Bug#845385: Privilege escalation via removal

2016-11-30 Thread Emmanuel Bourg
Le 30/11/2016 à 00:20, Markus Koschany a écrit : > rm -rf /etc/tomcat8 > > I mean purge means purge. Remove all files, don't leave anything behind. That's tempting but I wonder if we aren't missing something. Other packages are installing things under /etc/tomcat8, for example solr-tomcat and j

Bug#846333: nvidia-graphics-drivers: CVE-2016-7382, CVE-2016-7389: missing permissions check and improper validation vulnerability

2016-11-30 Thread Luca Boccassi
On Wed, 30 Nov 2016 12:12:23 +0100 Andreas Beckmann wrote: > Source: nvidia-graphics-drivers > Severity: serious > Tags: security upstream > Control: clone -1 -2 -3 > Control: reassign -2 nvidia-graphics-drivers-legacy-340xx > Control: reassign -3 nvidia-graphics-drivers-legacy-304xx > Control: re

Bug#846332: nvidia-graphics-drivers: CVE-2016-7382, CVE-2016-7389: missing permissions check and improper validation vulnerability

2016-11-30 Thread Luca Boccassi
On Wed, 30 Nov 2016 12:12:23 +0100 Andreas Beckmann wrote: > Source: nvidia-graphics-drivers > Severity: serious > Tags: security upstream > Control: clone -1 -2 -3 > Control: reassign -2 nvidia-graphics-drivers-legacy-340xx > Control: reassign -3 nvidia-graphics-drivers-legacy-304xx > Control: re

Bug#846335: cross-toolchain-base: FTBFS in testing (2 out of 2 hunks FAILED)

2016-11-30 Thread Santiago Vila
Package: src:cross-toolchain-base Version: 14 Severity: serious Dear maintainer: I tried to build this package in stretch with "dpkg-buildpackage -A" (which is what the "Arch: all" autobuilder would do to build it) but it failed: --

Bug#846334: cross-toolchain-base-ports: FTBFS in testing (2 out of 2 hunks FAILED)

2016-11-30 Thread Santiago Vila
Package: src:cross-toolchain-base-ports Version: 7 Severity: serious Dear maintainer: I tried to build this package in stretch with "dpkg-buildpackage -A" (which is what the "Arch: all" autobuilder would do to build it) but it failed: -

Bug#846331: nvidia-graphics-drivers: CVE-2016-7382, CVE-2016-7389: missing permissions check and improper validation vulnerability

2016-11-30 Thread Andreas Beckmann
Source: nvidia-graphics-drivers Severity: serious Tags: security upstream Control: clone -1 -2 -3 Control: reassign -2 nvidia-graphics-drivers-legacy-340xx Control: reassign -3 nvidia-graphics-drivers-legacy-304xx Control: retitle -2 nvidia-graphics-drivers-legacy-340xx: CVE-2016-7382, CVE-2016-73

Processed: nvidia-graphics-drivers: CVE-2016-7382, CVE-2016-7389: missing permissions check and improper validation vulnerability

2016-11-30 Thread Debian Bug Tracking System
Processing control commands: > clone -1 -2 -3 Bug #846331 [src:nvidia-graphics-drivers] nvidia-graphics-drivers: CVE-2016-7382, CVE-2016-7389: missing permissions check and improper validation vulnerability Bug 846331 cloned as bugs 846332-846333 > reassign -2 nvidia-graphics-drivers-legacy-340x

Bug#846330: pirs: FTBFS on non-x86 architectures because it hard-wires CFLAGS

2016-11-30 Thread John Paul Adrian Glaubitz
Source: pirs Version: 2.0.2+dfsg-1 Severity: serious Justification: fails to build from source User: debian-sp...@lists.debian.org Usertags: sparc64 Hello! pirs fails to build from source on all non-x86 architectures because it hard-wires compiler flags and tries to build with -msse2 despite the

Bug#845388: marked as pending

2016-11-30 Thread Craig Small
tag 845388 pending thanks Hello, Bug #845388 reported by you has been fixed in the Git repository. You can see the changelog below, and you can check the diff of the fix at: http://git.debian.org/?p=collab-maint/wordpress.git;a=commitdiff;h=36f1043 --- commit 36f1043c67e1b1a9ccaf94f47aa9ed5

Processed: Bug#845388 marked as pending

2016-11-30 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tag 845388 pending Bug #845388 [src:wordpress] wordpress: FTBFS randomly (does not follow Policy 4.6) Added tag(s) pending. > thanks Stopping processing here. Please contact me if you need assistance. -- 845388: http://bugs.debian.org/cgi-bin/b

Processed: your mail

2016-11-30 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tags 844813 + pending Bug #844813 [src:freedict] freedict: FTBFS: E: Build killed with signal TERM after 150 minutes of inactivity Added tag(s) pending. > thanks Stopping processing here. Please contact me if you need assistance. -- 844813: htt

Bug#846322: golang-google-cloud: FTBFS (undefined: grpc.SupportPackageIsVersion3)

2016-11-30 Thread Santiago Vila
Package: src:golang-google-cloud Version: 0.0~git20160615-6 Severity: serious Dear maintainer: I tried to build this package in stretch with "dpkg-buildpackage -A" (which is what the "Arch: all" autobuilder would do to build it) but it failed:

Processed: Re: plastimatch: FTBFS: Tests failures

2016-11-30 Thread Debian Bug Tracking System
Processing control commands: > tags -1 pending Bug #844942 [src:plastimatch] plastimatch: FTBFS: Tests failures Added tag(s) pending. -- 844942: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=844942 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems

Bug#844942: plastimatch: FTBFS: Tests failures

2016-11-30 Thread Ghislain Vaillant
control: tags -1 pending On Sat, 19 Nov 2016 08:03:46 +0100 Lucas Nussbaum wrote: > The following tests FAILED: >421 - vf-invert-trans-1 (Failed) >422 - vf-invert-trans-1-stats (Failed) >423 - vf-invert-trans-1-check (Failed) >426 - wed-c (Failed) > Errors while running CTest >

Bug#846319: letsencrypt.sh: Fails to create fullchain.pem

2016-11-30 Thread Chris Boot
Package: letsencrypt.sh Version: 0.2.0-4 Severity: grave Tags: upstream patch Justification: renders package unusable Dear maintainer, Since openssl 1.1 has migrated to stretch I am unable to renew my Let's Encrypt certificates using letsencrypt.sh. The symptoms are: + Challenge is valid! + Re

Processed (with 1 error): Duplicate

2016-11-30 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > unarchive 768134 Bug #768134 {Done: Pietro Battiston } [gedit-latex-plugin] Plugin does not work with gedit > 3.8 Unarchived Bug 768134 > unarchive 770153 > unblock 768134 by 770153 Bug #768134 {Done: Pietro Battiston } [gedit-latex-plugin] Plug

Processed: tagging 828414

2016-11-30 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tags 828414 + patch Bug #828414 [src:libtorrent] libtorrent: FTBFS with openssl 1.1.0 Added tag(s) patch. > thanks Stopping processing here. Please contact me if you need assistance. -- 828414: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=82

Bug#846272: [Debichem-devel] Bug#846272: ga FTBFS on !x86 !ppc: error: unknown type name 'PAD_LOCK_T'

2016-11-30 Thread Michael Banck
severity 846272 important severity 846273 important thanks Hi, On Tue, Nov 29, 2016 at 08:56:55PM +0200, Adrian Bunk wrote: > Severity: serious It is my understanding that non-regression FTBFS errors are not RC, hence important. Thanks, Michael

Processed: Re: [Debichem-devel] Bug#846272: ga FTBFS on !x86 !ppc: error: unknown type name 'PAD_LOCK_T'

2016-11-30 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > severity 846272 important Bug #846272 [src:ga] ga FTBFS on !x86 !ppc: error: unknown type name 'PAD_LOCK_T' Severity set to 'important' from 'serious' > severity 846273 important Bug #846273 [src:ga] ga FTBFS on ppc64el: test failures Severity se

Bug#828351: inn2: FTBFS with openssl 1.1.0

2016-11-30 Thread Marco d'Itri
On Nov 29, Sebastian Andrzej Siewior wrote: > Please find attached a patch against the package which includes the > three three patches mentioned here and was sbuild tested. > Should I NMU it? NO! I have a new package ready, but it needs some mild testing. -- ciao, Marco signature.asc Descrip

<    1   2