Bug#559798: CVE-2009-3736 local privilege escalation

2009-12-07 Thread Moritz Muehlenhoff
On Sun, Dec 06, 2009 at 11:50:06PM -0500, Michael Gilbert wrote: Package: arts Severity: grave Tags: security Is arts still needed since KDE 4 uses Phonon or should we remove it for Squeeze? Cheers, Moritz -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a

Bug#536635: marked as done (libconfig8: Various library packaging errors)

2009-12-07 Thread Debian Bug Tracking System
Your message dated Mon, 07 Dec 2009 23:33:09 + with message-id e1nhn4n-0007i8...@ries.debian.org and subject line Bug#536635: fixed in libconfig 1.3.2-2 has caused the Debian Bug report #536635, regarding libconfig8: Various library packaging errors to be marked as done. This means that you

Bug#537311: marked as done (libconfig++8-dev: Missing dependency)

2009-12-07 Thread Debian Bug Tracking System
Your message dated Mon, 07 Dec 2009 23:33:09 + with message-id e1nhn4n-0007ie...@ries.debian.org and subject line Bug#537311: fixed in libconfig 1.3.2-2 has caused the Debian Bug report #537311, regarding libconfig++8-dev: Missing dependency to be marked as done. This means that you claim

Bug#559845: CVE-2009-3736 local privilege escalation

2009-12-07 Thread Simon Horman
On Mon, Dec 07, 2009 at 11:12:32PM +1100, Simon Horman wrote: On Mon, Dec 07, 2009 at 12:11:07AM -0500, Michael Gilbert wrote: Package: heartbeat Severity: grave Tags: security Hi, The following CVE (Common Vulnerabilities Exposures) id was published for libtool. I see that

Bug#558716: FTBFS: The return type is incompatible with vtkMultiProcessController.CreateSubController(vtkProcessGroup)

2009-12-07 Thread Denis Barbier
On 2009/11/30 Cyril Brulebois wrote: Package: vtk Version: 5.2.1-13 Severity: serious Justification: FTBFS Hi, your package FTBFS on kfreebsd-* with this error: | 65. ERROR in /build/buildd-vtk_5.2.1-13-kfreebsd-i386-uedLVA/vtk-5.2.1/Build/java/vtk/vtkMPIController.java (at line 47)

Bug#558716: FTBFS: The return type is incompatible with vtkMultiProcessController.CreateSubController(vtkProcessGroup)

2009-12-07 Thread Cyril Brulebois
Denis Barbier bou...@gmail.com (08/12/2009): This FTBFS bug can be reproduced on any architecture when compiling with gcj. The error just above is caused by covariant return types, which have been introduced in Java 5. A fix has been committed. Thanks! Mraw, KiBi. signature.asc

Bug#559836: [Pkg-openmpi-maintainers] Bug#559836: CVE-2009-3736 local privilege escalation

2009-12-07 Thread Manuel Prinz
Hi Michael! Am Montag, den 07.12.2009, 00:06 -0500 schrieb Michael Gilbert: The following CVE (Common Vulnerabilities Exposures) id was published for libtool. I have determined that this package embeds a vulnerable copy of the libtool source code. However, since this is a mass bug filing

Processed: reassign 559952 to kdebase-workspace-bin, forcibly merging 559349 559952

2009-12-07 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: reassign 559952 kdebase-workspace-bin Bug #559952 [kdebase] kdebase is not installable Bug reassigned from package 'kdebase' to 'kdebase-workspace-bin'. forcemerge 559349 559952 Bug#559349: kdebase-workspace-bin: not installable due to missing

Bug#559349: marked as done (kdebase-workspace-bin: not installable due to missing dependency libxklavier15, renders KDE unusable)

2009-12-07 Thread Debian Bug Tracking System
Your message dated Tue, 8 Dec 2009 02:15:53 +0200 with message-id 200912080216.00381.modes...@vainius.eu and subject line libxklavier15 in testing, kdebase-workspace-bin is no longer broken has caused the Debian Bug report #559349, regarding kdebase-workspace-bin: not installable due to missing

Bug#559550: marked as done (kaddressbook depends on libgnokii5)

2009-12-07 Thread Debian Bug Tracking System
Your message dated Tue, 8 Dec 2009 02:16:12 +0200 with message-id 200912080216.13221.modes...@vainius.eu and subject line libgnokii5 in testing, kaddressbook is no longer broken has caused the Debian Bug report #559550, regarding kaddressbook depends on libgnokii5 to be marked as done. This means

Bug#559536: marked as done (Missing dependency in testing)

2009-12-07 Thread Debian Bug Tracking System
Your message dated Tue, 8 Dec 2009 02:15:53 +0200 with message-id 200912080216.00381.modes...@vainius.eu and subject line libxklavier15 in testing, kdebase-workspace-bin is no longer broken has caused the Debian Bug report #559349, regarding Missing dependency in testing to be marked as done.

Bug#559638: FTBFS [hppa]: unrecognized command line option -m32

2009-12-07 Thread Domenico Andreoli
Hi, -m32 is a machine dependent option, on x86 it is used to build 32bit code whereas -m64 is for 64bit code. it is not available on hppa because userland is 32bit only. regards, Domenico -[ Domenico Andreoli, aka cavok --[ http://www.dandreoli.com/gpgkey.asc ---[ 3A0F 2F80 F79C 678A

Bug#559713: marked as done (KDE not installable)

2009-12-07 Thread Debian Bug Tracking System
Your message dated Tue, 8 Dec 2009 02:15:53 +0200 with message-id 200912080216.00381.modes...@vainius.eu and subject line libxklavier15 in testing, kdebase-workspace-bin is no longer broken has caused the Debian Bug report #559349, regarding KDE not installable to be marked as done. This means

Bug#559952: marked as done (kdebase is not installable)

2009-12-07 Thread Debian Bug Tracking System
Your message dated Tue, 8 Dec 2009 02:15:53 +0200 with message-id 200912080216.00381.modes...@vainius.eu and subject line libxklavier15 in testing, kdebase-workspace-bin is no longer broken has caused the Debian Bug report #559349, regarding kdebase is not installable to be marked as done. This

Bug#559962: FTBFS [hppa]: *** [mime_types.erl] Error 1

2009-12-07 Thread dann frazier
Package: yaws Version: 1.85-1 Severity: serious User: debian-h...@lists.debian.org Usertags: hppa yaws reliably fails to build on hppa: https://buildd.debian.org/build.php?pkg=yawsver=1.85-1arch=hppafile=log From the most recent build attempt: [...] ./yaws_log.erl:13: Warning: undefined

Bug#559836: [Pkg-openmpi-maintainers] Bug#559836: CVE-2009-3736 local privilege escalation

2009-12-07 Thread Manuel Prinz
Here's the debdiff. Changes are checked into our SVN repo. Best regards Manuel diff -u openmpi-1.3.3/debian/changelog openmpi-1.3.3/debian/changelog --- openmpi-1.3.3/debian/changelog +++ openmpi-1.3.3/debian/changelog @@ -1,3 +1,10 @@ +openmpi (1.3.3-4) unstable; urgency=medium + + * Fixed

Processed: tagging bug

2009-12-07 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: tags 559836 + confirmed patch pending Bug #559836 [openmpi] CVE-2009-3736 local privilege escalation Added tag(s) confirmed, pending, and patch. thanks Stopping processing here. Please contact me if you need assistance. Debian bug tracking

Bug#559966: FTBFS [hppa]: java.nio.charset.UnmappableCharacterException

2009-12-07 Thread dann frazier
Package: libsaxon-java Version: 1:6.5.5-5 Severity: serious User: debian-h...@lists.debian.org Usertags: hppa libsaxon-java reliably fails to build on hppa: https://buildd.debian.org/build.php?pkg=libsaxon-javaver=1%3A6.5.5-5arch=hppafile=log From the most recent build attempt: [...] dh_clean

Bug#528029: marked as done (googleearth-package: Workaround symbol problem in libcrypto prevents googleearth from starting)

2009-12-07 Thread Debian Bug Tracking System
Your message dated Tue, 08 Dec 2009 01:02:20 + with message-id e1nhot6-00012h...@ries.debian.org and subject line Bug#528029: fixed in googleearth-package 0.5.7 has caused the Debian Bug report #528029, regarding googleearth-package: Workaround symbol problem in libcrypto prevents googleearth

Bug#559967: FTBFS [hppa]: method openConnection() in the type URL is not...

2009-12-07 Thread dann frazier
Package: libxmlrpc3-java Version: 3.1.2-1 Severity: serious User: debian-h...@lists.debian.org Usertags: hppa libxmlrpc3-java reliably fails to build on hppa: https://buildd.debian.org/build.php?pkg=libxmlrpc3-javaver=3.1.2-1arch=hppafile=log From the most recent build attempt: [...]

Bug#528687: marked as done (googleearth-package: googleearth binary fails with undefined symbol EVP_idea_cbc)

2009-12-07 Thread Debian Bug Tracking System
Your message dated Tue, 08 Dec 2009 01:02:20 + with message-id e1nhot6-00012h...@ries.debian.org and subject line Bug#528029: fixed in googleearth-package 0.5.7 has caused the Debian Bug report #528029, regarding googleearth-package: googleearth binary fails with undefined symbol EVP_idea_cbc

Bug#537837: marked as done (googleearth-package: googleearth fails to start due to undefined symbol: EVP_idea_cbc)

2009-12-07 Thread Debian Bug Tracking System
Your message dated Tue, 08 Dec 2009 01:02:20 + with message-id e1nhot6-00012h...@ries.debian.org and subject line Bug#528029: fixed in googleearth-package 0.5.7 has caused the Debian Bug report #528029, regarding googleearth-package: googleearth fails to start due to undefined symbol:

Bug#559628: FTBFS [hppa]: could not run sample program

2009-12-07 Thread Domenico Andreoli
hi, i'm rebuilding erlang on my hppa box, just in case anything (like NPTL transition) has changed/improved the erl interpreter behaviour in the meanwhile. stay tuned. cheers, Domenico -[ Domenico Andreoli, aka cavok --[ http://www.dandreoli.com/gpgkey.asc ---[ 3A0F 2F80 F79C 678A

Processed: severity of 526655 is important

2009-12-07 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: severity 526655 important Bug #526655 [kino] kino: Kino plays files accelerated without sound. There is no possibilities to play files normaly. Severity set to 'important' from 'grave' End of message, stopping processing here. Please contact

Bug#559970: zfs-fuse 0.6.0~beta+433snapshot-3 should depend upon libfuse2 (= 1.8)

2009-12-07 Thread Joseph Spiros
Package: zfs-fuse Version: 0.6.0~beta+433snapshot-3 Severity: grave Justification: renders package unusable This latest version of zfs-fuse incorrectly specifies a dependency upon libfuse2 (= 2.6). When attempting to run zfs-fuse with libfuse2 2.7.4-2, zfs-fuse exits with an error, noting that it

Bug#559971: itsalltext: Source package does not contain corresponding source for work

2009-12-07 Thread Ben Finney
Package: itsalltext Version: 1.3.1-1 Severity: serious Justification: Policy 2.3 The source package for ‘itsalltext’ is not the corresponding source for the work. Instead, it is a bundling of the binary ‘*.jar’ libraries. This violates the license terms of the work (GPLv3 §6) and as such means

Processed (with 1 errors): Fix title and tags for #549407

2009-12-07 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: retitle 549407 ivtools: FTBFS because of imake changing $(ARCH) string Bug #549407 [buildd.debian.org,ivtools] ivtools 1.2.6-1 FTBFS on sparc and powerpc Changed Bug title to 'ivtools: FTBFS because of imake changing $(ARCH) string' from

Bug#549407: [buildd-tools-devel] Bug#549407: ivtools 1.2.6-1 FTBFS on sparc and powerpc

2009-12-07 Thread Agustin Martin
2009/12/6 Agustin Martin agmar...@debian.org: Good news. I finally found the reason for this problem. An explanation was not that far. Quoting http://www.ivtools.org/ivtools/faq.html, --- ... For example, most PC-based uses of gcc have i386 defined to 1, so a path like

Bug#559978: FTBFS [hppa]: Template Haskell splice illegal in a stage-1 compiler

2009-12-07 Thread dann frazier
Package: pandoc Version: 1.2.1-1 Severity: serious pandoc reliably fails to build on hppa: https://buildd.debian.org/build.php?pkg=pandocver=1.2.1-1arch=hppafile=log From the most recent build attempt: [...] Using pkg-config version 0.22 found on system at: /usr/bin/pkg-config Using ranlib

Bug#559980: aptitude: Totally broken on GNU/kFreeBSD

2009-12-07 Thread Cyril Brulebois
Package: aptitude Version: 0.6.1.3-3 Severity: serious Tags: patch Justification: Broken package manager, broken d-i, etc. User: debian-...@lists.debian.org Usertags: kfreebsd Hi, for quite a while, we've had broken GNU/kFreeBSD d-i images, users complaining about installation being stuck at 1%.

Bug#552876: patch #552876

2009-12-07 Thread Ruben Molina
tags 552876 + confirmed patch thanks Hi, I can confirm this FTBFS on i386 too... The attached patch seems to fix the issue. Regards, Ruben Molina --- vftool-2.0alpha.orig/mkvsyvf.c +++ vftool-2.0alpha/mkvsyvf.c @@ -69,7 +69,7 @@ char mirror_end[SPLEN]; int mirror_end_len; -getline(sp,

Processed: patch #552876

2009-12-07 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: tags 552876 + confirmed patch Bug #552876 [src:vftool] vftool: FTBFS: mkvsyvf.c:72: error: conflicting types for 'getline' Added tag(s) confirmed and patch. thanks Stopping processing here. Please contact me if you need assistance. Debian bug

Processed: closing 521271

2009-12-07 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: close 521271 Bug#521271: Wrong library dependencies for nslookup 'close' is deprecated; see http://www.debian.org/Bugs/Developer#closing. Bug closed, send any further explanations to forum+deb...@km.mydyn.de End of message, stopping processing

Bug#559843: marked as done (CVE-2009-3736 local privilege escalation)

2009-12-07 Thread Debian Bug Tracking System
Your message dated Tue, 08 Dec 2009 04:47:45 + with message-id e1nhrzf-0004yo...@ries.debian.org and subject line Bug#559843: fixed in babel 1.4.0.dfsg-5 has caused the Debian Bug report #559843, regarding CVE-2009-3736 local privilege escalation to be marked as done. This means that you

Bug#559986: FTBFS: default-jdk-builddep: Depends: gcj-jdk but it is not going to be installed

2009-12-07 Thread Cyril Brulebois
Package: babel Version: 1.4.0.dfsg-5 Severity: serious Justification: FTBFS Your package FTBFS, slightly differently depending on the arch: | default-jdk-builddep: Depends: default-jdk (= 1.5-33) but it is not going to be installed or: | default-jdk-builddep: Depends: gcj-jdk but it is not

Bug#559989: FTBFS [hppa] - spinning waf process

2009-12-07 Thread dann frazier
Package: midori Version: 0.2.0-1 Severity: serious User: debian-h...@lists.debian.org Usertags: hppa midori reliably fails to build on hppa: https://buildd.debian.org/build.php?pkg=midoriver=0.2.0-1arch=hppafile=log From the most recent build attempt: [...] [ 13/106] cc: katze/katze-utils.c

Bug#559770: RM: libwordpress-xmlrpc-perl/testing -- ROM; Based on recent source changes, we believe the quality of code is poor.

2009-12-07 Thread Jonathan Yu
Here are some reasons why: 1. We discussed this in the ITP for libleocharre-perl [0]; the whole idea of the LEOCHARRE:: modules is flawed in many ways, and also exports random symbols to the 'main' namespace with no way of stopping it from doing so. 2. The overhead involved with patching in the

Bug#559991: FTBFS [hppa] - jni_md.h: No such file or directory

2009-12-07 Thread dann frazier
Package: libreadline-java Version: 0.8.0.1-8.1 Severity: serious User: debian-h...@lists.debian.org Usertags: hppa libreadline-java reliably fails to build on hppa: https://buildd.debian.org/build.php?pkg=libreadline-javaver=0.8.0.1-8.1arch=hppafile=log Possibly related to this discussion:

Bug#559993: FTBFS [hppa] - jni_md.h: No such file or directory

2009-12-07 Thread dann frazier
Package: postgresql-pljava Version: 1.4.0-1.1 Severity: serious User: debian-h...@lists.debian.org Usertags: hppa postgresql-pljava relabily fails to build on hppa: https://buildd.debian.org/build.php?pkg=postgresql-pljavaver=1.4.0-1.1arch=hppafile=log From a recent build attempt: [...]

Bug#559992: FTBFS [hppa] - ruby1.9: command not found

2009-12-07 Thread dann frazier
Package: stfl Version: 0.21-1 Severity: serious User: debian-h...@lists.debian.org Usertags: hppa stfl reliably fails to build on hppa: https://buildd.debian.org/build.php?pkg=stflver=0.21-1arch=hppafile=log From the most recent build attempt: [...] mv -f Makefile.deps_new Makefile.deps

Processed: your mail

2009-12-07 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: block 559524 by 559995 Bug #559524 [wnpp] ITP: libleocharre-perl -- Bundle of several modules in the LEOCHARRE:: namespace Was not blocked by any bugs. Added blocking bug(s) of 559524: 559995 block 559770 by 559995 Bug #559770

Bug#559346: marked as done (Most packages based on source package mysql-dfsg-5.1 are missing from squeeze)

2009-12-07 Thread Debian Bug Tracking System
Your message dated Tue, 8 Dec 2009 07:29:09 +0100 with message-id 20091208062909.ga32...@station.luk.local and subject line Re: Bug#559346: Most packages based on source package mysql-dfsg-5.1 has caused the Debian Bug report #559346, regarding Most packages based on source package mysql-dfsg-5.1

Bug#559836: [Pkg-openmpi-maintainers] Bug#559836: CVE-2009-3736 local privilege escalation

2009-12-07 Thread Luk Claes
Manuel Prinz wrote: Hi Michael! Am Montag, den 07.12.2009, 00:06 -0500 schrieb Michael Gilbert: The following CVE (Common Vulnerabilities Exposures) id was published for libtool. I have determined that this package embeds a vulnerable copy of the libtool source code. However, since this

Bug#559980: aptitude: Totally broken on GNU/kFreeBSD

2009-12-07 Thread Christian Perrier
Quoting Cyril Brulebois (k...@debian.org): Package: aptitude Version: 0.6.1.3-3 Severity: serious Tags: patch Justification: Broken package manager, broken d-i, etc. User: debian-...@lists.debian.org Usertags: kfreebsd Gee, what a great bug report, Kibi...:-) Great analysis, huge work

Processed: severity of 434926 is serious

2009-12-07 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: severity 434926 serious Bug #434926 [prime-el] prime-el: please prefer emacs22 Severity set to 'serious' from 'important' End of message, stopping processing here. Please contact me if you need assistance. Debian bug tracking system

Bug#559857: marked as done (libcv-dev: cv.h does not compile with -DHAVE_CONFIG_H from autotools/autoheader)

2009-12-07 Thread Debian Bug Tracking System
Your message dated Tue, 08 Dec 2009 07:35:19 + with message-id e1nhubp-0001zr...@ries.debian.org and subject line Bug#559857: fixed in opencv 2.0.0-2 has caused the Debian Bug report #559857, regarding libcv-dev: cv.h does not compile with -DHAVE_CONFIG_H from autotools/autoheader to be

Bug#559855: marked as done (libcv-dev: cv.h does not compile with -DHAVE_CONFIG_H from autotools/autoheader)

2009-12-07 Thread Debian Bug Tracking System
Your message dated Tue, 08 Dec 2009 07:35:19 + with message-id e1nhubp-0001zr...@ries.debian.org and subject line Bug#559857: fixed in opencv 2.0.0-2 has caused the Debian Bug report #559857, regarding libcv-dev: cv.h does not compile with -DHAVE_CONFIG_H from autotools/autoheader to be

<    1   2