Bug#437148: Security Hole in scponly, due to svn support

2007-08-12 Thread Florian Weimer
* Joachim Breitner: messing around with some friends here, I tried to access his computer with only a scponly protected account. I discovered this way of gaining full shell access: I locally created a subversion repository /tmp/blubb with a /tmp/blubb/hooks/post-commit that contains the

Processed: Re: Bug#436232: notfixed 436232 in 4.7.0+git20070708-1

2007-08-12 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: reassign 436232 texlive-base-bin Bug#436232: latex-cjk-chinese: postinst and uninstall fail: Package color Error: No driver specified. Bug#435660: latex-cjk-chinese: installing/upgrading/removing package fails Bug reassigned from package

Bug#436994: Recompiling ecj against gcj-4.2 fixes this

2007-08-12 Thread Daniel Schepler
clone 436994 -1 reassign -1 ecj 3.3.0-2 retitle -1 ecj: Experimental needs ecj compiled with gcj-4.2 tags -1 + experimental block 436994 with -1 retitle 436994 java-gcj-compat-dev: Needs to tighten dependency on ecj thanks When I built a version of ecj with s/4.1/4.2/g and s/gcj7/gcj8/g, the

Processed: Recompiling ecj against gcj-4.2 fixes this

2007-08-12 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: clone 436994 -1 Bug#436994: java-gcj-compat-dev: javac doesn't work on trivial program Bug 436994 cloned as bug 437367. reassign -1 ecj 3.3.0-2 Bug#437367: java-gcj-compat-dev: javac doesn't work on trivial program Bug reassigned from package

Bug#434216: marked as done (rss-glx: Cannot install due to missing dependency - libglew1)

2007-08-12 Thread Debian Bug Tracking System
Your message dated Sun, 12 Aug 2007 08:35:57 +0200 with message-id [EMAIL PROTECTED] and subject line (no subject) has caused the attached Bug report to be marked as done. This means that you claim that the problem has been dealt with. If this is not the case it is now your responsibility to

Processed: Re: [Pkg-mythtv-maintainers] Bug#437298: ivtv: FTBFS on i386 with 2.6.22-1

2007-08-12 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: severity 437298 normal Bug#437298: ivtv: FTBFS on i386 with 2.6.22-1 Severity set to `normal' from `serious' thanks Stopping processing here. Please contact me if you need assistance. Debian bug tracking system administrator (administrator, Debian

Bug#437298: [Pkg-mythtv-maintainers] Bug#437298: ivtv: FTBFS on i386 with 2.6.22-1

2007-08-12 Thread Daniel Baumann
severity 437298 normal thanks Mark Purcell wrote: ivtv 0.10.x is only for kernels = 2.6.18 and = 2.6.21.x didn't know that, sorry. the ivtv modules have been incorporated into the kernel from 2.6.22 onwards and the ivtv package 1.0.x is for kernels = 2.6.22. This release does NOT contain

Bug#434274: marked as done (gcc-snapshot 20070720-1 fails to compile trivial code)

2007-08-12 Thread Debian Bug Tracking System
Your message dated Sun, 12 Aug 2007 10:32:01 +0200 with message-id [EMAIL PROTECTED] and subject line Bug#434274: gcc-snapshot 20070720-1 fails to compile trivial code has caused the attached Bug report to be marked as done. This means that you claim that the problem has been dealt with. If this

Bug#435146: confirmed with asterisk 1:1.4.10~dfsg-1, libopenh323 1.18.0.dfsg-3

2007-08-12 Thread Mark Purcell
Package: asterisk-h323 Version: 1:1.4.10~dfsg-1 Followup-For: Bug #435146 Installing the -develop versions provides some additional information. (gdb) bt #0 0x in ?? () #1 0xb7700228 in PFactoryH323Capability, PString::~PFactory () from /usr/lib/libopenh323.so.1.18.0 #2 0xb706b128 in

Bug#393374: Bug #393374: Source package contains non-free IETF RFC/I-D's

2007-08-12 Thread Dmitry E. Oboukhov
Hi, Teemu Hukkanen! I've made a repackage for this package, closed all the bugs and prepared it for NMU. You can see the package here: http://uvw.ru/debian/unstable/httptunnel/ If You don't mind I will make an upload with the help of my sponsor (Al Nikolov, [EMAIL PROTECTED]) two weeks later.

Bug#433824: marked as done (frozen-bubble: [amd64] Can't locate auto/SDL/IMGLoad.al)

2007-08-12 Thread Debian Bug Tracking System
Your message dated Sun, 12 Aug 2007 11:29:07 +0200 with message-id [EMAIL PROTECTED] and subject line Bug#433824: Can't start the game! has caused the attached Bug report to be marked as done. This means that you claim that the problem has been dealt with. If this is not the case it is now your

Processed: Bug #393374: Source package contains non-free IETF RFC/I-D's

2007-08-12 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: tags 393374 pending Bug#393374: Source package contains non-free IETF RFC/I-D's Tags were: etch-ignore Tags added: pending tags 429885 pending Bug#429885: [patch] fix broken --stdin-stdout option on hts and htc that writes to stdin Tags were: patch

Bug#435146: confirmed with asterisk 1:1.4.10~dfsg-1, libopenh323 1.18.0.dfsg-3

2007-08-12 Thread Kilian Krause
Hi Mark, On Sun, Aug 12, 2007 at 10:03:58AM +0100, Mark Purcell wrote: Package: asterisk-h323 Version: 1:1.4.10~dfsg-1 Followup-For: Bug #435146 Installing the -develop versions provides some additional information. can you also install the asterisk-dbg? Thanks! -- Best regards, Kilian

Bug#435788: marked as done (python-sip4-dev is lacking a dependency on python(-dev))

2007-08-12 Thread Debian Bug Tracking System
Your message dated Sun, 12 Aug 2007 09:47:04 + with message-id [EMAIL PROTECTED] and subject line Bug#435788: fixed in sip4-qt3 4.7-2 has caused the attached Bug report to be marked as done. This means that you claim that the problem has been dealt with. If this is not the case it is now your

Processed: severity of 437345 is minor

2007-08-12 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: # Automatically generated email from bts, devscripts version 2.10.6 severity 437345 minor Bug#437345: aterm: symbol lookup error: /usr/lib/libGL.so.1: undefined symbol: XDamageAdd Severity set to `minor' from `grave' End of message, stopping

Bug#435146: confirmed with asterisk 1:1.4.10~dfsg-1, libopenh323 1.18.0.dfsg-3

2007-08-12 Thread Mark Purcell
On Sun, 12 Aug 2007, Kilian Krause wrote: Hi Mark, Hi Kilian, Installing the -develop versions provides some additional information. can you also install the asterisk-dbg? That was with asterisk-dbg and the -develop files installed: ii asterisk 1:1.4.10~dfsg-1

Bug#437148: Security Hole in scponly, due to svn support

2007-08-12 Thread Joachim Breitner
Hi, Am Sonntag, den 12.08.2007, 07:58 +0200 schrieb Florian Weimer: * Joachim Breitner: messing around with some friends here, I tried to access his computer with only a scponly protected account. I discovered this way of gaining full shell access: I locally created a subversion

Bug#435735: marked as done (CVE-2007-3791: Buffer overflow in policyd)

2007-08-12 Thread Debian Bug Tracking System
Your message dated Sun, 12 Aug 2007 11:02:03 + with message-id [EMAIL PROTECTED] and subject line Bug#435735: fixed in postfix-policyd 1.80-2.2 has caused the attached Bug report to be marked as done. This means that you claim that the problem has been dealt with. If this is not the case it

Bug#436965: [Karl Berry] Bug#435132: [tex-live] Bug#435132: texlive-metapost: Please include latest latexmp version

2007-08-12 Thread Frank Küster
---BeginMessage--- Thank you very much - his address is still the one above? That is where I wrote, yes. No answer yet. -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED] ---End Message--- -- Frank Küster Single Molecule

Processed: Changed email address

2007-08-12 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: submitter 315713 ! Bug#315713: sudoedit - wrong gid of new files Changed Bug submitter from Sven Joachim [EMAIL PROTECTED] to Sven Joachim [EMAIL PROTECTED]. submitter 317928 ! Bug#317928: aptitude: visual mode does not check terminal capabilities

Processed: tagging bugs that are closed by packages in NEW as pending

2007-08-12 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: # the following bugs are closed by packages in NEW # tags 434766 pending Bug#434766: Should be named libogg-vorbis-perl There were no tags set. Tags added: pending tags 437179 pending Bug#437179: ITP: libsoundgen -- Simple sound generator library

Bug#425978: marked as done (libgd2: Multiple issues in GIF loader)

2007-08-12 Thread Debian Bug Tracking System
Your message dated Sun, 12 Aug 2007 14:33:32 +0200 with message-id [EMAIL PROTECTED] and subject line Bug fixed in 2.0.34 has caused the attached Bug report to be marked as done. This means that you claim that the problem has been dealt with. If this is not the case it is now your responsibility

Processed: Unmerge

2007-08-12 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: package wine Ignoring bugs not assigned to: wine unmerge 381341 Bug#381341: replace amd64 hack with something better Bug#430845: wine: Firefox 2 and Netscape web browsers can't access network Disconnected #381341 from all other report(s). severity

Processed: tagging 436382

2007-08-12 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: # Automatically generated email from bts, devscripts version 2.10.7 tags 436382 + pending Bug#436382: loop-aes: FTBFS: unmet b-dep linux-support-2.6.21-2 There were no tags set. Tags added: pending End of message, stopping processing here. Please

Bug#437423: /usr/share/common-licenses/GPL-3 do not exist

2007-08-12 Thread Juhapekka Tolvanen
Package: ed Version: 0.7-1 Severity: serious /usr/share/doc/ed/copyright says: You should have received a copy of the GNU General Public License with your Debian GNU system, in /usr/share/common-licenses/GPL-3, or with the Debian GNU ed source package as the file COPYING. If not, see

Bug#437424: Unusable with openbox = 3.4

2007-08-12 Thread Gabriele 'LightKnight' Stilli
Package: obconf Version: 1.6-1 Severity: grave Fixed: 2.0.1-1 --- Please enter the report below this line. --- [EMAIL PROTECTED]:~$ obconf obconf: error while loading shared libraries: libobrender.so.0: cannot open shared object file: No such file or directory This happens with obconf 1.6-1

Bug#436322: sylpheed-claws-gtk2-extra-plugins: FTBFS: make[2]: *** No targets specified and no makefile found. Stop.

2007-08-12 Thread Ricardo Mones
On Thu, 09 Aug 2007 08:53:25 +0200 Lucas Nussbaum [EMAIL PROTECTED] wrote: On 09/08/07 at 08:00 +0200, Ricardo Mones wrote: Maybe the time for removal of this source package from sid has come... Probably. Do you want me to take care of that? Thanks, I've already taken care of filing the

Processed: fixed 437424 in 2.0.1-1

2007-08-12 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: # Automatically generated email from bts, devscripts version 2.10.6 fixed 437424 2.0.1-1 Bug#437424: Unusable with openbox = 3.4 Bug marked as fixed in version 2.0.1-1. End of message, stopping processing here. Please contact me if you need

Processed: setting package to cduce, tagging 419892

2007-08-12 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: # Automatically generated email from bts, devscripts version 2.10.7 package cduce Ignoring bugs not assigned to: cduce tags 419892 + pending Bug#419892: cduce_0.4.1-1+b1(ia64/unstable): FTBFS: SEGV runing ./cduce There were no tags set. Tags added:

Bug#437424: Unusable with openbox = 3.4

2007-08-12 Thread Nico Golde
Hi, * Gabriele 'LightKnight' Stilli [EMAIL PROTECTED] [2007-08-12 15:36]: Package: obconf Version: 1.6-1 Severity: grave Fixed: 2.0.1-1 [EMAIL PROTECTED]:~$ obconf obconf: error while loading shared libraries: libobrender.so.0: cannot open shared object file: No such file or directory

Processed: blocked

2007-08-12 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: block 436394 by 437395 Bug#437395: dh-make-php: pear.mk makes php-benchmark FTBFS Bug#436394: php-benchmark: FTBFS: /bin/sh: -c: line 0: syntax error near unexpected token `(' Was not blocked by any bugs. Blocking bugs of 436394 added: 437395 stop

Bug#430237: marked as done (ldbl128 transition for alpha, powerpc, sparc, s390)

2007-08-12 Thread Debian Bug Tracking System
Your message dated Sun, 12 Aug 2007 10:02:01 -0600 with message-id [EMAIL PROTECTED] and subject line invalid bug has caused the attached Bug report to be marked as done. This means that you claim that the problem has been dealt with. If this is not the case it is now your responsibility to

Bug#427157: CVE-2007-2807: stack-based buffer overflow

2007-08-12 Thread Nico Golde
Hi, I intend to upload an NMU to fix this problem, attached is a patch which should fix CVE-2007-2807. The patch is also archived on: http://people.debian.org/~nion/nmu-diff/eggdrop-1.6.18-1_1.6.18-1.1.patch Kind regards Nico -- Nico Golde - http://ngolde.de - [EMAIL PROTECTED] - GPG:

Bug#437454: CVE-2007-3770: execute arbitrary commands via crafted links using Open Link functionality

2007-08-12 Thread Darren Salt
Package: xfce4-terminal Version: 0.2.5.6rc1-2 Severity: grave Tags: security, patch CVE-2007-3770 says: The terminal_helper_execute function in terminal/terminal.c in Xfce Terminal 0.2.6 allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a

Bug#435660: latex-cjk-chinese: installing/upgrading/removing package fails

2007-08-12 Thread Norbert Preining
On Don, 02 Aug 2007, Danai SAE-HAN =?UTF-8?Q?(=E9=9F=93=E9=81=94=E8=80=90) ?= wrote: My goodness, so the purge doesn't work because it can't find pdftexconfig anymore. I'll see if this bug has already been fixed by a more recent Debian TexLive version, or if anything has changed recently. I

Bug#435660: latex-cjk-chinese: installing/upgrading/removing package fails

2007-08-12 Thread Danai SAE-HAN (韓達耐)
On 12-08-07 18:39, Norbert Preining wrote: On Don, 02 Aug 2007, Danai SAE-HAN =?UTF-8?Q?(=E9=9F=93=E9=81=94=E8=80=90) ?= wrote: I am not up2date with respect to this bug, but it IS is bug in texlive-base-bin and texlive-base which can lead to this situation. We are preparing an upload that

Bug#435660: latex-cjk-chinese: installing/upgrading/removing package fails

2007-08-12 Thread Norbert Preining
On Son, 12 Aug 2007, Danai SAE-HAN (?) wrote: I guess you could merge this with #436235. Or fifty others ;-) I have packages already ready but want to do more testing ... Best wishes Norbert --- Dr. Norbert

Bug#435660: latex-cjk-chinese: installing/upgrading/removing package fails

2007-08-12 Thread Frank Küster
Norbert Preining [EMAIL PROTECTED] wrote: On Don, 02 Aug 2007, Danai SAE-HAN =?UTF-8?Q?(=E9=9F=93=E9=81=94=E8=80=90) ?= wrote: My goodness, so the purge doesn't work because it can't find pdftexconfig anymore. I'll see if this bug has already been fixed by a more recent Debian TexLive

Bug#433824: closed by Josselin Mouette [EMAIL PROTECTED] (Re: Bug#433824: Can't start the game!)

2007-08-12 Thread Kartik Mistry
On 8/12/07, Debian Bug Tracking System [EMAIL PROTECTED] wrote: Hi, sorry for the late reply. [SDL Init] Can't locate auto/SDL/IMGLoad.al in @INC (@INC contains: /etc/perl /usr/local/lib/perl/5.8.8 /usr/local/share/perl/5.8.8 /usr/lib/perl5 /usr/share/perl5 /usr/lib/perl/5.8

Bug#437454: marked as done (CVE-2007-3770: execute arbitrary commands via crafted links using Open Link functionality)

2007-08-12 Thread Debian Bug Tracking System
Your message dated Sun, 12 Aug 2007 17:47:15 + with message-id [EMAIL PROTECTED] and subject line Bug#437454: fixed in xfce4-terminal 0.2.6-3 has caused the attached Bug report to be marked as done. This means that you claim that the problem has been dealt with. If this is not the case it is

Bug#419892: marked as done (cduce_0.4.1-1+b1(ia64/unstable): FTBFS: SEGV runing ./cduce)

2007-08-12 Thread Debian Bug Tracking System
Your message dated Sun, 12 Aug 2007 18:02:03 + with message-id [EMAIL PROTECTED] and subject line Bug#419892: fixed in cduce 0.5.0-1 has caused the attached Bug report to be marked as done. This means that you claim that the problem has been dealt with. If this is not the case it is now your

Processed (with 1 errors): aptitude: [hppa] Does not cleanly finish

2007-08-12 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: unmerge 434861 Bug#434861: aptitude: [hppa] segfault during startup Bug#430050: aptitude: Crashes with SIGSEV when running simultaneously at some points Bug#430061: Reproducible SIGSEGV on startup in aptitude in experimental Bug#430865: crash when

Bug#437452: banshee: Correction of the bug origins, not affected by bug #428190

2007-08-12 Thread Safir Secerovic
Package: banshee Version: 0.12.1+dfsg-5 Followup-For: Bug #437452 As corrected by the mono-jit package maintainer, this bug is not related to bug #428190 which has thus been fixed in mono-jit package. This bug may come from either of banshee, gtk# or mono or... -- System Information: Debian

Bug#430836: marked as done (python-pygresql: Missing dependency on libpq4)

2007-08-12 Thread Debian Bug Tracking System
Your message dated Sun, 12 Aug 2007 21:12:33 + with message-id [EMAIL PROTECTED] and subject line Bug#430836: fixed in pygresql 1:3.8.1-2 has caused the attached Bug report to be marked as done. This means that you claim that the problem has been dealt with. If this is not the case it is now

Bug#433038: libapache2-mod-python: mod_python collides with mod_php5, rendering psp ususuable without proper error messages

2007-08-12 Thread Robert Edmonds
Gunter Ohrner wrote: Package: libapache2-mod-python Version: 3.3.1-2 Severity: grave Justification: renders package unusable Hi, Gunter: I'll try to replicate this bug, but could you please send me some additional information: - Any relevant apache configuration. I assume you're using

Processed: fixed 425978 in 2.0.34-1

2007-08-12 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: # Automatically generated email from bts, devscripts version 2.10.7 # marking fixed version right fixed 425978 2.0.34-1 Bug#425978: libgd2: Multiple issues in GIF loader Bug marked as fixed in version 2.0.34-1. End of message, stopping processing

Processed: found 425978 in 2.0.33-5.2

2007-08-12 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: # Automatically generated email from bts, devscripts version 2.10.7 found 425978 2.0.33-5.2 Bug#425978: libgd2: Multiple issues in GIF loader Bug marked as found in version 2.0.33-5.2. End of message, stopping processing here. Please contact me if

Bug#384276: marked as done (netatalk does not start if there are no interfaces available)

2007-08-12 Thread Debian Bug Tracking System
Your message dated Sun, 12 Aug 2007 22:17:03 + with message-id [EMAIL PROTECTED] and subject line Bug#384276: fixed in netatalk 2.0.3-6 has caused the attached Bug report to be marked as done. This means that you claim that the problem has been dealt with. If this is not the case it is now

Bug#437505: gnome-screensaver: Unable to unlock a locked screen

2007-08-12 Thread Sam Morris
Package: gnome-screensaver Version: 2.18.2-1 Severity: grave Justification: renders package unusable -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 I am trying out the new version of PAM (0.99.7) from experimental. Ever since I upgraded libpam-modules and libpam-runtime, I have been unable to

Bug#431959: marked as done (nvidia-kernel-legacy-96xx-2.6.18-4-amd64: spelling mistake in provides field)

2007-08-12 Thread Debian Bug Tracking System
Your message dated Sun, 12 Aug 2007 23:47:02 + with message-id [EMAIL PROTECTED] and subject line Bug#431959: fixed in nvidia-graphics-legacy-96xx-modules-amd64 1.0.9639+2 has caused the attached Bug report to be marked as done. This means that you claim that the problem has been dealt with.

Bug#437514: udev: Boot hang with kernel 2.6.21

2007-08-12 Thread Dominique Brazziel
Package: udev Version: 0.105-4 Severity: critical Justification: breaks the whole system After line 'Waiting for /dev to be fully populated' the system hangs. Eventually it will timeout but then hang forever (/dev not fully populated). If I set loglevel to 'info' it is possible to get things

Bug#437514: udev: Boot hang with kernel 2.6.21

2007-08-12 Thread Marco d'Itri
severity 437514 normal tag 437514 unreproducible moreinfo thanks Try upgrading udev. You probably compiled your kernel without enabling some feature(s) needed by older udev releases. -- ciao, Marco signature.asc Description: Digital signature

Bug#437514: udev: Boot hang with kernel 2.6.21

2007-08-12 Thread Marco d'Itri
On Aug 13, Dominique Brazziel [EMAIL PROTECTED] wrote: I doubt that I left out any needed features to support udev, as I used the .config of my 2.6.18 kernel. I doubt that you fully understand the process of building your own kernel. How can I easily upgrade just the udev package and it's

Processed: your mail

2007-08-12 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: close 353460 12.3.91-2 Bug#353460: im-sdk_12.3.91-0.1(hppa/experimental): FTBFS: typo in debian/control 'close' is deprecated; see http://www.debian.org/Bugs/Developer#closing. Bug marked as fixed in version 12.3.91-2, send any further explanations to

Bug#437222: marked as done (asterisk: Depends on libpri1.0 = 1.4, should this be libpri1.2 = 1.4?)

2007-08-12 Thread Debian Bug Tracking System
Your message dated Mon, 13 Aug 2007 06:25:49 +0100 with message-id [EMAIL PROTECTED] and subject line Fwd: libpri_1.4.1-1_i386.changes ACCEPTED has caused the attached Bug report to be marked as done. This means that you claim that the problem has been dealt with. If this is not the case it is

Bug#437530: bashism in init.d script: unexpected operator: ==

2007-08-12 Thread martin f krafft
Package: lirc Version: 0.8.0-11 Severity: serious Starting lirc daemon:[: 133: ==: unexpected operator [: 133: ==: unexpected operator Use of == within [], such as [ $START_LIRCD == true ] is a bashism. Since the init.d script uses /bin/sh, please change s/==/=/ Thanks, -- System