Bug#616673: rhythmbox-plugins: CVE-2012-3355 Plugin context contains hardcoded path to /tmp/context/

2013-01-18 Thread Jonathan Wiltshire
Package: rhythmbox-plugins Dear maintainer, Recently you fixed one or more security problems and as a result you closed this bug. These problems were not serious enough for a Debian Security Advisory, so they are now on my radar for fixing in the following suites through point releases: squeeze

Bug#679283: CVE-2012-2825

2013-01-18 Thread Jonathan Wiltshire
Package: libxslt Dear maintainer, Recently you fixed one or more security problems and as a result you closed this bug. These problems were not serious enough for a Debian Security Advisory, so they are now on my radar for fixing in the following suites through point releases: squeeze (6.0.7) -

Bug#694810: plib: CVE-2012-4552

2013-01-18 Thread Jonathan Wiltshire
Package: plib Dear maintainer, Recently you fixed one or more security problems and as a result you closed this bug. These problems were not serious enough for a Debian Security Advisory, so they are now on my radar for fixing in the following suites through point releases: squeeze (6.0.7) -

Bug#694407: freeradius: CVE-2011-4966

2013-01-18 Thread Jonathan Wiltshire
Package: freeradius Dear maintainer, Recently you fixed one or more security problems and as a result you closed this bug. These problems were not serious enough for a Debian Security Advisory, so they are now on my radar for fixing in the following suites through point releases: squeeze

Bug#680059: revelation: FPM exporter doesn't encrypt password files [CVE-2012-3818]

2013-01-18 Thread Jonathan Wiltshire
Package: revelation Dear maintainer, Recently you fixed one or more security problems and as a result you closed this bug. These problems were not serious enough for a Debian Security Advisory, so they are now on my radar for fixing in the following suites through point releases: squeeze

Bug#686764: xen: Multiple security issues

2013-01-18 Thread Jonathan Wiltshire
Package: xen Dear maintainer, Recently you fixed one or more security problems and as a result you closed this bug. These problems were not serious enough for a Debian Security Advisory, so they are now on my radar for fixing in the following suites through point releases: squeeze (6.0.7) - use

Bug#698402: marked as done (wicd-curses: crashes on start)

2013-01-18 Thread Debian Bug Tracking System
Your message dated Fri, 18 Jan 2013 14:33:48 +0100 with message-id CAJN4MBPa6xqYE+Ke48RY9JsPWpxBxrhX0d1wB7kMv-wf=zx...@mail.gmail.com and subject line Re: Bug#698402: please close, solved has caused the Debian Bug report #698402, regarding wicd-curses: crashes on start to be marked as done. This

Bug#697197: marked as done (mha4mysql-manager: masterha_master_switch aborts during failover with 'Use of uninitialized value')

2013-01-18 Thread Debian Bug Tracking System
Your message dated Fri, 18 Jan 2013 13:47:59 + with message-id e1twciz-0003ua...@franck.debian.org and subject line Bug#697197: fixed in mha4mysql-manager 0.53-2 has caused the Debian Bug report #697197, regarding mha4mysql-manager: masterha_master_switch aborts during failover with 'Use of

Bug#698439: couchdb: CVE-2012-5650 CVE-2012-5649

2013-01-18 Thread Moritz Muehlenhoff
Package: couchdb Severity: grave Tags: security Justification: user security hole Please see http://seclists.org/fulldisclosure/2013/Jan/82 http://seclists.org/fulldisclosure/2013/Jan/80 Please apply isolated fixes instead of updating to a full new release. Cheers, Moritz -- To

Bug#698440: ruby-rack: CVE-2012-6109 CVE-2013-0184 CVE-2013-0183

2013-01-18 Thread Moritz Muehlenhoff
Package: ruby-rack Severity: grave Tags: security Justification: user security hole Please see these links for details: http://seclists.org/oss-sec/2013/q1/80 http://seclists.org/oss-sec/2013/q1/83 Cheers, Moritz -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with

Bug#686650: bcron update for stable

2013-01-18 Thread Gerrit Pape
Hi, as suggested by Jonathan below, I prepared a bcron package fixing #686650 as candidate for the next squeeze point release. A debdiff is attached, the package ready for upload. Regards, Gerrit. On Thu, Jan 17, 2013 at 11:42:08AM -, Jonathan Wiltshire wrote: Package: bcron Dear

Bug#695224: Locale::Maketext security fix: real world breakage?

2013-01-18 Thread Dominic Hargreaves
On Wed, Dec 05, 2012 at 04:05:01PM -0500, Ricardo Signes wrote: * Dominic Hargreaves d...@earth.li [2012-12-05T13:51:19] I wondered (and the question has arised within the Debian project) whether anyone might be relying on the previous behaviour? Have you been able to do any assessment of

Bug#697617: jenkins: remote code execution vulnerability

2013-01-18 Thread Miguel Landaeta
On Thu, Jan 10, 2013 at 2:29 PM, Miguel Landaeta mig...@miguel.cc wrote: On Thu, Jan 10, 2013 at 2:03 PM, James Page james.p...@ubuntu.com wrote: I'm trying to get some advice from upstream on this - hopefully I'll hear back in the next ~24hrs Good to know, I'll stay tuned. Hi James, is

Bug#697892: marked as done (kmk_sed fails to parse character classes)

2013-01-18 Thread Debian Bug Tracking System
Your message dated Fri, 18 Jan 2013 18:32:47 + with message-id e1twgkb-0004gt...@franck.debian.org and subject line Bug#697892: fixed in kbuild 1:0.1.9998svn2543+dfsg-1 has caused the Debian Bug report #697892, regarding kmk_sed fails to parse character classes to be marked as done. This

Bug#690151: Stable upload request - Fw: Bug#690151: claws-mail: CVE-2012-4507

2013-01-18 Thread Ricardo Mones
Hi release team, As requested by Jonathan, I've prepared an upload with the minimal changes required for fixing this, debdiff attached. IIRC this is the first time I'm going to upload something to stable, so, before uploading, any hints on missing bits or common pitfalls awaiting would be

Bug#665012: CVE-2012-1570: maradns deleted domain record cache persistance flaw

2013-01-18 Thread Sam Trenholme
Upstream here. It's a six-line patch: http://maradns.org/download/patches/security/maradns-1.4.11-ghostdomain.patch This should not be too difficult to apply. Also, the security report is somewhat inaccurate. Both MaraDNS and Deadwood were never vulnerable to the Ghost Domain bug as described

Bug#690151: Stable upload request - Fw: Bug#690151: claws-mail: CVE-2012-4507

2013-01-18 Thread Adam D. Barratt
Control: found -1 3.7.6-4 On Fri, 2013-01-18 at 20:08 +0100, Ricardo Mones wrote: As requested by Jonathan, I've prepared an upload with the minimal changes required for fixing this, debdiff attached. IIRC this is the first time I'm going to upload something to stable, so, before

Processed: Re: Stable upload request - Fw: Bug#690151: claws-mail: CVE-2012-4507

2013-01-18 Thread Debian Bug Tracking System
Processing control commands: found -1 3.7.6-4 Bug #690151 {Done: Ricardo Mones mo...@debian.org} [claws-mail] claws-mail: CVE-2012-4507 Marked as found in versions claws-mail/3.7.6-4. -- 690151: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=690151 Debian Bug Tracking System Contact

Bug#686650: bcron update for stable

2013-01-18 Thread Adam D. Barratt
Control: found -1 0.09-11 On Fri, 2013-01-18 at 14:57 +, Gerrit Pape wrote: as suggested by Jonathan below, I prepared a bcron package fixing #686650 as candidate for the next squeeze point release. A debdiff is attached, the package ready for upload. Please go ahead; thanks. Regards,

Processed: Re: bcron update for stable

2013-01-18 Thread Debian Bug Tracking System
Processing control commands: found -1 0.09-11 Bug #686650 {Done: Gerrit Pape p...@smarden.org} [bcron] bcron: CVE-2012-6110: bcron file descriptors not closed Marked as found in versions bcron/0.09-11. -- 686650: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=686650 Debian Bug Tracking

Bug#698439: marked as done (couchdb: CVE-2012-5650 CVE-2012-5649)

2013-01-18 Thread Debian Bug Tracking System
Your message dated Fri, 18 Jan 2013 20:47:33 + with message-id e1twiqb-0004yi...@franck.debian.org and subject line Bug#698439: fixed in couchdb 1.2.0-4 has caused the Debian Bug report #698439, regarding couchdb: CVE-2012-5650 CVE-2012-5649 to be marked as done. This means that you claim

Processed: Re: wims: still modifies shipped files: /var/lib/wims/public_html/gifs/*

2013-01-18 Thread Debian Bug Tracking System
Processing control commands: found -1 1:4.04~dfsg-2 Bug #687947 {Done: Georges Khaznadar georg...@debian.org} [wims] wims: modifies shipped files: /var/lib/wims/public_html/gifs/*, /var/lib/wims/public_html/themes/* Marked as found in versions wims/1:4.04~dfsg-2; no longer marked as fixed in

Bug#687947: wims: still modifies shipped files: /var/lib/wims/public_html/gifs/*

2013-01-18 Thread Andreas Beckmann
Followup-For: Bug #687947 Control: found -1 1:4.04~dfsg-2 Hi, not much has changed in the last release ... therefore reopening. 1m19.5s ERROR: FAIL: debsums reports modifications inside the chroot: /var/lib/wims/public_html/gifs/symbols/20/_Arrow-h.gif

Bug#688738: marked as done (docbookwiki: ships a SVN repository in /usr, modified by postinst, overwritten during upgrade)

2013-01-18 Thread Debian Bug Tracking System
Your message dated Fri, 18 Jan 2013 21:19:42 + with message-id e1twjli-0003sr...@franck.debian.org and subject line Bug#696930: Removed package(s) from unstable has caused the Debian Bug report #688738, regarding docbookwiki: ships a SVN repository in /usr, modified by postinst, overwritten

Bug#694138: marked as done (docbookwiki: fails to install: svn: E180001: Unable to connect to a repository at URL 'file:///usr/share/docbookwiki/content/SVN/repository')

2013-01-18 Thread Debian Bug Tracking System
Your message dated Fri, 18 Jan 2013 21:19:42 + with message-id e1twjli-0003sr...@franck.debian.org and subject line Bug#696930: Removed package(s) from unstable has caused the Debian Bug report #694138, regarding docbookwiki: fails to install: svn: E180001: Unable to connect to a repository

Bug#698462: FTBFS due to inkscape

2013-01-18 Thread Picca Frédéric-Emmanuel
Package: taurus Version: 3.0.0-1 Severity: serious inkscape ask a few question during the build. It means that it stop the build - FTBFS now we use imagemagick as fallback -- System Information: Debian Release: 7.0 APT prefers unstable APT policy: (500, 'unstable'), (500, 'testing'),

Bug#698463: openarena-dbg: copyright file missing after upgrade (policy 12.5)

2013-01-18 Thread Andreas Beckmann
Package: openarena-dbg Version: 0.8.8-7 Severity: serious User: debian...@lists.debian.org Usertags: piuparts Hi, a test with piuparts revealed that your package misses the copyright file after an upgrade from squeeze to wheezy, which is a violation of Policy 12.5:

Bug#698466: apt-cacher-ng: fails to install: apt-cacher-ng.postinst: curl: not found

2013-01-18 Thread Andreas Beckmann
Package: apt-cacher-ng Version: 0.7.12-1 Severity: serious User: debian...@lists.debian.org Usertags: piuparts Hi, during a test with piuparts I noticed your package failed to install. As per definition of the release team this makes the package too buggy for a release, thus the severity. From

Processed: found 694889 in openjdk-7-source/7u3-2.1.4-1, found 669278 in kraft/0.45-2 ..., affects 698375

2013-01-18 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: found 694889 openjdk-7-source/7u3-2.1.4-1 Bug #694889 [ca-certificates-java] ca-certificates-java: early triggered jks-keystore may fail and leave the temporary /etc/java-7-openjdk/jvm-$arch.cfg Bug #694888 [ca-certificates-java]

Bug#698481: mantis: multiple XSS vulnerabilities

2013-01-18 Thread Salvatore Bonaccorso
Package: mantis Severity: grave Tags: security Justification: user security hole -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Hi Some vulnerabilities in mantis where reported: [1]: http://www.mantisbt.org/bugs/view.php?id=15373 (CVE-2013-0197)