Bug#1091761: bookworm-pu: package poco/1.11.0-3+deb12u1

2024-12-30 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal Tags: bookworm X-Debbugs-Cc: p...@packages.debian.org Control: affects -1 + src:poco User: release.debian@packages.debian.org Usertags: pu Fix for CVE-2023-52389 (which doesn't warrant a DSA), debdiff below. Cheers, Moritz diff -Nru poco-1

Bug#1086506: RM: mathtex -- RoQA; dead upstram, open security issues, orphaned

2024-10-31 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal Tags: security X-Debbugs-Cc: math...@packages.debian.org, Debian Security Team Control: affects -1 + src:mathtex User: ftp.debian@packages.debian.org Usertags: remove Please remove mathtex, it's dead upstream and there are open security issues. The la

Bug#1086301: RM: mathtex -- RoQA; orphaned, dead upstream, open security issues

2024-10-29 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal Tags: security X-Debbugs-Cc: math...@packages.debian.org, Debian Security Team Control: affects -1 + src:mathtex User: ftp.debian@packages.debian.org Usertags: remove Please remove mathtex. It's dead upstream and there are open security issues. Cheer

Bug#1079690: RM: perl-doc-html -- RoQA; unmaintained, outdated

2024-08-26 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal X-Debbugs-Cc: perl-doc-h...@packages.debian.org Control: affects -1 + src:perl-doc-html User: ftp.debian@packages.debian.org Usertags: remove Please remove perl-doc-html. It contains outdated docs, has been dropped from testing since 2018 and is orphane

Bug#1079656: RM: haskell98-tutorial -- RoQA; unmaintained, RC-buggy

2024-08-25 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal X-Debbugs-Cc: haskell98-tutor...@packages.debian.org Control: affects -1 + src:haskell98-tutorial User: ftp.debian@packages.debian.org Usertags: remove Please remove haskell98-tutorial. It's RC-buggy since 2021 and up for adoption without any takers sin

Bug#1079645: RM: ifscheme -- RoQA; RC-buggy, unmaintained

2024-08-25 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal X-Debbugs-Cc: ifsch...@packages.debian.org Control: affects -1 + src:ifscheme User: ftp.debian@packages.debian.org Usertags: remove Please remove ifscheme. It's broken since at least 2021 (#981637) and orphaned without an adopter since 2020. Cheers,

Bug#1079308: RM: picprog -- RoQA; RC-buggy, unmaintained

2024-08-22 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal X-Debbugs-Cc: picp...@packages.debian.org Control: affects -1 + src:picprog User: ftp.debian@packages.debian.org Usertags: remove Please remove picprog. It's RC-buggy since 2019 and thus missed the last two stable releases (since Linux 5.5 entered Debia

Bug#1074225: RM: watchcatd -- RoQA; dead upstream, obsolete

2024-06-24 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal X-Debbugs-Cc: watchc...@packages.debian.org Control: affects -1 + src:watchcatd User: ftp.debian@packages.debian.org Usertags: remove Please remove watchcatd. It's dead upstream and generally obsolete, such process supervision is built into systemd nati

Bug#1073968: RM: sleepd -- RoQA; unmaintained, dead upstream

2024-06-20 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal X-Debbugs-Cc: sle...@packages.debian.org Control: affects -1 + src:sleepd User: ftp.debian@packages.debian.org Usertags: remove Please remove sleepd. Upstream development has stopped a long time ago, and it's orphaned for a decade without an adopter. C

Bug#1073277: RM: ramond -- RoQA; unmaintained, dead upstream, unused

2024-06-15 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal X-Debbugs-Cc: ram...@packages.debian.org Control: affects -1 + src:ramond User: ftp.debian@packages.debian.org Usertags: remove Please remove ramond. It's dead upstream, the last maintainer upload was in 2012 without a new adopter and it's basically non

Bug#1061572: bullseye-pu: package unadf/0.7.11a-4+deb11u1

2024-01-26 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal Tags: bullseye User: release.debian@packages.debian.org Usertags: pu X-Debbugs-Cc: un...@packages.debian.org Control: affects -1 + src:unadf Addresses two no-dsa security issues, same fix already rolled out for Bookworm. Debdiff below. Cheers,

Bug#1056696: bookworm-pu: package unadf/0.7.11a-5+deb12u1

2023-11-24 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal Tags: bookworm User: release.debian@packages.debian.org Usertags: pu X-Debbugs-Cc: un...@packages.debian.org Control: affects -1 + src:unadf Fixes two minor security issues. These have actually been in past releases (wheezy/jessie), but the patch wa

Bug#1055308: RM: golang-github-go-macaron-bindata -- RoQA; obsolete

2023-11-03 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal User: ftp.debian@packages.debian.org Usertags: remove X-Debbugs-Cc: golang-github-go-macaron-bind...@packages.debian.org Control: affects -1 + src:golang-github-go-macaron-bindata Please remove golang-github-go-macaron-bindata. The version in the archiv

Bug#1050743: RM: elida -- RoQA; obsolete, unused, dead upstream

2023-08-28 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal User: ftp.debian@packages.debian.org Usertags: remove X-Debbugs-Cc: el...@packages.debian.org Control: affects -1 + src:elida Please remove elida, it's obsolete, unused and without an adopter for years. Upstream is also gone, the former maintainer was a

Bug#1041864: RM: netkit-rsh -- RoQA; obsolete, dead upstream, open security issues

2023-07-24 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal User: ftp.debian@packages.debian.org Usertags: remove X-Debbugs-Cc: netkit-...@packages.debian.org Control: affects -1 + src:netkit-rsh Please remove netkit-rsh. It's obsolete, dead upstream and has open security issues.

Bug#1040238: RM: gsm0710muxd -- RoQA; obsolete, dead upstream, uses legacy libs

2023-07-03 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal User: ftp.debian@packages.debian.org Usertags: remove X-Debbugs-Cc: gsm0710m...@packages.debian.org Control: affects -1 + src:gsm0710muxd Please remove gsm0710muxd. It's been orphaned since nine years and removal was already suggested in the original O:

Bug#1040239: RM: apf-firewall -- RoQA; obsolete, unmaintained

2023-07-03 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal User: ftp.debian@packages.debian.org Usertags: remove X-Debbugs-Cc: apf-firew...@packages.debian.org Control: affects -1 + src:apf-firewall Please remove apf-firewall. Removal was already hinted at in the original orphan bug from 2016 and at this point

Bug#1040236: RM: mason -- RoQA; dead upstream, alternatives exist

2023-07-03 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal User: ftp.debian@packages.debian.org Usertags: remove X-Debbugs-Cc: ma...@packages.debian.org Control: affects -1 + src:mason Please remove mason, it's orphaned without an adopter since 2018, upstream is dead upstream (vanished off the internet) and it

Bug#1040237: RM: masqmail -- RoQA; dead upstream, RC-buggy

2023-07-03 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal User: ftp.debian@packages.debian.org Usertags: remove X-Debbugs-Cc: masqm...@packages.debian.org Control: affects -1 + src:masqmail Please remove masqmail. It's dead upstream, orphaned without an adopter since 2015 and RC-buggy (dropped from testing sin

Bug#1039949: RM: pads -- RoQA; dead upstream, unmaintained, depends on obsolete libs

2023-06-29 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal User: ftp.debian@packages.debian.org Usertags: remove X-Debbugs-Cc: p...@packages.debian.org Control: affects -1 + src:pads Please move pads. It's dead upstream, orphaned without a new maintainer since 2015 and depends on the legacy PCRE.

Bug#1039729: RM: freelan -- RoQA; unmaintained, RC-buggy, dead upstream

2023-06-28 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal User: ftp.debian@packages.debian.org Usertags: remove X-Debbugs-Cc: free...@packages.debian.org Control: affects -1 + src:freelan Please remove freelan. It's orphaned without an adopter since five years and FTBFS since almost two years due to a lack of

Bug#1034883: RM: golang-github-go-macaron-csrf -- RoQA; Obsolete, open security issues

2023-04-26 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal User: ftp.debian@packages.debian.org Usertags: remove X-Debbugs-Cc: golang-github-go-macaron-c...@packages.debian.org Control: affects -1 + src:golang-github-go-macaron-csrf Please remove golang-github-go-macaron-csrf. It was only packaged for Gitea, wh

Bug#1034839: RM: golang-github-go-macaron-i18n -- RoQA; obsolete, open security issue

2023-04-25 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal User: ftp.debian@packages.debian.org Usertags: remove X-Debbugs-Cc: golang-github-go-macaron-i...@packages.debian.org Control: affects -1 + src:golang-github-go-macaron-i18n Please remove golang-github-go-macaron-i18n. It was only packaged for gitea, wh

Bug#1031044: RM: latd -- RoQA; obsolete, orphaned for a long time, dead upstream

2023-02-10 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal User: ftp.debian@packages.debian.org Usertags: remove X-Debbugs-Cc: l...@packages.debian.org Control: affects -1 + src:latd Please remove latd. It's orphaned without an adopter since 2014, dead upstream and practically unused per popcon. Cheers,

Bug#1031043: RM: xavante -- RoQA; orphaned, uses old Lua releases, alternatives exist

2023-02-10 Thread Moritz Muehlenhoff
Package: ftp.debian.org Severity: normal User: ftp.debian@packages.debian.org Usertags: remove X-Debbugs-Cc: xava...@packages.debian.org Control: affects -1 + src:xavante Please remove xavante, the last maintainer upload was in 2013, there's plenty of web servers in the archive and it depends

Bug#1025011: Keep out of bookworm unless actively maintained

2022-11-28 Thread Moritz Muehlenhoff
Source: netatalk Version: 3.1.13~ds-2 Severity: serious netatalk should not enter bookworm unless it gets adopted and actively maintained. Cheers, Moritz

Bug#1005988: Don't release with bookworm

2022-02-18 Thread Moritz Muehlenhoff
Source: dpatch Version: 2.0.41 Severity: serious dpatch has been obsoleted by source format 3.0 (quilt), there's only 19 reverse dependencies in the archive (5 of them in testing), for which bugs have been filed. Cheers, Moritz

Bug#1005979: Please migrate away from dpatch

2022-02-18 Thread Moritz Muehlenhoff
Source: efax Version: 1:0.9a-20 Severity: serious dpatch is deprecated and will be removed before the bookworm release. Please migrate to source format 3.0 (quilt) instead.

Bug#988985: CVE-2020-23856

2021-05-22 Thread Moritz Muehlenhoff
Package: cflow Severity: normal Tags: security X-Debbugs-Cc: Debian Security Team This was assigned CVE-2020-23856: https://lists.gnu.org/archive/html/bug-cflow/2020-07/msg0.html Cheers, Moritz

Bug#988151: CVE-2020-23922

2021-05-06 Thread Moritz Muehlenhoff
Source: giflib Severity: important Tags: security X-Debbugs-Cc: Debian Security Team CVE-2020-23922: https://sourceforge.net/p/giflib/bugs/151/

Bug#973385: CVE-2020-27739 CVE-2020-27740 CVE-2020-27741 CVE-2020-27742

2020-10-29 Thread Moritz Muehlenhoff
Source: webcit Severity: grave Tags: security X-Debbugs-Cc: Debian Security Team http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27739 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27740 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27741 http://cve.mitre.org/cgi-bin/c

Bug#972642: CVE-2020-12648 CVE-2020-17480

2020-10-21 Thread Moritz Muehlenhoff
Package: tinymce Severity: important Tags: security X-Debbugs-Cc: Debian Security Team CVE-2020-12648: https://labs.bishopfox.com/advisories/tinymce-version-5.2.1 CVE-2020-17480: https://github.com/tinymce/tinymce/security/advisories/GHSA-27gm-ghr9-4v95

Bug#970256: CVE-2019-1010091

2020-09-13 Thread Moritz Muehlenhoff
Package: tinymce Severity: important Tags: security X-Debbugs-Cc: Debian Security Team This was assigned CVE-2019-1010091: https://github.com/tinymce/tinymce/issues/4394 Cheers, Moritz

Bug#924613: CVE-2009-5155

2019-03-14 Thread Moritz Muehlenhoff
Source: gnulib Severity: grave Tags: security Please see https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-5155 Patch: http://git.savannah.gnu.org/cgit/gnulib.git/commit/?id=5513b40999149090987a0341c018d05d3eea1272 Cheers, Moritz

Bug#921471: Should pdf2htmlex be removed?

2019-02-05 Thread Moritz Muehlenhoff
Package: pdf2htmlex Severity: serious Should pdf2htmlex be removed? It's RC-buggy for over a year and upstream development seems to have stopped: http://pdf2htmlex.blogspot.de/2016/12/looking-for-new-maintainer.html Cheers, Moritz

Bug#917347: Obsolete build dependency on libssl1.0-dev

2018-12-26 Thread Moritz Muehlenhoff
Source: lighttpd Severity: normal Your package uses "libssl-dev | libssl1.0-dev" as a build dependency on OpenSSL. openssl1.0 is scheduled for removal, the alternate build dependency can now be removed. Cheers, Moritz

Bug#907724: Don't ship with buster

2018-08-31 Thread Moritz Muehlenhoff
Source: twitter-bootstrap Severity: serious src:twitter-bootstrap is a 6.5 year old version of Bootstrap which is orphaned since 2013. "Current" packages are in the archive as src:twitter-bootstrap3. The vintage version should not be in buster, reverse deps should migrate to src:twitter-bootstrap3

Bug#904114: CVE-2018-11490

2018-07-19 Thread Moritz Muehlenhoff
Source: giflib Severity: important Tags: security https://sourceforge.net/p/giflib/bugs/113/

Bug#904113: CVE-2018-11489

2018-07-19 Thread Moritz Muehlenhoff
Source: giflib Severity: important Tags: security https://sourceforge.net/p/giflib/bugs/112/

Bug#897281: doc-debian-fr: Should this package be removed?

2018-05-01 Thread Moritz Muehlenhoff
Package: doc-debian-fr Severity: serious These docs have been updated the last time over 12 years ago, is this actually still useful or rather misleading and should be removed? Cheers, Moritz

Bug#858255: Multiple security issues

2017-03-20 Thread Moritz Muehlenhoff
Source: virglrenderer Severity: grave Tags: security Please see: https://security-tracker.debian.org/tracker/CVE-2017-5956 https://security-tracker.debian.org/tracker/CVE-2017-5957 https://security-tracker.debian.org/tracker/CVE-2017-5993 https://security-tracker.debian.org/tracker/CVE-2017-5994 h

Bug#854728: CVE-2016-10214 / CVE-2017-5937

2017-02-09 Thread Moritz Muehlenhoff
Package: virglrenderer Severity: important Tags: security Please see https://security-tracker.debian.org/tracker/CVE-2017-5937 and https://security-tracker.debian.org/tracker/CVE-2016-10214 Cheers, Moritz

Bug#848978: removal of src:courier *now* probably a diservice to our users

2017-01-26 Thread Moritz Muehlenhoff
On Wed, Jan 11, 2017 at 05:09:24PM +, Holger Levsen wrote: > control: severity -1 important > > Hi Ondřej, > > first of all, thanks for all your work on courier, despite not even > using it! > > Second, I think I disagree with your conclusion (from December 26th > 2016!) that courier should

Bug#828253: not fixed at all

2016-11-12 Thread Moritz Muehlenhoff
These bugs are not fixed and should not be closed. Even if they're switched temporarily to openssl 1.0.2, this will go away after the stretch release. Also, they should at least be forwarded upstream before flipping to 1.0.2.

Bug#795428: OpenSLP 1.2 should not be part of stretch

2015-08-13 Thread Moritz Muehlenhoff
Source: openslp-dfsg Severity: serious The last maintainer upload of openslp happened in 2007 and it's orphaned for 5.5 years now. The 1.2 branch is completely abandoned upstream. At the minimum the package should be upgraded to 2.0, but the comment at https://bugzilla.redhat.com/show_bug.cgi?id=

Bug#795429: CVE-2015-5177

2015-08-13 Thread Moritz Muehlenhoff
Source: openslp-dfsg Severity: grave Tags: security Please see https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2015-5177 Cheers, Moritz

Bug#772008: CVE request: mpfr: buffer overflow in mpfr_strtofr

2014-12-29 Thread Moritz Muehlenhoff
On Mon, Dec 08, 2014 at 01:45:12PM +0100, Vasyl Kaigorodov wrote: > Hello, > > A buffer overflow was reported [1] in mpfr. > This is due to incorrect GMP documentation for mpn_set_str about the > size of a buffer (discussion is at [1]; first fix in the GMP > documentation is at [2]). This bug is p

Bug#750562: sendmail: CVE-2014-3956

2014-06-04 Thread Moritz Muehlenhoff
Package: sendmail Severity: grave Tags: security Justification: user security hole Hi, please see http://www.openwall.com/lists/oss-security/2014/06/03/1 for details. Cheers, Moritz -- To UNSUBSCRIBE, email to debian-qa-packages-requ...@lists.debian.org with a subject of "unsubscribe".

Bug#721052: aqualung: lacks support AC3, AAC, WavPack, WMA, etc. after being rebuilt against libav 9

2014-05-12 Thread Moritz Muehlenhoff
retitle 721052 aqualung: lacks support AC3, AAC, WavPack, WMA, etc. after being rebuilt against libav 9/10 thanks Sebastian Ramacher wrote: > Source: aqualung > Version: 0.9~beta11-1.2 > Severity: normal > > aqualung fails to detect libav when rebuilt against libav 9. The build > log to rebuil a

Bug#745524: Please migrate to lcms2

2014-04-22 Thread Moritz Muehlenhoff
Package: xsane Severity: important As pre-announced in https://lists.debian.org/debian-devel/2013/12/msg00570.html it is planned to remove lcms1 for jessie. Please adapt your package. The severity will be bumped to RC-level before the jessie freeze. Cheers, Moritz -- To UNSUBSCRIBE, e

Bug#745518: Please migrate to lcms2

2014-04-22 Thread Moritz Muehlenhoff
Source: devil Severity: important As pre-announced in https://lists.debian.org/debian-devel/2013/12/msg00570.html it is planned to remove lcms1 for jessie. Please adapt your package. The severity will be bumped to RC-level before the jessie freeze. Cheers, Moritz -- To UNSUBSCRIBE, em

Bug#739239: FTBFS with libav10

2014-02-16 Thread Moritz Muehlenhoff
Package: forked-daapd Severity: important Hi, your package fails to build from source against libav 10 (currently packaged in experimental). This bug will become release-critical at some point when the libav10 transition starts. Migration documentation can be found at https://wiki.libav.org/Migra

Bug#724574: please document what the modules are needed for

2013-10-18 Thread Moritz Muehlenhoff
On Wed, Sep 25, 2013 at 08:15:42AM +0200, Marc Haber wrote: > Package: open-vm-tools-dkms > Severity: minor > > Hi, > > from trying, it looks like Open-vm-tools work fine with basic > functionality if one does not install the kernel modules inside the VM. > > Please document (for example in the

Bug#717154: open-vm-tools-dkms: Fails to build against Linux 3.10

2013-07-17 Thread Moritz Muehlenhoff
Package: open-vm-tools-dkms Severity: grave open-vm-tools-dkms fails to build against Linux 3.10-1 from current Debian sid: Mi 17. Jul 14:26:10 CEST 2013 Using 2.6.x kernel build system. make: Entering directory `/var/lib/dkms/open-vm-tools/9.2.3/build/vmblock' make -C /lib/modules/3.10-1-amd64/b

Bug#714133: python-qpid: CVE-2013-1909

2013-06-25 Thread Moritz Muehlenhoff
Package: python-qpid Severity: grave Tags: security Please see https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-1909 for details. Cheers, Moritz -- To UNSUBSCRIBE, email to debian-qa-packages-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@list

Bug#691451: lgeneral: ships non-free files in contrib

2012-10-31 Thread Moritz Muehlenhoff
On Fri, Oct 26, 2012 at 03:15:31PM +0200, Markus Koschany wrote: > tags 691451 patch > thanks > > My new package is available at mentors.debian.net > > http://mentors.debian.net/package/lgeneral > > and in Git at > > http://git.debian.org/pkg-games/lgeneral.git > > Please see also bug #690683.

Bug#689417: opencryptoki: CVE-2012-4454 CVE-2012-4455

2012-10-30 Thread Moritz Muehlenhoff
On Sun, Oct 21, 2012 at 10:57:38PM +0200, Arthur de Jong wrote: > On Tue, 2012-10-02 at 14:37 +0200, Moritz Muehlenhoff wrote: > > Please see the thread starting at > > http://www.openwall.com/lists/oss-security/2012/09/07/2 > > for details. > > I've had a quick l

Bug#193061: Please provide free game data for LGeneral

2012-10-12 Thread Moritz Muehlenhoff
On Thu, Oct 11, 2012 at 05:07:04PM +0200, Markus Koschany wrote: > Hi everyone, > > i intend to adopt LGeneral and would like to maintain it as part of the > Debian Games Team. Nice! > I'm also cc'ing Moritz and Drew because you seemed > to be interested in LGeneral in the past and to let you k

Bug#689417: opencryptoki: CVE-2012-4454 CVE-2012-4455

2012-10-02 Thread Moritz Muehlenhoff
Package: opencryptoki Severity: grave Tags: security Justification: user security hole Please see the thread starting at http://www.openwall.com/lists/oss-security/2012/09/07/2 for details. Cheers, Moritz -- To UNSUBSCRIBE, email to debian-qa-packages-requ...@lists.debian.org with a s

Bug#687597: openslp-dfsg: CVE-2012-4428

2012-09-13 Thread Moritz Muehlenhoff
Package: openslp-dfsg Severity: grave Tags: security Justification: user security hole Please see https://bugzilla.redhat.com/show_bug.cgi?id=857242. Cheers, Moritz -- To UNSUBSCRIBE, email to debian-qa-packages-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact

Bug#660545: CVE-2011-1679 / CVE-2011-1680

2012-02-19 Thread Moritz Muehlenhoff
Package: ncpfs Severity: important Tags: security Please see http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1679 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1680 Cheers, Moritz -- To UNSUBSCRIBE, email to debian-qa-packages-requ...@lists.debian.org with a subject of

Bug#656507: Please enabled hardened build flags

2012-01-19 Thread Moritz Muehlenhoff
Source: libcdaudio Severity: important Tags: patch Please enabled hardened build flags through dpkg-buildflags. Patch attached. Cheers, Moritz diff -aur libcdaudio-0.99.12p2.harden/debian/rules libcdaudio-0.99.12p2/debian/rules --- libcdaudio-0.99.12p2.harden/debian/rules 2012-01-18 15:5

Bug#656009: Please enabled hardened build flags

2012-01-15 Thread Moritz Muehlenhoff
Package: loop-aes-utils Severity: important Tags: patch Please enabled hardened build flags through dpkg-buildflags. Patch attached. Cheers, Moritz diff -aur loop-aes-utils-2.16.2.harden/debian/rules loop-aes-utils-2.16.2/debian/rules --- loop-aes-utils-2.16.2.harden/debian/rules 2011-02

Bug#638566: Needs to be adapted for libav/0.7.1

2011-08-19 Thread Moritz Muehlenhoff
Package: avifile Severity: important Hi, the transition from ffmpeg/0.6.2 to libav/0.7 is planned soonish. (libav is a ffmpeg fork, to which Debian will switch, see http://en.wikipedia.org/wiki/FFmpeg for more information) Your package currently fails to build from source when built against libav

Bug#638563: Needs to be adapted for libav/0.7.1

2011-08-19 Thread Moritz Muehlenhoff
Package: kradio4 Severity: important Hi, the transition from ffmpeg/0.6.2 to libav/0.7 is planned soonish. (libav is a ffmpeg fork, to which Debian will switch, see http://en.wikipedia.org/wiki/FFmpeg for more information) Your package currently fails to build from source when built against libav

Bug#193061: lgeneral doesn't recommend data files anymore

2010-12-20 Thread Moritz Muehlenhoff
severity 193061 wishlist retitle 193061 Check status of replacement data files thanks On Sun, Dec 19, 2010 at 10:13:43PM -0600, Drew Scott Daniels wrote: > unarchive 193061 > found 193061 1.1.1-3 > thanks > Removing recommends lgeneral-data for dfsg caused this bug to be a problem > again. I'm not

Bug#603450: offlineimap: fails check the remote servers ssl certificate is valid

2010-11-30 Thread Moritz Muehlenhoff
On Sun, Nov 14, 2010 at 07:55:23PM +1100, david b wrote: > Package: offlineimap > Severity: grave > Tags: security > Justification: user security hole > > offlineimap performs absolutely no ssl certificate checking. So users > could/can be the victim of a man in the middle attack. > In debian the

Bug#564938: wip: should this package be removed?

2010-09-03 Thread Moritz Muehlenhoff
severity 564938 normal reassign 564938 ftp.debian.org retitle 564938 RM: wip -- RoQA; unused, orphaned since 3.5 years, dead upstream thanks On Tue, Jan 12, 2010 at 09:12:46PM +, Simon McVittie wrote: > Source: wip > Severity: wishlist > User: debian...@lists.debian.org > Usertags: proposed-r

Bug#564930: aap: should this package be removed?

2010-08-31 Thread Moritz Muehlenhoff
severity 564930 normal reassign 564930 ftp.debian.org retitle 564930 RM: aap -- RoQA; orphaned, low popcon, no rdepends, alternatives thanks On Tue, Jan 12, 2010 at 08:42:21PM +, Simon McVittie wrote: > Source: aap > Severity: wishlist > Justification: low-popcon build tool with no rdepends >

Bug#572937: Multiple security issues

2010-03-07 Thread Moritz Muehlenhoff
Package: ncpfs Severity: grave Tags: security Please see http://seclists.org/fulldisclosure/2010/Mar/122 for details and a patch. I don't know why the ncp mount needs to be setuid root in the first, dropping the setuidness seems like an equally adequate fix to me. Cheers, Moritz -- Syst

Bug#572556: CVE-2010-0055: Signature verification bypass

2010-03-04 Thread Moritz Muehlenhoff
Package: xar Severity: grave Tags: security The following was reported to us by Braden Thomas of the Apple Security Team: >> Description: >> We've discovered a signature verification bypass issue in xar. The >> issue is that xar_open assumes that the checksum is stored at offset >> 0, but xar_si

Bug#567631: Two security issues

2010-01-30 Thread Moritz Muehlenhoff
Package: ytnef Severity: grave Tags: security Please see http://www.ocert.org/advisories/ocert-2009-013.html This is CVE-2009-3721 (buffer overflows) and CVE-2009-3887 (traversal) Cheers, Moritz -- System Information: Debian Release: squeeze/sid APT prefers unstable APT policy: (500

Bug#559425: Update (other files)

2010-01-26 Thread Moritz Muehlenhoff
Karl Goetz wrote: > Hi, The following files might also be DFSG problems: > > BSDish licence + advertising clauses. BSD + advertising clause is DFSG compliant. > These have no licence grant: > ./ippd/md4.{c,h} > radius.c This code comes from RFC 1186: http://tools.ietf.org/html/rfc1186 >

Bug#560920: CVE-2009-3560 and CVE-2009-3720 denial-of-services

2009-12-16 Thread Moritz Muehlenhoff
severity 560920 normal tags 560920 -security thanks On Sat, Dec 12, 2009 at 10:48:50PM -0500, Michael Gilbert wrote: > package: matanza > severity: serious > tags: security > > Hi, > > The following CVE (Common Vulnerabilities & Exposures) ids were > published for expat. I have determined that

Bug#558173: Update 17 fixes several security issues

2009-11-26 Thread Moritz Muehlenhoff
Package: sun-java6 Severity: grave Tags: security Update 17 fixes a lot of security issues: [58]CVE-2009-3728 Directory traversal vulnerability in the ICC_Profile.getInstance ... [59]CVE-2009-3729 Unspecified vulnerability in the TrueType font parsing functionality ... [60]CVE-2009-386

Bug#542848: End of life in two months

2009-08-21 Thread Moritz Muehlenhoff
Package: sun-java5 Severity: serious Sun Java 5 is end-of-lifed in October, see http://www.j2ee.me/products/archive/eol.policy.html Since security issues are frequent and cannot be fixed w/o the source, we should probably not include it in Squeeze and remove it from the archive. Cheers,

Bug#540716: Needs to be actively maintained or removed

2009-08-09 Thread Moritz Muehlenhoff
Package: egroupware Severity: serious Egroupware has had its share of security issues in the past and is difficult to fix/test by the Security Team w/o maintainer support. Unless it finds an adopter before the Squeeze release, it should rather be removed. Cheers, Moritz -- System Inform

Bug#540635: Deprecated for Squeeze

2009-08-09 Thread Moritz Muehlenhoff
Package: glib1.2 Severity: serious glib1.2 is deprecated along with GTK 1.2. Cheers, Moritz -- System Information: Debian Release: squeeze/sid APT prefers unstable APT policy: (500, 'unstable') Architecture: i386 (i686) Kernel: Linux 2.6.30-1-686 (SMP w/1 CPU core) Locale: LANG=C, l

Removal of remaining packages using GTK 1.2

2009-05-17 Thread Moritz Muehlenhoff
As requested by the release managers here's the announcement that the remaining packages still using GTK 1.2 will be removed from testing soon now that KDE 4 has transitioned to Squeeze (kdegraphics 3 still used imlib 1 and kdebindings from KDE 3 still had bindings for GTK 1.2): icewm linpopup wmc

Bug#517888: Should be removed for Squeeze

2009-03-02 Thread Moritz Muehlenhoff
Package: gnome-libs Severity: serious gnome-libs is deprecated for Squeeze. Cheers, Moritz -- System Information: Debian Release: squeeze/sid APT prefers unstable APT policy: (500, 'unstable') Architecture: i386 (i686) Kernel: Linux 2.6.26-1-686 (SMP w/1 CPU core) Locale: LANG=C, lc

Bug#496411: #496411: nothing was fixed at all

2008-11-22 Thread Moritz Muehlenhoff
fixed 496411 20060918-3 thanks On Sun, Nov 23, 2008 at 02:23:13AM +0100, Jiri Palecek wrote: > Hello, > > On Thursday 20 November 2008 03:25:41 Raphael Geissert wrote: > > I have found all of the reported issues in BOTH versions marked as fixed. > > Please stop blindly closing this report and *do

Bug#496411: Closing

2008-11-20 Thread Moritz Muehlenhoff
On Thu, Nov 06, 2008 at 09:33:54AM +0100, Jiří Paleček wrote: > Version: 20081031+dfsg-1 > > Hello, > > I've attempted to close the bug, but have written malformed closing > statement in the changelog. Therefore, I'm closing it manually. Jiri, I saw that you've adopted LTP and prepared new pac

Bug#503702: lockvc: Segfaults.

2008-10-29 Thread Moritz Muehlenhoff
Kurt Roeckx wrote: > Package: lockvc > Version: 4.0.5-6 > Severity: serious > > Hi, > > It seems that lockvc sometimes segfaults on me. It's not doing it all > time, but atleast once a week. > > I'm setting it to serious since the console is unlocked at that point, > and so I consider it to be

Bug#496397: remove feta?

2008-08-25 Thread Moritz Muehlenhoff
On Mon, Aug 25, 2008 at 11:36:05PM +0200, Moritz Muehlenhoff wrote: > On Mon, Aug 25, 2008 at 05:44:21PM +0200, Thijs Kinkhorst wrote: > > Hi, > > > > > It's still very useful, but I don't have the time to maintain it myself. > > > Unless it becomes

Bug#496397: remove feta?

2008-08-25 Thread Moritz Muehlenhoff
On Mon, Aug 25, 2008 at 05:44:21PM +0200, Thijs Kinkhorst wrote: > Hi, > > > It's still very useful, but I don't have the time to maintain it myself. > > Unless it becomes unusable for some reason I'd like to see it kept. > > Well, it now has an RC bug about a temp file issue. No-one has turned u

Bug#487007: tapiir: diff for NMU version 0.7.1-9.1

2008-06-27 Thread Moritz Muehlenhoff
=low + + * Non-maintainer upload. + * Fix FTBFS (Closes: #487007) + + -- Moritz Muehlenhoff <[EMAIL PROTECTED]> Fri, 27 Jun 2008 21:36:51 +0200 + tapiir (0.7.1-9) unstable; urgency=medium * QA upload. diff -u tapiir-0.7.1/debian/control tapiir-0.7.1/debian/control --- tapiir-0.7.1/

Bug#462203: briquolo: diff for NMU version 0.5.6-2.1

2008-03-20 Thread Moritz Muehlenhoff
) unstable; urgency=low + + * Non-maintainer upload. + * Fix GCC 4.3 compatibility, based on initial patch by Kumar Appaiah +(Closes: #462203) + + -- Moritz Muehlenhoff <[EMAIL PROTECTED]> Fri, 21 Mar 2008 00:36:31 +0100 + briquolo (0.5.6-2) unstable; urgency=low * Orphaning package, s

Bug#455784: briquolo: segfaults with new kernel

2008-03-20 Thread Moritz Muehlenhoff
severity 455784 normal thanks On Tue, Dec 11, 2007 at 02:12:43PM -0600, Gus wrote: > Package: briquolo > Version: 0.5.5-1 > Severity: grave > Justification: renders package unusable > > *** Please type your report below this line *** > > After installing a new kernel this morning, i get segfaults

Bug#454866: lineak-defaultplugin: diff for NMU version 1:0.9-4.1

2008-03-19 Thread Moritz Muehlenhoff
/changelog @@ -1,3 +1,10 @@ +lineak-defaultplugin (1:0.9-4.1) unstable; urgency=low + + * Non-maintainer upload. + * Fix GCC 4.3 compatibility, patch by Cyril Brulebois (Closes: #454866) + + -- Moritz Muehlenhoff <[EMAIL PROTECTED]> Thu, 20 Mar 2008 01:24:26 +0100 + lineak-defaultplugin (1

Bug#133170: freetype1 deprecation

2007-07-08 Thread Moritz Muehlenhoff
severity 133170 important thanks Hi, for Lenny we'd like to stop supporting two freetype packages in the archive. freetype1 has been in oldlibs for Etch, it has very few reverse deps left and we'll try to phase it out now. Please adapt your package, so that it links against the regular freetype pa

Bug#431781: vflib3: freetype1 deprecation

2007-07-04 Thread Moritz Muehlenhoff
Package: vflib3 Severity: important Hi, for Lenny we'd like to stop supporting two freetype packages in the archive. freetype1 has been in oldlibs for Etch, it has very few reverse deps left and we'll try to phase it out now. Please adapt your package, so that it links against the regular freetype

Bug#431784: pike7.6-image: freetype1 deprecation

2007-07-04 Thread Moritz Muehlenhoff
Package: pike7.6-image Severity: important Hi, for Lenny we'd like to stop supporting two freetype packages in the archive. freetype1 has been in oldlibs for Etch, it has very few reverse deps left and we'll try to phase it out now. Please adapt your package, so that it links against the regular f

Bug#431782: vflib2: freetype1 deprecation

2007-07-04 Thread Moritz Muehlenhoff
Package: vflib2 Severity: important Hi, for Lenny we'd like to stop supporting two freetype packages in the archive. freetype1 has been in oldlibs for Etch, it has very few reverse deps left and we'll try to phase it out now. Please adapt your package, so that it links against the regular freetype

Bug#431779: tex-guy: freetype1 deprecation

2007-07-04 Thread Moritz Muehlenhoff
Package: tex-guy Severity: important Hi, for Lenny we'd like to stop supporting two freetype packages in the archive. freetype1 has been in oldlibs for Etch, it has very few reverse deps left and we'll try to phase it out now. Please adapt your package, so that it links against the regular freetyp

Bug#429338: Needs to use libphp-phpmailer

2007-06-17 Thread Moritz Muehlenhoff
Package: flyspray Severity: serious Your package includes a copy of PHPMailer, which also is packaged as libphp-phpmailer in the archive. You need to fix your package to use the system-wide library. Otherwise it requires too much overhead whenever a vulnerability in PHPMailer is found. (like right

Bug#401081: libapache2-mod-layout: Filed for removal, keep it out of Etch

2006-11-30 Thread Moritz Muehlenhoff
Package: libapache2-mod-layout Severity: grave It's been filed for removal from sid: reassign 392229 ftp.debian.org retitle 392229 RM: libapache2-mod-layout -- RoM; orphaned, buggy thanks On Wed, Nov 15, 2006 at 03:47:45PM +0100, Luk Claes wrote: > > You uploaded libapache2-mod-layout 4.0.

Bug#401079: timezoneconf: Filed for removal, keep it out of Etch

2006-11-30 Thread Moritz Muehlenhoff
Package: timezoneconf Severity: grave It's been filed for removal from sid: reassign 379035 ftp.debian.org retitle 379035 RM: timezoneconf -- RoQA; orphaned, unsupportably buggy thanks Some of the more unsupportable bugs are 275289 and 289637. Like localeconf and etherconf, this is one of

Bug#393524: hubcot-source: Doesn't compile with 2.6.18

2006-10-16 Thread Moritz Muehlenhoff
Package: hubcot-source Severity: grave Justification: renders package unusable This kernel driver is from 2001 and I've been unable to compile it against 2.6.18. Since the kernel build system is based on Kconfig nowadays the Makefile would nee rework (and most probably the driver itself as well to

Bug#390463: drupal: Shouldn't be part of Etch in the current state

2006-10-01 Thread Moritz Muehlenhoff
Package: drupal Severity: grave Drupal is currently orphaned and two major releases behind upstream. It is regularly subject to vulnerabilities being actively exploited. I've seen that there has been some interest in adopting it in June, but nothing has materialised yet (also not in NEW). The cu

Bug#373672: libjpeg-mmx: CVE-2006-3005: memory exhaustion

2006-06-15 Thread Moritz Muehlenhoff
On Wed, Jun 14, 2006 at 05:53:45PM -0500, Alec Berryman wrote: > Package: libjpeg-mmx > Severity: important > Tags: security patch > > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > CVE-2006-3005: "The JPEG library in media-libs/jpeg before 6b-r7 on > Gentoo Linux is built without the -maxme

  1   2   >