Frank Küster | 1 Apr 2011 21:00
Picon
Favicon

Re: SVN tex-common commit: r4812 - in tex-common/trunk: conf/texmf.d debian debian/po

Norbert Preining <preining <at> logic.at> wrote:

> On Di, 29 Mär 2011, Frank Küster wrote:
>> > - disable shell_escape completely, fix for DSA-2198-1, CVE-2011-1400
>> 
>> Is the rationale for this change somewhere documented?  Will upstream
>> follow the same reasoning?
>
> Reason: arbitrary code execution
> upstream ha retracted before the releae of TL2009, but we forgot
> to follow that in our texmf.cnf in tex-common. It was some time
> in TL2009 dev cycle.
>
> For TL2010 this was activated again for a very limited amount
> of programs where we verfied that no arbitrary writing outside
> the local dir etc can be done.

Ah, thanks.  We, and I, indeed bluntly forgot that:  When the activation
of a limited number of programs was discussed in TL 2010, I followed the
discussion and was sure that we had it deactivated...

Regards, Frank
--

-- 
Dr. Frank Küster
VCD Miltenberg, ADFC Aschaffenburg-Miltenberg
B90/Grüne KV Miltenberg
Debian Developer (TeXLive)

Hilmar Preusse | 2 Apr 2011 13:58
X-Face
Picon

Bug#569576: Any progress on this?

tags 569576 + upstream
severity 569576 normal
stop

On 26.05.10 Norbert Preining (preining <at> logic.at) wrote:
> On Di, 25 Mai 2010, Keith Hellman wrote:

Hi,

> > Done (see attached).  The current maintainer says this does seem to be
> > a bug.  But his time is limited :^(
> 
> Bad.
> 
For now I tag that bug upstream and lower the severity to normal.

H.
--

-- 
sigmentation fault

Debian Bug Tracking System | 2 Apr 2011 14:00
Picon

Processed: Re: Bug#569576: Any progress on this?

Processing commands for control <at> bugs.debian.org:

> tags 569576 + upstream
Bug #569576 [texlive-latex-recommended] texlive-latex-recommended: listings package shows wrong
line numbers in file listings
Added tag(s) upstream.
> severity 569576 normal
Bug #569576 [texlive-latex-recommended] texlive-latex-recommended: listings package shows wrong
line numbers in file listings
Severity set to 'normal' from 'important'

> stop
Stopping processing here.

Please contact me if you need assistance.
--

-- 
569576: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=569576
Debian Bug Tracking System
Contact owner <at> bugs.debian.org with problems

Hilmar Preusse | 2 Apr 2011 16:29
X-Face
Picon

Bug#595243: install-info: `(null) --help'

forwarded 595243 https://savannah.gnu.org/bugs/index.php?32975
stop

On 02.09.10 Krasu (ksquirrel.iv <at> gmail.com) wrote:

Dobrui den,

> In Russian locale install-info shows `(null) --help'. It is
> probably due to printf() call with a null string instead of argv[0]
> 
I forwarded your issue to upstream: https://savannah.gnu.org/bugs/index.php?32975

Thanks,
  Hilmar
--

-- 
sigmentation fault

Debian Bug Tracking System | 2 Apr 2011 16:33
Picon

Processed: Re: Bug#595243: install-info: `(null) --help'

Processing commands for control <at> bugs.debian.org:

> forwarded 595243 https://savannah.gnu.org/bugs/index.php?32975
Bug #595243 [install-info] install-info: `(null) --help'
Set Bug forwarded-to-address to 'https://savannah.gnu.org/bugs/index.php?32975'.
> stop
Stopping processing here.

Please contact me if you need assistance.
--

-- 
595243: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=595243
Debian Bug Tracking System
Contact owner <at> bugs.debian.org with problems

Cyril Brulebois | 4 Apr 2011 06:29
Picon
Favicon

Re: Bug#568109: xfonts-scalable: Utopia has been Free software for a good amount of time

Hi,

Rogério Brito <rbrito <at> ime.usp.br> (02/02/2010):
> Package: xfonts-scalable
> Version: 1:1.0.1-1
> Severity: normal
> 
> One thing that is interesting to note is that Utopia is present in
> Type 1 format in the texlive packages, but it seems that texlive
> doesn't register the fonts with X, as they are installed in a
> directory other than /usr/share/fonts: […]
>
> I would, therefore, propose some coordination between
> debian-tex-maint, debian-x and the fonts team.
> 
> Since I am interested in the fonts thing, I am willing to help, but
> I don't have many rights, as I am only a Debian Maintainer.

as far as the xfonts-scalable package is concerned, if you want fonts
to be added in there, the best way to go is reporting bugs upstream:
  https://bugs.freedesktop.org/

(Feel free to Cc me while submitting.)

As far as coordination between the various teams goes, I guess the
fonts team is the one with a fonts policy or something? I didn't check
yet, I've only ever uploaded new revisions of xfonts-* packages, only
doing some housekeeping in there (copying, build system updates, …).

KiBi.
(Continue reading)

Debian FTP Masters | 4 Apr 2011 15:01
Picon
Favicon

Processing of biblatex_1.4-1_amd64.changes

biblatex_1.4-1_amd64.changes uploaded successfully to ftp-master.debian.org
along with the files:
  biblatex_1.4-1.dsc
  biblatex_1.4.orig.tar.gz
  biblatex_1.4-1.debian.tar.gz
  biblatex_1.4-1_all.deb

Greetings,

	Your Debian queue daemon (running on host kassia.debian.org)

Debian FTP Masters | 4 Apr 2011 15:02
Picon
Favicon

Processing of etoolbox_2.1-1_amd64.changes

etoolbox_2.1-1_amd64.changes uploaded successfully to ftp-master.debian.org
along with the files:
  etoolbox_2.1-1.dsc
  etoolbox_2.1.orig.tar.gz
  etoolbox_2.1-1.debian.tar.gz
  etoolbox_2.1-1_all.deb

Greetings,

	Your Debian queue daemon (running on host kassia.debian.org)

Debian FTP Masters | 4 Apr 2011 15:02
Picon
Favicon

Processing of etoolbox_2.1-1_amd64.changes

etoolbox_2.1-1_amd64.changes uploaded successfully to localhost
along with the files:
  etoolbox_2.1-1.dsc
  etoolbox_2.1.orig.tar.gz
  etoolbox_2.1-1.debian.tar.gz
  etoolbox_2.1-1_all.deb

Greetings,

	Your Debian queue daemon (running on host franck.debian.org)

Debian FTP Masters | 4 Apr 2011 15:02
Picon
Favicon

Processing of biblatex_1.4-1_amd64.changes

biblatex_1.4-1_amd64.changes uploaded successfully to localhost
along with the files:
  biblatex_1.4-1.dsc
  biblatex_1.4.orig.tar.gz
  biblatex_1.4-1.debian.tar.gz
  biblatex_1.4-1_all.deb

Greetings,

	Your Debian queue daemon (running on host franck.debian.org)


Gmane