Bug#684177: okular cannot search anymore

2012-08-07 Thread Remi Denis-Courmont
Package: okular Version: 4:4.8.4-2 Severity: important Dear Maintainer, With recent Wheezy packages (not sure exactly which), the search function in Okular consistently fails. The waiting spinning cursor shows and the search never completes, nor finding any match nor reporting search failure. How

Bug#661983: cdbs automake rules set libexecdir incorrectly

2012-03-03 Thread Remi Denis-Courmont
Package: cdbs Version: 0.4.105 Severity: normal Hello, The autotools rules in cdbs set libexecdir to /usr/lib/$pkg instead of simply /usr/lib. As a consequence pkglibexecdir becomes /usr/lib/$pkg/$pkg. libexecdir and libdir are supposed to be identical in Debian. See also http://bugs.deb

Bug#638620: /usr/i686-w64-mingw32/include/d2d1.h: Typing mistakes make unusable

2011-08-20 Thread Remi Denis-Courmont
Package: mingw-w64-dev Version: 2.0~rc1-1 Severity: normal File: /usr/i686-w64-mingw32/include/d2d1.h Tags: upstream patch Hello, There are two typing mistakes in that render the file unusable for inclusion. Patch atteched. -- System Information: Debian Release: wheezy/sid APT prefers uns

Bug#634294: nettle-dev: please support pkg-config

2011-07-18 Thread Remi Denis-Courmont
Package: nettle-dev Version: 2.1-2 Severity: wishlist Tags: upstream Hello, nettle-dev does not provide a .pc file for use with pkg-config. This would be much more convenient to detect the development package from autotools and friends. Best regards, -- System Information: Debian Relea

Bug#633675: vlc-nox: heap overflow in AVI plugin

2011-07-12 Thread Remi Denis-Courmont
Package: vlc-nox Version: 1.1.10-1+b1 Severity: grave Tags: security upstream Justification: user security hole See upstream advisory for details: http://www.videolan.org/security/sa1106.html -- System Information: Debian Release: wheezy/sid APT prefers unstable APT policy: (100, 'unstable')

Bug#633674: vlc: heap overflow in RealMedia plugin

2011-07-12 Thread Remi Denis-Courmont
Package: vlc-nox Version: 1.1.10-1+b1 Severity: grave Tags: security upstream Justification: user security hole See upstream advisory for details: http://www.videolan.org/security/sa1105.html -- System Information: Debian Release: wheezy/sid APT prefers unstable APT policy: (100, 'unstable')

Bug#626522: libfuse-dev: examples file fioc.h missing

2011-05-12 Thread Remi Denis-Courmont
Package: libfuse-dev Version: 2.8.4-1.4 Severity: minor Hello, Some of the example codes in libfuse-dev depend on "fioc.h" which is nowhere to be found. The examples are thus unusable as is. Best regards, -- System Information: Debian Release: wheezy/sid APT prefers unstable APT po

Bug#625966: libmodplug1: libmodplug <= 0.8.8.2 .abc Stack-Based Buffer Overflow

2011-05-07 Thread Remi Denis-Courmont
Package: libmodplug1 Version: 1:0.8.8.1-2 Severity: grave Tags: security upstream Justification: user security hole Hello, As the security contact for VLC media player, this was brought to my attention: http://www.exploit-db.com/exploits/17222/ I can confirm the bug happens, but I have

Bug#622091: libmodplug ReadS3M stack overflow

2011-04-10 Thread Remi Denis-Courmont
Package: libmodplug Version: 1:0.8.8.1-2 Severity: grave Tags: security upstream Justification: user security hole Hello, An exploitable memory corruption vulnerability has been publicized against libmodplug 0.8.8.1: http://seclists.org/fulldisclosure/2011/Apr/113 Upstream version 0.8.8

Bug#619963: gcc-4.6: wrongly optimizes memmove() into memcpy()

2011-03-28 Thread Remi Denis-Courmont
Package: gcc-4.6 Version: 4.6.0-1 Severity: grave Justification: renders package unusable Hello, Trying to compile VLC media player using Debian gcc-4.6. It turns out that the compiler is silently replacing memmove() calls with memcpy() ones, when it is clearly NOT a legal optimization.

Bug#614835: libebml0: useless /usr/include directory

2011-02-23 Thread Remi Denis-Courmont
Package: libebml0 Version: 0.7.7-3.1 Severity: minor Hello, The libebml0 binary package creates /usr/include. As a run-time package it should probably not do that. And indeed, it does not hold any file in that directory. Regards, -- System Information: Debian Release: wheezy/sid APT

Bug#600958: RFA: pax-utils -- Security-focused ELF files checking tool

2010-10-21 Thread Remi Denis-Courmont
Package: wnpp Severity: normal I request an adopter for the pax-utils package. This package is NOT to be confused with GNU paxutils. The package description is: This is a small set of various PaX aware and related utilities for ELF binaries. It can check ELF binary files and running processes

Bug#592669: vlc-nox: ID3v2 parser crash on some MP3 file (CVE-2010-2937)

2010-08-11 Thread Remi Denis-Courmont
Package: vlc-nox Version: 1.1.1-1 Severity: important Tags: upstream patch security Hello, VLC fails to perform sufficient input validation when trying to extract some meta-informations about input media through ID3v2 tags. In the failure case, VLC attempt dereference an invalid memory addr

Bug#588465: libmodplug0c2: trackers become silent in VLC with 0.8.8 update

2010-07-08 Thread Remi Denis-Courmont
Package: libmodplug0c2 Version: 1:0.8.8-2 Severity: important Tags: upstream Hello, libmodplug0c2 0.8.8 makes playback of MOD files completely silent with vlc from Debian. Downgrading to libmodplug0c2 0.8.7-1 works around the problem. -- System Information: Debian Release: squeeze/sid A

Bug#580396: libkio5 exit handler crashes

2010-05-05 Thread Remi Denis-Courmont
Package: libkio5 Version: 4:4.4.3-1 Severity: normal Tags: upstream Hello, libkio5 appears to register a buggy exit handler. This triggers a crash after VLC returns from its main(), if and only if the Open file dialog has been shown. libkio is loaded by KDE dialog plugins for libQt4Gui,

Bug#580257: kdelibs5: KDE desktop does not start after 4.4 upgrade

2010-05-04 Thread Remi Denis-Courmont
Package: kdelibs5 Version: 4:4.4.3-1 Severity: grave Justification: renders package unusable Hello, After upgrading to KDE 4.4 from Sid, login from KDM just return a wallpaper and a mouse. The KDE startup progress bar is never shown. Nothing ever happens. Invoking startx from the text m

Bug#578273: libc6-dev: Please provide thread-safe dlerror() replacement

2010-04-18 Thread Remi Denis-Courmont
Package: libc6-dev Version: 2.10.2-6 Severity: wishlist Tags: upstream Hello, The current glibc implementation of dlerror() calls strerror(). The current implementation of strerror() is not thread-safe. While this is allowed by POSIX, this is quite inconvenient for thread-safe programs o

Bug#578161: liblivemedia-dev: GPL patch is incompatible with LGPL distribution

2010-04-17 Thread Remi Denis-Courmont
Package: liblivemedia-dev Version: 2010.02.10-1 Severity: serious Justification: Policy 2.3 Hello, The liblivemedia-dev packages applies a patch explicitly licensed under the GPL. In my understanding, this makes the resulting binaries GPL. Yet the copyright file claims Debian provides t

Bug#572723: manpages-fr-extra: /usr/share/man/fr/man1/rand.1SSL.gz badly encoded

2010-03-05 Thread Remi Denis-Courmont
Package: manpages-fr-extra Version: 20090906 Severity: normal Hello, Accentuated characters in /usr/share/man/fr/man1/rand.1SSL.gz (man 1 rand) are incorrectly encoded. It seems the file has been transcoded from Latin-1 to UTF-8 *twice*. Best regards, -- System Information: Debian Rele

Bug#569835: xdg-utils: xdg-screensaver does not support KDE4/FreeDesktop screensaver

2010-02-14 Thread Remi Denis-Courmont
Package: xdg-utils Version: 1.0.2-6.1 Severity: important Hello, xdg-screensaver as found in Debian does not inhibit the KDE desktop screensaver (which uses the FreeDesktop DBus API). Nothing happens, except for the dcop error already noted in Debian bug #557104. The current version fro

Bug#567186: RFH: miredo -- Teredo IPv6 tunneling through NATs

2010-01-27 Thread Remi Denis-Courmont
Package: wnpp Severity: normal Hello, I request assistance with maintaining the miredo package. The last update has unfortunately introduced a severe regression. That bug was upstream, but that's hardly an excuse since I am upstream too. In the mean time, I have lost contact of my sponsor (n

Bug#565178: mpeg2dec: fails with BadMatch XVideo error

2010-01-13 Thread Remi Denis-Courmont
Package: mpeg2dec Version: 0.4.1-3 Severity: important Hello, mpeg2dec systematically crashes at start with the default settings: 0.4.1 - by Michel Lespinasse and Aaron Holtzman X Error of failed request: BadMatch (invalid parameter attributes) Major opcode of failed request: 132 (

Bug#564610: clang: MB_LEN_MAX definition is wrong

2010-01-10 Thread Remi Denis-Courmont
Package: clang Version: 2.6-1 Severity: grave Justification: renders package unusable Hello, Debian clang's defines MB_LEN_MAX to 1. Debian eglibc insists on MB_LEN_MAX being equal to 16 (/usr/include/bits/stdlib.h:89). Otherwise it fails explicitly into an #error. Regardless of eglib

Bug#563477: vlc-nox: hotkeys plugin needed for command line interface

2010-01-03 Thread Remi Denis-Courmont
Package: vlc-nox Version: 1.0.4-1 Severity: normal Hello, Since version 1.0.4-1, the hotkeys plugin is part of vlc instead of vlc-nox. This is quite unfortunate as the command line interface (rvlc) does use hotkeys (with the key command) too, not just the X11 UIs. -- System Information: Deb

Bug#563476: vlc: upgrade fails

2010-01-03 Thread Remi Denis-Courmont
Package: vlc Version: 1.0.4-1 Severity: normal Hello, Upgrading vlc and vlc-nox from 1.0.3-1 to 1.0.4-1 fails as the hotkeys plugin has changed from the latter package to the former. -- System Information: Debian Release: squeeze/sid APT prefers unstable APT policy: (100, 'unstable') Arc

Bug#557104: /usr/bin/xdg-screensaver: xdg-screensaver: wrongly complains about missing dcop

2009-11-19 Thread Remi Denis-Courmont
Package: xdg-utils Version: 1.0.2-6.1 Severity: minor File: /usr/bin/xdg-screensaver Hello, With Debian KDE 4.3, xdg-screensaver keeps complaining that dcop is not present. In my understanding, this is a normal situation with KDE 4, so it should not print an error. Best regards, -- Sys

Bug#551903: libc6-i686 pthread_cond_wait fails to reacquire mutex upon cancellation

2009-10-21 Thread Remi Denis-Courmont
Package: libc6-i686 Version: 2.10.1-1 Severity: critical Justification: breaks unrelated software Hello, With the upgrade to 2.10.1, pthread_cond_wait() fails to re-acquire the provided mutex when acting on a deferred cancellation event from another thread. This is seen if (and apparentl

Bug#551494: libc6-dev: Please define O_CLOEXEC in fcntl.h

2009-10-18 Thread Remi Denis-Courmont
Package: libc6-dev Version: 2.9-27 Severity: wishlist Hello, Recent kernel versions introduced the O_CLOEXEC open() flag to support setting the close-on-exec in a thread-safe manner (i.e. atomic w.r.t. the process file descriptor table). Unfortunately, the definition for O_CLOEXEC is on

Bug#551201: /usr/share/man/man3/insque.3.gz: insque() description contradicts POSIX and actual behaviour

2009-10-16 Thread Remi Denis-Courmont
Package: manpages-dev Version: 3.22-1 Severity: normal File: /usr/share/man/man3/insque.3.gz Hello, The manual page for insque() states that insque(&elem, NULL); is invalid. However, the POSIX standards and the actual glibc implementation both explicitly allows this: http://www.openg

Bug#550866: kdelibs5: KDE password prompts broken, busy loops

2009-10-13 Thread Remi Denis-Courmont
Package: kdelibs5 Version: 4:4.3.2-2 Severity: important Hello, Since the last update, all KDE-based password prompt fields appear to enter a busy loop when they get the focus. Pressing Enter does not work. Clicking on the confirmation button has no effect either. This is visible in the KDE

Bug#496715: [Xcb] Bug#496715: libpthread-stubs: Should provide more pthread_* functions

2009-10-11 Thread Remi Denis-Courmont
- Message d'origine - > Hello, > > Here is a patch that adds only pthread_condattr_init/destroy, > pthread_cond_timedwait, pthread_exit, and makes both cond_*wait abort > instead of just returning 0. I would expect cond_timedwait to sleep for the specified interval rather than abort (thou

Bug#540109: libtheora-dev: libtheora.la refers to non-existent libogg.la

2009-08-05 Thread Remi Denis-Courmont
Package: libtheora-dev Version: 1.0-2 Severity: grave Justification: renders package unusable Hello, /usr/lib/libtheora.la refers to libogg.la which is nowhere to be found among the dependencies of libtheora-dev. I gues libogg-dev stops providing libtool archives. This causes any attemp

Bug#532688: libxcb-randr0-dev: Please depend on libxcb-render0-dev (or do not include its header)

2009-06-10 Thread Remi Denis-Courmont
Package: libxcb-randr0-dev Version: 1.3-2 Severity: minor Hello, from libxcb-randr0-dev includes "render.h", which is part of the libxcb-render0-dev package. Effectively, the Randr development package is useless without the Render one. Hence, the former should depend (Depends:) on the latte

Bug#530560: libxcb-shm0-dev: xcb_shm_completion_event_t mislaid out

2009-05-25 Thread Remi Denis-Courmont
Package: libxcb-shm0-dev Version: 1.2-1 Severity: important Hello, It would seem that the layout of the xcb_shm_completion_event_t structure has the segment XID swapped with the event minor/major numbers. This breaks processing of SHM completion event pretty badly (without an ugly work a

Bug#529633: mozilla-plugin-vlc: Logging through Javascript hurts privacy

2009-05-20 Thread Remi Denis-Courmont
Package: mozilla-plugin-vlc Version: 0.9.9a-2 Severity: important Tags: security Hello, The logging Javascript API (vlc.log.*) provided by this plugin can leak sensitive informations to third party websites. For instance, one can enumerate the content of file system by "opening" a direct

Bug#528044: vlc: invalid symlink at /usr/share/vlc/http/.hosts

2009-05-10 Thread Remi Denis-Courmont
Package: vlc Version: 0.9.9a-2 Severity: minor The symbolic link at /usr/share/vlc/http/.hosts leads nowhere. I assume a dot is missing in the target path. I would expect this would leave the HTTP interface world-writable by default, but somehow it does not? -- System Information: Debian Release

Bug#526985: kmail: SSL connection with CAcert cannot be secured

2009-05-04 Thread Remi Denis-Courmont
Package: kmail Version: 4:4.2.2-1 Severity: grave Tags: security Justification: user security hole Hello, Contrary to that in KDE 3.5, kmail in KDE 4.2 is incapable of verifying IMAP server credentials when TLS is used. This means that the user has to decide between fetching mail at all

Bug#526979: konqueror: cannot import SSL root certificates

2009-05-04 Thread Remi Denis-Courmont
Package: konqueror Version: 4:4.2.2-1 Severity: important Hello, Since upgrading from 3.5 to 4.2, Konqueror has become completely unable to import root certificates with the certificate manager. That makes secure connections to, e.g. Cacert.org-certified websites _impossible_. Needless to men

Bug#525540: kwallnetmanager: looses pass key strokes when opening the wallet

2009-04-25 Thread Remi Denis-Courmont
Package: kwalletmanager Version: 4:4.2.2-1 Severity: important Hello, Just upgraded from KDE 3.5.10 to 4.2.2 from unstable. As per my older configuration, the KDE password widgets are printing 3 dots instead of just 1, whenever a key is pressed. However, this has now become horribly slow

Bug#512564: libxcb1-dev: Please package the developper documentation

2009-01-21 Thread Remi Denis-Courmont
Package: libxcb1-dev Version: 1.1.92-0.1 Severity: wishlist Hello, The libxcb source includes Doxygen documentation and a plain HTML tutorial in the doc/ directory. It would be nice to not have to have it in libxcb-doc or whatever, besides just the source package. Regards, -- System Infor

Bug#504639: vlc: buffer overflow in CUE support

2008-11-05 Thread Remi Denis-Courmont
Package: vlc-nox Version: 0.8.6.h-4.1 Severity: grave Tags: security Justification: user security hole Hello, When parsing the header of an invalid CUE image file or an invalid RealText subtitle file, stack-based buffer overflows might occur: http://www.videolan.org/security/sa0810.html

Bug#502726: libty_plugin: vlc: exploitable buffer overflow in TY demux

2008-10-19 Thread Remi Denis-Courmont
Package: vlc-nox Version: 0.8.6.h-4 Severity: grave File: libty_plugin Tags: security Justification: user security hole VLC versions 0.8.2 through 0.9.4 are prone to an exploitable stack-based buffer overflow in the TY (TiVo) file parser. See also http://www.videolan.org/security/sa0809.html N.

Bug#495411: libtool-doc: info pages not available anymore

2008-08-16 Thread Remi Denis-Courmont
Package: libtool-doc Version: 2.2.2-1 Severity: normal Tags: experimental Hello, With libtool-doc from experimental, "info libtool" does not work anymore. It brings up the shortened manual page instead of the info pages. Regards, -- System Information: Debian Release: lenny/sid APT p

Bug#493459: kopete: XMPP DNS SRV lookups

2008-08-02 Thread Remi Denis-Courmont
Package: kopete Version: 4:3.5.9-3 Severity: wishlist Hello, Kopete will only try A/ DNS lookups to connect to a Jabber/XMPP server. If the domain uses SRV records, the only way to connect is to lookup the server manually, e.g. with dig, and hard-code it in the Kopete configuration.

Bug#493458: kopete: XMPP StartTLS not supported

2008-08-02 Thread Remi Denis-Courmont
Package: kopete Version: 4:3.5.9-3 Severity: normal Hello, Kopete appears to be unable to handle StartTLS for XMPP/Jabber. If the server requires it (e.g. ovi.com), it is entirely impossible to connect to the service. Works fine with pidgin. -- System Information: Debian Release: lenny/

Bug#348056: tcptraceroute sees no traffic from ppp0

2008-06-24 Thread Remi Denis-Courmont
Hello, On Tue, 24 Jun 2008 07:51:22 +0200, Daniel Baumann <[EMAIL PROTECTED]> wrote: > please retry with the current version (1.5beta7+debian-1 that is), which > I've just uploaded to sid. Sorry, I am not using the affected connection setup anymore, cannot test anymore. -- Rémi Denis-Courm

Bug#485813: manpages-fr-extra: pthread_mutex_lock EDEADLK wrong

2008-06-11 Thread Remi Denis-Courmont
Package: manpages-fr-extra Version: 20080429 Severity: normal Tags: l10n Hello, The error case EDEADLK for pthread_mutex_lock is described as the opposite of when it actually happens. Please check the original version. Regards -- System Information: Debian Release: lenny/sid APT pref

Bug#239073: /usr/bin/ogg123: French status translation is too wide

2008-05-18 Thread Remi Denis-Courmont
Package: vorbis-tools Version: 1.2.0-1 Followup-For: Bug #239073 I have the same problem. Widening the console to 81 columns works around the issue. Switching to another language also fixes the issue; it would the French translation for the status string is one character too wide. -- System Info

Bug#480370: mozilla-plugin-vlc: CVE-2007-6683 is not fixed at all

2008-05-09 Thread Remi Denis-Courmont
Package: mozilla-plugin-vlc Version: 0.8.6.e-2.1 Severity: grave Tags: security patch Justification: user security hole The "vlc" binary package part of CVE-2007-6683 has been fixed as per #458318. However, the issue affecting the mozilla plugin as noted here: http://mailman.videolan.org/pipermai

Bug#468801: libc6: RFC3484 scoping rules should only affect IPv6, not IPv4

2008-03-01 Thread Remi Denis-Courmont
Package: libc6 Version: 2.7-9 Severity: normal Tags: patch Hello, Rule 2 of the Destination Address Selection algorithm in RFC3484 specifies: | Rule 2: Prefer matching scope. | If Scope(DA) = Scope(Source(DA)) and Scope(DB) <> Scope(Source(DB)), | then prefer DA. Similarly, if Scope(D

Bug#467652: vlc: arbitrary memory overwrite in the MP4 demuxer

2008-02-26 Thread Remi Denis-Courmont
Package: vlc Version: 0.8.6.c-6 Severity: grave Tags: security Justification: user security hole "VLC media player's MPEG-4 file format parser (a.k.a. the MP4 demuxer) suffers from an arbitrary memory overwrite vulnerability when using specially crafted (invalid) MP4 input files. If successful,

Bug#466276: libdvbpsi4-dev: dvbpsi_SDTServiceAddDescriptor not defined

2008-02-17 Thread Remi Denis-Courmont
Package: libdvbpsi4-dev Version: 0.1.5-3 Severity: important Tags: fixed-upstream Hello, The dvbpsi_SDTServiceAddDescriptor API is not defined by . As such, the compiler assumes all of its parameters are interger. This creates incorrect (segfaulting) code on 64-bits platforms, as the poi

Bug#466237: xml2rfc: fails to run with tcl8.5

2008-02-17 Thread Remi Denis-Courmont
Package: xml2rfc Version: 1.32.dfsg-1 Severity: grave Justification: renders package unusable Hello, Since I switched from tcl8.4 to tcl8.5 (pulled by planetpenguin-racer-data), xml2rfc will not work at all anymore. It simply fails with: xml2rfc: error: can't read "counter(section)": no

Bug#464261: New linux headers?

2008-02-06 Thread Remi Denis-Courmont
tags 464261 + confirmed upstream fixed-upstream thanks Right. This would be due to >= 2.6.24 linux-kernel-headers, I guess. Upstream SVN has a patch for this. -- Rémi

Bug#462837: fluidsynth: heavy memory leaks

2008-01-27 Thread Remi Denis-Courmont
Package: libfluidsynth1 Version: 1.0.7a-1 Severity: normal Tags: fixed-upstream Hello, Fluidsynth 1.0.7 leaks memory quite heavily (depending on the soundfonts size, I guess) when it is initialized and deinitialized multiple times from within the same process. It would seem that upstrea

Bug#333418: #333418 not an iptables bug

2006-08-09 Thread Remi Denis-Courmont
reported: it simply returns the EINVAL back from the kernel. The iptables manpage should mention the limitations though, and correctly. -- Remi Denis-Courmont http://www.simphalempin.com/home/ -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Cont

Bug#338128: Plans to integrate in Debian?

2006-06-21 Thread Remi Denis-Courmont
to kill anyone (I hope). If someone has a more FTP-master-friendly implementation of anything they didn't like (MD5?), that's a possible option as well. -- Remi Denis-Courmont http://www.simphalempin.com/home/ -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Bug#338128: miredo: alternative package available

2006-06-13 Thread Remi Denis-Courmont
for teleport-iabg. As for the other relays, HotNIC is running something on FreeBSD, and ConsulIntel runs miredo atop RHEL, but that's slightly out of topic. -- Remi Denis-Courmont http://www.simphalempin.com/home/ -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]