Bug#1082849: bluez: CVE-2024-8805

2024-10-05 Thread Sylvain Beucler
a potential RCE fix (it just prints a warning). Is there a mistake in the ZDI advisory? Cheers! Sylvain Beucler Debian LTS Team

Bug#1078445: autopkgtest: debian/tests/lxc-old-testbed no longer works: cannot find Ubuntu 14.04 signing key

2024-09-02 Thread Sylvain Beucler
works. I am not intending to work on this myself (I don't use suites this old and am not paid to maintain them). FTR I referenced this issue in the ELTS internal tracker. (I didn't see follow-ups to this bug until I checked again by chance; honestly I'm still puzzled on how the BTS is supposed to help with that.) Cheers! Sylvain Beucler Debian LTS Team

Bug#1070962: ruby2.7: FTBFS: failing tests

2024-09-02 Thread Sylvain Beucler
Control: fixed -1 2.7.4-1+deb11u2 thanks

Bug#1080306: RFS: prandom/1.0r1 -- whish list - First package

2024-09-01 Thread Sylvain
gards, Sylvain Saucier, Proud author of prandom

Bug#1007884: bullseye-pu: package glewlwyd/2.5.2-2+deb11u3

2024-08-14 Thread Sylvain Beucler
opose a debdiff at debian-...@lists.debian.org (ideally along with test procedures) and the LTS Team will take care of the administrativia. Cheers! Sylvain Beucler Debian LTS Team

Bug#1007884: bullseye-pu: package glewlwyd/2.5.2-2+deb11u3

2024-08-14 Thread Sylvain Beucler
15 as well? (as in bookworm 12.6, "fix open redirection via redirect_uri") Is it something a LTS contributor could help with? Cheers! Sylvain Beucler Debian LTS Team

Bug#1078445: autopkgtest: debian/tests/lxc-old-testbed no longer works: cannot find Ubuntu 14.04 signing key

2024-08-12 Thread Sylvain Beucler
025-06-30 so it would be nice to keep this working. I believe ci.freexian.com runs the same autopkgtest on all dists, e.g.: https://ci.freexian.com/packages/r/rails/jessie/i386/91105/ Btw there was a similar discussion for debusine at: https://salsa.debian.org/freexian-team/debusine/-/issues/459 Cheers! Sylvain Beucler Debian LTS Team

Bug#1076554: Regression: error parsing URL //: Invalid host/port

2024-07-18 Thread Sylvain Beucler
Package: apache2 Version: 2.4.61-1~deb12u1 Severity: important Dear Maintainer, Following DSA 5729-1 (2.4.61-1~deb12u1), access to Sympa broke. User error: Bad Request Log error: AH01059: error parsing URL //: Invalid host/port I believe the issue is related to this line: SetHandler "proxy:un

Bug#834059: dose-builddebcheck: outputs wrong yaml

2024-06-22 Thread Sylvain Beucler
Reported upstream at https://gitlab.com/irill/dose3/-/issues/18 :) -- Sylvain

Bug#1064063: plasma-workspace: CVE-2024-1433

2024-06-18 Thread Sylvain Beucler
-tracker/-/commit/f0cddbc1a89d6988e0891225dfe9eb40374b1d8d I'm leaving the bug open but feel free to close it if the above sounds sensible :) Cheers! Sylvain Beucler Debian LTS Team On Fri, 16 Feb 2024 16:16:09 +0100 =?UTF-8?Q?Moritz_M=C3=BChlenhoff?= wrote: Source: plasma-workspace X-De

Bug#1067807: reportbug: Increase vm.max_map_count for game/application compatibility

2024-03-26 Thread Sylvain GIRARDOT
dification should be tested to assess its impact on system performance and resource consumption before being integrated by default, through debian sid for example. -- Package-specific info: ** Environment settings: INTERFACE="gtk" ** /home/sylvain/.reportbugrc: reportbug_version &qu

Bug#1066983: monopd: Fails to start monopd.service

2024-03-25 Thread Sylvain Rochet
Hi Markus, On Mon, Mar 25, 2024 at 02:36:59AM +0100, Markus Koschany wrote: > Sylvain Rochet wrote: > > Actually, the main problem is /lib/systemd/system/monopd.socket which > > set Accept=yes while monopd needs Accept=no (which is the default value). > > I wonder if m

Bug#1066983: monopd: Fails to start monopd.service

2024-03-24 Thread Sylvain Rochet
Hi, On Sat, Mar 23, 2024 at 09:35:38PM +0100, Sylvain Rochet wrote: > > That might be related to the latest change "Add a service template for > compatibility reasons with monopd.socket.". Actually, the main problem is /lib/systemd/system/monopd.socket which set Accept=yes

Bug#1066983: monopd: Fails to start monopd.service

2024-03-23 Thread Sylvain Rochet
for me: # systemctl stop monopd@*.service # systemctl stop system-monopd.slice # systemctl stop monopd.socket # systemctl mask monopd.socket # systemctl enable monopd.service # systemctl start monopd.service Kind regards, Sylvain signature.asc Description: Digital signature

Bug#1067113: libhiredis-dev: cmake config incompatible with upstream

2024-03-18 Thread Sylvain Joubert
Package: libhiredis-dev Version: 1.2.0-6 Severity: normal X-Debbugs-Cc: joubert...@gmail.com Dear Maintainer, The CMake config provided by this package seems incompatible with the upstream one. Currently, the package provides data under the name "Hiredis" with a capital leading H, while upstream

Bug#1056992: freerdp2 version 3

2024-02-23 Thread Sylvain Archenault
Hi Mike & team, Is there something blocking you to start packaging v3 ? Thanks Sylvain

Bug#1059560: libwebkit2gtk-4.1-0: Can not add google online account via gnome-controle-center without : export WEBKIT_DISABLE_DMABUF_RENDERER=1

2023-12-28 Thread Maurin Sylvain
On Thu, 2023-12-28 at 14:25 +, Alberto Garcia wrote: > Control: tags -1 moreinfo > > On Thu, Dec 28, 2023 at 12:40:06PM +0100, Sylvain Maurin wrote: > > After a fresh install on a DELL Precision 3620 with i915 and Quadro > > K420 display adapters (used with Nvidia l

Bug#1059560: libwebkit2gtk-4.1-0: Can not add google online account via gnome-controle-center without : export WEBKIT_DISABLE_DMABUF_RENDERER=1

2023-12-28 Thread Sylvain Maurin
tors: 3 0: +*DP-1 1920/546x1200/352+1050+404 DP-1 1: +DP-1-2 1200/518x1920/324+2970+0 DP-1-2 2: +HDMI-1-2 1050/473x1680/296+0+254 HDMI-1-2 ``` Thank's you for you work and happy holidays, Sylvain -- System Information: Debian Release: 12.4 APT prefers stable-updates APT polic

Bug#1057671: cytadela: game include non free graphical assets

2023-12-07 Thread Sylvain Beucler
ar archives contains textures and game fonts. Since the game engine is made specially for these 'contrib' data, it basically depends on them, so it goes to 'contrib' as well. It can go in 'main' as soon as the original data goes in 'main'. Cheers! Sylvain

Bug#1026898: deprecate QUOTAUSER post-bookworm

2023-11-27 Thread Sylvain Beucler
Hi, On 26/11/2023 11:32, Marc Haber wrote: On Sun, Nov 26, 2023 at 10:00:27AM +0100, Sylvain Beucler wrote: I use QUOTAUSER on a multi-user remote system, for a non-profit, where people tend to forget about disk space, to ensure any new 'adduser' sets a reasonable quota. If

Bug#1026898: deprecate QUOTAUSER post-bookworm

2023-11-26 Thread Sylvain Beucler
Hi, I use QUOTAUSER on a multi-user remote system, for a non-profit, where people tend to forget about disk space, to ensure any new 'adduser' sets a reasonable quota. If there's an alternative please let me know. I might contribute some tests but probably not soon. Cheers! Sylvain

Bug#1056593: transmission-remote-gtk: upstrean LOCALEDIR envvar bug avoids loading locale file

2023-11-23 Thread Sylvain CANOINE
Package: transmission-remote-gtk Version: 1.5.1-1 Severity: normal Tags: l10n upstream X-Debbugs-Cc: cano...@9online.fr Dear Maintainer, The current version has a bug which prevents loading the appropriate locale file, so transmission-remote-gtk isn't translated for non-english-speaking users.

Bug#1055415: Wrong order for the `resolve' option in nsswitch.conf

2023-11-05 Thread Sylvain Garrigues
Le dimanche 5 novembre 2023, Michael Biebl a écrit : > > See https://salsa.debian.org/systemd-team/systemd/-/merge_requests/162 > > This is indeed related. Yet the changes (as of today) do not seem to fix the order for `resolve'. This merge request seems to be waiting for a consensus before it ca

Bug#1055415: Wrong order for the `resolve' option in nsswitch.conf

2023-11-05 Thread Sylvain Garrigues
Package: libnss-resolve Version: 252.17-1~deb12u1 X-Debbugs-CC: pkg-systemd-maintain...@lists.alioth.debian.org The debian postinstall script for libnss-resolve inserts `resolve' in the `hosts:' line of /etc/nsswitch.conf before `dns', therefore after `files'. This does not seem optimal, as per `m

Bug#1053562: nvidia-driver: Please package version 535 (possibly solves issues with running Dota 2).

2023-10-06 Thread Sylvain BOILARD
Package: nvidia-driver Version: 530.41.03-3 Severity: normal Dear Maintainer, Please consider packaging version 535 of the NVIDIA drivers as that version seems to solve an issue with the game Dota 2 as is discussed here: https://github.com/ValveSoftware/Dota-2/issues/2414 . To briefly summarize

Bug#1043011: clazy: Incompatibility with gcc/libstdc++ version 13

2023-08-04 Thread Sylvain Joubert
Package: clazy Version: 1.11-4 Severity: important X-Debbugs-Cc: joubert...@gmail.com Dear Maintainer, Using clazy on Debian testing with the newly updated libstdc++ to version 13 I now get the following error: /usr/bin/../lib/gcc/x86_64-linux- gnu/13/../../../../include/c++/13/chrono:2320:48: e

Bug#1035875: Arbitrary code execution vulnerability in versions < 2.3

2023-06-20 Thread Sylvain Beucler
msi_dirent_new() Fix more fuzzer errors etc. so most probably there isn't a single clean patch to apply :/ We might want to just bump to buster and bullseye to 2.3, there's only one rdep AFAICS. Cheers! Sylvain Beucler Debian LTS Team (this week's Front-Desk person)

Bug#1033604: runc_1.0.0~rc6+dfsg1-3+deb10u2_amd64.deb: Built-Using refers to non-existing source package

2023-03-28 Thread Sylvain Beucler
-mrunalp-fileutils (= 0.0~git20160930.0.4ee1cc9-1) AFAICT we're missing these at security.debian.org/pool/: - golang-github-mrunalp-fileutils (= 0.0~git20160930.0.4ee1cc9-1) - golang-github-urfave-cli (= 1.20.0-1) Could an ftp-master inject these dependencies and re-process the .changes? Cheers! Sylvain Beucler Debian LTS Team

Bug#1032482:

2023-03-07 Thread Sylvain Tgz
I found a related issue on upstream git. https://github.com/lxc/lxd/pull/11333 Following date of 5.0.2 and issue creation. This fix is not present on 5.0.2.

Bug#1032482: LXD - issue with btrfs backend loop file

2023-03-07 Thread Sylvain Tgz
fore, changelog of 5.0.2 seems have the fix : https://linuxcontainers.org/lxd/news/#lxd-502-lts-has-been-released "lxd/storage/drivers/driver/btrfs/utils: Fix getQGroup to suport BTRFS >= 6.0.1" I will also try to inform upstream devs. I will keep you if I have news from them. Sylvain

Bug#922729: debootstrap: unable to override arch-test

2023-01-12 Thread Sylvain LÉVÊQUE
Package: debootstrap Followup-For: Bug #922729 Hello The workaround I found was to install the binfmt-support and qemu-user-static packages, when debootstrap'ing an arm64 chroot on a amd64 host. Thank you -- Sylvain

Bug#1025297: Fixed in 22.3.2-1

2023-01-07 Thread Sylvain Archenault
After upgrading to 22.3.2-1 - issue seems resolved for me.

Bug#1025798: dolphin-emu: depends on obsolete packages libmbedcrypto3, libmbedtls12, libmbedx509-0

2022-12-09 Thread Sylvain BOILARD
4.1 dolphin-emu recommends no packages. dolphin-emu suggests no packages. -- no debconf information -- Sylvain BOILARD

Bug#1025432: LXD - suggestion to moving dnsmasq to recommended dependencie

2022-12-04 Thread Sylvain Tgz
s good. I hope that other user will send their opinion Sylvain [1] - https://lists.debian.org/debian-go/2022/12/msg6.html [2] - https://debian-handbook.info/browse/stable/sect.package-meta-information.html

Bug#1025297: thunderbird segfault with 22.3

2022-12-02 Thread Sylvain Archenault
Hi, I'm also encountering issues with 22.3.0-1 with thunderbird. The application doesn't start - here's GDB backtrace: #0 _dl_close (_map=0x0) at ./elf/dl-close.c:795 #1 0x77b6de9a in __GI__dl_catch_exception (exception=exception@entry=0x7fff9a70, operate=, args=) at ./elf/dl-err

Bug#1023884: vtun: patch for libssl3

2022-11-23 Thread Sylvain Rochet
Hi, Attached patch is a better approach to fix that by loading providers in main instead of crypto module. That way it also works for legacy VTun crypto module (VTun <= 2.6) if there are any users left and is future proof for auth module. Sylvain diff -Nru vtun-3.0.4.orig/main.c vtun-3.

Bug#1023884: vtun: patch for libssl3

2022-11-11 Thread Sylvain Rochet
Package: vtun Version: 3.0.4-2+b1 Severity: important Dear Maintainer, gdb: Program received signal SIGSEGV, Segmentation fault. 0x77c063a2 in EVP_CIPHER_CTX_set_key_length () from /lib/x86_64-linux-gnu/libcrypto.so.3 OpenSSL 3.0 introduced providers, legacy algorithms such as RC4 o

Bug#1023473: tinyproxy: Bad owner for /var/log/tinyproxy with bullseye bpo

2022-11-04 Thread Sylvain Tgz
Package: tinyproxy Version: 1.11.1-1~bpo11+1 Severity: important X-Debbugs-Cc: tarjaiz...@gmail.com Dear Maintainer, With 1.11.1-1~bpo11+1 version, owner of /var/log/tinyproxy is not set to tinyproxy user. During starting service, we have this error : ERROR: Could not create log file /var/log/t

Bug#961654: buster-pu: package bzip2/1.0.6-9.2~deb10u1

2022-09-13 Thread Sylvain Beucler
Hi, IIUC this is about fixing 2 non-security bugs, that were introduced prior to buster's initial release. I personally don't think this fits the LTS project scope. Maybe other LTS members will have a different opinion. Cheers! Sylvain Beucler Debian LTS Team On 13/09/2022 15:27

Bug#1006682: /usr/lib/cmake/mathgl2/MathGL2Config.cmake: Could NOT find OpenMP_CXX

2022-08-31 Thread Sylvain Joubert
ily dependent on the clang version used/installed. Given that understanding I'd be fine with leaving things as is. And maybe it's the upstream MathGL2Config.cmake that needs a rework to deal more easily with various setups. Anyway, thanks for taking a look. Le mer. 31 août 2022 à 1

Bug#1006682: /usr/lib/cmake/mathgl2/MathGL2Config.cmake: Could NOT find OpenMP_CXX

2022-08-31 Thread Sylvain Joubert
installed I get the initial reported error. Le mar. 30 août 2022 à 22:03, Rafael Laboissière a écrit : > Control: tags -1 moreinfo > > * Sylvain Joubert [2022-03-02 11:17]: > > > Package: libmgl-dev > > Version: 8.0.1-1 > > Severity: normal > > > &

Bug#819341: [unison] Please build unison-fsmonitor

2022-08-12 Thread Sylvain Leroy
n number > in the unison package name, since it has an effect on the behavior. Right. I've already uploaded unison-2.48 to NEW, let's settle on that first. I will add the OCaml version number in the next OCaml transition. Any news on the unison-fsmonitor helper to be compiled and bundled with the unison package ? -- Sylvain Leroy Président Eternilab https://www.eternilab.com

Bug#1010349: closed by Sylvain Beucler (Re: librecad: CVE-2021-21897 - heap-based buffer overflow loading a DXF file via embedded dxflib)

2022-08-03 Thread Sylvain Beucler
Hi, On 03/08/2022 19:31, Moritz Mühlenhoff wrote: > Am Sat, May 28, 2022 at 06:36:29PM +0200 schrieb Sylvain Beucler: >> - the package uses system dxflib, cf. debian/patches/debian_build.patch > > But is that functional/working as expected? librecad does not > have and depend

Bug#1014064: libqpid-proton-cpp12-dev: Missing CMake config files

2022-06-29 Thread Sylvain Joubert
(using find_package) I believe the same issue also applies to the libqpid-proton11-dev package The missing files should be in /usr/lib/cmake/ProtonCpp/ and in /usr/lib/cmake/Proton/ for libqpid-proton11-dev Sylvain. -- System Information: Debian Release: bookworm/sid APT prefers testing APT

Bug#1010349: librecad: CVE-2021-21897 - heap-based buffer overflow loading a DXF file via embedded dxflib

2022-05-28 Thread Sylvain Beucler
p for 'groupCode==42'), this particular file is not used in the build process AFAICT Can you confirm and update the security tracker accordingly? Cheers! Sylvain Beucler Debian LTS Team On Fri, 29 Apr 2022 11:09:43 +0100 Neil Williams wrote: Source: librecad Version: 2.1.3-3 Seve

Bug#1006682: /usr/lib/cmake/mathgl2/MathGL2Config.cmake: Could NOT find OpenMP_CXX

2022-03-02 Thread Sylvain Joubert
#x27;m not sure this is the correct package to depend on. Thanks, Sylvain -- System Information: Debian Release: bookworm/sid APT prefers testing APT policy: (990, 'testing'), (800, 'stable-updates'), (800, 'stable'), (700, 'unstable'), (90, 'exp

Bug#995368: libapache2-mod-proxy-uwsgi - CVE-2021-36160 regression, altered PATH_INFO

2021-12-01 Thread Sylvain Beucler
The regression fix is now officially staged upstream for 2.4.52: https://github.com/apache/httpd/commit/8966e290a6e947fad0289bf4e243b0b552e13726 Cheers! Sylvain Beucler Debian LTS Team

Bug#998679:

2021-11-08 Thread Sylvain Tgz
Hello, I have the same issue with firefox-esr 91.3.0esr-1. Downgrading to 91.2.0esr-1 remove the issue. Sylvain

Bug#998346: apt assigns priority 500 to package versions from debian-security

2021-11-02 Thread Sylvain BOILARD
Package: apt Version: 2.2.4 Severity: normal Dear maintainer, APT does not consider package versions from debian-security for updates unless I change the priority assigned to these package versions to a more appropriate value with a preference configuration file (see the preferences.d/debian-sec

Bug#967939: dvb-apps: Update dvb-apps:amd64 1.1.1+rev1500-1.2 => 1.1.1+rev1500-1.4 breaks gnutv

2021-11-01 Thread Sylvain L. Sauvage
Hi, Bug confirmed on Bullseye (1.1.1+rev1500-1.4). gnutv only writes meta-data, no audio, no video, no subtitles…. So no errors but an empty stream. At least, 1.1.1+rev1500-1.2 from Buster can be installed on Bullseye without too much hassle and still works. Sincerely, -- Sylvain L. Sauvage

Bug#980052: xfce4-terminal: Does not honor Drop-down “Move to monitor with pointer” option

2021-10-30 Thread Sylvain Garancher
Hello, I discovered this bug today, after upgrading from buster to bullseye. It seems to be fixed upstream : https://gitlab.xfce.org/xfce/libxfce4ui/-/merge_requests/41 -- Regards, Sylvain OpenPGP_signature Description: OpenPGP digital signature

Bug#996551: llvm-13-dev: Missing dependency to libomp-13-dev

2021-10-19 Thread Sylvain Joubert
Package: llvm-13-dev Version: 1:13.0.0-6 Followup-For: Bug #996551 X-Debbugs-Cc: joubert...@gmail.com Dear Maintainer, I believe this bug still exists in version 1:13.0.0-6 with the same error. With a quick glance at the patch/fix I believe the regex that comments the relevant line is at fault (u

Bug#996551: llvm-13-dev: Missing dependency to libomp-13-dev

2021-10-15 Thread Sylvain Joubert
Package: llvm-13-dev Version: 1:13.0.0-5 Severity: important X-Debbugs-Cc: joubert...@gmail.com Dear Maintainer, With the recent move of llvm-omp-device-info from llvm-X to libomp8-dev, done in llvm-toolchain-13 (1:13.0.0-4), this package should now depend on libomp-X-dev The current situation i

Bug#995368: libapache2-mod-proxy-uwsgi - CVE-2021-36160 regression, altered PATH_INFO

2021-10-09 Thread Sylvain Beucler
Hi, On 05/10/2021 18:41, Sylvain Beucler wrote: forwarded 995368 https://bz.apache.org/bugzilla/show_bug.cgi?id=65616 The Apache developers say there's an incorrect configuration in the first place. For example, ProxyPassMatch ^/ui uwsgi://127.0.0.1:8081/ should be ProxyPassMatch

Bug#995368: libapache2-mod-proxy-uwsgi - CVE-2021-36160 regression, altered PATH_INFO

2021-10-05 Thread Sylvain Beucler
tags 995368 + upstream forwarded 995368 https://bz.apache.org/bugzilla/show_bug.cgi?id=65616 thanks Note: there doesn't seem to be actual path duplication at the UWSGI level, AFAICS Django just gets confused by the additional '/' at the start of PATH_INFO and incorrectly duplicates the path in

Bug#995368: libapache2-mod-proxy-uwsgi 2.0.14+20161117-3+deb9u4 - duplicated request path

2021-10-05 Thread Sylvain Beucler
y upstream, that'd make the 5th..) KO: ProxyPass /uwsgi-pp uwsgi://localhost:8001/ OK: ProxyPass /uwsgi-pps/ uwsgi://localhost:8001/ KO: ProxyPassMatch ^/admin uwsgi://localhost:8001/ I'll open a ticket on bz.apache.org. Cheers! Sylvain Beucler Debian LTS Team On 05/10/2021 14:39, Ph

Bug#995368: libapache2-mod-proxy-uwsgi 2.0.14+20161117-3+deb9u4 - duplicated request path

2021-10-05 Thread Sylvain Beucler
/TestSuites/uwsgi ) so currently I cannot reproduce the problem. Regards, Sylvain Beucler Debian LTS Team On 05/10/2021 10:36, Moritz Mühlenhoff wrote: reassign 995368 uwsgi thanks Am Fri, Oct 01, 2021 at 04:16:05PM +0200 schrieb Josef Kejzlar, wpj s.r.o.: I can confirm this regression. After

Bug#995604: (no subject)

2021-10-04 Thread Sylvain Archenault
Running latest kernel 5.14.0-2-amd64 #1 SMP Debian 5.14.9-2 seems to fix the issue.

Bug#995604: ntfs-3g: mount.ntfs stuck in D state

2021-10-02 Thread sylvain
et me know if you need more information. Thank you Sylvain -- System Information: Debian Release: bookworm/sid APT prefers unstable-debug APT policy: (500, 'unstable-debug'), (500, 'unstable'), (1, 'experimental') Architecture: amd64 (x86_64) Kernel: Lin

Bug#994057:

2021-09-17 Thread Sylvain Tgz
hardware ? I found newer application with artifact : VLC, simplescreenrecorder Sylvain

Bug#994057: libegl-mesa0: 21.2.1-2 with intel graphic card produces artifact on firefox-esr

2021-09-10 Thread Sylvain Tgz
Package: libegl-mesa0 Version: 21.2.1-2 Severity: serious Justification: unknow X-Debbugs-Cc: tarjaiz...@gmail.com Dear Maintainer, After upgraded libegl-mesa0 libgbm1 libgl1-mesa-dri libglapi-mesa libglx-mesa0 libllvm11 to 21.2.1-2, I have artifacts with firefox-esr. For example, with right cl

Bug#992118: squid3-dbg: uninstallable cruft package from src:squid3 in jessie-elts

2021-08-12 Thread Sylvain Beucler
Hi, Note that jessie-elts is not part of the official Debian project, see https://wiki.debian.org/LTS/Extended So using Debian-specific resources (the BTS) for elts-specific issues may be considered an abuse. Cheers! Sylvain Beucler Debian LTS Team On Thu, 12 Aug 2021 00:17:36 +0200 Andreas

Bug#991008: php7.4: typo in TEST_PHP_CGI_EXECUTABLE triggers many test suite errors

2021-07-12 Thread Sylvain Beucler
or should it be fixed? Cheers! Sylvain Beucler Debian LTS Team

Bug#986804: CVE-2021-28116

2021-06-01 Thread Sylvain Beucler
Hi, I asked upstream for further information about this vulnerability: https://bugs.squid-cache.org/show_bug.cgi?id=5131 Cheers! Sylvain Beucler Debian LTS Team

Bug#976070: issues fixed

2021-05-29 Thread Sylvain Archenault
Actually my issue seems different, i think it was this issue in network-manager: https://gitlab.gnome.org/GNOME/NetworkManager-openvpn/-/issues/64. This has been fixed in 1.8.14-1 currently in experimental.

Bug#986581: debian-security-support: logic behind version-based filters

2021-04-26 Thread Sylvain Beucler
Hi, On 16/04/2021 10:41, Sylvain Beucler wrote: I dropped the version-based check and adapted the test suite: https://salsa.debian.org/debian/debian-security-support/-/merge_requests/9 pending review with secteam. I think we are all OK with this particular change. Can you review the MR

Bug#986333: debian-security-support: Match ecosystems with limited support

2021-04-19 Thread Sylvain Beucler
html https://lists.debian.org/debian-lts/2021/04/msg00031.html I made alternate suggestions and am waiting for maintainers feedback: https://lists.debian.org/debian-lts/2021/04/msg00036.html - Sylvain

Bug#986581: debian-security-support: logic behind version-based filters

2021-04-16 Thread Sylvain Beucler
Hi Christoph, Thanks a lot for your precisions, On 13/04/2021 10:02, Christoph Biedl wrote: Sylvain Beucler wrote... We could not find a valid use case for this feature, while it is causing some missing reports as with 'nodejs', as explained in the above BTS entry. Did we miss

Bug#986581: debian-security-support: logic behind version-based filters

2021-04-08 Thread Sylvain Beucler
e missing reports as with 'nodejs', as explained in the above BTS entry. Did we miss something? Cheers! Sylvain

Bug#986581: debian-security-support: omits installed packages with higher version

2021-04-07 Thread Sylvain Beucler
document that a future version will be unsupported? Most probably the user's system is partially upgraded, and the package is likely unsupported already. What is the concrete use case for excluding packages based on version? Do we need to fix the code or security-support-ended.deb9? Cheers! Sylvain

Bug#986333: debian-security-support: Match ecosystems with limited support

2021-04-03 Thread Sylvain Beucler
matching would help. (debian-security-support is an important tool in the Debian LTS/ELTS offering, so I believe we could offer help/time in this area.) What do you think? Cheers! Sylvain

Bug#976623: godot3-server: Provide both headless and server binaries with current server renamed to headless

2021-02-12 Thread Sylvain Beucler
vide:s. FTR their terminology is: https://godotengine.org/download/server * "The _headless_ build includes the editor tool functionality that enables it to run tests and export projects in an automated manner." * "The _server_ build is optimized to run dedicated game servers and does not include editor tools, graphics or audio support." Cheers! Sylvain

Bug#862139: [flash-kernel] Please, stop flashing multiple times

2021-02-07 Thread Sylvain L. Sauvage
(badly) shown on the excerpt the files are flashed both just when the package is installed (immediate) and when the whole update is finished (deferred). -- Sylvain L. Sauvage

Bug#980353: feed2imap: missing dependency on ruby-rubymail

2021-01-17 Thread Sylvain L. Sauvage
suggests: pn imap-server ii kmail [imap-client] 4:20.08.3-1 -- no debconf information -- Sylvain L. Sauvage

Bug#972114: sympa: CVE-2020-26880

2021-01-05 Thread Sylvain Beucler
x27; as root. This could be done e.g. setuid-wrapping not sympa but just the 'newaliases' command, or dropping support for root 'newaliases' entirely. - Upstream tracks this issue at https://github.com/sympa-community/sympa/issues/1009 Discuss the issue there in priority. Cheers! Sylvain

Bug#978932: sympa: webinterface broken after installing 6.2.40~dfsg-1+deb10u1

2021-01-02 Thread Sylvain Beucler
nginx+spawn-fcgi: https://sympa-community.github.io/manual/install/configure-http-server-spawnfcgi.html See also: https://bugs.debian.org/972189 https://github.com/sympa-community/sympa/issues/1020 Cheers! Sylvain On 31/12/2020 17:41, Tobias Frost wrote: Package: sympa Version: 6.2.40~d

Bug#976070: openvpn fails with iproute option

2021-01-01 Thread Sylvain Archenault
Hello, Has any progress been made on this? i tried to apply the Arch patch manually, but either it doesn't work or I didn't do it right. Downgrading to 2.4 is only workaround for me Thank you

Bug#947431: xerces-c: CVE-2018-1311: use-after-free vulnerability processing external DTD

2020-12-15 Thread Sylvain Beucler
Excellent! I just re-uploaded 3.2.2+debian-1+deb10u1 with the updated patch. (and tested in a i386 chroot for good measure) I'm now adapting for stretch-lts (which has a monolithic test result). Cheers! Sylvain

Bug#961491: CVE-2020-10936: Security flaws in setuid wrappers

2020-12-14 Thread Sylvain Beucler
On 07/12/2020 12:06, Stefan Hornburg (Racke) wrote: On 12/7/20 10:52 AM, Sylvain Beucler wrote: This high-severity issue was marked with: [buster] - sympa (Will be fixed via point release) Consequently I am surprised that it wasn't part of last week's Debian 10.7 point rele

Bug#947431: xerces-c: CVE-2018-1311: use-after-free vulnerability processing external DTD

2020-12-11 Thread Sylvain Beucler
security master. (and I'm preparing another update for LTS.) Cheers! Sylvain

Bug#947431: xerces-c: CVE-2018-1311: use-after-free vulnerability processing external DTD

2020-12-09 Thread Sylvain Beucler
Hi, Here's a debdiff against buster. The testsuite passes, provided we modify MemHandlerTest1 to take the leak into account. What do you think? Cheers! Sylvain Beucler Debian LTS Team On 24/11/2020 17:39, Bill Blough wrote: The package has a test suite, so that's probably the mi

Bug#961491: CVE-2020-10936: Security flaws in setuid wrappers

2020-12-07 Thread Sylvain Beucler
Hi, On Sat, 10 Oct 2020 09:45:42 +0300 "Stefan Hornburg (Racke)" wrote: On 10/7/20 3:03 PM, Sylvain Beucler wrote: > I noticed this local root escalation yesterday and I'm working on a > Stretch LTS update. > See also https://salsa.debian.org/sympa-team/sympa/-/merge_r

Bug#947431: xerces-c: CVE-2018-1311: use-after-free vulnerability processing external DTD

2020-11-23 Thread Sylvain Beucler
Hi, I can assist with this, notably a LTS upload - not necessarily immediately either. Bill, do you have testing procedures to recommend for this package? Security Team, before issuing a LTS upload, what is your view on a Stable upload for this issue? Cheers! Sylvain Beucler Debian LTS

Bug#891469: awstats: Path traversal in config parameter if site config is missing.

2020-11-21 Thread Sylvain Beucler
Hi, Since awstats is currently unmaintained, can you request a new CVE for this at https://cveform.mitre.org/ ? This way it'll be properly monitored and taken care of in distros. Cheers! Sylvain On Sun, 25 Feb 2018 21:33:34 +0100 =?utf-8?b?VG9tYcW+IMWgb2xj?= wrote: Package: aw

Bug#890414: awstats: run-parts doesnt work with .sh files

2020-11-21 Thread Sylvain Beucler
For your consideration: https://salsa.debian.org/debian/awstats/-/merge_requests/2 The awstats package is orphaned. Depending on the answers I may do a NMU. Cheers! Sylvain On Wed, 6 May 2020 13:36:23 + debian_reportbug_202...@michaelaltfield.net wrote: Package: awstats Version: 7.6+dfsg

Bug#947431: xerces-c: CVE-2018-1311: use-after-free vulnerability processing external DTD

2020-11-21 Thread Sylvain Beucler
ource/SPackages/xerces-c-3.1.1-10.el7_7.src.rpm) Do we want to follow suit? Cheers! Sylvain Beucler Debian LTS Team On Thu, 26 Dec 2019 21:40:38 +0100 Salvatore Bonaccorso wrote: Source: xerces-c Version: 3.2.2+debian-1 Severity: important Tags: security upstream Forwarded: https://issues.apach

Bug#974991: sagemath: segfault on startup

2020-11-20 Thread Sylvain LÉVÊQUE
rchive/debian/20200628T024451Z unstable main" to /etc/apt/sources.list - sudo apt -o Acquire::Check-Valid-Until=false update - sudo apt install python3-cypari2=2.1.1-2+b2 It seems it is a recurring situation, 906796 happened two years ago. -- Sylvain

Bug#974034: Update obsolete/non-free FPM configuration procedure

2020-11-09 Thread Sylvain Beucler
Package: php7.4-fpm Tags: patch Cross-referencing https://salsa.debian.org/php-team/php/-/merge_requests/5 Cheers! Sylvain

Bug#972114: sympa: CVE-2020-26880

2020-11-07 Thread Sylvain Beucler
Hi Stefan, On 05/11/2020 15:29, Stefan Hornburg (Racke) wrote: On 11/5/20 3:19 PM, Sylvain Beucler wrote: @racke, following your work at https://github.com/sympa-community/sympa/pull/1015 it seems we'd need a new debconf question to ask the user whether they want the setuid wrapper

Bug#972189: sympa: CVE-2020-10936 regression - removal of needed environment variables

2020-11-06 Thread Sylvain Beucler
Debian documentation, so I plan to add a note in README.Debian or NEWS.Debian. https://github.com/sympa-community/sympa/issues/1020#issuecomment-710763168 Given there were no other reports I believe this addresses the issue. Cheers! Sylvain Beucler Debian LTS Team

Bug#972114: sympa: CVE-2020-26880

2020-11-05 Thread Sylvain Beucler
lity (aka fix it for every MTA but sendmail AFAICS) Cheers! Sylvain Beucler Debian LTS Team

Bug#973544: www.debian.org: LTS Security Advisories RSS links to wrong locations

2020-11-02 Thread Sylvain Beucler
case in get_recent_list()/grab_titles(). Cheers! Sylvain On 01/11/2020 21:13, Laura Arjona Reina wrote: Hi Nobuhiro Ban, Thanks for reporting this issue. The build of those RSS feeds is done via the get_recent_list() function in the recent_list template: https://salsa.debian.org/webmaster-team/web

Bug#972189: sympa: CVE-2020-10936 regression - removal of needed environment variables

2020-10-15 Thread Sylvain Beucler
://github.com/sympa-community/sympa/issues/1020 for work-arounds. Cheers! Sylvain

Bug#971904: sympa: restrict access to sympa_newaliases-wrapper (setuid root) to group sympa

2020-10-09 Thread Sylvain Beucler
Source: sympa Tags: patch Cross-referencing https://salsa.debian.org/sympa-team/sympa/-/merge_requests/1 Cheers! Sylvain Beucler Debian LTS Team

Bug#961491: fixed in sympa 6.2.40~dfsg-5

2020-10-07 Thread Sylvain Beucler
Hi, I noticed this local root escalation yesterday and I'm working on a Stretch LTS update. See also https://salsa.debian.org/sympa-team/sympa/-/merge_requests/1 Are there plans to update buster? Cheers! Sylvain

Bug#971560: libsane-common 1.0.25-4.1+deb9u1 Stretch security update missing lots of files

2020-10-03 Thread Sylvain Beucler
Hi, The package is in this state since Aug 17, I think we can afford to wait a few more days for testing. So yes, please do test on Tuesday. Cheers! Sylvain On 03/10/2020 00:41, Ivan Baldo wrote: > Hello. > The soonest I could try to check, is this Tuesday 6th 19:00 -0300, sorry. > Le

Bug#908678: Update on the security-tracker git discussion

2020-10-02 Thread Sylvain Beucler
f/post-merge b/conf/post-merge new file mode 100755 index 00..a9991c1cc9 --- /dev/null +++ b/conf/post-merge @@ -0,0 +1,3 @@ +#!/bin/sh +echo "post-merge" +[ -f data/CVE/1999.list ] && cat data/CVE/*.list > data/CVE/list diff --git a/conf/pre-commit b/conf/pre-commit index 767e478e36..12e781e97d 100755 --- a/conf/pre-commit +++ b/conf/pre-commit @@ -5,3 +5,4 @@ set -e exec 1>&2 make check-syntax +bin/split-by-year.py ? Cheers! Sylvain

Bug#971560: libsane-common 1.0.25-4.1+deb9u1 Stretch security update missing lots of files

2020-10-02 Thread Sylvain Beucler
Hi, On 02/10/2020 13:51, Ivan Baldo wrote: > El vie., 2 de oct. de 2020 a la(s) 06:48, Sylvain Beucler > (b...@beuc.net) escribió: >> >> Hi, >> >>> El jue., 1 de oct. de 2020 a la(s) 19:32, Sylvain Beucler >>> (b...@beuc.net) escribió: >>>>

Bug#971592: sane-backends: filtering out libsane-dll doesn't work on combined builds

2020-10-02 Thread Sylvain Beucler
232 2020-09-27 13:38 ./usr/lib/x86_64-linux-gnu/sane/libsane-dll.so.1.0.31 lrwxrwxrwx root/root 0 2020-09-27 13:38 ./usr/lib/x86_64-linux-gnu/sane/libsane-dll.so.1 -> libsane-dll.so.1.0.31 Cheers! Sylvain Beucler Debian LTS Team

Bug#971560: libsane-common 1.0.25-4.1+deb9u1 Stretch security update missing lots of files

2020-10-02 Thread Sylvain Beucler
Hi, > El jue., 1 de oct. de 2020 a la(s) 19:32, Sylvain Beucler > (b...@beuc.net) escribió: >> This could be due to a bug when building the 'all' and 'amd64' packages >> separately. I can reproduce the 2 debdiff-s with 'debuild -A' and 'debui

  1   2   3   4   5   6   7   8   9   10   >