Bug#649336: libglib2.0-0: severe memory problems

2011-11-19 Thread Christoph Anton Mitterer
Package: libglib2.0-0 Version: 2.30.2-4 Severity: critical Justification: breaks unrelated software Hi. Since the most recent uploads to unstalbe I see problems like the following: $ eog Untitled\ 1.png GLib-ERROR **: /tmp/buildd/glib2.0-2.30.2/./glib/gmem.c:170: failed to allocate 546343776 b

Bug#631950: remmina-plugin-nx unable to connect with libssh-4_0.5.0-2

2011-09-09 Thread Christoph Anton Mitterer
Hi Laurent. It seems this has been fixed in their repo,... can you cherry pick that patch? https://red.libssh.org/issues/60 Chris. -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#631950: remmina-plugin-nx unable to connect with libssh-4_0.5.0-2

2011-09-01 Thread Christoph Anton Mitterer
reassign 631950 libssh-4 forwarded 631950 https://red.libssh.org/issues/60 stop Ok, reassigning this back then to libssh-4 for now, and marking it as forwarded. Chris. smime.p7s Description: S/MIME cryptographic signature

Bug#631950: issues with NX plugin and current libssh

2011-09-01 Thread Christoph Anton Mitterer
On Thu, 2011-09-01 at 10:18 +0200, Laurent Bigonville wrote: > But I've the feeling that libssh shouldn't change his behavior like > that. Guess you're not alone with your feeling ;) Chris. smime.p7s Description: S/MIME cryptographic signature

Bug#631950: issues with NX plugin and current libssh

2011-09-01 Thread Christoph Anton Mitterer
reassign 631950 remmina-plugin-nx stop Hi Vic. Thanks for tracing this up :) Laurent, thanks for you help, too. I'm reassign this now to remmina-plugin-nx. Luca, could you please apply the patches from Vic (or take a new upstream version, if there's already one)?, Thanks all, Chris. smime.p

Bug#631950: issues with NX plugin and current libssh

2011-08-31 Thread Christoph Anton Mitterer
On Wed, 31 Aug 2011 22:39:48 +0800, Vic Lee wrote: > In main window, please open Help->Debug Window menu, then connecting to > the server. You should be able to see many NX related output. With 0.5.1: [NX] HELLO NXSERVER - Version 3.2.0-74-SVN OS (GPL, using backend: 3.5.0) [NX] NX> 105 (after

Bug#631950: issues with NX plugin and current libssh

2011-08-31 Thread Christoph Anton Mitterer
Hi Vic. We have some problems with the NX plugin and current versions of libssh (0.5.1) as you can read in this bug report: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=631950 Can you help or have you got any idea what could cause the troubles? Cheers, Chris. btw: It seems that the NX plu

Bug#631950: remmina-plugin-nx unable to connect with libssh-4_0.5.0-2

2011-08-29 Thread Christoph Anton Mitterer
On Mon, 29 Aug 2011 09:41:39 +0200, Laurent Bigonville wrote: > Could you try to rebuild remmina-plugin-nx package and see if it fix > the issue? Rebuilt both, remmina itself (which also has a dep on libssh-4) and -plugin-nx,... doesn't seem to help though :-( Cheers, Chris. -- To UNSUBSCRIBE

Bug#638449: iptables-persistent: rules aren't loaded at all

2011-08-19 Thread Christoph Anton Mitterer
forcemerge 637796 638449 stop (My original report made it through now ^^... therefore merging) Nico, iptables-persistent loads the iptables rules at boot, and thus it should be quite clear, why this can be security critical. Just imagine that for some reasons you have rsh, or telnet or something

Bug#638449: iptables-persistent: rules aren't loaded at all

2011-08-19 Thread Christoph Anton Mitterer
Package: iptables-persistent Version: 0.5.2 Severity: critical Tags: security Justification: root security hole Hi. Since the most recent upload, rules aren't loaded any more at all: Wed Aug 17 13:17:07 2011: Mounting local filesystems...done. Wed Aug 17 13:17:07 2011: Activating swapfile swap..

Bug#631950: remmina-plugin-nx unable to connect with libssh-4_0.5.0-2

2011-08-19 Thread Christoph Anton Mitterer
Hi. Yeah I've seen it... Still doesn't work however :( Chris. -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#637435: ifupdown: interfaces are not brought up anymore

2011-08-12 Thread Christoph Anton Mitterer
On Fri, 2011-08-12 at 16:42 +0300, O. Andrew wrote: > Well, that's exactly what I suspected to happen. Tomorrow I will > prepare a new release which should fix this issue. Thx in advance, Cheers, Chris. smime.p7s Description: S/MIME cryptographic signature

Bug#637435: ifupdown: interfaces are not brought up anymore

2011-08-12 Thread Christoph Anton Mitterer
On Thu, 2011-08-11 at 20:41 +0300, Andrew O. Shadoura wrote: > Sorry, can't reproduce. I've just installed a clean unstable system, > and it just doesn't happen. > > Please provide more details. Well during ifupdown-clean on boot i get a cannot remove /etc/network/run/ifstate ... ro filesystem (sh

Bug#631950: remmina-plugin-nx unable to connect with libssh-4_0.5.0-2

2011-08-11 Thread Christoph Anton Mitterer
On Thu, 11 Aug 2011 16:12:04 +0200, Laurent Bigonville wrote: >> Not sure why it doesn't show the names,... do you drop the debug info? > Be sure you have libc6-dbg and libssh-dbg installed I had... -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of "unsubscri

Bug#631950: remmina-plugin-nx unable to connect with libssh-4_0.5.0-2

2011-08-11 Thread Christoph Anton Mitterer
On Thu, 11 Aug 2011 15:54:26 +0200, Laurent Bigonville wrote: > Is anybody still able to reproduce this? Yes. > If so could you please provide me a backtrace? NX: detected keyboard type pc105/de Remmina plugin NX (type=Protocol) registered. Remmina plugin SFTP (type=Protocol) registered. Remmina

Bug#617763: please rebuild

2011-08-11 Thread Christoph Anton Mitterer
Hi. Well could someone then please rebuild this? Cheers, Chris. -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#631950: remmina-plugin-nx unable to connect with libssh-4_0.5.0-2

2011-08-11 Thread Christoph Anton Mitterer
Hi. Any news with respect to this? Cheers, Chris. -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#637439: qtnx: stores keys world readable

2011-08-11 Thread Christoph Anton Mitterer
Package: qtnx Version: 0.9-3 Severity: grave Tags: security Justification: user security hole Hi. It seems that qtnx stores any non-custom ssh keys world-readable: $ ls -al ~/.qtnx/ total 12 drwxr-xr-x 2 user user 4096 Aug 11 15:01 . drwx-- 51 user user 4096 Aug 11 15:01 .. -rw-r--r-- 1 us

Bug#637435: ifupdown: interfaces are not brought up anymore

2011-08-11 Thread Christoph Anton Mitterer
Package: ifupdown Version: 0.7~alpha5+really0.6.11 Severity: critical Justification: breaks the whole system Hi. Since the recent upload to unstable, ifupdown seems to no longer bring up any interfaces, not even lo. $ ifconfig shows nothing,... after bringing down and then up lo,... it appears

Bug#626112: openssh-server: ssh doesn't log some failed authentications to auth.log anymore

2011-07-27 Thread Christoph Anton Mitterer
Hi Colin. On Sun, 2011-07-24 at 11:02 +0100, Colin Watson wrote: > Did this work as you expect in some previous version? Which one? Yes definitely,.. but unfortunately,.. I don not remember which one.. > If you use 'LogLevel VERBOSE', does that help? > > Can you provide some examples of log me

Bug#626112: openssh-server: ssh doesn't log some failed authentications to auth.log anymore

2011-05-08 Thread Christoph Anton Mitterer
Package: openssh-server Version: 1:5.8p1-4 Severity: grave Tags: security Justification: user security hole Hi. For *some* failed connections ssh seems to put no logging into auth.log anymore. This can be quite security relevant when using e.g. fail2ban which relies on this. Only some (types?)

Bug#621099: isc-dhcp-client: CVE-2011-0997

2011-04-06 Thread Christoph Anton Mitterer
Package: isc-dhcp-client Version: 4.1.1-P1-16 Severity: critical Tags: security Justification: root security hole Hi. CVE-2011-0997 has been found (http://www.isc.org/software/dhcp/advisories/cve-2011-0997), which allows a DHCP server to execute shell commands on the clients. Cheers, Chris.

Bug#611461: iceweasel still does insecure ssl renegotiation?!

2011-01-29 Thread Christoph Anton Mitterer
On Sat, 2011-01-29 at 18:47 +0100, Stefan Fritsch wrote: > This has to be balanced between compatibility and security. Currently > less than 50% of the servers on the internet are patched. So it is > sensible to not deny renegotiation for unpatched servers. > > Patched servers usually won't all

Bug#611461: iceweasel still does insecure ssl renegotiation?!

2011-01-29 Thread Christoph Anton Mitterer
Package: iceweasel Version: 3.5.16-4 Severity: grave Tags: security Justification: user security hole Hi. It seems that iceweasel still is vulnerable to the SSL renegotiation attack, as simply is configured per default to allow the vulnerable renegotiation: security.ssl.require_safe_negotiation;

Bug#608331: pidgin: newer upstream version, fixing security issue

2010-12-29 Thread Christoph Anton Mitterer
Package: pidgin Version: 2.7.7-1 Severity: grave Tags: security Justification: user security hole Hi. A newer upstream version 2.7.9 is available, fixing a security issue. Cheers, Chris. -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of "unsubscribe". Tr

Bug#554506: [pkg-cryptsetup-devel] Bug#554506: (ugly) patch which should fix dm-crypt-on-lvm setups

2010-11-04 Thread Christoph Anton Mitterer
I haven't fully looked at this so perhaps it's unrelated,... But one main problem I see here (that may be related), is that lvm's init-scripts are simply wrong, and abusing some things. I've already told Bastian this and there are even several bugs open. The problem is that lvm's init script simp

Bug#598432: python-apt: upgrade fails

2010-09-28 Thread Christoph Anton Mitterer
Package: python-apt Version: 0.7.98 Severity: grave Justification: renders package unusable Hi. Upgrading to the most recent version fails with: Setting up python-apt (0.7.98) ... Traceback (most recent call last): File "/usr/bin/pycentral", line 2334, in main() File "/usr/bin/pycentral

Bug#595331: new version of crypttab doesn't work without changing config file: it is uncompatible with previous version

2010-09-20 Thread Christoph Anton Mitterer
On Mon, 2010-09-20 at 12:55 +0400, Dmitry E. Oboukhov wrote: > CAM> less /usr/share/doc/cryptsetup/NEWS.Debian.gz > > It is a wrong way. > If a user upgrades his system from lenny to squeeze, he wont be able > to read *all* changed packages' news. > > I think that tests must show warning and then

Bug#595331: [pkg-cryptsetup-devel] Bug#595331: new version of crypttab doesn't work without changing config file: it is uncompatible with previous version

2010-09-15 Thread Christoph Anton Mitterer
Quoting Matthias Kirschner : Just upgraded a friend's machine, and had the same problem. I also had to change "check=ext2" to "check=blkid". (I was lucky as it only affected the home partition, so I did not have to use a live system to make this changes.) less /usr/share/doc/cryptsetup/NEWS.Debi

Bug#595157: udev doesn create dm-crypt and filesystem links (UUID/LABEL)

2010-09-02 Thread Christoph Anton Mitterer
Hi Marco. Sorry for the late reply,... had to prepare a lecture for next week... On Thu, 2 Sep 2010 10:46:51 +0200, m...@linux.it (Marco d'Itri) wrote: > On Sep 01, Marco d'Itri wrote: > >> > Maybe this is the same as #593375. >> You can easily verify this: apply this pseudo-patch to the init s

Bug#595157: udev doesn create dm-crypt and filesystem links (UUID/LABEL)

2010-09-01 Thread Christoph Anton Mitterer
Package: udev Version: 161-1 Severity: critical Justification: breaks unrelated software Hi. Maybe this is the same as #593375. Since some recent version, udev does not longer create the symlinks in /dev/disk/by-label and by-uuid for some cases. E.g. I have non of the by-label/by-uuid links cre

Bug#591607: changing severity

2010-08-11 Thread Christoph Anton Mitterer
severity 591607 critical stop Can confirm this. IMO it deserves a much higher severity, as it enabling _ALL_ CAs might be a security hole for many setups. Downgrading to 20090814 (in testing) and everything seems to be fine. Cheers, Chris. -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@l

Bug#592237: iptables fails to install as it has a file already shipped by xtables-addon-common

2010-08-08 Thread Christoph Anton Mitterer
On Sun, 2010-08-08 at 16:30 -0400, Laurence J. Lane wrote: > Of course, I think /lib/xtables/libxt_TEE.so should be > removed from xtables-addon-common. If that's a bother, > I'll gladly remove from iptables and pretend it does not > exist. Sorry,.. I've missed that this was added in the main iptab

Bug#592115: apt seems to somehow use ~/.gnupg dir when checking package integrity which might be used for security attacks

2010-08-07 Thread Christoph Anton Mitterer
On Sat, 2010-08-07 at 21:27 +0200, Julian Andres Klode wrote: > As everyone should know, dpkg unpacks the source packages and verifies > them using gpg. APT knows that the package is secure, because the source > is secure. Ah I've missed that this is from the debsig, and not from checking the integ

Bug#592115: apt seems to somehow use ~/.gnupg dir when checking package integrity which might be used for security attacks

2010-08-07 Thread Christoph Anton Mitterer
Package: apt Version: 0.7.20.2+lenny2 Severity: grave Tags: security Justification: user security hole Hi. I found out some strange issue, which IMO might be used for security attacks on secure-apt: I've only tested it with "apt-get source", but maybe other actions or aptitude are also affected

Bug#589227: cpmtools: possible FHS violation, as fsck.cpm and mkfs.cpm are not in /sbin

2010-07-19 Thread Christoph Anton Mitterer
Then I guess we can close this or mark it wontfix. Cheers, Chris. smime.p7s Description: S/MIME cryptographic signature

Bug#581182: changing severity

2010-07-17 Thread Christoph Anton Mitterer
+0200, gregor herrmann wrote: > On Fri, 04 Jun 2010 15:30:29 +0200, Christoph Anton Mitterer wrote: > > > Changing severity to grave ("makes the package in question unusable or > > mostly so") as it seems that also 2.6.32 kernels are affected, which are > > now in

Bug#589340: evolution crashes with multiple glibc and similar errors

2010-07-16 Thread Christoph Anton Mitterer
Package: evolution Version: 2.30.2-1 Severity: grave Justification: renders package unusable Hi. Not sure whether this is an upstream issue, as it seems that there are glibc problems? The issue appears (but not always) when opening my folder that holds the debian-devel list archive. Then evolu

Bug#589227: cpmtools: possible FHS violation, as fsck.cpm and mkfs.cpm are not in /sbin

2010-07-16 Thread Christoph Anton Mitterer
On Thu, 2010-07-15 at 17:13 -0600, Bdale Garbee wrote: > I interpret "corresponding subsystem is installed" to mean that the > kernel knows how to mount and use the filesystem type in question. Well I'm not sure whether this is actually meant... but this doesn't mean I think it's wrong ;) > To >

Bug#589229: vmfs-tools: possible FHS violation, as fsck.vmfs is not in /sbin

2010-07-16 Thread Christoph Anton Mitterer
On Fri, 2010-07-16 at 11:18 +0200, Mike Hommey wrote: > So until the program actually does what it is intended to, I'm not > exactly sure it is safe to put it in /sbin. OTOH, I could rename it, but > except for nitpicking, what exactly would be the point? So then let's downgrade the severity and le

Bug#589230: lustre-utils: possible FHS violation, as mkfs.lustre is not in /sbin

2010-07-15 Thread Christoph Anton Mitterer
Package: lustre-utils Severity: serious Justification: Policy 9.1.1 Hi. I might have spotted a policy violation here (therefore the sevirity serious). Policy section 9.1.1. specifies: "The location of all installed files and directories must comply with the Filesystem Hierarchy Standard (FHS),

Bug#589229: vmfs-tools: possible FHS violation, as fsck.vmfs is not in /sbin

2010-07-15 Thread Christoph Anton Mitterer
Package: vmfs-tools Severity: serious Justification: Policy 9.1.1 Hi. I might have spotted a policy violation here (therefore the sevirity serious). Policy section 9.1.1. specifies: "The location of all installed files and directories must comply with the Filesystem Hierarchy Standard (FHS), v

Bug#589228: mtd-utils: possible FHS violation, as mkfs.jffs2 and mkfs.ubifs are not in /sbin

2010-07-15 Thread Christoph Anton Mitterer
Package: mtd-utils Version: 20090606-1 Severity: serious Justification: Policy 9.1.1 Hi. I might have spotted a policy violation here (therefore the sevirity serious). Policy section 9.1.1. specifies: "The location of all installed files and directories must comply with the Filesystem Hierarchy

Bug#589227: cpmtools: possible FHS violation, as fsck.cpm and mkfs.cpm are not in /sbin

2010-07-15 Thread Christoph Anton Mitterer
Package: cpmtools Severity: serious Justification: Policy 9.1.1 Hi. I might have spotted a policy violation here (therefore the sevirity serious). Policy section 9.1.1. specifies: "The location of all installed files and directories must comply with the Filesystem Hierarchy Standard (FHS), ver

Bug#589222: possible FHS violation, as zcat and gunzip are not symbolic or hard links to gzip

2010-07-15 Thread Christoph Anton Mitterer
Package: gzip Version: 1.3.12-9 Severity: serious Justification: Policy 9.1.1 Hi. I might have spotted a policy violation here (therefore the sevirity serious). Policy section 9.1.1. specifies: "The location of all installed files and directories must comply with the Filesystem Hierarchy Stand

Bug#562234: Cache file location in violation of FHS

2010-06-24 Thread Christoph Anton Mitterer
Hi. I'm not sure whether it's a good idea to make such exceptions to FHS. I mean that would dilute it more and more. Alasdair, could you please tell us which concrete problems you've had? btw: /boot is not always on non-LVM or really available. I for example have my /boot on an USB-stick... (

Bug#584595: grub-pc: package upgrade fails with "/usr/sbin/grub-probe: error: no such disk.

2010-06-05 Thread Christoph Anton Mitterer
On Sat, 2010-06-05 at 13:34 +0100, Colin Watson wrote: > > *** BEGIN /boot/grub/device.map > > (hd0) /dev/sda > > (hd1) /dev/sdb > > *** END /boot/grub/device.map > Does this device.map match the devices you actually have? In > particular, check

Bug#584595: grub-pc: package upgrade fails with "/usr/sbin/grub-probe: error: no such disk.

2010-06-04 Thread Christoph Anton Mitterer
Package: grub-pc Version: 1.98+20100602-2 Severity: grave Justification: renders package unusable Hi. When upgrading the package with the current version, I got the following: Installing new version of config file /etc/grub.d/00_header ... Setting up grub-pc (1.98+20100602-2) ... Generating grub.

Bug#571140: [DebianGIS-dev] Bug#571140: drop plugins with problematic license?

2010-05-24 Thread Christoph Anton Mitterer
On Sun, 2010-05-23 at 15:12 +0200, Giovanni Mascellani wrote: > Sorry for the delayed reply. No problem. > The licensing problems were solved, now we're just waiting for a > dependency the pass the NEW queue (libjgrapht0.8-java). Great :) > As soon as that package is accepted, josm-plugns shoul

Bug#582295: [Evolution] Bug#582295: evolution: crashes immediately after starting

2010-05-19 Thread Christoph Anton Mitterer
On Wed, 2010-05-19 at 22:05 +0200, Yves-Alexis Perez wrote: > Could you precise your configuration? What exactly do you want? > Does that happens everytime? Yes,.. a few seconds after the window opens up... > Can > you try in offline mode? No help,... neither when disabling the plugins. I've s

Bug#582295: evolution: crashes immediately after starting

2010-05-19 Thread Christoph Anton Mitterer
Package: evolution Version: 2.30.1.2-2 Severity: grave Justification: renders package unusable Hi. Immediately after starting evolution I get: $ evolution (evolution:9428): evolution-network-manager-WARNING **: The name org.freedesktop.NetworkManager was not provided by any .service files ***

Bug#581967: vegastrike: uninstallable, probably outdated

2010-05-18 Thread Christoph Anton Mitterer
On Tue, 2010-05-18 at 22:23 +0200, Moritz Muehlenhoff wrote: > Upstream is still very actively working towards a release, so we should > leave vegastrike in sid. We should keep it in sid for now. Great :) Wasn't there an email some days ago,... where it was considered to be dropped from Debian? C

Bug#567926: setting up an DSA? Why took fixing so long?

2010-05-18 Thread Christoph Anton Mitterer
Hi. Two questions: 1) Are we sure that this only affected gnupg 2.0.14? Werner does not mention concretely whether versions before are affected or not (http://marc.info/?l=gnupg-users&m=126451730710129&w=2). When entered 2.0.14 testing, and do we need to release a DSA? Has the security tea

Bug#567926: setting up an DSA? Why took fixing so long?

2010-05-18 Thread Christoph Anton Mitterer
Hi again. I might have completely overestimated the criticality of that issue... if so, sorry in advance for making noise. Was it "just" that the number iteration was wrongly written, or was it also, that s2k was _always_ only iterated 65536? The first would mean that the key itself is co

Bug#581967: vegastrike: uninstallable, probably outdated

2010-05-17 Thread Christoph Anton Mitterer
Package: vegastrike Version: 0.5~svn12126-2 Severity: grave Justification: renders package unusable Hi. The package can't be installed due to unsatisfied dependencies. Has this package, and the corresponding -data and -music packages, been orphaned? Cheers, Chris. -- System Information: Debi

Bug#571140: drop plugins with problematic license?

2010-05-09 Thread Christoph Anton Mitterer
Hi In order to make this progress,... wouldn't it be possible to simply drop those plugins whit problematic license? Cheers, Chris. This message was sent using IMP, the Internet Messaging Program. -- To UNSUBSCRIBE, email

Bug#571140: anything new here?

2010-04-20 Thread Christoph Anton Mitterer
Hi. Anything new here in the meantime? Lincense problems still not resolved? Cheers, Chris. This message was sent using IMP, the Internet Messaging Program. -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org

Bug#576604: libao-common... something missing?

2010-04-10 Thread Christoph Anton Mitterer
Hi. I just wondered... isn't something missing here? libao2 still contains the config/docs,... libao4 not at all,... and nobody depends on libao-common?! Best wishes, Chris. -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact

Bug#576687: explanation?

2010-04-09 Thread Christoph Anton Mitterer
Hi. What did this exactly mean? Than any normal user on the system was able to read the cleartext dmcrypt keys? How can udisk know of them? Shouldn't they be just in kernel memory? What's if I use LUKS? Thanks, Chris. -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a s

Bug#576665: openoffice.org: crashes when loading a presenter document

2010-04-06 Thread Christoph Anton Mitterer
Package: openoffice.org Version: 1:3.2.0-5 Severity: grave Justification: renders package unusable Hi. Since 1:3.2.0-5 OOo crashes when opening a presentation document. I tried several of my documents but it happens with all of them, nevertheless I don't know whether it's something specific, so

Bug#561918: client certificate authentication broken

2010-02-27 Thread Christoph Anton Mitterer
FYI: RFC 5746 provides the solution to the renegotiation security attack. Cheers, Chris. This message was sent using IMP, the Internet Messaging Program. -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with

Bug#568383: more information

2010-02-15 Thread Christoph Anton Mitterer
Hi. I think it would be a good idea if you give more information on this hole. What it is about (break in or "just" DoS),... and perhaps some reasonable defaults for that config option. btw: In the news file you talk about "outgoing connections" IIRC, but I think it's about incomming connec

Bug#568304: breaks touchpad

2010-02-06 Thread Christoph Anton Mitterer
Sorry for the late reply. The uploaded fix solves the problem :) Cheers, Chris. smime.p7s Description: S/MIME cryptographic signature

Bug#568304: breaks touchpad

2010-02-03 Thread Christoph Anton Mitterer
Package: gpointing-device-settings Version: 1.5.0-1 Justification: breaks unrelated software Severity: critical Hi. Upgrading to the 1.5.0-1 breaks the touchpad. On the login-screen (gdm) the touchpad still works. As soon as logon happened the touchpad stops working. Downgrading to 1.3 from t

Bug#564601: possible problems when switching UID/GIDs in delivery mode when run as root

2010-01-11 Thread Christoph Anton Mitterer
On Sun, 2010-01-10 at 12:29 -0500, Sam Varshavchik wrote: > This depends on the maildrop configuration, but generally setgroupid won't > have any effect if maildrop is invoked as root, since maildrop will use the > userid specified by the -d option to set its running group and userid > anyway. U

Bug#564601: possible problems when switching UID/GIDs in delivery mode when run as root

2010-01-10 Thread Christoph Anton Mitterer
Package: maildrop Justification: user security hole Severity: grave Tags: security Hi. Not sure if this actually a hole or if I just misunderstand something,... but: In debian /usr/bin/maildrop ist installed: -rwxr-sr-x 1 root mail 163k Nov 9 01:11 /usr/bin/maildrop So I'd expect that the foll

Bug#561918: client certificate authentication broken

2009-12-22 Thread Christoph Anton Mitterer
On Tue, 2009-12-22 at 23:59 +0100, Mike Hommey wrote: > This just confirms the diagnostic, which is that nss 3.12.5 disabled > renegotiation because of CVE-2009-3555. Now, we need to decide how to > allow client authentication without putting users too much at risk. ok,.. I've already suspected thi

Bug#561918: client certificate authentication broken

2009-12-22 Thread Christoph Anton Mitterer
Hi Mike. On Tue, 2009-12-22 at 19:37 +0100, Mike Hommey wrote: > Can you try after setting the NSS_SSL_ENABLE_RENEGOTIATION environment > variable to 1 ? (with nss 3.12.5-1, obviously). Yes this "fixes" the problem. Cheers, Chris. smime.p7s Description: S/MIME cryptographic signature

Bug#561918: client certificate authentication broken

2009-12-21 Thread Christoph Anton Mitterer
Package: libnss3-1d Version: 3.12.5-1 Justification: renders package unusable Severity: grave Hi. With the most recent version, client certificate authentication is broken. An error occurs even before iceweasel, epiphany, etc. ask for the certificate to select. downgrading to 3.12.4-1 fixes t

Bug#554703: bind accepts any incomming zone transfers if the tsig key is not found

2009-11-05 Thread Christoph Anton Mitterer
Package: bind9 Version: 1:9.6.1.dfsg.P1-3 Severity: critical Tags: security Hi. I think this is quite security critical,... if my observations should prove wrong, decrease than please priority ;) When bind is configured to us TSIGs between master and slave when tranferring a zone, via a m

Bug#546834: debootstrap because of conflicting package and init.d script dependencies

2009-09-18 Thread Christoph Anton Mitterer
Hi. Anything that prevents this from being uploaded? This breaks so many things... Cheers, Chris. smime.p7s Description: S/MIME cryptographic signature

Bug#546508: txt uninstallable due to dependency on timout

2009-09-13 Thread Christoph Anton Mitterer
Package: tct Justification: renders package unusable Severity: grave Hi. tct depends on timeout,.. but coreutils (essential) conflicts with this. Thus one cannot install tct. Regards, Chris. -- System Information: Debian Release: squeeze/sid APT prefers unstable APT policy: (500, 'unstab

Bug#546500: postrm does not remove dpkg-statoverride entry which makes dpkg broken if scard group is removed

2009-09-13 Thread Christoph Anton Mitterer
btw: /var/run/openct is not removed either... Always thought the policy would mandate, that packages should not left over cruft. Best wishes, Chris. -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.

Bug#546500: postrm does not remove dpkg-statoverride entry which makes dpkg broken if scard group is removed

2009-09-13 Thread Christoph Anton Mitterer
Package: openct Justification: breaks the whole system Severity: critical Hi. openct adds a group scard and an entry with it to dpkg-statoverride. If openct is purged, neither the group nor the statoverride entry are removed. If one removes the group manually (but not the statoverride entry) many

Bug#545240: no hashsum checks of downloaded content, thus allowing downloading and installation of malicious content

2009-09-07 Thread Christoph Anton Mitterer
Quoting Christian Holm Christensen : On Sun, 2009-09-06 at 00:41 +0200, Christoph Anton Mitterer wrote: Package: ttf-root-installer Version: 5.18.00-2.3 Severity: critical Tags: security ... ^^ Sorry for the critical/security,... but first of all,.. this draws attention,... and secondly

Bug#545246: closed by Ben Hutchings (Re: Bug#545246: no hashsum checks of downloaded content, thus allowing downloading and installation of malicious content)

2009-09-06 Thread Christoph Anton Mitterer
Hi. There is already a packaged version of the rt73 firmware in firmware-ralink. update-rt73-firmware provides a convenient way to download and install a newer, unpackaged version. Unfortunately there is no way to verify an arbitrary new version of the firmware. Why not? You could add include

Bug#545241: no hashsum checks of downloaded content, thus allowing downloading and installation of malicious content

2009-09-06 Thread Christoph Anton Mitterer
Hi. Just looked over it again... How do you actuallly do you check? I've seen that you include a OpenPGP key, and it seems that you're this is from some Adobe employee and the md5.txt is also from them? SO in this case I'd still consider this security critical, because now "we" (Debian) fu

Bug#545241: no hashsum checks of downloaded content, thus allowing downloading and installation of malicious content

2009-09-06 Thread Christoph Anton Mitterer
Quoting Nico Golde : This is not entirely correct, actually the packages checks md5 hashes (yes, i know this is broken). Really?! Sorry,.. I must have overlooked this :( Then may I suggest to switch to something better (e.g. SHA512) and make sure, that installation fails and the user is warne

Bug#545246: no hashsum checks of downloaded content, thus allowing downloading and installation of malicious content

2009-09-05 Thread Christoph Anton Mitterer
Package: rt73-common Version: 1:1.0.3.6-cvs20090424-dfsg1-1 Severity: critical Tags: security Hi. I'm currently looking at Debian packages which download and install files from the internet (as their main content) whether they check the validity of these files. This package does not make a

Bug#545245: no hashsum checks of downloaded content, thus allowing downloading and installation of malicious content

2009-09-05 Thread Christoph Anton Mitterer
Package: em8300 Version: 0.16.4-4 Severity: critical Tags: security Hi. I'm currently looking at Debian packages which download and install files from the internet (as their main content) whether they check the validity of these files. This package does not make any hashsum check (e.g. SHA

Bug#545239: no hashsum checks of downloaded content, thus allowing downloading and installation of malicious content

2009-09-05 Thread Christoph Anton Mitterer
Package: susv3 Version: 6.1 Severity: critical Tags: security Hi. I'm currently looking at Debian packages which download and install files from the internet (as their main content) whether they check the validity of these files. This package does not make any hashsum check (e.g. SHA512, w

Bug#545240: no hashsum checks of downloaded content, thus allowing downloading and installation of malicious content

2009-09-05 Thread Christoph Anton Mitterer
Package: ttf-root-installer Version: 5.18.00-2.3 Severity: critical Tags: security Hi. I'm currently looking at Debian packages which download and install files from the internet (as their main content) whether they check the validity of these files. This package does not make any hashsum

Bug#545241: no hashsum checks of downloaded content, thus allowing downloading and installation of malicious content

2009-09-05 Thread Christoph Anton Mitterer
Package: flashplugin-nonfree Version: 1:2.7 Severity: critical Tags: security Hi. I'm currently looking at Debian packages which download and install files from the internet (as their main content) whether they check the validity of these files. This package does not make any hashsum check

Bug#545238: no hashsum checks of downloaded content, thus allowing downloading and installation of malicious content

2009-09-05 Thread Christoph Anton Mitterer
Package: susv2 Version: 1.1 Severity: critical Tags: security Hi. I'm currently looking at Debian packages which download and install files from the internet (as their main content) whether they check the validity of these files. This package does not make any hashsum check (e.g. SHA512, w

Bug#544113: tiger depends on diff

2009-08-28 Thread Christoph Anton Mitterer
Package: tiger Justification: Policy 3.5 Severity: serious Hi. Tiger depends on diff,... which it should probably not: Packages are not required to declare any dependencies they have on other packages which are marked Essential (see below), and should not do so unless they depend on a particular

Bug#542889: nvidia-kernel-source: kernel panic on amd64 with 185.18.31 drivers, Quadro card

2009-08-23 Thread Christoph Anton Mitterer
Hi. This does not only affect Quadro cards... btw: Could you please hurry up to upload the fixed version? Or could you please reupload the older version? Best wishes, Chris. smime.p7s Description: S/MIME cryptographic signature

Bug#540546: insserv changes my system without asking

2009-08-17 Thread Christoph Anton Mitterer
On Mon, 2009-08-17 at 13:36 +0200, Petter Reinholdtsen wrote: > There is a medium priority debconf question being asked. The default > is set to convert if the testing indicate that it is safe to convert, > and the default is set to not convert if there is a problem. Yeah,... I've already assumed

Bug#511753: insserv: Missing symlinks in rcN.d after removing insserv

2009-08-14 Thread Christoph Anton Mitterer
Im not totally sure (please correct me if I'm wrong) but isn't this "desired"? When uninstalling insserv, the only thing it can do to recover the old rcN.d/links is, to is the backups it made during its own installation, right? Of course, the ones from packages installed afterwards (like your

Bug#540546: insserv changes my system without asking

2009-08-14 Thread Christoph Anton Mitterer
Hi Michael. Is this still the case with the current version of insserv in sid? When I've installed it a week or two ago,... I _was_ asked. I even think that I was asked with the lenny version of sid (IIRC). You meant that your debconf priority is set to low? Regards, Chris.

Bug#537323: Perhaps a critical mistake in the example for chaining with Tor?

2009-07-16 Thread Christoph Anton Mitterer
Package: privoxy Version: 3.0.13-1 Justification: user security hole Severity: grave Tags: security Hi. Since the last release or so, the config template gives this as an example for chaining privoxy with Tor: # To chain Privoxy and Tor, both running on the same system, # you would

Bug#535469: sks does not longer start

2009-07-02 Thread Christoph Anton Mitterer
Package: sks Version: 1.1.0-5 Justification: renders package unusable Severity: grave Hi. Since 1.1.0-5 sks does not longer work,.. and I see these messages in dmesg: [80773.190585] sks[23453]: segfault at 0 ip (null) sp bfad072c error 4 in sks[8048000+db000] [80785.802317] sks[23450]: segfault

Bug#531315: aptitude seems to use hidden processes, rendering HIDS systems like unhide nearly useless

2009-05-31 Thread Christoph Anton Mitterer
Package: aptitude Version: 0.4.11.11-1+b1 Justification: user security hole Severity: grave Tags: security Hi. I'm running several intrusion detection systems, e.g. rkhunter (which in turn uses unhide). For quite some time now, unhide gave me false positives (I'm quite sure, that my system

Bug#531100: after startup, infinite number of nautilus "tabs" appear in the window list on the panel

2009-05-29 Thread Christoph Anton Mitterer
Package: gnome-panel Version: 2.26.2-1 Justification: renders package unusable Severity: grave Hi. I have this problem on two systems, one a normal laptop (one screen) the other a dual head monitor system (two separate X screens, no Xinerama or something like this): After starting gnome, the win

Bug#523345: gstreamer0.10-plugins-bad: Still crashes Pidgin

2009-05-09 Thread Christoph Anton Mitterer
Hi Sebastian. Attached you'll find a backtrace by bugbuddy. Some symbols are missing unfortunately,... I'm quite busy atm,.. if you should need them,.. please ask, and I'll create it manually (with all symbols)... thx, Chris. --

Bug#523345: gstreamer0.10-plugins-bad: Still crashes Pidgin

2009-05-06 Thread Christoph Anton Mitterer
On Wed, 2009-05-06 at 09:39 +0200, Sebastian Dröge wrote: > Yes, those versions shouldn't crash Uhm,... but it does ;) Anything I can do to help debugging this? Chris. smime.p7s Description: S/MIME cryptographic signature

Bug#523345: gstreamer0.10-plugins-bad: Still crashes Pidgin

2009-04-27 Thread Christoph Anton Mitterer
Hi On Sat, 2009-04-25 at 06:08 +0200, Sebastian Dröge wrote: > Which version of gstreamer0.10-plugins-bad, liblrdf0 and dependending > packages do you have installed? I was using the most recent (unstable) versions from all packages: gstreamer0.10-plugins-bad 0.10.11-2+b1 liblrdf0 0.4.0-1.2 librap

Bug#523345: gstreamer0.10-plugins-bad: Still crashes Pidgin

2009-04-24 Thread Christoph Anton Mitterer
Hi. Is anyone looking at this? Or is this package orphaned? This bug is very annoying as it prevents one from installing gnome-desktop-environment (which depends on empathy) and thus gnome. Chris. smime.p7s Description: S/MIME cryptographic signature

Bug#525144: make-kpgk fails to build kernel (segfaults)

2009-04-22 Thread Christoph Anton Mitterer
On Wed, 2009-04-22 at 14:38 -0500, Manoj Srivastava wrote: > I note that man make-kpkg says: > , > |WARNING: Do NOT set the -j option in MAKEFLAGS directly, this > |shall cause the build to fail. Use CONCURRENCY_LEVEL as specified > |below. > ` > though I t

Bug#525144: make-kpgk fails to build kernel (segfaults)

2009-04-22 Thread Christoph Anton Mitterer
Package: kernel-package Version: 12.009 Justification: renders package unusable Severity: grave Hi. make-kpkg --revision 0.1 --append-to-version '-heisenberg' --initrd buildpackage fails with: ... ... LD [M] sound/drivers/snd-serial-u16550.ko LD [M] sound/drivers/snd-virmidi.ko LD [M]

Bug#523325: pidgin crashes at start when gstreamer0.10-plugins-bad is installed

2009-04-09 Thread Christoph Anton Mitterer
Package: pidgin Version: 2.5.5-1 Justification: renders package unusable Severity: grave Hi. Whenever gstreamer0.10-plugins-bad is installed, pidgin crashes with the attached bug-report, from bug-buddy. In the meantime it is not even easily possible to simply remove gstreamer0.10-plugins-b

<    1   2   3   4   5   6   >