Bug#575763: gnupg: simplification of README

2010-11-13 Thread Thijs Kinkhorst
Hi, Thank you for your suggestions and work. As for the shipped README, although there's irrelevant information for Debian users there's also a lot of useful information in it. I do not perceive this as something that needs changing per se - if upstream would change that sometime it would be

Bug#598471: [Pkg-gnupg-maint] Bug#598471: using insecure memory on GNU/kFreeBSD

2010-11-13 Thread Thijs Kinkhorst
On Wed, September 29, 2010 14:36, Werner Koch wrote: On Wed, 29 Sep 2010 11:41, r...@debian.org said: Upstream recommends [2] setting the SUID bit and assures that the program drops root privileges as soon as locked memory is allocated. However it is much easier and more secure to enable

Bug#596899: Please unblock ia32-libs/20101012

2010-11-13 Thread Thijs Kinkhorst
On Saturday 13 November 2010 00:10:56 Julien Cristau wrote: Dropping wine means dropping those, fwiw. Not that I really care, but if somebody does want to keep wine in squeeze the build fix seems trivial enough... For the record, the build fix has been uploaded to delayed/7 last week; not

Bug#602593: pu: package sun-java6/6-22-0lenny1

2010-11-13 Thread Thijs Kinkhorst
On Friday 12 November 2010 06:55:48 Torsten Werner wrote: On Thu, Nov 11, 2010 at 8:16 PM, Adam D. Barratt a...@adam-barratt.org.uk wrote: On Sat, 2010-11-06 at 11:19 +0100, Torsten Werner wrote: a new version of sun-java6 for stable is available at http://people.debian.org/~twerner/.

Bug#549116: [Pkg-mailman-hackers] Bug#549116: mailman: Probably fixed by #517997, not in lenny yet

2010-11-13 Thread Thijs Kinkhorst
On Friday 12 November 2010 11:33:45 Hermann Lauer wrote: Probably the fix (http://www.mail-archive.com/mailman-us...@python.org/msg52700.html) for #517997 (which is already archived) will fix this too. Why is that fix not in lenny ? Applying it local avoided the exception here (and thus

Bug#598471: [Pkg-gnupg-maint] Bug#598471: using insecure memory on GNU/kFreeBSD

2010-11-13 Thread Thijs Kinkhorst
On Saturday 13 November 2010 14:58:29 Robert Millan wrote: Upstream recommends [2] setting the SUID bit and assures that the program drops root privileges as soon as locked memory is allocated. However it is much easier and more secure to enable encrypted swap space than to use mlock.

Bug#596899: Please unblock ia32-libs/20101012

2010-11-09 Thread Thijs Kinkhorst
On Tue, November 9, 2010 05:21, Michael Gilbert wrote: On Mon, Nov 8, 2010 at 3:22 PM, Julien Cristau wrote: On Mon, Nov  8, 2010 at 19:02:08 +0100, Moritz Muehlenhoff wrote: Given that wine in Squeeze is the vintage 1.0 release that already shipped with Lenny, we should rather dump it

Bug#595594: (no subject)

2010-10-30 Thread Thijs Kinkhorst
On Sun, October 10, 2010 16:57, Adam D. Barratt wrote: On Sun, 2010-09-12 at 00:54 +0200, J.M.Roth wrote: tags 595594 +pending thanks Ok, our own database functions now exit even more gracefully on failure. The previous fix (586759) seemed to address a similar issue but only when dbconfig

Bug#601621: Missing dependency: libperlX.XX

2010-10-29 Thread Thijs Kinkhorst
On Wed, October 27, 2010 22:58, Nicolas Fournel wrote: Package: wakeonlan Version: 0.41-10 It seems that the package is missing a dependency over libperlX.XX (libperl5.10 in current versions). On some very light installation of debian, on routers or firewall for example, this package is

Bug#601462: change home directory of www-data to something other than /var/www

2010-10-26 Thread Thijs Kinkhorst
Package: base-passwd Severity: wishlist Hi, www-data has as its home directory /var/www: www-data:x:33:33:www-data:/var/www:/bin/sh This seems about the least logical choice for this, as the www-data user is meant to *not* own the web content. /var/www is the default location for web

Bug#599833: [Pkg-mailman-hackers] Bug#599833: mailman: NMU diff for 1:2.1.13-4.1

2010-10-25 Thread Thijs Kinkhorst
On Friday 15 October 2010 11:39:01 jari.aa...@cante.net wrote: Here is the NMU diff according to DevRef 5.11.1[1][2] for bug: #599833. See the debian/patches directory for the important fixes. Please let me know it it's okay to proceed with NMU. Thanks for the NMU, it was very helpful as I

Bug#597219: squirrelmail: can not change password

2010-09-19 Thread Thijs Kinkhorst
On Fri, September 17, 2010 20:16, Mario wrote: Package: squirrelmail Version: 2:1.4.15-4+lenny3.1 Severity: normal When I try to change the password via the webmail interface I get the following message: ERROR: Could not make database connection Hi, It's not by default possible to

Bug#575258: ttf-mscorefonts-installer: Missing monotype.ttf?

2010-09-07 Thread Thijs Kinkhorst
severity 575258 wishlist thanks On Wed, March 24, 2010 18:25, Hellekin O. Wolf wrote: Package: ttf-mscorefonts-installer Version: 3.2 Severity: normal Hello, I came across an exe archive at CERN[1] including the MSFT fonts and the License. Their version provide a monotype.ttf font that

Bug#595974: phpmyadmin: Please package 3.3.7

2010-09-07 Thread Thijs Kinkhorst
On tiisdei 7 Septimber 2010, Micah Gersten wrote: Package: phpmyadmin Severity: wishlist Thanks. Thanks for your reminders. We are however tracking upstream mailinglists (Michal is even an upstream developer) so we're well aware of new upstreams being released and will package them as soon

Bug#580383: [php-maint] Bug#580383: Bug#580383: php-xml-parser uses deprecated eregi and reference of new object

2010-09-03 Thread Thijs Kinkhorst
On Fri, September 3, 2010 11:28, Thomas Goirand wrote: I made a much much smaller patch for the package. Could you please have a look at the interdiff, and let me know what you think before I upload? Also, should I put myself in the Uploaders: list rather than doing it as an NMU? Let me know.

Bug#580383: [php-maint] Bug#580383: Bug#580383: php-xml-parser uses deprecated eregi and reference of new object

2010-09-01 Thread Thijs Kinkhorst
On Tue, August 31, 2010 23:28, Thomas Goirand wrote: Because of upstream insisting to support ante-diluvian version of php, and my will to have the patch upstreamed. preg_match has been available since PHP 3.0, relased 1998. cheers, Thijs -- To UNSUBSCRIBE, email to

Bug#580383: [php-maint] Bug#580383: Bug#580383: php-xml-parser uses deprecated eregi and reference of new object

2010-08-31 Thread Thijs Kinkhorst
On Tue, August 31, 2010 20:16, Thomas Goirand wrote: Thijs Kinkhorst wrote: Two questions: 1) Why is it needed to pass the object by reference? It looks like it could just as well be passed by value. 2) Why is this bug of grave severity? As I understand it, using this only generates

Bug#580383: [php-maint] Bug#580383: Bug#580383: php-xml-parser uses deprecated eregi and reference of new object

2010-08-29 Thread Thijs Kinkhorst
Hi, On woansdei 5 Maaie 2010, Thomas Goirand wrote: Replying to myself, as I didn't know it would go back to the list! :) My patch fixes the eregi calls, but not this one: $err = new XML_Parser_Error($msg, $ecode); return parent::raiseError($err); What's the way to fix

Bug#579922: [php-maint] Bug#579922: Bug#579922: libapache2-mod-php5: change allow_url_fopen = Off

2010-08-29 Thread Thijs Kinkhorst
On woansdei 5 Maaie 2010, Raphael Geissert wrote: On Sunday 02 May 2010 05:47:13 Toni Mueller wrote: I suggest that this be changed to allow_url_fopen = Off to reduce the change of PHP applications being exploited, and, if you really need to, place a big flashing warning

Bug#594262: quagga: Two BGP security problems fixed in 0.99.17

2010-08-25 Thread Thijs Kinkhorst
Hi Christian, On woansdei 25 Augustus 2010, Christian Hammers wrote: Meanwhile I upload 0.99.17 to sid and ask if 0.99.10 (lenny) is affected and if there's a 0.99.16 backport for the frozen squeeze. Good to hear that you're on to of it. As for squeeze, from reading the changelog it looks

Bug#387688: [Pkg-gnupg-maint] Bug#592902: Bug#387688: Add gnupg as apt dependency in Squeeze to be able to solve #387688 in Squeeze+1?

2010-08-22 Thread Thijs Kinkhorst
On Sun, August 22, 2010 00:46, Carsten Hey wrote: * Build a new package gpgv-tiny, configured with --without-readline. Just wondering here if there would be any need for a regular 'gpgv' package if 'gpgv-tiny' exists. In other words, we could already build gpgv separately, without readline,

Bug#593737: [Pkg-mailman-hackers] Bug#593737: mailman: user list does not have a home directory (/var/list)

2010-08-21 Thread Thijs Kinkhorst
reassign 593737 base-passwd thanks Hi, On tongersdei 19 Augustus 2010, mzagr...@d.umn.edu wrote: Package: mailman Version: 1:2.1.11-11+lenny1 Severity: normal When su - list, the home directory does not exist for the 'list' user. /var/list Also, chapter 5 of the FHS states:

Bug#593465: squirrelmail: Unimplemented function sqimap_run_literal_command() after security update

2010-08-20 Thread Thijs Kinkhorst
On Thu, August 19, 2010 09:25, Jan Kontze wrote: Hi Thijs! Hi Jan, On woansdei 18 Augustus 2010, Jan Kontze wrote: User who used 8bit chars in their imap passwords now get a: Fatal error: Call to undefined function sqimap_run_literal_command() in

Bug#592294: [Pkg-gnupg-maint] Bug#592294: [gnupg/1265] gnupg: OpenPGP is nowadays RFC 4880, adapt documentation' from 'gnupg: OpenPGP is nowadays RFC 4880, adapt documentation

2010-08-20 Thread Thijs Kinkhorst
tag 592294 fixed-upstream thanks On Fri, August 20, 2010 15:20, Christoph Anton Mitterer wrote: fixed upstream... at least in parts,... guess they're a bit lazy That upstream has other priorities for their time than you does not make them lazy. At least one knows now, not to waste time in

Bug#564556: [pkg-lighttpd] Bug#564556: lighttpd still unusable by default

2010-08-19 Thread Thijs Kinkhorst
Hi Olaf, On Wed, Aug 18, 2010 at 11:15 PM, Bernd Zeimetz be...@bzed.de wrote: as there is still no fixed version of lighttpd in Squeeze (nor in unstable), I'm rising the severity to serious. YMMV, but in the current state it is just not usable for people running some kind of ipv6 on their

Bug#497825: gnupg: ignores expiry of archive keys

2010-08-18 Thread Thijs Kinkhorst
Hi Peter, On tongersdei 17 Juny 2010, Peter Palfrader wrote: | wea...@intrepid:~/tmp$ wget -nv | http://snapshot.debian.org/archive/debian-volatile/20090903T013716Z/dist | s/etch/volatile/Release{.gpg,} 2010-06-17 20:09:56 |

Bug#593465: squirrelmail: Unimplemented function sqimap_run_literal_command() after security update

2010-08-18 Thread Thijs Kinkhorst
Hi Jan, On woansdei 18 Augustus 2010, Jan Kontze wrote: User who used 8bit chars in their imap passwords now get a: Fatal error: Call to undefined function sqimap_run_literal_command() in /usr/share/squirrelmail/functions/imap_general.php on line 528 error and cannot log in any more.

Bug#593345: /usr/sbin/squirrelmail-configure: say press any key but accepts only CR or LF

2010-08-18 Thread Thijs Kinkhorst
tags 593345 fixed-upstream thanks On tiisdei 17 Augustus 2010, Leonardo Boselli wrote: if i select some of the default configuration for the various imap servers, i am prompted with a message press any key to continue, but to continue it does accept only CR or LF . Thanks. Will be fixed in

Bug#497825: gpgv should return non-zero exitcode on expired keys (was: Re: gnupg: ignores expiry of archive keys)

2010-08-18 Thread Thijs Kinkhorst
retitle 497825 gpgv should return non-zero exitcode on expired keys tags 497825 upstream thanks Hi Peter, On woansdei 18 Augustus 2010, Peter Palfrader wrote: Thanks for clarifying again what exactly you're observing. I can indeed reproduce that situation. However, aren't you comparing

Bug#593363: phpmyadmin: I would like to hide the versionnumber in the login-screen

2010-08-17 Thread Thijs Kinkhorst
On tiisdei 17 Augustus 2010, Christoph Kluenter wrote: It would be nice, if the Version-Number could be hidden on the login-Page. At the moment, the String is in PMA_VERSION in /usr/share/phpmyadmin/libraries/Config.class.php It would be nice if PMA_VERSION could be set in

Bug#593203: make cacti.apache.conf work with fastcgi setup

2010-08-16 Thread Thijs Kinkhorst
process, which is not an uncommon setup. Attached patch wraps those directives in an IfModule clause. Also, I've changed DirectoryMatch to Directory since it doesn't use any wildcards in the pattern. Cheers, Thijs -- Thijs Kinkhorst th...@uvt.nl – LIS Unix Universiteit van Tilburg – Library

Bug#514305: smarty: Please sync the install path with Ubuntu

2010-08-15 Thread Thijs Kinkhorst
On snein 15 Augustus 2010, Raphael Hertzog wrote: On Thu, 12 Aug 2010, Thijs Kinkhorst wrote: I agree that given that Ubuntu has made this rather poor decision, we're only left with this inelegant way forward to unify the packages again. Obviously we cannot have this changed for Squeeze

Bug#592937: should we keep libapache2-mod-fastcgi?

2010-08-14 Thread Thijs Kinkhorst
Package: libapache2-mod-fastcgi Severity: important Hi, We currently have both libapache2-mod-fastcgi and libapache2-mod-fcgid in the archive. This package, mod-fastcgi, has not seen new upstream releases since 2007. Also, anyone I know recommends to use mod_fcgid over mod_fastcgi. Is there a

Bug#514305: smarty: Please sync the install path with Ubuntu

2010-08-12 Thread Thijs Kinkhorst
Hi Raphaël, It was a poor choice of Ubuntu to diverge here... anyway I agree that at this point it's best if Debian updates his package to use the new path. It should however add some transition symlink /usr/share/php/smarty/libs - /usr/share/php/smarty to avoid breaking instantly. I agree

Bug#559073: [pkg-kolab] Bug#559073: Regression on single quote escaping since #504328

2010-08-12 Thread Thijs Kinkhorst
Hi Mathieu, Sorry for not getting back on this earlier, the issue seems to have slipped through the cracks while Smarty didn't have an active maintainer. As it seems, the two iterations upstream have done to fix this issue have been mixed up in the security update. I have now corrected this.

Bug#592797: ITA: smarty -- Template engine for PHP

2010-08-12 Thread Thijs Kinkhorst
Package: wnpp Severity: normal Hi, Smarty has been orphaned by Moritz recently, but as it seems without corresponding O: bug filed. http://packages.qa.debian.org/s/smarty/news/20100805T154716Z.html I'm willing to adopt the package at least for the time being. However, I don't have changes to

Bug#592294: [Pkg-gnupg-maint] Bug#592294: gnupg: OpenPGP is nowadays RFC 4880, adapt documentation

2010-08-11 Thread Thijs Kinkhorst
On moandei 9 Augustus 2010, Christoph Anton Mitterer wrote: Attached patch, corrects some minor typos and changes everything in debian/* from RFC 2440 to RFC 4880 (which is now the standard). Thanks, I've applied the patch to debian/control; changing patches to upstream is not useful until we

Bug#590670: insecure setuid usage, local root exploit

2010-07-28 Thread Thijs Kinkhorst
Package: hsolink Version: 1.0.118-3 Severity: critical Tags: security Hi, Following was reported by Christian Jaeger. -- hsolink-1.0.118 contains a binary hsolinkcontrol that is setuid root. The binary - neither sets PATH - nor fixes other environment variables - nor checks

Bug#488290:

2010-07-28 Thread Thijs Kinkhorst
severity 488290 minor thanks Indeed, this is a bug not a wish. The tags can be configured via: http://debtags.alioth.debian.org/edit.html?pkg=lcdproc and must not be part of the description field. http://packages.debian.org/sid/lcdproc shows that this has a wrong result. Cheers, Thijs

Bug#590467: [Pkg-mailman-hackers] Bug#590467: mailman: update-rc.d error

2010-07-27 Thread Thijs Kinkhorst
forcemerge 590249 590467 thanks On Mon, July 26, 2010 15:40, Rick Pasotto wrote: Package: mailman Version: 1:2.1.13-3 Severity: important qrunner not running. output from 'aptitude install': Thanks, will be fixed as soon as possible. However, in the future please check if the bug you

Bug#445203: debian-policy: 10.8. Log files: /etc/logrotate.d/package preferred

2010-07-19 Thread Thijs Kinkhorst
On snein 11 July 2010, Steve Langasek wrote: On Thu, Jul 08, 2010 at 09:22:28AM -0700, Russ Allbery wrote: Guillem Jover guil...@debian.org writes: On Wed, 2010-07-07 at 08:59:24 -0700, Russ Allbery wrote: +postrotate +[ -f /var/run/foo.pid ] kill -s HUP `cat

Bug#589671: Required package set can be fully usable

2010-07-19 Thread Thijs Kinkhorst
Hi Neil, On moandei 19 July 2010, Neil Williams wrote: This sentence in Policy 2.5 is too prohibitive: Systems with only the required packages are probably unusable, but they do have enough functionality to allow the sysadmin to boot and install more software. I would suggest a more open

Bug#257102: mailman: bad url in private archive index page

2010-07-18 Thread Thijs Kinkhorst
Hi Willy, If mailling list has private status, mailman displays auth form to the clients after filling this form (if authentication successful) redirect to list archive index page. But the authentication process remove the trailing / from url http://server/path/listname/ to

Bug#425981: [Pkg-mailman-hackers] Bug#425981: mailman: public list archive has invalid URL, only private URL works

2010-07-18 Thread Thijs Kinkhorst
Hi Gabor, On freed 25 Maaie 2007, Nagy Gabor Peter wrote: I have a list, archiving is activated, the archive is set to be public. On the listinfo page and on tha admin page the links to the list archives point to http://server/pipermail/listname Following this link you get 404. I think

Bug#589538: patch to fix spelling error in Dutch templates translation

2010-07-18 Thread Thijs Kinkhorst
Package: postfix Version: 2.7.1-1 Severity: minor Tags: l10n patch Hi, Please find attached a patch that fixes a prominent spelling (grammar) error in the Dutch PO translation. Thanks, Thijs --- debian/po/nl.po.orig 2010-07-18 17:12:52.0 +0200 +++ debian/po/nl.po 2010-07-18

Bug#589155: [Pkg-mailman-hackers] Bug#589155: mailman: move web interface to a separate package

2010-07-15 Thread Thijs Kinkhorst
forcemerge 101163 589155 thanks On Thu, July 15, 2010 14:17, Bilal Akhtar wrote: Package: mailman Severity: wishlist As requested on launchpad bug #547249 ( http://edge.launchpad.net/bugs/547249 ) , it would be better to split the mailman source package into 2 binary packages, so that

Bug#586602: Your package libnids in Debian

2010-07-13 Thread Thijs Kinkhorst
Hi Vasilis, You are listed as the maintainer of the libnids package in Debian: http://packages.qa.debian.org/libn/libnids.html However, the maintainer field of that package still lists your vpap...@ics.forth.gr email address, which doesn't work anymore. Currently, having a broken maintainer

Bug#578981: phpldapadmin: php class 'LDAPServers' not found when opening webpage

2010-07-11 Thread Thijs Kinkhorst
Hi, As it seems config.php is not handled as a conffile, so the user is not prompted on upgrades automatically. I indeed think it's necessary to add a bit better handling here to bring attention to the required change. Cheers, Thijs signature.asc Description: This is a digitally signed

Bug#587536: phpldapadmin: ships Apache configuration setting PHP register_globals On

2010-06-29 Thread Thijs Kinkhorst
Package: phpldapadmin Version: 1.2.0.5-1 Severity: serious Tags: security Justification: requiring rg on not supported by security team Hi, The file debian/conf/apache.conf sets PHP's register_globals setting to On: php_flag register_globals On The Debian Security Team does not support

Bug#585783: patch for 585783

2010-06-27 Thread Thijs Kinkhorst
tag 585783 patch thanks Hi, Attached patch addresses this bug. Thijs diff -Nur kingston-update-notifier-1.0.orig/src/notifier.cpp kingston-update-notifier-1.0/src/notifier.cpp --- kingston-update-notifier-1.0.orig/src/notifier.cpp 2010-05-02 13:48:59.0 +0200 +++

Bug#586759: fails to install

2010-06-27 Thread Thijs Kinkhorst
tags 586759 moreinfo thanks Hi Holger, On tiisdei 22 Juny 2010, Holger Levsen wrote: On Dienstag, 22. Juni 2010, Julien Cristau wrote: Why? It's not configured, it won't work, why should it pretend the installation was successful? because you want the package in stable? having

Bug#587205: feh: Arbitrary code execution with --wget-timestamp and URLs

2010-06-27 Thread Thijs Kinkhorst
Hi Daniel, On sneon 26 Juny 2010, Daniel Friesel wrote: there exists an (IMHO rather unlikely, but still possible) arbitrary code execution hole in feh. All versions = 1.7 down to at least the 1.3.4 in stable (I didn't check earlier ones) are affected. See

Bug#586759: fails to install

2010-06-27 Thread Thijs Kinkhorst
On snein 27 Juny 2010, J.M.Roth wrote: Technically, the failure is trigged by the set -e of the maintainer script, since dbc_go fails. This is by no means a failure of the phpbb3 package, only a consequence of the failure of dbconfig-common. As far as debconf is concerned, people use

Bug#559458: kgpg: default selection is considered weak

2010-06-18 Thread Thijs Kinkhorst
On Thu, June 17, 2010 18:39, Daniel Leidert wrote: This issue is only present in Debian stable/Lenny. Version 1.4.10 of GnuPG prefers SHA-256 over SHA-1. My question to the security team: Should this be backported to Lenny? I don't have a patch for this atm - we need to search the upstream

Bug#478295: Sha1 and sha256 in .changes and .dsc file

2010-06-15 Thread Thijs Kinkhorst
On sneon 12 Juny 2010, Russ Allbery wrote: + p + These fields contain a list of files with a checksum and size + for each one. Both ttChecksums-Sha1/tt + and ttChecksums-Sha256/tt have the same syntax and differ + only in the checksum algorithm

Bug#569174: [PATCH] Correction of RFC number for date format -- bug #569174.

2010-06-01 Thread Thijs Kinkhorst
On tiisdei 1 Juny 2010, Charles Plessy wrote: --- a/policy.sgml +++ b/policy.sgml @@ -1610,7 +1610,7 @@ /p p - The vardate/var must be in RFC822 formatfootnote + The vardate/var must be in RFC5322 formatfootnote This is generated by ttdate

Bug#557514: Package uploaded and in NEW queue

2010-06-01 Thread Thijs Kinkhorst
tag 557514 pending thanks Hi, Packages of version 1.6.0 have been uploaded and are now in the NEW queue. Meanwhile they are also available from: deb http://non-gnu.uvt.nl/debian lenny simplesamlphp (not guaranteed to remain available after the packages have entered Debian proper) Cheers,

Bug#267243: setting package to mailman, tagging 267243, tagging 582259

2010-05-25 Thread Thijs Kinkhorst
# Automatically generated email from bts, devscripts version 2.10.35lenny7 # via tagpending # # mailman (1:2.1.13-3) UNRELEASED; urgency=low # # * Add 25_site_logo patch by Paul Wise (closes: #267243). # * Do not compress PDF's under /u/s/d/mailman (closes: #582259). # package mailman tags

Bug#582585: eekboek: emacs eekboek-mode for .eb files

2010-05-24 Thread Thijs Kinkhorst
On sneon 22 Maaie 2010, Kevin Ryde wrote: Running up emacs -q /usr/share/doc/eekboek/examples/opening.eb gives a buffer in fundamental-mode. I hoped 50eekboek.el would setup eekboek-mode for .eb files. Thanks for your report. As I don't know anything about emacs I don't really know

Bug#562700: [Pkg-mailman-hackers] Bug#562700: mailman-loop not handled by recommended Exim config

2010-05-24 Thread Thijs Kinkhorst
On tiisdei 18 Maaie 2010, Roger Lynn wrote: I was intending to follow up to this bug with a suggested router and transport pair for Exim, as soon as I got around to working them out. However, I prefer the alternative approach suggested by upstream in

Bug#582357: ITP: ocs -- Open Conference Systems: scholary conference management system

2010-05-20 Thread Thijs Kinkhorst
Package: wnpp Severity: wishlist Owner: Thijs Kinkhorst th...@debian.org * Package name: ocs Version : 2.1.2-1 Upstream Author : Public Knowledge Project * URL : http://pkp.sfu.ca/?q=ocs * License : GPL2 or later Programming Lang: PHP Description : Open

Bug#580684: phpmyadmin: Upgrade from 4:3.3.2-1 to 4:3.3.2-2 has problems

2010-05-17 Thread Thijs Kinkhorst
On Sun, May 16, 2010 22:13, Joerg Pietschmann wrote: On 16.05.2010 21:18, Thijs Kinkhorst wrote: What exactly did you try before you concluded that you were in a loop (the log you submitted shows two iterations only)? Did you choose 'abort' more than 4 times? I first tried the usual

Bug#581988: [Pkg-mailman-hackers] Bug#581988: mailman adds duplicate MIME-Version header

2010-05-17 Thread Thijs Kinkhorst
On moandei 17 Maaie 2010, Martin Michlmayr wrote: I just went through the amavis folder on a server and noticed a lot of message in bad-header-quarantine. They were all mails from a local mailing list (handled by mailman) and were rejected because of this: X-Amavis-Alert: BAD HEADER

Bug#581821: consider switching to php-net-ldap2

2010-05-16 Thread Thijs Kinkhorst
Package: turba2 Version: 2.3.3+debian0-3 Severity: wishlist Hi, Upstream of Net::LDAP / php-net-ldap has declared that project to be obsolete for some time now, and refer to Net::LDAP2 / php-net-ldap2 as a replacement. It would probably be beneficial in the long term if you would switch to

Bug#581822: consider switching to php-net-ldap2

2010-05-16 Thread Thijs Kinkhorst
Package: kolab-webadmin Version: 2.2.3-20091217-2 Severity: wishlist Hi, Upstream of Net::LDAP / php-net-ldap has declared that project to be obsolete for some time now, and refer to Net::LDAP2 / php-net-ldap2 as a replacement. It would probably be beneficial in the long term if you would

Bug#580684: phpmyadmin: Upgrade from 4:3.3.2-1 to 4:3.3.2-2 has problems

2010-05-16 Thread Thijs Kinkhorst
On snein 16 Maaie 2010, Joerg Pietschmann wrote: On 14.05.2010 18:46, Thijs Kinkhorst wrote: Interesting. Do you have an idea where this error could come from? Why doesn't a 'phpmyadmin' database exist when you're trying to upgrade the package? Or does it exist? I have no idea

Bug#581646: dbconfig-common enters configuration stage after error during purge

2010-05-14 Thread Thijs Kinkhorst
Package: dbconfig-common Version: 1.8.46 Hi, When making an error during package purge (e.g. a typo in the admin password) you are prompted to retry. Then, the package first wants to (re)install/configure the database, and only after that, starts the purge sequence again. Steps to reproduce:

Bug#580684: phpmyadmin: Upgrade from 4:3.3.2-1 to 4:3.3.2-2 has problems

2010-05-14 Thread Thijs Kinkhorst
On freed 7 Maaie 2010, J.Pietschmann wrote: Setting up phpmyadmin (4:3.3.2-2) ... dbconfig-common: writing config to /etc/dbconfig-common/phpmyadmin.conf Replacing config file /etc/phpmyadmin/config-db.php with new version creating database backup in /var/cache/dbconfig-

Bug#579681: pu: package sun-java5/1.5.0-22-0lenny1

2010-05-07 Thread Thijs Kinkhorst
the non-free Sun JDKs often have security issues and can only be updated through new upstream versions since we do not have source code. 1.5.0-22 will be the last upstream update because this version has been declared EOL (end of life). The security team asked me to update the package through

Bug#579265: [Pkg-mailman-hackers] Bug#579265: mailman: installation fails because of invalid user

2010-05-02 Thread Thijs Kinkhorst
Hi Éric, On moandei 26 April 2010, Éric Araujo wrote: install: invalid user `list' invoke-rc.d: initscript mailman, action start failed. The user 'list' is defined in base-files and is guaranteed to be available by Debian Policy. Did you by any chance remove that user by hand? cheers,

Bug#576739: [Secure-testing-team] Bug#576739: [ca-certificates] Please remove RSA Security 1024 V3 root certificate

2010-05-02 Thread Thijs Kinkhorst
severity 576739 normal thanks Dear ca-certificates maintainers, I hereby request that the certificate RSA_Security_1024_v3.crt be removed from the ca-certificates package, as it's declared obsolete by the private key owner. It's in the package by virtue of being in Mozilla's store, and as

Bug#578909: SQL injection in templates_export

2010-04-23 Thread Thijs Kinkhorst
Package: cacti Version: 0.8.7b-2 Severity: serious Tags: security patch Hi, An SQL injection issue was published in Cacti: http://seclists.org/fulldisclosure/2010/Apr/272 Both stable and testing/unstable are affected. Upstream blessed patch is here:

Bug#577746: debcheck: not updated since 12 Feb 2010

2010-04-14 Thread Thijs Kinkhorst
Package: qa.debian.org User: qa.debian@packages.debian.org Usertags: debcheck Hi, The pages at http://qa.debian.org/debcheck.php have not been updated anymore since two months now, as the footer shows. Thijs signature.asc Description: This is a digitally signed message part.

Bug#577734: [php-maint] Bug#577734: php5: squeeze must not ship 5.3.1

2010-04-14 Thread Thijs Kinkhorst
On woansdei 14 April 2010, Raphael Geissert wrote: Since there's apparently not much progress by others to fix their packages so that php 5.3.2 can finally migrate, I'm filing a dummy RC bug that I'm going to mark as fixed by 5.3.2. Nobody wants to release squeeze with 5.3.1. What do you

Bug#576739: [Secure-testing-team] Bug#576739: [ca-certificates] Please remove RSA Security 1024 V3 root certificate

2010-04-07 Thread Thijs Kinkhorst
severity 576739 wishlist tags 576739 -security thanks Hi Dererk, On Tue, April 6, 2010 22:23, Dererk wrote: Package: ca-certificates Version: 20090814 Severity: critical Tags: security X-Debbugs-CC: secure-testing-t...@lists.alioth.debian.org Hello. Please remove RSA Security 1024 V3

Bug#575912: phpmyadmin: Server running with Suhosin. Please refer to documentation for possible issues.

2010-04-07 Thread Thijs Kinkhorst
On Tue, April 6, 2010 17:11, Olaf van der Spek wrote: On 2-4-2010 15:38, Michal Čihař wrote: I'd rather not have to do that. The is no way around - Suhosin imposes limits on lengths of request, it's content and lengths of variables. Depending on your tables you can be easily hit by those

Bug#576117: [signing-party] springgraph depends on libgd-gd2*-perl

2010-04-02 Thread Thijs Kinkhorst
Hi Per, On Fri, April 2, 2010 13:50, Per W. wrote: Hi Thijs! Thijs Kinkhorst wrote: It's common practice to use Recommends in Debian for packages that only enable certain non-essential functionality in a package. This seems exactly such a case where the whole of signing-party works fine

Bug#557514: owner 557514

2010-03-22 Thread Thijs Kinkhorst
On Mon, March 22, 2010 14:22, Olivier Berger wrote: On Mon, Dec 07, 2009 at 02:14:58PM +0100, Thijs Kinkhorst wrote: # Automatically generated email from bts, devscripts version 2.10.35lenny7 owner 557514 ! Any news about this packaging ? Yes, in the sense that I have a package here

Bug#574826: example-interpreter-not-absolute false positive for non-executable files

2010-03-21 Thread Thijs Kinkhorst
Package: lintian Version: 2.3.3 Severity: minor Hi, My package triggered the following info-level Lintian tests: I: eekboek: example-interpreter-not-absolute ./usr/share/doc/eekboek/examples/Kasverkoop.pm #!perl I: eekboek: example-wrong-path-for-interpreter

Bug#573559: print should be printf, confirmed

2010-03-21 Thread Thijs Kinkhorst
retitle 573559 some output strings not interpolated tags 573559 patch thanks Hi, printf instead of print should be called in line 448 of svn-buildpackage. Confirmed, and there's another instance. Attached patch fixes them. cheers, Thijs --- svn-buildpackage.orig 2010-03-21 15:26:02.0

Bug#574859: override: eekboek-db-postgresql:perl/extra, eekboek-gui:perl/extra

2010-03-21 Thread Thijs Kinkhorst
Package: ftp.debian.org Hi, On snein 21 Maart 2010, Archive Administrator wrote: eekboek-db-postgresql_2.00.00~RC2-1_all.deb: package says priority is extra, override says optional. eekboek-gui_2.00.00~RC2-1_all.deb: package says priority is extra, override says optional. Please change

Bug#574760: phpCAS XSS vulnerablity PHPCAS-52

2010-03-20 Thread Thijs Kinkhorst
Package: glpi Severity: serious Tags: security patch Hi, phpCAS, which is embedded by GLPI, has fixed an XSS vulnerablity. Details and the patch are availbale at their bug tracker: http://www.ja-sig.org/issues/browse/PHPCAS-52 Can you please see that this bug gets fixed in the GLPI copy of

Bug#574757: phpCAS XSS vulnerablity PHPCAS-52

2010-03-20 Thread Thijs Kinkhorst
Package: moodle Severity: serious Tags: security patch Hi, phpCAS, which is embedded by Moodle, as fixed an XSS vulnerablity. Details and the patch are availbale at their bug tracker: http://www.ja-sig.org/issues/browse/PHPCAS-52 Can you please see that this bug gets fixed in the Moodle copy

Bug#545979: squirrelmail: Wrong message timestamp (ie Date: Thu, 10 Sep 0000 13:05:15 -0200)

2010-03-07 Thread Thijs Kinkhorst
reassign 545979 php5 forcemerge 542301 545979 thanks Hi JKB, On tongersdei 10 Septimber 2009, JKB wrote: I have installed a long time ago squirrelmail on a Sun Blade 2000. This web service ran fine, but for a few days, all message sent by squirrelmail are sent with a wrong date: year is

Bug#571762: [php-maint] Bug#571762: Bug#571762: Bug#571762: [php5] please get rid of Warning: date() [function.date]: It is not safe to rely on the system's timezone settings.

2010-03-07 Thread Thijs Kinkhorst
On moandei 1 Maart 2010, sean finney wrote: okay, i think we should consider just disabling this error message entirely, as long as we're applying the system timezonedb patch. after all, isn't the point of the patch that we can trust the local timezone database? thoughts? Sounds like a

Bug#550452: Squirrelmail (1.4.20~rc2-1) w/ Courier-IMAP fails to execute some IMAP operations

2010-03-07 Thread Thijs Kinkhorst
On sneon 10 Oktober 2009, Andrea Gozzi wrote: After update to 1.4.20rc2, Squirrelmail has trouble executing various commands on the Courier-IMAP backend. Access to the mailbox is granted but operations such as FETCH and SORT are not understood by the IMAP server and rejected with a Error

Bug#571735: Deprecated comment style generates warning in PHP 5.3

2010-02-27 Thread Thijs Kinkhorst
Package: php5-ming Version: 1:0.4.3-1 Severity: normal Hi, Your package ships a config file under /etc/php5/cli/conf.d/ which looks something like this: # configuration for php XXX module extension=XXX.so PHP upstream has decided that using '#' as a comment marker wasn't a good idea

Bug#571736: Deprecated comment style generates warning in PHP 5.3

2010-02-27 Thread Thijs Kinkhorst
Package: php5-lasso Version: 2.2.1-4 Severity: normal Hi, Your package ships a config file under /etc/php5/cli/conf.d/ which looks something like this: # configuration for php XXX module extension=XXX.so PHP upstream has decided that using '#' as a comment marker wasn't a good idea

Bug#571737: Deprecated comment style generates warning in PHP 5.3

2010-02-27 Thread Thijs Kinkhorst
Package: php5-ps Version: 1.3.6-3 Severity: normal Hi, Your package ships a config file under /etc/php5/cli/conf.d/ which looks something like this: # configuration for php XXX module extension=XXX.so PHP upstream has decided that using '#' as a comment marker wasn't a good idea afterall

Bug#570548: [Pkg-mailman-hackers] Bug#570548: mailman: postfix-to-mailman.py doesn't work with lists ending in -admin

2010-02-20 Thread Thijs Kinkhorst
tags 570548 pending thanks Hi Axel, On freed 19 Febrewaris 2010, Axel Beckert wrote: The following patch fixes this behaviour by first checking if a mailing list named with the full local part exists, and only if not, tries to parse an administrative suffix out of the local part and then

Bug#570659: O: serendipity -- Weblog manager with extensive theming and plugin support

2010-02-20 Thread Thijs Kinkhorst
Package: wnpp Severity: normal Hi, I don't use Serendipity a lot anymore, and have to make some choices in my Debian activities to be able to keep doing a good job, so I'm orphaning Serendipity. I believe the current packaging is not in a bad shape; however, the package is some versions behind

Bug#570660: RFA: phpbb3

2010-02-20 Thread Thijs Kinkhorst
Package: wnpp Severity: normal Hi, As a maintainer I cannot dedicate the required amount of time to the phpBB3 package at this moment. Jeroen, the other maintainer, is still interested to contribute but may not have enough time available, so the package needs new contributors in its packaging

Bug#566220: [PATCH] Clarify “copyright and distribution license”

2010-02-14 Thread Thijs Kinkhorst
On moandei 8 Febrewaris 2010, Jonathan Nieder wrote: diff --git a/policy.sgml b/policy.sgml index 76ac0d4..ea3ed35 100644 --- a/policy.sgml +++ b/policy.sgml @@ -569,8 +569,8 @@ headingCopyright considerations/heading p - Every package must be accompanied by a

Bug#418642: Cannot reproduce unusability of smart

2010-02-14 Thread Thijs Kinkhorst
severity 418642 normal thanks Hi, I have tried to reproduce the original issue. With smartpm installed but rpm not, current smartpm is perfectly usable for Debian channels. I have not found an ordering of installing smart and installing/removing rpm that triggers such a bug. Hence I think

Bug#560953: Patch for 2.1-5.1 nmu

2010-02-14 Thread Thijs Kinkhorst
issue +(Closes: #560953). + + -- Thijs Kinkhorst th...@debian.org Sun, 14 Feb 2010 14:23:15 +0100 + smart (1.2-5) unstable; urgency=low * Add 06_CVE-2009-3720 patch (Closes: #560953) only in patch2: unchanged: --- smart-1.2.orig/debian/patches/06_CVE-2009-3560.patch +++ smart-1.2/debian

Bug#568052: have to enter same password over and over in same session

2010-02-03 Thread Thijs Kinkhorst
On Tue, February 2, 2010 03:51, jida...@jidanni.org wrote: Package: signing-party Version: 1.1.2-1 Severity: wishlist File: /usr/bin/caff I have no idea of what caff is supposed to save effort of: we have to It's primary intent was not to save effort. It is to create an extra layer of

Bug#524361: phpbb3 package unmaintained?

2010-01-13 Thread Thijs Kinkhorst
Hi Richard, On Wed, January 13, 2010 08:56, Richard van den Berg wrote: The last activity shown on http://packages.qa.debian.org/p/phpbb3.html is from almost a year ago. Should we consider the phpbb3 package to be unmaintained? I was just discussing that with my co-maintainer. We both do not

Bug#564558: SyntaxError: invalid syntax (except TTBException as ex:)

2010-01-10 Thread Thijs Kinkhorst
Package: ttb Version: 1.0.1-2 Severity: grave Justification: renders package unusable A fresh install just crashes when started: th...@volta:~$ ttb /usr/bin/ttb:906: Warning: 'as' will become a reserved keyword in Python 2.6 File /usr/bin/ttb, line 906 except TTBException as ex:

Bug#563907: dbconfig-common: Fix documented path for removal SQL

2010-01-06 Thread Thijs Kinkhorst
Package: dbconfig-common Version: 1.8.39 Severity: minor Hi, As far as I can see from using dbconfig-common, and reading the code, the documented paths for placing SQL removal instructions are not correct in the documentation: see attached patch. It also removes a comment about Lintian

Bug#542381: Bug#542383: fails to install

2010-01-06 Thread Thijs Kinkhorst
Michael Biebl wrote: Holger Levsen wrote: Package: rsyslog-mysql Version: 4.2.0-1 Severity: serious User: debian...@lists.debian.org Usertags: piuparts piuparts.d.o Hi, during a test with piuparts I noticed your package failed to install. From the attached log (scroll to the

<    4   5   6   7   8   9   10   11   12   13   >