Bug#1057671: cytadela: game include non free graphical assets

2023-12-07 Thread Sylvain Beucler
Hi, I know this may come as a shock, given how often this isn't the case, but the contrib status is dutifully documented in the copyright file: https://metadata.ftp-master.debian.org/changelogs//contrib/c/cytadela/cytadela_1.1.0-4_copyright ;) Please review and revise severity / close

Bug#1035875: Arbitrary code execution vulnerability in versions < 2.3

2023-06-20 Thread Sylvain Beucler
in msi_dirent_new() Fix more fuzzer errors etc. so most probably there isn't a single clean patch to apply :/ We might want to just bump to buster and bullseye to 2.3, there's only one rdep AFAICS. Cheers! Sylvain Beucler Debian LTS Team (this week's Front-Desk person)

Bug#992118: squid3-dbg: uninstallable cruft package from src:squid3 in jessie-elts

2021-08-12 Thread Sylvain Beucler
Hi, Note that jessie-elts is not part of the official Debian project, see https://wiki.debian.org/LTS/Extended So using Debian-specific resources (the BTS) for elts-specific issues may be considered an abuse. Cheers! Sylvain Beucler Debian LTS Team On Thu, 12 Aug 2021 00:17:36 +0200 Andreas

Bug#961491: CVE-2020-10936: Security flaws in setuid wrappers

2020-12-14 Thread Sylvain Beucler
On 07/12/2020 12:06, Stefan Hornburg (Racke) wrote: On 12/7/20 10:52 AM, Sylvain Beucler wrote: This high-severity issue was marked with: [buster] - sympa (Will be fixed via point release) Consequently I am surprised that it wasn't part of last week's Debian 10.7 point release. What

Bug#961491: CVE-2020-10936: Security flaws in setuid wrappers

2020-12-07 Thread Sylvain Beucler
Hi, On Sat, 10 Oct 2020 09:45:42 +0300 "Stefan Hornburg (Racke)" wrote: On 10/7/20 3:03 PM, Sylvain Beucler wrote: > I noticed this local root escalation yesterday and I'm working on a > Stretch LTS update. > See also https://salsa.debian.org/sympa-team/sympa

Bug#961491: fixed in sympa 6.2.40~dfsg-5

2020-10-07 Thread Sylvain Beucler
Hi, I noticed this local root escalation yesterday and I'm working on a Stretch LTS update. See also https://salsa.debian.org/sympa-team/sympa/-/merge_requests/1 Are there plans to update buster? Cheers! Sylvain

Bug#908678: Update on the security-tracker git discussion

2020-10-02 Thread Sylvain Beucler
Hi, On Tue, 6 Aug 2019 08:28:43 +0200 Salvatore Bonaccorso wrote: > Thanks for keeping track and following up. > > On Tue, Aug 06, 2019 at 08:05:11AM +0200, Bastian Blank wrote: > > Moin > > > > On Tue, Jul 02, 2019 at 01:38:10PM +0200, Moritz Muehlenhoff wrote: > > > On Tue, Jul 02, 2019 at

Bug#964950: nginx: CVE-2020-11724

2020-07-13 Thread Sylvain Beucler
In case this helps, here's some documentation to test the issue with the new upstream test cases: https://wiki.debian.org/LTS/TestSuites/nginx and my planned stretch package: https://www.beuc.net/tmp/debian-lts/nginx/ Cheers! Sylvain Beucler Debian LTS Team diff -Nru nginx-1.10.3/debian

Bug#964950: nginx: CVE-2020-11724

2020-07-13 Thread Sylvain Beucler
the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2020-11724     https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11724 Cheers! Syl

Bug#963713: net-snmp: CVE-2019-20892

2020-07-07 Thread Sylvain Beucler
Hi, On 07/07/2020 17:07, Sylvain Beucler wrote: > On 06/07/2020 19:11, Sylvain Beucler wrote: >> Do we have definite info on what versions are affected? >> >> I cannot reproduce the issue in jessie/stretch/buster (5.7.x). >> >> Incidentally Salvatore's tes

Bug#963713: net-snmp: CVE-2019-20892

2020-07-07 Thread Sylvain Beucler
Hi, On 06/07/2020 19:11, Sylvain Beucler wrote: > Do we have definite info on what versions are affected? > > I cannot reproduce the issue in jessie/stretch/buster (5.7.x). > > Incidentally Salvatore's test now yields an error in bullseye > (5.8dfsg-3), though I

Bug#963713: [Pkg-net-snmp-devel] Bug#963713: net-snmp: CVE-2019-20892

2020-07-06 Thread Sylvain Beucler
-u testuser -a SHA -A testpass -x AES -X testpass 127.0.0.1 1.3.6.1.2.1.1.5 1.3.6.1.2.1.1.7 Error in packet. Reason: (genError) A general failure occured Cheers! Sylvain Beucler Debian LTS Team

Bug#926923: Acknowledgement (gradle: CVE-2019-11065)

2019-04-12 Thread Sylvain Beucler
control: severity -1 important thanks

Bug#926923: gradle: CVE-2019-11065

2019-04-12 Thread Sylvain Beucler
elog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2019-11065     https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11065     https://github.com/gradle/gradle/pull/8927 Cheers! Sylvain Beucler

Bug#926712: evolution-ews: CVE-2019-3890

2019-04-09 Thread Sylvain Beucler
s/27 https://gitlab.gnome.org/GNOME/evolution-ews/issues/36 https://bugzilla.redhat.com/show_bug.cgi?id=1678313 Note: depends on evolution-data-server patch Cheers! Sylvain Beucler / Debian LTS

Bug#920823: phpmyadmin: CVE-2019-6799: PMASA-2019-1

2019-02-27 Thread Sylvain Beucler
Uploaded to jessie-security.

Bug#920823: phpmyadmin: CVE-2019-6799: PMASA-2019-1

2019-02-24 Thread Sylvain Beucler
Hi, FYI I prepared a patch for jessie, see: https://lists.debian.org/debian-lts/2019/02/msg00164.html For stretch, it is worth noting that the fix depends on whether mysql or mysqli is enabled, whether open_basedir is in effect, and whether we're protecting against user SQL queries or

Bug#729986: libnss-mysql-bg: Patch 04_shadow.diff Introduces Lock Acquisition Hang

2014-03-05 Thread Sylvain Beucler
Package: libnss-mysql-bg Version: 1.5-3+b1 Followup-For: Bug #729986 Confirmed here, I just lost two evenings tracing down a weird rsync issue at Gna(.org) down to this. https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=641404 sheds some light on the patch's purpose. I guess it was tested with

Bug#647697: libsfml-dev: libsfml embeds non-free Arial font

2011-11-05 Thread Sylvain Beucler
Package: libsfml-dev Version: 1.6+dfsg1-2+b1 Severity: serious Justification: Policy 2.2.1 Hi, In the SFML fonts tutorial, it is mentioned that SFML provides a default built-in one, which is Arial with a character size of 30. http://sfml-dev.org/tutorials/1.6/graphics-fonts.php The file is

Bug#587931: cytadela: Uninstallable; libvlc2 unavailable

2010-07-03 Thread Sylvain Beucler
Tested, new package 1.0.1-1 that uses libvlc5 works fine. Closing bug. :-) Neat, thanks for testing. Enjoy the game :) -- Sylvain -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#587931: cytadela: Uninstallable; libvlc2 unavailable

2010-07-02 Thread Sylvain Beucler
1h too late - I actually just uploaded 1.0.1 which uses newer libvlc, please test when it's built for your architecture :) - Sylvain On Fri, Jul 02, 2010 at 06:09:50PM -0400, Chris wrote: Package: cytadela Version: 1.0.0-2 Severity: grave Justification: renders package unusable cytadela

Bug#583702: beneath-a-steel-sky: package ships data that cannot be modified

2010-06-07 Thread Sylvain Beucler
The idea to place it in _contrib_ (not in 'non-free') makes sense to me. Placing it in 'main' encourages DDs to add more non-modifiable data there. If the tools to modify were lost, then users are locked anyway. Similarly we wouldn't place executable binaries in 'main' if people had lost the

Bug#584022: page-crunch: Security bugs in ghostscript

2010-06-03 Thread Sylvain Beucler
OK, so as far as I understand, we'd better pass '-dSAFER -P-' to 'ps2pdf' (which is AFAICS the only ghostscript script that's used in page-crunch). David, what do you think? - Sylvain On Tue, Jun 01, 2010 at 11:14:06AM +1000, Paul Szabo wrote: Package: page-crunch Severity: grave Tags:

Bug#578444: [br...@clisp.org: Re: install-reloc error on Debian-hurd and Debian-kfreebsd]

2010-04-20 Thread Sylvain Beucler
Thanks, I already identified the bug and I think I'll make a new upstream release. - Sylvain - Forwarded message from Bruno Haible br...@clisp.org - Date: Tue, 20 Apr 2010 00:29:29 +0200 From: Bruno Haible br...@clisp.org To: bug-gnu...@gnu.org Cc: Sylvain Beucler b...@beuc.net Subject

Bug#570850: Fix CVE-2009-4029 in Lenny/stable

2010-03-31 Thread Sylvain Beucler
Hi, Any progress? -- Sylvain -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#570850: automake: Fix CVE-2009-4029 in Lenny/stable

2010-02-21 Thread Sylvain Beucler
. -- no debconf information --- automake1.10-1.10.1/debian/changelog +++ automake1.10-1.10.1/debian/changelog @@ -1,3 +1,11 @@ +automake1.10 (1:1.10.1-4) stable-security; urgency=high + + [ Sylvain Beucler ] + * Fix CVE-2009-4029, which created world-writable directories in +distribution tarballs

Bug#570850: Fix CVE-2009-4029 in Lenny/stable

2010-02-21 Thread Sylvain Beucler
Note: the patch comes from: http://lists.gnu.org/archive/html/automake-patches/2009-11/msg00017.html -- Sylvain signature.asc Description: Digital signature

Bug#516708: Debtorrent just won't give up after receiving 404

2010-01-24 Thread Sylvain Beucler
Hi, Any progress on that RC issue? For the record, I saw that there were commits towards v2.0 (9/2009): http://svn.debian.org/wsvn/debtorrent/debtorrent/trunk/debian/changelog but they do not reference this particular bug. -- Sylvain @BSP2010 signature.asc Description: Digital signature

Bug#559835: CVE-2009-3736 update

2010-01-24 Thread Sylvain Beucler
Hi, The 'lam' package uses the AC_LIBLTDL_CONVENIENCE macro, which forces the use of the bundled copy. It only supports --disable-ltdl-convenience which just produces an error (this package needs a convenience libltdl). Note that this is a libtool 1.5 feature, not libtool 2 (where it's

Bug#562723: with slapd.d don't work

2010-01-23 Thread Sylvain Beucler
Package: slapd Severity: normal When you use: slaptest -f /etc/ldap/slapd.conf -F /etc/ldap/slapd.d/ slapd converts slapd.conf to /etc/ldap/slapd.d/ . So it's possible that both are not desync'd on your system, and that only slapd.conf is a valid configuration. Can you precise what errors

Bug#560940: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-24 Thread Sylvain Beucler
On Tue, Dec 15, 2009 at 01:31:30PM +0100, Sylvain Beucler wrote: Patched package available at: http://mentors.debian.net/cgi-bin/sponsor-pkglist?action=details;package=tla Ben noticed that part of the bundled libexpat was still used. I missed 2 -I ../lib/expat occurrences, I'll upload a new

Bug#560940: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-24 Thread Sylvain Beucler
by Sylvain Beucler b...@beuc.net ## ## All lines beginning with `## DP:' are a description of the patch. -## DP: use system expat to address CVE-2009-3560 and CVE-2009-3720 DoS -## DP: see also debian/rules, target 'clean' +## DP: No description. tla-1.3.5+dfsg.orig/src/tla/tla/Makefile.in -+++ tla

Bug#560940: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-15 Thread Sylvain Beucler
Patched package available at: http://mentors.debian.net/cgi-bin/sponsor-pkglist?action=details;package=tla -- Sylvain signature.asc Description: Digital signature

Bug#560940: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-14 Thread Sylvain Beucler
I'm having a look at this. I had worked on this package a while ago, and I'm currently doing a NM TasksSkills, so it's a pleasure ;) -- Sylvain signature.asc Description: Digital signature

Bug#513796: php5-xapian: PHP license incompatible with Xapian

2009-02-01 Thread Sylvain Beucler
Package: php5-xapian Version: 1.0.7-3.1 Severity: serious Justification: Policy 2.3 The PHP license is incompatible with the GNU GPL license due to strong restrictions on the usage of the term 'PHP'. Thus combining PHP and Xapian through the php5-xapian module is not permitted and cannot be

Bug#512111: iceweasel: Iceweasel disable Firefox upgrade checks

2009-01-17 Thread Sylvain Beucler
Package: iceweasel Version: 3.0.5-1 Severity: grave Tags: security Justification: user security hole Since Debian stable is a frozen distro, it's not uncommon to install the official Firefox binaries when the next version of Firefox is released, and isn't packaged in stable or backported yet.

Bug#503712: the gs-common problem

2008-12-28 Thread Sylvain Beucler
For the latter, it would be cool if the maintainers of the affected packages, Vincent for latex-make Sylvain and David for page-crunch the Zope guys and Andreas and Fabio for zope-textindexng3 could weigh in here. I'll look at your packages, but if you already know whether

Bug#409384: gnome: Fail to mount CD-ROM

2007-02-02 Thread Sylvain Beucler
Package: gnome Version: 1:2.14.3.5 Severity: grave Justification: renders package unusable Steps to reproduce: - put CD in drive - click on the computer icon - click on the cdrom drive You get something like impossible to mount the selected volume, and in the detailed log there is:

Bug#382465: FTBFS on arm, sparc, ia64, hppa

2006-08-11 Thread Sylvain Beucler
tla 1.3.5+dfsg-2 fails to build from source on arm, sparc, ia64 and hppa[1]. Actually it builds, but the test suite fails on those architectures. I reported that upstream and they're working on it. http://lists.gnu.org/archive/html/gnu-arch-users/2006-08/msg6.html Maybe we can drop the