Bug#1079342: FTBFS with newer imagemagick7

2024-08-22 Thread Bastien Roucariès
Source: lebiniou Tags: ftbfs Control: block 1060103 by -1 Control: tag -1 + sid Dear Maintainer, You package FTBFS with newer imagemagick Could you help the transition Full log could be found here https://salsa.debian.org/debian/imagemagick/-/jobs/6158076 Thanks Rouca signature.asc Descript

Bug#1073529: bookworm-pu: package pymongo/3.11.0-1+deb11u1

2024-06-16 Thread Bastien Roucariès
Package: release.debian.org Severity: normal Tags: bullseye X-Debbugs-Cc: pymo...@packages.debian.org Control: affects -1 + src:pymongo User: release.debian@packages.debian.org Usertags: pu [ Reason ] CVE-2024-5629 [ Impact ] An out-of-bounds read in the 'bson' module allows deserialization

Bug#1073524: bookworm-pu: package pymongo/3.11.0-1+deb12u1

2024-06-16 Thread Bastien Roucariès
Package: release.debian.org Severity: normal Tags: bookworm X-Debbugs-Cc: pymo...@packages.debian.org Control: affects -1 + src:pymongo User: release.debian@packages.debian.org Usertags: pu [ Reason ] CVE-2024-5629 [ Impact ] An out-of-bounds read in the 'bson' module allows deserialization

Bug#1073231: bullseye-pu: package sendmail/8.15.2-22+deb11u1

2024-06-14 Thread Bastien Roucariès
Package: release.debian.org Severity: normal Tags: bullseye X-Debbugs-Cc: sendm...@packages.debian.org Control: affects -1 + src:sendmail User: release.debian@packages.debian.org Usertags: pu [ Reason ] Fix CVE-2023-51765 (smtp smugling) [ Impact ] SMTP smugling [ Tests ] Manual test using

Bug#1071449: bookworm-pu: package sendmail/8.17.1.9-2+deb12u1

2024-05-19 Thread Bastien Roucariès
Package: release.debian.org Severity: normal Tags: bookworm X-Debbugs-Cc: sendm...@packages.debian.org Control: affects -1 + src:sendmail User: release.debian@packages.debian.org Usertags: pu [ Reason ] sendmail was affected by CVE-2023-51765 [ Impact ] close CVE-2023-51765 and reject NUL mai

Bug#1070190: sendmail-bin: CVE-2023-51765 SMTP smuggling with NUL followup

2024-05-09 Thread Bastien Roucariès
Le samedi 4 mai 2024, 12:40:25 UTC Andreas Beckmann a écrit : > On 04/05/2024 13.02, Andreas Beckmann wrote: > >> I have patched sendmail in order to enable O RejectNUL=True directive, > >> but I do not achieved the fact to enable it by default. > > >> Andreas could you get a glimpse at how to ren

Bug#1070190: sendmail-bin: CVE-2023-51765 SMTP smuggling with NUL followup

2024-05-01 Thread Bastien Roucariès
Package: sendmail-bin Severity: important Tags: security help Forwarded: https://marc.info/?l=oss-security&m=171447187004229&w=2 Dear Maintainer, CVE-2023-51765 is not fully fixed at least for forwarding bad mail. We must reject NUL including mail as a stop gap method. I have patched sendmail i

Bug#1039086: collada2gltf: Embed yajl

2023-06-25 Thread Bastien Roucariès
Source: collada2gltf Severity: serious Justification: devref Dear Maintainer, Your package embed a copy a yajl Could you: - build against yajl package - remove by repacking the code copy in order to avoid in the future accidental code compilation against the embed code copy Thanks Bastien --

Bug#1017513: isa-support: mktemp on /usr/lib and base64 encoded binary in preinst are evil

2022-08-17 Thread Bastien Roucariès
Source: isa-support Version: 7 Severity: grave Tags: patch Justification: causes non-serious data loss Dear Maintainer, mktemp could fail and base64 is preinst is not nice -- System Information: Debian Release: bookworm/sid APT prefers testing APT policy: (900, 'testing') Architecture: amd6

Bug#900601: [src:libantlr3c] Non free file : unicode

2018-06-01 Thread Bastien ROUCARIÈS
Package: src:libantlr3c Version: 3.2-3 Severity: serious The following file source files include material under a non-free license from Unicode Inc. Therefore, it is not possible to ship this in main or contrib. src/antlr3convertutf.* This license does not grant any permission to modify the fil

Bug#787355: [RC][cc-by-nc-sa] Please clarify license of a few svg files

2015-05-31 Thread bastien ROUCARIÈS
Package: src:openclipart2 Version: 2.0+dfsg-1 Severity: serious user: lintian-ma...@debian.org usertags: license-problem-cc-by-nc-sa Hi, Could you please clarify the license of: clipart/worms_x/worms_x_French_butter_croissant.svg clipart/rugby471/rugby471_Tango_Style_Cheese_Wheel.svg

Bug#709500: Documentation is non free

2013-05-23 Thread Bastien ROUCARIÈS
Package: src:tla Severity: serious user: debian...@lists.debian.org usertags: gfdl-invariant severity: serious The documentation of your package is non free under gfdl with invariants sections. Particularly: src/hackerlab/libhackerlab/libhackerlab.doc src/tla/libarch/libarch.doc src/