[Bug 1352504] Re: Regression in 2.11.1-0ubuntu7.14; segfault in getservbyname

2014-08-05 Thread Alex Vandiver
Confirmed that fixes the problem for me. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1352504 Title: Regression in 2.11.1-0ubuntu7.14; segfault in getservbyname To manage notifications about this

[Bug 1352504] [NEW] Regression in 2.11.1-0ubuntu7.14; segfault in getservbyname

2014-08-04 Thread Alex Vandiver
Public bug reported: After taking security updates to 2.11.1-0ubuntu7.14 on Lucid, calls to getservbyname() are causing segfaults; backtrace attached. I suspect a failure in debian/patches/any/CVE-2013-4357.diff nscd is installed and in use as a caching layer for openldap, which use used for

[Bug 1352504] Re: Regression in 2.11.1-0ubuntu7.14; segfault in getservbyname

2014-08-04 Thread Alex Vandiver
Please apply https://sourceware.org/git/?p=glibc.git;a=commitdiff;h=c8fc0c91 which I believe will fix the segfault. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1352504 Title: Regression in

[Bug 1352504] Re: Regression in 2.11.1-0ubuntu7.14; segfault in getservbyname

2014-08-04 Thread Alex Vandiver
** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2013-4357 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1352504 Title: Regression in 2.11.1-0ubuntu7.14; segfault in getservbyname

Re: [Bug 1192367] Re: No security release provided in Lucid for CVE-2013-3567

2013-06-20 Thread Alex Vandiver
On Wed, 2013-06-19 at 11:55 +, Marc Deslauriers wrote: That file is the authoritative list of packages supported by the security team, and contains the list the packages we deemed able to support for 5 years instead of the base 3 years. Understood, and not unreasonable. However, I did not

Re: [Bug 1192367] Re: No security release provided in Lucid for CVE-2013-3567

2013-06-20 Thread Alex Vandiver
On Thu, 2013-06-20 at 18:13 +, Marc Deslauriers wrote: Yes, we realized that the exact list wasn't very exposed in locations where people would look. I've now added it to the Lucid release manifest wiki page, which is linked from the releases wiki page:

Re: [Bug 1192367] Re: No security release provided in Lucid for CVE-2013-3567

2013-06-20 Thread Alex Vandiver
On Wed, 2013-06-19 at 11:55 +, Marc Deslauriers wrote: That file is the authoritative list of packages supported by the security team, and contains the list the packages we deemed able to support for 5 years instead of the base 3 years. Understood, and not unreasonable. However, I did not

Re: [Bug 1192367] Re: No security release provided in Lucid for CVE-2013-3567

2013-06-20 Thread Alex Vandiver
On Thu, 2013-06-20 at 18:13 +, Marc Deslauriers wrote: Yes, we realized that the exact list wasn't very exposed in locations where people would look. I've now added it to the Lucid release manifest wiki page, which is linked from the releases wiki page:

[Bug 1192367] [NEW] No security release provided for CVE-2013-3567

2013-06-18 Thread Alex Vandiver
Public bug reported: Lucid's version of puppet is listed as ignored (reached end-of-life) on the CVE tracking page for CVE-2013-3567 [1]. However, Ubuntu Lucid has not reached end-of-life for the server release -- indeed, `apt-cache show puppet` shows Supported: 5y. The Ubuntu wiki[2] states

[Bug 1192367] Re: No security release provided for CVE-2013-3567

2013-06-18 Thread Alex Vandiver
** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2013-3567 -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to puppet in Ubuntu. https://bugs.launchpad.net/bugs/1192367 Title: No security release provided for

[Bug 1192367] [NEW] No security release provided for CVE-2013-3567

2013-06-18 Thread Alex Vandiver
Public bug reported: Lucid's version of puppet is listed as ignored (reached end-of-life) on the CVE tracking page for CVE-2013-3567 [1]. However, Ubuntu Lucid has not reached end-of-life for the server release -- indeed, `apt-cache show puppet` shows Supported: 5y. The Ubuntu wiki[2] states

[Bug 1192367] Re: No security release provided for CVE-2013-3567

2013-06-18 Thread Alex Vandiver
** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2013-3567 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1192367 Title: No security release provided for CVE-2013-3567 To manage

[Bug 423252] Re: NSS using LDAP+SSL breaks setuid applications like su, sudo, apache2 suexec, and atd

2012-03-11 Thread Alex Vandiver
I can confirm that the use nscd workaround no longer works in the current Precise beta. This will cause anyone updating from the current LTS to the forthcoming LTS to be unable to run su, sudo, apache2 suexec, and atd from LDAP accounts. -- You received this bug notification because you are a

[Bug 423252] Re: NSS using LDAP+SSL breaks setuid applications like su, sudo, apache2 suexec, and atd

2012-03-11 Thread Alex Vandiver
I can confirm that the use nscd workaround no longer works in the current Precise beta. This will cause anyone updating from the current LTS to the forthcoming LTS to be unable to run su, sudo, apache2 suexec, and atd from LDAP accounts. -- You received this bug notification because you are a

[Bug 769765] Re: Missing dependency for libapache-dbi-perl

2011-12-02 Thread Alex Vandiver
I just took a quick look at this, and replicated it. However, libapache-dbi-perl _is_ in the dependencies of rt3.8-apache2, but because of the way the dependencies have been phrased, apt decides to install speedy-cgi-perl is a fine stand-in for libapache-dbi-perl, and installs that instead. I

[Bug 778184] Re: package request-tracker3.8 3.8.10-1 failed to install/upgrade: ErrorMessage: subprocess installed post-installation script returned error exit status 1

2011-10-03 Thread Alex Vandiver
** Changed in: request-tracker3.8 (Ubuntu) Status: New = Invalid -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/778184 Title: package request-tracker3.8 3.8.10-1 failed to install/upgrade:

[Bug 444046] Re: rt-setup-database-3.8 does not seem to work

2011-10-03 Thread Alex Vandiver
4.0-trunk has just merged a branch which explicitly disables empty branch names at configure time, which may catch this flavor of user error earlier. ** Changed in: request-tracker3.8 (Ubuntu) Status: New = Invalid -- You received this bug notification because you are a member of Ubuntu

[Bug 524281] Re: Tens of wakes per second in [kernel scheduler] Load balancing tick on Core 2 Duo even with only 1 core enabled

2010-12-06 Thread Alex Vandiver
The commit to backport would be 83cd4fe, which has many more changes than just to kernel/time/tick-sched.c You can look at the complete diff at https://github.com/mirrors/linux-2.6/commit/83cd4fe af5ab27 might also help somewhat, but I believe the other one is the major culprit. -- You

[Bug 377367] Re: gnome-terminal doesn't handle colons in URLs

2010-11-02 Thread Alex Vandiver
** Branch linked: lp:~ubuntu-desktop/gnome-terminal/ubuntu -- gnome-terminal doesn't handle colons in URLs https://bugs.launchpad.net/bugs/377367 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mailing list

[Bug 377367] Re: gnome-terminal doesn't handle colons in URLs

2010-11-02 Thread Alex Vandiver
** Branch unlinked: lp:~ubuntu-desktop/gnome-terminal/ubuntu -- gnome-terminal doesn't handle colons in URLs https://bugs.launchpad.net/bugs/377367 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mailing list