Debian Bug report logs - #505983
Please depend on phpCAS package instead of shipping a copy inside glpi

version graph

Package: glpi; Maintainer for glpi is Pierre Chifflier <pollux@debian.org>; Source for glpi is src:glpi.

Reported by: Olivier Berger <olivier.berger@it-sudparis.eu>

Date: Mon, 17 Nov 2008 13:42:02 UTC

Severity: normal

Fixed in version glpi/0.80.7-2

Done: Pierre Chifflier <pollux@debian.org>

Bug is archived. No further changes may be made.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, Pierre Chifflier <pollux@debian.org>:
Bug#505983; Package glpi. (Mon, 17 Nov 2008 13:42:08 GMT) Full text and rfc822 format available.

Acknowledgement sent to Olivier Berger <olivier.berger@it-sudparis.eu>:
New Bug report received and forwarded. Copy sent to Pierre Chifflier <pollux@debian.org>. (Mon, 17 Nov 2008 13:42:12 GMT) Full text and rfc822 format available.

Message #5 received at submit@bugs.debian.org (full text, mbox):

From: Olivier Berger <olivier.berger@it-sudparis.eu>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: Please depend on phpCAS package instead of shipping a copy inside glpi
Date: Mon, 17 Nov 2008 14:33:52 +0100
Package: glpi
Severity: wishlist

Hi.

You may have noticed the following RFS for libcas-php, a package that would provide phpCAS for Debian.

http://www.nabble.com/RFS%3A-libcas-php-to20539390.html

Should it enter Debian, then the glpi package should depend on it instead of shipping a copy of phpCAS.

Feel free to subscribe to the corresponding ITP for more details : #495542

Thanks in advance.



-- System Information:
Debian Release: lenny/sid
  APT prefers testing-proposed-updates
  APT policy: (500, 'testing-proposed-updates'), (500, 'testing')
Architecture: i386 (i686)

Kernel: Linux 2.6.26-1-openvz-686 (SMP w/2 CPU cores)
Locale: LANG=fr_FR.UTF-8, LC_CTYPE=fr_FR.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/bash

Versions of packages glpi depends on:
ii  apache2                       2.2.9-10   Apache HTTP Server metapackage
ii  apache2-mpm-prefork [apache2] 2.2.9-10   Apache HTTP Server - traditional n
pn  dbconfig-common               <none>     (no description available)
ii  debconf [debconf-2.0]         1.5.24     Debian configuration management sy
ii  libapache2-mod-php5           5.2.6-5    server-side, HTML-embedded scripti
ii  php5                          5.2.6-5    server-side, HTML-embedded scripti
ii  php5-mysql                    5.2.6-5    MySQL module for php5

glpi recommends no packages.

glpi suggests no packages.




Information forwarded to debian-bugs-dist@lists.debian.org, Pierre Chifflier <pollux@debian.org>:
Bug#505983; Package glpi. (Fri, 01 Jul 2011 09:16:05 GMT) Full text and rfc822 format available.

Acknowledgement sent to Gonéri Le Bouder <goneri@rulezlan.org>:
Extra info received and forwarded to list. Copy sent to Pierre Chifflier <pollux@debian.org>. (Fri, 01 Jul 2011 09:16:10 GMT) Full text and rfc822 format available.

Message #10 received at 505983@bugs.debian.org (full text, mbox):

From: Gonéri Le Bouder <goneri@rulezlan.org>
To: 505983@bugs.debian.org
Cc: control@bugs.debian.org
Subject: Re: Bug#505983: Please depend on phpCAS package instead of shipping a copy inside glpi
Date: Fri, 1 Jul 2011 11:11:35 +0200
severity 505983 normal
thanks

Hi,

This is a violation of the Policy, section 4.13 and so a real bug.
See: http://www.debian.org/doc/debian-policy/ch-source.html#s-embeddedfiles

Best regards,

     Gonéri




Severity set to 'normal' from 'wishlist' Request was from Gonéri Le Bouder <goneri@rulezlan.org> to control@bugs.debian.org. (Fri, 01 Jul 2011 09:16:14 GMT) Full text and rfc822 format available.

Reply sent to Pierre Chifflier <pollux@debian.org>:
You have taken responsibility. (Sat, 10 Mar 2012 12:07:23 GMT) Full text and rfc822 format available.

Notification sent to Olivier Berger <olivier.berger@it-sudparis.eu>:
Bug acknowledged by developer. (Sat, 10 Mar 2012 12:08:28 GMT) Full text and rfc822 format available.

Message #17 received at 505983-close@bugs.debian.org (full text, mbox):

From: Pierre Chifflier <pollux@debian.org>
To: 505983-close@bugs.debian.org
Subject: Bug#505983: fixed in glpi 0.80.7-2
Date: Sat, 10 Mar 2012 12:03:49 +0000
Source: glpi
Source-Version: 0.80.7-2

We believe that the bug you reported is fixed in the latest version of
glpi, which is due to be installed in the Debian FTP archive:

glpi_0.80.7-2.debian.tar.gz
  to main/g/glpi/glpi_0.80.7-2.debian.tar.gz
glpi_0.80.7-2.dsc
  to main/g/glpi/glpi_0.80.7-2.dsc
glpi_0.80.7-2_all.deb
  to main/g/glpi/glpi_0.80.7-2_all.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 505983@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Pierre Chifflier <pollux@debian.org> (supplier of updated glpi package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Sat, 10 Mar 2012 11:41:05 +0100
Source: glpi
Binary: glpi
Architecture: source all
Version: 0.80.7-2
Distribution: unstable
Urgency: high
Maintainer: Pierre Chifflier <pollux@debian.org>
Changed-By: Pierre Chifflier <pollux@debian.org>
Description: 
 glpi       - IT and Asset management software
Closes: 429344 505983 662944
Changes: 
 glpi (0.80.7-2) unstable; urgency=high
 .
   * Do not install embedded copy of phpCAS (Closes: #505983, #662944)
     As phpCAS is not yet packaged, this removes the related functionality.
     If you need phpCAS, see the README.Debian file for instructions.
     This closes the following security problems: CVE-2012-1104 CVE-2012-1105
   * Bump Standards Version to 3.9.3
   * Remove embedded code copy of tinymce, and depend on the Debian package
   * Remove embedded code copy of phpmailer, and replace it by the Debian
     package (Closes: #429344)
Checksums-Sha1: 
 3dd748f6fa15a852e57faba4cb824ba7a2a4de98 1638 glpi_0.80.7-2.dsc
 ba75b4b388eb5c2520124259eb64fdaa8c5ec434 16382 glpi_0.80.7-2.debian.tar.gz
 a5339cd99209447859628cbea45eed23eef7d6e5 3466814 glpi_0.80.7-2_all.deb
Checksums-Sha256: 
 b1296bb1241b43310bae1cfa503b3b6caca178375f9b4fca5de551185be5dcde 1638 glpi_0.80.7-2.dsc
 f31f33c583289cd4fed88a60761d5224186c0f36e71370dc417370d1e34314ab 16382 glpi_0.80.7-2.debian.tar.gz
 a02e6fdb33dce7b5e1390afeaeb6d263d5b0f0399e062351945135f6e75e403e 3466814 glpi_0.80.7-2_all.deb
Files: 
 ad4c59b30030cb249ad60f360a0249f8 1638 web optional glpi_0.80.7-2.dsc
 6321a8a4cedfa0f9a4fe8fd715240988 16382 web optional glpi_0.80.7-2.debian.tar.gz
 ec33655d94ca4ee5e6a40e4a10870f21 3466814 web optional glpi_0.80.7-2_all.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQIcBAEBCAAGBQJPWzBmAAoJEMYaZNzxOTmY2UcP/3LjSyibjtbodgSAjjW87ozA
VgXgkfhI7l07OlsWnE5zmtEDRXvJA073M6US5W4jHaaV6COXlTk2TyvuDyuJUC/B
ihixgXBuofTvXBTJXFb6WkCa4r3xu+XQASoOfgofRMMnHxpuaktXB7VTudlfpyh/
YjLyx+dbMw/GqlU3m/pQFam2NyDhdqCcjhBVeIpxevDlHXbx7EpvIDALBA8E8gjn
LZmOQhndkwN6aDtqOB+nT5aBaU3hia+U21TyTxHqkzddqk4e1xpJ03H7dPbV25W6
3Cl5nuerf4bCoIGIlBfUfl7LF5VMsTHThOlAOjcMi4dLsOIIKQPfvqmk+ucNvgPE
WjXnIQMZT8l2T22BBUwVvvpQyoCnrJiUGiluuDndM9WI0vs7An/yoBCwxIVIvP67
u5DswvLn/GVm9AG9PbklihWPm1+/Q63tVi2m61TSuK84We0mAlnR9aTgsjIW248N
9j61F6ddIjKIXgDH/d3adAUF0mwPHRGjz8oPyt4D/6MvAajptkriT90nTQu5NPVr
0HoSSwepVMvvOpe5fuIphdQ/0xUsAmBrX0Y26+Fmva2tUoZAEIU+GE9QQl/A66f9
cbXf7xgyA6q3vB6LyKBXzIk9XAJsUVarHGJh5NBCB//+hH5+iKlu4VRVrpZaAJgs
dSnOpwGf4mfO7jJBYKfH
=ET7b
-----END PGP SIGNATURE-----





Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Tue, 10 Apr 2012 07:41:24 GMT) Full text and rfc822 format available.

Bug unarchived. Request was from Olivier Berger <obergix@debian.org> to control@bugs.debian.org. (Thu, 28 Jun 2012 20:30:07 GMT) Full text and rfc822 format available.

Information forwarded to debian-bugs-dist@lists.debian.org, Pierre Chifflier <pollux@debian.org>:
Bug#505983; Package glpi. (Thu, 28 Jun 2012 20:57:02 GMT) Full text and rfc822 format available.

Acknowledgement sent to Olivier Berger <olivier.berger@it-sudparis.eu>:
Extra info received and forwarded to list. Copy sent to Pierre Chifflier <pollux@debian.org>. (Thu, 28 Jun 2012 20:57:03 GMT) Full text and rfc822 format available.

Message #26 received at 505983@bugs.debian.org (full text, mbox):

From: Olivier Berger <olivier.berger@it-sudparis.eu>
To: glpi@packages.qa.debian.org
Cc: 505983@bugs.debian.org
Subject: GLPI and php-cas - Was: Re: Bug#505983 closed by Pierre Chifflier <pollux@debian.org> (Bug#505983: fixed in glpi 0.80.7-2)
Date: Thu, 28 Jun 2012 22:55:05 +0200
Hi.

FYI, php-cas has entered unstable (http://packages.qa.debian.org/p/php-cas.html).

Maybe it's time to adjust some of the GLPI packaging so that it can use it again, and from system library, provided that the packaged version is indeed supported.

Hope this helps.

Best regards,

On Sat, Mar 10, 2012 at 12:08:28PM +0000, Debian Bug Tracking System wrote:
> This is an automatic notification regarding your Bug report
> which was filed against the glpi package:
> 
> #505983: Please depend on phpCAS package instead of shipping a copy inside glpi
> 
> It has been closed by Pierre Chifflier <pollux@debian.org>.
> 
> Their explanation is attached below along with your original report.
> If this explanation is unsatisfactory and you have not received a
> better one in a separate message then please contact Pierre Chifflier <pollux@debian.org> by
> replying to this email.
> 
> 
> -- 
> 505983: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=505983
> Debian Bug Tracking System
> Contact owner@bugs.debian.org with problems

> Date: Sat, 10 Mar 2012 12:03:49 +0000
> From: Pierre Chifflier <pollux@debian.org>
> To: 505983-close@bugs.debian.org
> Subject: Bug#505983: fixed in glpi 0.80.7-2
> 
> Source: glpi
> Source-Version: 0.80.7-2
> 
> We believe that the bug you reported is fixed in the latest version of
> glpi, which is due to be installed in the Debian FTP archive:
> 
> glpi_0.80.7-2.debian.tar.gz
>   to main/g/glpi/glpi_0.80.7-2.debian.tar.gz
> glpi_0.80.7-2.dsc
>   to main/g/glpi/glpi_0.80.7-2.dsc
> glpi_0.80.7-2_all.deb
>   to main/g/glpi/glpi_0.80.7-2_all.deb
> 
> 
> 
> A summary of the changes between this version and the previous one is
> attached.
> 
> Thank you for reporting the bug, which will now be closed.  If you
> have further comments please address them to 505983@bugs.debian.org,
> and the maintainer will reopen the bug report if appropriate.
> 
> Debian distribution maintenance software
> pp.
> Pierre Chifflier <pollux@debian.org> (supplier of updated glpi package)
> 
> (This message was generated automatically at their request; if you
> believe that there is a problem with it please contact the archive
> administrators by mailing ftpmaster@debian.org)
> 
> 
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA256
> 
> Format: 1.8
> Date: Sat, 10 Mar 2012 11:41:05 +0100
> Source: glpi
> Binary: glpi
> Architecture: source all
> Version: 0.80.7-2
> Distribution: unstable
> Urgency: high
> Maintainer: Pierre Chifflier <pollux@debian.org>
> Changed-By: Pierre Chifflier <pollux@debian.org>
> Description: 
>  glpi       - IT and Asset management software
> Closes: 429344 505983 662944
> Changes: 
>  glpi (0.80.7-2) unstable; urgency=high
>  .
>    * Do not install embedded copy of phpCAS (Closes: #505983, #662944)
>      As phpCAS is not yet packaged, this removes the related functionality.
>      If you need phpCAS, see the README.Debian file for instructions.
>      This closes the following security problems: CVE-2012-1104 CVE-2012-1105
>    * Bump Standards Version to 3.9.3
>    * Remove embedded code copy of tinymce, and depend on the Debian package
>    * Remove embedded code copy of phpmailer, and replace it by the Debian
>      package (Closes: #429344)
> Checksums-Sha1: 
>  3dd748f6fa15a852e57faba4cb824ba7a2a4de98 1638 glpi_0.80.7-2.dsc
>  ba75b4b388eb5c2520124259eb64fdaa8c5ec434 16382 glpi_0.80.7-2.debian.tar.gz
>  a5339cd99209447859628cbea45eed23eef7d6e5 3466814 glpi_0.80.7-2_all.deb
> Checksums-Sha256: 
>  b1296bb1241b43310bae1cfa503b3b6caca178375f9b4fca5de551185be5dcde 1638 glpi_0.80.7-2.dsc
>  f31f33c583289cd4fed88a60761d5224186c0f36e71370dc417370d1e34314ab 16382 glpi_0.80.7-2.debian.tar.gz
>  a02e6fdb33dce7b5e1390afeaeb6d263d5b0f0399e062351945135f6e75e403e 3466814 glpi_0.80.7-2_all.deb
> Files: 
>  ad4c59b30030cb249ad60f360a0249f8 1638 web optional glpi_0.80.7-2.dsc
>  6321a8a4cedfa0f9a4fe8fd715240988 16382 web optional glpi_0.80.7-2.debian.tar.gz
>  ec33655d94ca4ee5e6a40e4a10870f21 3466814 web optional glpi_0.80.7-2_all.deb
> 
> -----BEGIN PGP SIGNATURE-----
> Version: GnuPG v1.4.12 (GNU/Linux)
> 
> iQIcBAEBCAAGBQJPWzBmAAoJEMYaZNzxOTmY2UcP/3LjSyibjtbodgSAjjW87ozA
> VgXgkfhI7l07OlsWnE5zmtEDRXvJA073M6US5W4jHaaV6COXlTk2TyvuDyuJUC/B
> ihixgXBuofTvXBTJXFb6WkCa4r3xu+XQASoOfgofRMMnHxpuaktXB7VTudlfpyh/
> YjLyx+dbMw/GqlU3m/pQFam2NyDhdqCcjhBVeIpxevDlHXbx7EpvIDALBA8E8gjn
> LZmOQhndkwN6aDtqOB+nT5aBaU3hia+U21TyTxHqkzddqk4e1xpJ03H7dPbV25W6
> 3Cl5nuerf4bCoIGIlBfUfl7LF5VMsTHThOlAOjcMi4dLsOIIKQPfvqmk+ucNvgPE
> WjXnIQMZT8l2T22BBUwVvvpQyoCnrJiUGiluuDndM9WI0vs7An/yoBCwxIVIvP67
> u5DswvLn/GVm9AG9PbklihWPm1+/Q63tVi2m61TSuK84We0mAlnR9aTgsjIW248N
> 9j61F6ddIjKIXgDH/d3adAUF0mwPHRGjz8oPyt4D/6MvAajptkriT90nTQu5NPVr
> 0HoSSwepVMvvOpe5fuIphdQ/0xUsAmBrX0Y26+Fmva2tUoZAEIU+GE9QQl/A66f9
> cbXf7xgyA6q3vB6LyKBXzIk9XAJsUVarHGJh5NBCB//+hH5+iKlu4VRVrpZaAJgs
> dSnOpwGf4mfO7jJBYKfH
> =ET7b
> -----END PGP SIGNATURE-----
> 
> 

> Date: Mon, 17 Nov 2008 14:33:52 +0100
> From: Olivier Berger <olivier.berger@it-sudparis.eu>
> To: Debian Bug Tracking System <submit@bugs.debian.org>
> Subject: Please depend on phpCAS package instead of shipping a copy inside
>  glpi
> X-Mailer: reportbug 3.45
> 
> Package: glpi
> Severity: wishlist
> 
> Hi.
> 
> You may have noticed the following RFS for libcas-php, a package that would provide phpCAS for Debian.
> 
> http://www.nabble.com/RFS%3A-libcas-php-to20539390.html
> 
> Should it enter Debian, then the glpi package should depend on it instead of shipping a copy of phpCAS.
> 
> Feel free to subscribe to the corresponding ITP for more details : #495542
> 
> Thanks in advance.
> 
> 
> 
> -- System Information:
> Debian Release: lenny/sid
>   APT prefers testing-proposed-updates
>   APT policy: (500, 'testing-proposed-updates'), (500, 'testing')
> Architecture: i386 (i686)
> 
> Kernel: Linux 2.6.26-1-openvz-686 (SMP w/2 CPU cores)
> Locale: LANG=fr_FR.UTF-8, LC_CTYPE=fr_FR.UTF-8 (charmap=UTF-8)
> Shell: /bin/sh linked to /bin/bash
> 
> Versions of packages glpi depends on:
> ii  apache2                       2.2.9-10   Apache HTTP Server metapackage
> ii  apache2-mpm-prefork [apache2] 2.2.9-10   Apache HTTP Server - traditional n
> pn  dbconfig-common               <none>     (no description available)
> ii  debconf [debconf-2.0]         1.5.24     Debian configuration management sy
> ii  libapache2-mod-php5           5.2.6-5    server-side, HTML-embedded scripti
> ii  php5                          5.2.6-5    server-side, HTML-embedded scripti
> ii  php5-mysql                    5.2.6-5    MySQL module for php5
> 
> glpi recommends no packages.
> 
> glpi suggests no packages.
> 
> 


-- 
Olivier BERGER 
http://www-public.it-sudparis.eu/~berger_o/ - OpenPGP-Id: 2048R/5819D7E8
Ingenieur Recherche - Dept INF
Institut Mines-Telecom, Telecom SudParis, Evry (France)





Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Fri, 27 Jul 2012 07:32:21 GMT) Full text and rfc822 format available.

Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Apr 16 19:04:12 2014; Machine Name: beach.debian.org

Debian Bug tracking system
Copyright (C) 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson.