[Bug 877740] Re: CVE-2011-3368 Apache2 mod_proxy reverse proxy exposure

2011-10-25 Thread Michael Jeanson
My bad, sorry if anyone tried this package, I had only tested on hardy. I uploaded a fixed package to my ppa. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to apache2 in Ubuntu. https://bugs.launchpad.net/bugs/877740 Title: CVE-2011-3

[Bug 877740] Re: CVE-2011-3368 Apache2 mod_proxy reverse proxy exposure

2011-10-19 Thread Michael Jeanson
Debdiff for lucid, also available in my ppa. ** Patch added: "apache2_2.2.14-5ubuntu8.7.debdiff" https://bugs.launchpad.net/ubuntu/hardy/+source/apache2/+bug/877740/+attachment/2560947/+files/apache2_2.2.14-5ubuntu8.7.debdiff -- You received this bug notification because you are a member of

[Bug 877740] Re: CVE-2011-3368 Apache2 mod_proxy reverse proxy exposure

2011-10-19 Thread Michael Jeanson
I built a fixed package for hardy in my ppa (2.2.8-1ubuntu0.22~ppa1) and tested it in our environment, I confirm it fixes the exploit. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to apache2 in Ubuntu. https://bugs.launchpad.net/bugs/87

[Bug 877740] Re: CVE-2011-3368 Apache2 mod_proxy reverse proxy exposure

2011-10-18 Thread Michael Jeanson
Debdiff for hardy, including patch from http://www.apache.org/dist/httpd/patches/apply_to_2.2.21/CVE-2011-3368.patch ** Patch added: "apache2_2.2.8-1ubuntu0.22.debdiff" https://bugs.launchpad.net/ubuntu/+source/apache2/+bug/877740/+attachment/2558586/+files/apache2_2.2.8-1ubuntu0.22.debdiff -

[Bug 877740] [NEW] CVE-2011-3368 Apache2 mod_proxy reverse proxy exposure

2011-10-18 Thread Michael Jeanson
*** This bug is a security vulnerability *** Public security bug reported: The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configur

[Bug 632554] Re: tomcat fails to start with: /bin/bash already running.

2010-12-08 Thread Michael Jeanson
SRU for lucid (https://wiki.ubuntu.com/StableReleaseUpdates) 1. Impact : If tomcat6 is runned under a user that has a running bash process, trying to start or restart the service will fail. 2. Fix in development version : The fix is a oneliner in the initscript, add the missing -p option in sta

[Bug 513273] Re: kvm with -vga std is broken since karmic

2010-03-05 Thread Michael Jeanson
Tested 0.12.3-0ubuntu5~ppa3 with libvirt using : -- kvm with -vga std is broken since karmic https://bugs.launchpad.net/bugs/513273 You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to qemu-kvm in ubuntu. -- Ubuntu-server-bu

[Bug 513273] Re: kvm with -vga std give error and do not works

2010-03-01 Thread Michael Jeanson
Using" -vga std" with the default bios files, it won't boot and I get : unaligned pointer 0x8ecc0002 Aborted. Press any key to exit. I built the bios files from the qemu-kvm package source and using those with the "-L" switch it works. -- kvm with -vga std give error and do not works https://bu

[Bug 492093] Re: Sync munin 1.4.3-2 (main) from Debian unstable (main)

2010-02-23 Thread Michael Jeanson
MIR done in bug #526480 -- Sync munin 1.4.3-2 (main) from Debian unstable (main) https://bugs.launchpad.net/bugs/492093 You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to munin in ubuntu. -- Ubuntu-server-bugs mailing list Ubuntu-server-bug

[Bug 492093] Re: Sync munin 1.4.0-1 (main) from Debian unstable (main)

2009-12-16 Thread Michael Jeanson
I wrote the MIR at https://wiki.ubuntu.com/MIRliblog-log4perl-perl but by doing so, I discovered that the package build-depends on 2 packages in universe who in turn depends on 3 packages in universe. This means we have 5 other MIRs to write, right? -- Sync munin 1.4.0-1 (main) from Debian unstab

[Bug 492093] Re: Sync munin 1.4.0-1 (main) from Debian unstable (main)

2009-12-15 Thread Michael Jeanson
On it. -- Sync munin 1.4.0-1 (main) from Debian unstable (main) https://bugs.launchpad.net/bugs/492093 You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to munin in ubuntu. -- Ubuntu-server-bugs mailing list Ubuntu-server-bugs@lists.ubuntu.co

[Bug 492093] Re: Sync munin 1.4.0-1 (main) from Debian unstable (main)

2009-12-03 Thread Michael Jeanson
Munin 1.4.0 is the new stable release, the 1.2.x tree won't get much love from now on. This would be nice to have in the LTS. -- Sync munin 1.4.0-1 (main) from Debian unstable (main) https://bugs.launchpad.net/bugs/492093 You received this bug notification because you are a member of Ubuntu Serve

[Bug 492093] [NEW] Sync munin 1.4.0-1 (main) from Debian unstable (main)

2009-12-03 Thread Michael Jeanson
Public bug reported: Please sync munin 1.4.0-1 (main) from Debian unstable (main) Explanation of the Ubuntu delta and why it can be dropped: * Suugest libdate-manip-perl (LP: #306274) : - It's now a recommend in the Debian package * Recommend "cron". (LP: #225061) - It's now a depend in the

[Bug 458521] Re: kvm crash when using virtio for network, hardy guest

2009-11-03 Thread Michael Jeanson
I installed the package from proposed and it solved the problem for me. I ran the test provided in this bug report and some file tranfers with scp that used to crash and it worked flawlessly. -- kvm crash when using virtio for network, hardy guest https://bugs.launchpad.net/bugs/458521 You receiv

[Bug 340120] Re: OpenVPN unexpected operator on startup

2009-03-09 Thread Michael Jeanson
Here is the debdiff containing the patch. ** Attachment added: "openvpn_2.1~rc11-1ubuntu3.debdiff" http://launchpadlibrarian.net/23671320/openvpn_2.1%7Erc11-1ubuntu3.debdiff -- OpenVPN unexpected operator on startup https://bugs.launchpad.net/bugs/340120 You received this bug notification bec

[Bug 340120] Re: OpenVPN unexpected operator on startup

2009-03-09 Thread Michael Jeanson
** Changed in: openvpn (Ubuntu) Assignee: (unassigned) => Michael Jeanson (mjeanson) Status: New => In Progress -- OpenVPN unexpected operator on startup https://bugs.launchpad.net/bugs/340120 You received this bug notification because you are a member of Ubuntu Server Team, wh

[Bug 282456] Re: redhat-cluster-suite metapackage should include system-config-cluster

2009-02-26 Thread Michael Jeanson
Same thing on hardy, but it should really be in suggested packages. I don't want the gui to be installed on all my nodes. -- redhat-cluster-suite metapackage should include system-config-cluster https://bugs.launchpad.net/bugs/282456 You received this bug notification because you are a member of

[Bug 220724] Re: Assertion error in schema_init.c:366: octetStringIndexer

2008-04-25 Thread Michael Jeanson
Here is how I reproduced the bug: # Download and extract bug220724.tar.gz, then install the packages. apt-get install slapd ldap-utils # Copy the configuration cp -r bug220724/ldap/schema /etc/ldap/ cp bug220724/ldap/slapd.conf /etc/ldap/ # Stop the service /etc/init.d/slapd stop # Generate the

[Bug 220724] Re: Assertion error in schema_init.c:366: octetStringIndexer

2008-04-22 Thread Michael Jeanson
Here is a patch containing the fix, it's working fine on my servers. ** Attachment added: "fix-modify" http://launchpadlibrarian.net/13829941/fix-modify -- Assertion error in schema_init.c:366: octetStringIndexer https://bugs.launchpad.net/bugs/220724 You received this bug notification becaus

[Bug 220724] [NEW] Assertion error in schema_init.c:366: octetStringIndexer

2008-04-22 Thread Michael Jeanson
Public bug reported: Using slapd 2.4.7-6ubuntu3 on hardy i386, I get random crashes in modify operations. Log : oc_check_allowed type "modifyTimestamp" slapd: /build/buildd/openldap2.3-2.4.7/servers/slapd/schema_init.c:366: octetStringIndexer: Assertion `i > 0' failed. Abandon There is a debian