01-04 Thread Raphael Geissert
p://bugs.php.net/bugs-generating-backtrace.php > = { laEntry 2 } > Cannot adopt OID in UCD-SNMP-MIB: laIndex ::= { laEntry 1 } > That comes from snmp (via php5-snmp maybe) and is irrelevant. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UN

Bug#608837: ohcount: segfaults while checking lintian's source code

2011-01-03 Thread Raphael Geissert
t/git/gitweb.cgi?p=ohcount/ohcount;a=commitdiff;h=c0b28d67f27f6e954c93dabd71d098854896d679 Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble?

Bug#608837: ohcount: segfaults while checking lintian's source code

2011-01-03 Thread Raphael Geissert
, not sure if they are related: https://bugs.launchpad.net/ubuntu/+source/ohcount/+bug/605631 I will make DACA re-check all of the packages with empty reports (probably because of segfaults) and make it generate backtraces. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.de

Bug#608623: coreutils: please provide --no-dereference option for chmod

2011-01-02 Thread Raphael Geissert
Hi Michael, On Sunday 02 January 2011 10:09:34 Michael Stone wrote: > On Sat, Jan 01, 2011 at 10:24:47PM -0600, Raphael Geissert wrote: > >Attached patch is a quick implementation that behaves as expected. It > >works by opening (O_RDONLY) the files and using fchmod afterwards. Th

Bug#608623: coreutils: please provide --no-dereference option for chmod

2011-01-01 Thread Raphael Geissert
ciate your review of the patch, hoping that you also forward it upstream. Thanks in advance. Regards, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net diff -urpN coreutils-8.5-1.orig/src/chmod.c coreutils-8.5-1/src/chmod.c --- coreutils-8.5-1.orig/src/chmod.c 2010-01-01

Bug#607693: CVE Request -- MHonArc: Improper escaping of certain HTML sequences (XSS)

2010-12-21 Thread Raphael Geissert
(unless one of the existing routines misses something.) What do you think about it? Regards, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net diff -urpN mhonarc-2.6.16-1.orig/lib/mhtxthtml.pl mhonarc-2.6.16-1/lib/mhtxthtml.pl --- mhonarc-2.6.16-1.orig/lib/mhtxthtml.pl 20

Bug#606907: [debsnap] it is not documented that it downloads source packages

2010-12-12 Thread Raphael Geissert
o need for clarification :) Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#597217: [php-maint] Bug#597217: Similar problem with tidy.so

2010-12-09 Thread Raphael Geissert
's no dependency between php5 and php5-tidy ? Because it is not needed ;-) it is just php5-tidy's conffile that needs to be purged. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with

Bug#605537: fontforge: buffer overflow when opening .BDF files

2010-12-06 Thread Raphael Geissert
the changelog. Would be great if you could also prepare a fixed version for stable (usual coordination with t...@security.d.o applies.) Thanks in advance. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ

Bug#606151: nordugrid-arc-nox-arex: CVE-2010-3372: insecure library loading

2010-12-06 Thread Raphael Geissert
the CVE id CVE-2010-3372. Please make sure you mention it when fixing this bug. You should coordinate with the release team in order to fix this bug for Squeeze. [0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3372 [1] http://security-tracker.debian.org/tracker/CVE-2010-3372 Si

Bug#394144: Fwd: Bug#394144 closed by Eckhart Wörner ()

2010-12-05 Thread Raphael Geissert
closing. That's not the right way to go. The reproducer is attached to my original report, if you can open it and see the formulas then it's all fixed. -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.

Bug#605844: lintian: Consider pre-sorting keys %{$info->index}

2010-12-03 Thread Raphael Geissert
gging messages, to get a better idea without running a complete profiler. Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#426780: [php-maint] Bug#426780: Bug#426780: Init-script for php-cgi in external FASTCGI Mode (Daemon mode)

2010-12-02 Thread Raphael Geissert
keep track of those extra files that very few people use and that tend to get out of date (like the paranoid php.ini which hasn't been updated for 5.3, AFAIR.) Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ.

Bug#321237: [php-maint] Bug#321237: Bug#321237: Other related issues

2010-12-02 Thread Raphael Geissert
w, so I didn't know about the changes you mentioned.) Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#426780: [php-maint] Bug#426780: Init-script for php-cgi in external FASTCGI Mode (Daemon mode)

2010-12-02 Thread Raphael Geissert
(all?) the cases where one wants to start the cgi on its own what you want is -fpm (which has/had its own init script.) This bug should probably be tagged as wontfix, but I'm gonna wait for the input from the other team members. Cheers, -- Raphael Geissert - Debian Developer www.debian.org

Bug#598421: salome: CVE-2010-3377: insecure library loading

2010-09-29 Thread Raphael Geissert
On 29 September 2010 22:01, Adam C Powell IV wrote: > On Tue, 2010-09-28 at 21:07 +0000, Raphael Geissert wrote: > Would a secure change omit the former LD_LIBRARY_PATH?  That is, would > it fix this in runSalome to say: > > export LD_LIBRARY_PATH=${prefix}/lib:${libdir}:/usr/lib

Bug#598422: scilab: CVE-2010-3378: insecure library loading

2010-09-29 Thread Raphael Geissert
LIBRARY_PATH:+:$LD_LIBRARY_PATH} (be careful with the two colons, removing the first one re-introduces the vulnerability) Cheers, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of &q

Bug#598549: cluster-agents: CVE-2010-3389: insecure library loading

2010-09-29 Thread Raphael Geissert
everywhere: upstream and here at Debian.) [0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3389 [1] http://security-tracker.debian.org/tracker/CVE-2010-3389 Sincerely, Raphael Geissert -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#598418: closed by Alastair McKinstry (Bug#598418: fixed in magics++ 2.10.0.dfsg-5)

2010-09-29 Thread Raphael Geissert
t, why are you using -h? LD_LIBRARY_PATH may contain one directory or a colon-separated list of them. Regards, -- Raphael Geissert - Debian Developer www.debian.org - get.debian.net -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#598413: paxtest: CVE-2010-3373: insecure temporary files handling

2010-09-29 Thread Raphael Geissert
2010/9/28 Javier Fernández-Sanguino Peña : > On Tue, Sep 28, 2010 at 03:41:28PM -0500, Raphael Geissert wrote: >> paxtest writes to paxtest.log in $CWD, which might be abused by a local >> attacker to modify arbitrary files via a symlink or similar. > > This is hardly a

Bug#598424: texmacs: CVE-2010-3394: insecure library loading

2010-09-28 Thread Raphael Geissert
rding this report to upstream and when fixing this bug (everywhere: upstream and here at Debian.) [0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3394 [1] http://security-tracker.debian.org/tracker/CVE-2010-3394 Sincerely, Raphael Geissert -- To UNSUBSCRIBE, email to debian-bugs-di

Bug#598423: scilab-cli: CVE-2010-3378: insecure library loading

2010-09-28 Thread Raphael Geissert
-bin/cvename.cgi?name=CVE-2010-3378 [1] http://security-tracker.debian.org/tracker/CVE-2010-3378 Sincerely, Raphael Geissert -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#598422: scilab: CVE-2010-3378: insecure library loading

2010-09-28 Thread Raphael Geissert
010-3378. Please make sure you mention it when forwarding this report to upstream and when fixing this bug (everywhere: upstream and here at Debian.) [0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3378 [1] http://security-tracker.debian.org/tracker/CVE-2010-3378 Sincerely, Raphael Geis

Bug#598421: salome: CVE-2010-3377: insecure library loading

2010-09-28 Thread Raphael Geissert
am and here at Debian.) [0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3377 [1] http://security-tracker.debian.org/tracker/CVE-2010-3377 Sincerely, Raphael Geissert -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#598419: root-system-proofd: CVE-2010-3376: insecure library loading

2010-09-28 Thread Raphael Geissert
the CVE id CVE-2010-3376. Please make sure you mention it when forwarding this report to upstream and when fixing this bug (everywhere: upstream and here at Debian.) [0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3376 [1] http://security-tracker.debian.org/tracker/CVE-2010-3376 Sincerely, R

<    1   2   3   4   5   6   7   8   9   10   >