lilypond: CVE-2017-17523

Related Vulnerabilities: CVE-2017-17523   CVE-2018-10992  

Debian Bug report logs - #884136
lilypond: CVE-2017-17523

version graph

Reported by: Salvatore Bonaccorso <carnil@debian.org>

Date: Mon, 11 Dec 2017 20:15:01 UTC

Severity: important

Tags: confirmed, security, upstream

Found in version lilypond/2.18.2-4

Fixed in versions lilypond/2.18.2-13, lilypond/2.19.81-1~exp1, lilypond/2.18.2-12

Done: toddy@debian.org (Dr. Tobias Quathamer)

Bug is archived. No further changes may be made.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, carnil@debian.org, team@security.debian.org, secure-testing-team@lists.alioth.debian.org, team@security.debian.org, secure-testing-team@lists.alioth.debian.org, Don Armstrong <don@debian.org>:
Bug#884136; Package src:lilypond. (Mon, 11 Dec 2017 20:15:04 GMT) (full text, mbox, link).


Acknowledgement sent to Salvatore Bonaccorso <carnil@debian.org>:
New Bug report received and forwarded. Copy sent to carnil@debian.org, team@security.debian.org, secure-testing-team@lists.alioth.debian.org, team@security.debian.org, secure-testing-team@lists.alioth.debian.org, Don Armstrong <don@debian.org>. (Mon, 11 Dec 2017 20:15:04 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Salvatore Bonaccorso <carnil@debian.org>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: lilypond: CVE-2017-17523
Date: Mon, 11 Dec 2017 21:10:13 +0100
Source: lilypond
Version: 2.18.2-4
Severity: important
Tags: security upstream

Hi,

the following vulnerability was published for lilypond.

For a description of the issue see [1], in the "Similar
vulnerabilities in other packages" section.

CVE-2017-17523[0]:
| lilypond-invoke-editor in LilyPond 2.19.80 does not validate strings
| before launching the program specified by the BROWSER environment
| variable, which allows remote attackers to conduct argument-injection
| attacks via a crafted URL, as demonstrated by a --proxy-pac-file
| argument.

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2017-17523
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17523
[1] https://bugs.debian.org/881767

Regards,
Salvatore



Information forwarded to debian-bugs-dist@lists.debian.org, Don Armstrong <don@debian.org>:
Bug#884136; Package src:lilypond. (Mon, 11 Dec 2017 21:54:03 GMT) (full text, mbox, link).


Message #8 received at 884136@bugs.debian.org (full text, mbox, reply):

From: Don Armstrong <don@donarmstrong.com>
To: Salvatore Bonaccorso <carnil@debian.org>, 884136@bugs.debian.org
Subject: Re: Bug#884136: lilypond: CVE-2017-17523
Date: Mon, 11 Dec 2017 13:51:31 -0800
Control: forward -1 https://sourceforge.net/p/testlilyissues/issues/5243/

On Mon, 11 Dec 2017, Salvatore Bonaccorso wrote:
> If you fix the vulnerability please also make sure to include the
> CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

Thanks! This is being addressed upstream in
https://sourceforge.net/p/testlilyissues/issues/5243/; as soon as there
is a fix there with review, we'll backport it.

-- 
Don Armstrong                      https://www.donarmstrong.com

What prison taught me was that some people are born into a life where
they're going to be subjected to intense life experiences and personal
tragedy on an almost daily basis. [...] I don't think you get
enlightenment after something like that. I think all anyone really
wants, if they're honest with themselves, is a quiet, easy life
surrounded by people that love them. Anything else is a conceit.
 -- OP from 99chan



Reply sent to toddy@debian.org (Dr. Tobias Quathamer):
You have taken responsibility. (Mon, 29 Jan 2018 21:09:03 GMT) (full text, mbox, link).


Notification sent to Salvatore Bonaccorso <carnil@debian.org>:
Bug acknowledged by developer. (Mon, 29 Jan 2018 21:09:03 GMT) (full text, mbox, link).


Message #13 received at 884136-close@bugs.debian.org (full text, mbox, reply):

From: toddy@debian.org (Dr. Tobias Quathamer)
To: 884136-close@bugs.debian.org
Subject: Bug#884136: fixed in lilypond 2.18.2-12
Date: Mon, 29 Jan 2018 21:07:27 +0000
Source: lilypond
Source-Version: 2.18.2-12

We believe that the bug you reported is fixed in the latest version of
lilypond, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 884136@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Dr. Tobias Quathamer <toddy@debian.org> (supplier of updated lilypond package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Mon, 29 Jan 2018 20:59:58 +0100
Source: lilypond
Binary: lilypond lilypond-data lilypond-doc lilypond-doc-pdf lilypond-doc-html lilypond-doc-html-cs lilypond-doc-html-de lilypond-doc-html-es lilypond-doc-html-fr lilypond-doc-html-hu lilypond-doc-html-it lilypond-doc-html-ja lilypond-doc-html-nl lilypond-doc-html-zh lilypond-doc-pdf-de lilypond-doc-pdf-es lilypond-doc-pdf-fr lilypond-doc-pdf-hu lilypond-doc-pdf-it lilypond-doc-pdf-nl
Architecture: source
Version: 2.18.2-12
Distribution: unstable
Urgency: medium
Maintainer: Don Armstrong <don@debian.org>
Changed-By: Dr. Tobias Quathamer <toddy@debian.org>
Description:
 lilypond   - program for typesetting sheet music
 lilypond-data - LilyPond music typesetter (data files)
 lilypond-doc - LilyPond Documentation in info format (and metapackage)
 lilypond-doc-html - LilyPond HTML Documentation
 lilypond-doc-html-cs - LilyPond HTML Documentation in Czech
 lilypond-doc-html-de - LilyPond HTML Documentation in German
 lilypond-doc-html-es - LilyPond HTML Documentation in Spanish
 lilypond-doc-html-fr - LilyPond HTML Documentation in French
 lilypond-doc-html-hu - LilyPond HTML Documentation in Hungarian
 lilypond-doc-html-it - LilyPond HTML Documentation in Italian
 lilypond-doc-html-ja - LilyPond HTML Documentation in Japanese
 lilypond-doc-html-nl - LilyPond HTML Documentation in Dutch
 lilypond-doc-html-zh - LilyPond HTML Documentation in Chinese
 lilypond-doc-pdf - LilyPond PDF Documentation
 lilypond-doc-pdf-de - LilyPond PDF Documentation in German
 lilypond-doc-pdf-es - LilyPond PDF Documentation in Spanish
 lilypond-doc-pdf-fr - LilyPond PDF Documentation in French
 lilypond-doc-pdf-hu - LilyPond PDF Documentation in Hungarian
 lilypond-doc-pdf-it - LilyPond PDF Documentation in Italian
 lilypond-doc-pdf-nl - LilyPond PDF Documentation in Dutch
Closes: 884136
Changes:
 lilypond (2.18.2-12) unstable; urgency=medium
 .
   * Fix argument injection in lilypond-invoke-editor, CVE-2017-17523.
     This is a cherry-pick of upstream's fix, see
     https://sourceforge.net/p/testlilyissues/issues/5243/ (Closes: #884136)
   * Update Standards-Version to 4.1.3, no changes needed
   * Update d/copyright
   * Switch Vcs-URLs to salsa.d.o and add default branch for git
Checksums-Sha1:
 721bd0a5fd1b00c52fbd34538e94ce6230610b06 4101 lilypond_2.18.2-12.dsc
 e5c0d89f7db7cad9d1c551bac58e1cd8904a51da 58320 lilypond_2.18.2-12.debian.tar.xz
 7e986ea63a9675fa3060f81480fd9e5621d1648b 19427 lilypond_2.18.2-12_amd64.buildinfo
Checksums-Sha256:
 c4ee20940268e351d7766b1461beacf85572718e1bacf21226acac3a1e7a7f98 4101 lilypond_2.18.2-12.dsc
 1ab66f3effedf85fcd117f3011c56dbdc79e207628cc173a58e4bd80da9baacb 58320 lilypond_2.18.2-12.debian.tar.xz
 8102163522ac75c39370e8bc9a740f101b324d0eddf4f14e065b3812d707cb35 19427 lilypond_2.18.2-12_amd64.buildinfo
Files:
 ee04061124a8ae6073e846aa1f1c7275 4101 tex optional lilypond_2.18.2-12.dsc
 4107e4e1de7799e557b1e2e4ed2151d1 58320 tex optional lilypond_2.18.2-12.debian.tar.xz
 f17fedb7402580bb601b74ec22cfa9ca 19427 tex optional lilypond_2.18.2-12_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEE0cuPObxd7STF0seMEwLx8Dbr6xkFAlpvhjgACgkQEwLx8Dbr
6xmZzQ/+Oyg5eRwIWmF/y1gzwi/96dDDufA2TYgdA1zLyFY+vHLBtQEIiuv9umM+
TLw49xxkeaH8QnMGay1Fy5+/fogRkYEK7IN62nYXrLUj4pQmMfgQxzgulN7Cq1Mw
stRie0+GuQelQMOQWsiuEiLmvRhqx/nXyUSgHfGS8sIbg3mWXkSKadzi9pVI+IKx
RMiN9eHbXpurYNqUPI4ofkZXcOooU1XVUUGz9YGRTcoHjaYJ6p/cHvQ4t9wNVg1d
MFOel6/t/WiqTCEISQG5XOx9Opc71z1lA0PTmoiN7Yt78NX3QED5IIwRSvDHd6yO
5KPOEZGoKChwgRcVLAU+Uf3vIXX7U2dBoGz5jsf7OECKSEzKou5PDvl4EYrOdXb+
kuoC6GKEk1fFVgtdAEHiL3F65v8CVkfA1T6uFxwkcPD68Lw77yqg/zwmRpvOr3GP
FqQJ8hzfhN+fMFzwpS53MZtzYTNdtrlKJyOkZgq2G9va7Jxjy7p5UZUY8KHP8lCb
qc8JtRqdckvjGlh5ChZhpWdsSuTE+v5jCeJLmEljz46RBTJS2HMjvfChiPvxcISO
kTts5ZiEqHrLjOKtEtFXPqM9raVGxonCtXQwLXCYodCjoX2RNcUrQ/rzT/EsTNYV
kqyo0xbCtESYHKUb2dd4x/3P07Ip1/Us2e6OAw4XTqnFYzv30Yk=
=NNwc
-----END PGP SIGNATURE-----




Reply sent to toddy@debian.org (Dr. Tobias Quathamer):
You have taken responsibility. (Sun, 04 Feb 2018 13:42:07 GMT) (full text, mbox, link).


Notification sent to Salvatore Bonaccorso <carnil@debian.org>:
Bug acknowledged by developer. (Sun, 04 Feb 2018 13:42:07 GMT) (full text, mbox, link).


Message #18 received at 884136-close@bugs.debian.org (full text, mbox, reply):

From: toddy@debian.org (Dr. Tobias Quathamer)
To: 884136-close@bugs.debian.org
Subject: Bug#884136: fixed in lilypond 2.19.81-1~exp1
Date: Sun, 04 Feb 2018 13:38:14 +0000
Source: lilypond
Source-Version: 2.19.81-1~exp1

We believe that the bug you reported is fixed in the latest version of
lilypond, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 884136@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Dr. Tobias Quathamer <toddy@debian.org> (supplier of updated lilypond package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Sun, 04 Feb 2018 13:31:46 +0100
Source: lilypond
Binary: lilypond lilypond-data lilypond-doc lilypond-doc-pdf lilypond-doc-html lilypond-doc-html-ca lilypond-doc-html-cs lilypond-doc-html-de lilypond-doc-html-es lilypond-doc-html-fr lilypond-doc-html-hu lilypond-doc-html-it lilypond-doc-html-ja lilypond-doc-html-nl lilypond-doc-html-zh lilypond-doc-pdf-ca lilypond-doc-pdf-de lilypond-doc-pdf-es lilypond-doc-pdf-fr lilypond-doc-pdf-hu lilypond-doc-pdf-it lilypond-doc-pdf-nl
Architecture: source all amd64
Version: 2.19.81-1~exp1
Distribution: experimental
Urgency: medium
Maintainer: Don Armstrong <don@debian.org>
Changed-By: Dr. Tobias Quathamer <toddy@debian.org>
Description:
 lilypond   - program for typesetting sheet music
 lilypond-data - LilyPond music typesetter (data files)
 lilypond-doc - LilyPond Documentation in info format (and metapackage)
 lilypond-doc-html - LilyPond HTML Documentation
 lilypond-doc-html-ca - LilyPond HTML Documentation in Catalan
 lilypond-doc-html-cs - LilyPond HTML Documentation in Czech
 lilypond-doc-html-de - LilyPond HTML Documentation in German
 lilypond-doc-html-es - LilyPond HTML Documentation in Spanish
 lilypond-doc-html-fr - LilyPond HTML Documentation in French
 lilypond-doc-html-hu - LilyPond HTML Documentation in Hungarian
 lilypond-doc-html-it - LilyPond HTML Documentation in Italian
 lilypond-doc-html-ja - LilyPond HTML Documentation in Japanese
 lilypond-doc-html-nl - LilyPond HTML Documentation in Dutch
 lilypond-doc-html-zh - LilyPond HTML Documentation in Chinese
 lilypond-doc-pdf - LilyPond PDF Documentation
 lilypond-doc-pdf-ca - LilyPond PDF Documentation in Catalan
 lilypond-doc-pdf-de - LilyPond PDF Documentation in German
 lilypond-doc-pdf-es - LilyPond PDF Documentation in Spanish
 lilypond-doc-pdf-fr - LilyPond PDF Documentation in French
 lilypond-doc-pdf-hu - LilyPond PDF Documentation in Hungarian
 lilypond-doc-pdf-it - LilyPond PDF Documentation in Italian
 lilypond-doc-pdf-nl - LilyPond PDF Documentation in Dutch
Closes: 884136
Changes:
 lilypond (2.19.81-1~exp1) experimental; urgency=medium
 .
   * New upstream version 2.19.81
   * Fix argument injection in lilypond-invoke-editor, CVE-2017-17523.
     This is a cherry-pick of upstream's fix, see
     https://sourceforge.net/p/testlilyissues/issues/5243/ (Closes: #884136)
   * Update Standards-Version to 4.1.3, no changes needed
   * Update d/copyright
   * Switch Vcs-URLs to salsa.d.o and add default branch for git
Checksums-Sha1:
 4b2ee644421e9d4bd36053b1255d821e1d148754 4296 lilypond_2.19.81-1~exp1.dsc
 13b37383e69d96123630fc7519af4cd8b0feadb0 2510038 lilypond_2.19.81.orig-guile18.tar.gz
 6aeb3040bed1f94aaf00e18e6338a00bad55e92e 17303532 lilypond_2.19.81.orig.tar.gz
 fa7f6eb739b5b98f5125c95ba2283262423041d5 53812 lilypond_2.19.81-1~exp1.debian.tar.xz
 6c4be272475b4ac9a33bc4e78cbb766722ca64f2 2298968 lilypond-data_2.19.81-1~exp1_all.deb
 cefc987b52cfb90aae4ba9daa01622e23d4d1c70 31153272 lilypond-dbgsym_2.19.81-1~exp1_amd64.deb
 a78dfe91eb611f4bbaff086cb04dcae821ec7b2a 1602040 lilypond-doc-html-ca_2.19.81-1~exp1_all.deb
 3141294a3d77137ee8b96e52e1e489af9c454bc1 1335332 lilypond-doc-html-cs_2.19.81-1~exp1_all.deb
 74338898ff671673b526994c8ccef1ef1e22f725 1643772 lilypond-doc-html-de_2.19.81-1~exp1_all.deb
 4c5d50b05d825411ec1b3f1ca7c1d7136602b1bc 1747344 lilypond-doc-html-es_2.19.81-1~exp1_all.deb
 121dddec3fb0e74992d87053eee39538ac7ce197 1763332 lilypond-doc-html-fr_2.19.81-1~exp1_all.deb
 044c73d30d7d4bd490668dc7383d18ef87c485a6 1311156 lilypond-doc-html-hu_2.19.81-1~exp1_all.deb
 23614ea76d96b795aa7063dd9931ed5a5adbef39 1584028 lilypond-doc-html-it_2.19.81-1~exp1_all.deb
 f61255447dc7087adceca9a0767fbc502e9bb8a6 1669864 lilypond-doc-html-ja_2.19.81-1~exp1_all.deb
 af0ee0daa19d670c01a53c8444bdf1c5dde5682f 1313804 lilypond-doc-html-nl_2.19.81-1~exp1_all.deb
 b052c4430dc2191b3ee933d7a48edef955078f9f 1291820 lilypond-doc-html-zh_2.19.81-1~exp1_all.deb
 3f74cb18e9b3e7a12f60e1ab9ce5804167b3480d 8877348 lilypond-doc-html_2.19.81-1~exp1_all.deb
 83e1b7022941d1c64dba32726929a893beefeb47 8860452 lilypond-doc-pdf-ca_2.19.81-1~exp1_all.deb
 88bb25e83e11e5654ce6f72b40d17aa250ca3cc7 10228756 lilypond-doc-pdf-de_2.19.81-1~exp1_all.deb
 1e733c543a920477b8dd7858a65963c312660aa5 10742124 lilypond-doc-pdf-es_2.19.81-1~exp1_all.deb
 6cea8c0d4e19b3527aaec8e491bd7fc839bddf04 10781524 lilypond-doc-pdf-fr_2.19.81-1~exp1_all.deb
 c3afab1f8a5289fb165d36c00facc8d0dca445ba 4233804 lilypond-doc-pdf-hu_2.19.81-1~exp1_all.deb
 c3ed19421594e8127a518ffd7a547d6c9d798196 10455212 lilypond-doc-pdf-it_2.19.81-1~exp1_all.deb
 594790284772297f7396af0a8bd0ce077c7dc877 3115680 lilypond-doc-pdf-nl_2.19.81-1~exp1_all.deb
 09fb9280a97c8efce3b261ab294d410960060088 18252360 lilypond-doc-pdf_2.19.81-1~exp1_all.deb
 98d1b49c2192d26eb43dd67430b821ed6e35fb51 16606564 lilypond-doc_2.19.81-1~exp1_all.deb
 7bae94e44eaf6fd37d3d5e3bf8cf93b5b14ff0a4 20441 lilypond_2.19.81-1~exp1_amd64.buildinfo
 643a66304a717efd5f0fc8e90e24a01c4335ce8f 2135848 lilypond_2.19.81-1~exp1_amd64.deb
Checksums-Sha256:
 72a950409acc1a2b4a109b8fc05fa42c3767debfda6c02d94e214d16d4c15f01 4296 lilypond_2.19.81-1~exp1.dsc
 55ff45dd426c58ef7a5530b4e701c2a6a1e54043c2b69c64206fc105ddd247db 2510038 lilypond_2.19.81.orig-guile18.tar.gz
 2ac299045dc4a8fa3bd7c67af7b06877b21cdb50321fec5baa558e3173ed646c 17303532 lilypond_2.19.81.orig.tar.gz
 900b201fd7bed283e294d2039864d6d9b0e232a55f5bccf187c9ea8c134f8b0c 53812 lilypond_2.19.81-1~exp1.debian.tar.xz
 e3bcd6d363e827e7bc52cc00cbb127a67e97e3cb6f5b4a0b41b1cfe615476263 2298968 lilypond-data_2.19.81-1~exp1_all.deb
 8c747f9f317fef7d108f170eab6c70a46249933fe20fa6e4677ccd1002ba65ea 31153272 lilypond-dbgsym_2.19.81-1~exp1_amd64.deb
 c6edc6ebc7672f9aec6396ce4a783500108606d515d3da6bdac0af1ebce8aa5f 1602040 lilypond-doc-html-ca_2.19.81-1~exp1_all.deb
 19e24c9834c730282aad2730cd400d22cedca54e3dded4e832a0a098cf6cfb6b 1335332 lilypond-doc-html-cs_2.19.81-1~exp1_all.deb
 a9f3bea7a3149c2db37023da450582193d62590fc88d2859d31ddf8d1ed0506a 1643772 lilypond-doc-html-de_2.19.81-1~exp1_all.deb
 679f0d5f8c66f7a595015d725268c21ba35d91764b2a64bbd2222951ed597f06 1747344 lilypond-doc-html-es_2.19.81-1~exp1_all.deb
 f337757107e0bae49342ab4d96497e609ce11404ee7b776d5fc5c6a741e06b9d 1763332 lilypond-doc-html-fr_2.19.81-1~exp1_all.deb
 c01a3909106e783ef8e5a9a9d09d3accd5700ca33d086a2d4b063dd83535748c 1311156 lilypond-doc-html-hu_2.19.81-1~exp1_all.deb
 c1d66d75bdfd86e50cafcd3b755274360e452488cca0db6be48e91003cd9bb8e 1584028 lilypond-doc-html-it_2.19.81-1~exp1_all.deb
 49f6f55ca83b7d7db3089800ff6192785f3a3f81a816471cded5a8f8338aa49e 1669864 lilypond-doc-html-ja_2.19.81-1~exp1_all.deb
 ec1fb9c82d00084b74e91ea8fec56a44688c086176d4bfac78b044facd278929 1313804 lilypond-doc-html-nl_2.19.81-1~exp1_all.deb
 b4d37a5db9681536de4b6a0da74b72d544b8cc08d084649b4b3e6d172e907f0f 1291820 lilypond-doc-html-zh_2.19.81-1~exp1_all.deb
 b85ad330636416c9cbabc5793fa89719da8bae1231c88cf12255a20759b47015 8877348 lilypond-doc-html_2.19.81-1~exp1_all.deb
 f8b020296bff6cddcda27ac0791437679dd8cd3113effab6dd71574b62fbb8d8 8860452 lilypond-doc-pdf-ca_2.19.81-1~exp1_all.deb
 8ba79b34bbd5d9c607709796204b779b694eb9e45d8aebae9e1df078074f810a 10228756 lilypond-doc-pdf-de_2.19.81-1~exp1_all.deb
 2fc92f26ef6387360779987914bfefe4b50f60a59c85b8a3cb277318decf11e5 10742124 lilypond-doc-pdf-es_2.19.81-1~exp1_all.deb
 e5a598c0e53f6a43c7b449cadf5cc3fd157db3ef861deba4c693ee7eafeee982 10781524 lilypond-doc-pdf-fr_2.19.81-1~exp1_all.deb
 7d45a71b4618147e02a07afadcfd8e87289ef1b5d7fdc6bcfac091d0a8b2e8c3 4233804 lilypond-doc-pdf-hu_2.19.81-1~exp1_all.deb
 6f44b87ed0e537ec1e3f35dd10df54c91c515fdd7824c3de5dc311115727cdbd 10455212 lilypond-doc-pdf-it_2.19.81-1~exp1_all.deb
 18d387074368e95a868e8034231ba66fe955c5e8f80b83b6c68e843b41920c70 3115680 lilypond-doc-pdf-nl_2.19.81-1~exp1_all.deb
 2a0ce3544ea007fd26260fdccf3522a00ced1fed2e50c1eae50690418dfd26aa 18252360 lilypond-doc-pdf_2.19.81-1~exp1_all.deb
 b3cd944000e333c690c78a6b0887c10a9f26fd63b16e8c23a9851b25c7d3688f 16606564 lilypond-doc_2.19.81-1~exp1_all.deb
 6b84d225cb3ec01520e19849720567efbc005658da9c65c0735e992a5e72128d 20441 lilypond_2.19.81-1~exp1_amd64.buildinfo
 c827bc7479ab9b859d01eab1a8272aabcb6bbf44d461fbe167ab7146bd5a4e24 2135848 lilypond_2.19.81-1~exp1_amd64.deb
Files:
 9f41c89d3ad1fc458598961aba420f48 4296 tex optional lilypond_2.19.81-1~exp1.dsc
 2863f46023dd38e33ac37978302c078f 2510038 tex optional lilypond_2.19.81.orig-guile18.tar.gz
 e97ae84cccc68aeb59bbed34b1e8a243 17303532 tex optional lilypond_2.19.81.orig.tar.gz
 6810b266a4928b81b26d302a4d2e0b5a 53812 tex optional lilypond_2.19.81-1~exp1.debian.tar.xz
 f127c558145f9a3b2ccaba9a5726cc38 2298968 tex optional lilypond-data_2.19.81-1~exp1_all.deb
 5145d83f1086ffcdc9f552a1096d4841 31153272 debug optional lilypond-dbgsym_2.19.81-1~exp1_amd64.deb
 331ff53242bfcc1d2ce96f3c8cf19f3f 1602040 doc optional lilypond-doc-html-ca_2.19.81-1~exp1_all.deb
 e66cc5be4dfe341929ff6aaddd4d3ed3 1335332 doc optional lilypond-doc-html-cs_2.19.81-1~exp1_all.deb
 6268482030d460f0d24567f3d421f1d3 1643772 doc optional lilypond-doc-html-de_2.19.81-1~exp1_all.deb
 cefde1295458deea9b689fe7114faa23 1747344 doc optional lilypond-doc-html-es_2.19.81-1~exp1_all.deb
 587a67a7ad3d0e1d98e1686745c77732 1763332 doc optional lilypond-doc-html-fr_2.19.81-1~exp1_all.deb
 5dfc516575c15091595d1f142f95f07b 1311156 doc optional lilypond-doc-html-hu_2.19.81-1~exp1_all.deb
 254019c8601d98977b44afe40004c1fd 1584028 doc optional lilypond-doc-html-it_2.19.81-1~exp1_all.deb
 09794ff1df0cc87bcade5427a0b63ed2 1669864 doc optional lilypond-doc-html-ja_2.19.81-1~exp1_all.deb
 581794e60bc6275ddb90b5e92143bea5 1313804 doc optional lilypond-doc-html-nl_2.19.81-1~exp1_all.deb
 7cddbc90edfbb3a266b4d3f2a9081e3a 1291820 doc optional lilypond-doc-html-zh_2.19.81-1~exp1_all.deb
 4ee17a228c3e6f2efef9f52dc6c1f1c3 8877348 doc optional lilypond-doc-html_2.19.81-1~exp1_all.deb
 ae186aafafad8e82da0ddc48f7561206 8860452 doc optional lilypond-doc-pdf-ca_2.19.81-1~exp1_all.deb
 900e56cb4f92766d97eff8c66ff9f2da 10228756 doc optional lilypond-doc-pdf-de_2.19.81-1~exp1_all.deb
 9eacc05b13398495ca4deef52f2335bb 10742124 doc optional lilypond-doc-pdf-es_2.19.81-1~exp1_all.deb
 cf870bc8410c401e83fbc4bdb5fba0f4 10781524 doc optional lilypond-doc-pdf-fr_2.19.81-1~exp1_all.deb
 e377f2346d1d0a9bbf35319d41247735 4233804 doc optional lilypond-doc-pdf-hu_2.19.81-1~exp1_all.deb
 ed897e806c8bbd4d9a2b6a43c76fd9bd 10455212 doc optional lilypond-doc-pdf-it_2.19.81-1~exp1_all.deb
 00f0a25206246d61599f02c9f471d8e5 3115680 doc optional lilypond-doc-pdf-nl_2.19.81-1~exp1_all.deb
 c2e5726a83da98a638a895b188d8f178 18252360 doc optional lilypond-doc-pdf_2.19.81-1~exp1_all.deb
 86de17d7ca5c0e6d0439d90e5f08dfbd 16606564 doc optional lilypond-doc_2.19.81-1~exp1_all.deb
 8b6ffda237ce46f39641436a1674140b 20441 tex optional lilypond_2.19.81-1~exp1_amd64.buildinfo
 fe67174180ae2be61abbe146acf7562a 2135848 tex optional lilypond_2.19.81-1~exp1_amd64.deb

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEE0cuPObxd7STF0seMEwLx8Dbr6xkFAlp3B6YACgkQEwLx8Dbr
6xkT0BAAlB0xXH2omvJ2cw9wrJIuRqsSb+vI8udx2Woqj7xDHvbrlEI1UmadPK/h
zqcdDum+lQySLR9B/TNkpBivJolTDH+JEYfZWXvAwAY0TdkAlHBXUSQGNM+CLZsg
QMStmskT8MH4/1ocVBXHmHV7FxOpzuvEjNxxQkvFVWPQ73gUHgP6yEuutij6NV3p
/8acB1RXul3UMl3rEPEa2CsPDQeNYm2MgaNE5GwCEHW59ZMxx4ro0oqcQhZtcsOL
ZxG/nYkxpYEL+GZxVGte2Bp7Vc8kOVDp4B5VC7/0peCKv/vORbBmdPIy7kVtGcVf
ogvqcH99FMIk5j1/uiWJd3V4C67bmeyu9FkmY2KVuYj9qjt5gqBtp+JjTYIrP0D0
bY+w90dTJDVEdJZwOOY9b9Q/+qmsGIO+8nlPAmmpgf5FMewWkpyUMa5rRq0FMM3p
Z3hqnmUNU/0utfBgyNEZ/PPxQ/Y2BcdBeAgEWla9n+4B7hRnvAj5zeMLPOr8xb5c
8McDwoLZft///GC6FJ7FwveMjlIuUuhEMfLATEa3gZjN61ow0jddoHoSXpO1BLhL
r9PwTftAU/ISABS53y07ws7aBSaTZFFTmwcQbPTnTlFP3TCfkKmH+45IAYKvCb1j
sCiE7JqoPCxMrJH7wEOMi6fcQi09TKNkwIpwr+GkzVGsxADr9RQ=
=qZgz
-----END PGP SIGNATURE-----




Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Mon, 05 Mar 2018 07:26:43 GMT) (full text, mbox, link).


Bug unarchived. Request was from Don Armstrong <don@donarmstrong.com> to 898373-submit@bugs.debian.org. (Thu, 10 May 2018 23:18:03 GMT) (full text, mbox, link).


Marked as found in versions lilypond/2.18.2-12; no longer marked as fixed in versions lilypond/2.18.2-12. Request was from Don Armstrong <don@donarmstrong.com> to 898373-submit@bugs.debian.org. (Thu, 10 May 2018 23:18:04 GMT) (full text, mbox, link).


Marked as found in versions lilypond/2.19.81-1~exp1; no longer marked as fixed in versions lilypond/2.19.81-1~exp1 and reopened. Request was from Don Armstrong <don@donarmstrong.com> to 898373-submit@bugs.debian.org. (Thu, 10 May 2018 23:18:04 GMT) (full text, mbox, link).


Merged 884136 898373 Request was from Don Armstrong <don@debian.org> to control@bugs.debian.org. (Thu, 10 May 2018 23:39:07 GMT) (full text, mbox, link).


Added tag(s) confirmed. Request was from Don Armstrong <don@debian.org> to control@bugs.debian.org. (Thu, 10 May 2018 23:39:08 GMT) (full text, mbox, link).


Reply sent to Don Armstrong <don@debian.org>:
You have taken responsibility. (Fri, 11 May 2018 16:39:03 GMT) (full text, mbox, link).


Notification sent to Salvatore Bonaccorso <carnil@debian.org>:
Bug acknowledged by developer. (Fri, 11 May 2018 16:39:03 GMT) (full text, mbox, link).


Message #35 received at 884136-close@bugs.debian.org (full text, mbox, reply):

From: Don Armstrong <don@debian.org>
To: 884136-close@bugs.debian.org
Subject: Bug#884136: fixed in lilypond 2.18.2-13
Date: Fri, 11 May 2018 16:35:58 +0000
Source: lilypond
Source-Version: 2.18.2-13

We believe that the bug you reported is fixed in the latest version of
lilypond, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 884136@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Don Armstrong <don@debian.org> (supplier of updated lilypond package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Thu, 10 May 2018 17:24:03 -0700
Source: lilypond
Binary: lilypond lilypond-data lilypond-doc lilypond-doc-pdf lilypond-doc-html lilypond-doc-html-cs lilypond-doc-html-de lilypond-doc-html-es lilypond-doc-html-fr lilypond-doc-html-hu lilypond-doc-html-it lilypond-doc-html-ja lilypond-doc-html-nl lilypond-doc-html-zh lilypond-doc-pdf-de lilypond-doc-pdf-es lilypond-doc-pdf-fr lilypond-doc-pdf-hu lilypond-doc-pdf-it lilypond-doc-pdf-nl
Architecture: source all amd64
Version: 2.18.2-13
Distribution: unstable
Urgency: medium
Maintainer: Don Armstrong <don@debian.org>
Changed-By: Don Armstrong <don@debian.org>
Description:
 lilypond   - program for typesetting sheet music
 lilypond-data - LilyPond music typesetter (data files)
 lilypond-doc - LilyPond Documentation in info format (and metapackage)
 lilypond-doc-html - LilyPond HTML Documentation
 lilypond-doc-html-cs - LilyPond HTML Documentation in Czech
 lilypond-doc-html-de - LilyPond HTML Documentation in German
 lilypond-doc-html-es - LilyPond HTML Documentation in Spanish
 lilypond-doc-html-fr - LilyPond HTML Documentation in French
 lilypond-doc-html-hu - LilyPond HTML Documentation in Hungarian
 lilypond-doc-html-it - LilyPond HTML Documentation in Italian
 lilypond-doc-html-ja - LilyPond HTML Documentation in Japanese
 lilypond-doc-html-nl - LilyPond HTML Documentation in Dutch
 lilypond-doc-html-zh - LilyPond HTML Documentation in Chinese
 lilypond-doc-pdf - LilyPond PDF Documentation
 lilypond-doc-pdf-de - LilyPond PDF Documentation in German
 lilypond-doc-pdf-es - LilyPond PDF Documentation in Spanish
 lilypond-doc-pdf-fr - LilyPond PDF Documentation in French
 lilypond-doc-pdf-hu - LilyPond PDF Documentation in Hungarian
 lilypond-doc-pdf-it - LilyPond PDF Documentation in Italian
 lilypond-doc-pdf-nl - LilyPond PDF Documentation in Dutch
Closes: 884136
Changes:
 lilypond (2.18.2-13) unstable; urgency=medium
 .
   * Switch lilypond-invoke-editor to use system* instead of system to fix
     CVE-2017-17523 for non textedit:// URIs. (Closes: #884136)
Checksums-Sha1:
 e2dbdb0d7466b7c329075c47f0a50ad832719126 4101 lilypond_2.18.2-13.dsc
 5af8bc66624c76b6ad6a823dfa44f4ca3ddb336f 58568 lilypond_2.18.2-13.debian.tar.xz
 3c17dc901e4a61d50d1fd0494fac5e0eeac248a1 1816008 lilypond-data_2.18.2-13_all.deb
 b2d5e3924e81597fa97ab7cb3c327f14030feb22 23001108 lilypond-dbgsym_2.18.2-13_amd64.deb
 c6d38f1c7d38418a4e269b9f00febe8c778ab1af 1275300 lilypond-doc-html-cs_2.18.2-13_all.deb
 6c674f7e488036b4054b22a1c0c6bb82fd922de4 1536380 lilypond-doc-html-de_2.18.2-13_all.deb
 c040fc83580c4e53d56db8874d2d089b4afebc18 1601204 lilypond-doc-html-es_2.18.2-13_all.deb
 2c1b5f9e2065a761402e6b79c62e07dea0b3a845 1609212 lilypond-doc-html-fr_2.18.2-13_all.deb
 81b1aebbe5dd3c898494e1a081f9b23619e5aa0f 1244044 lilypond-doc-html-hu_2.18.2-13_all.deb
 06d4e2987e71846393111a26badb7721797f3c0c 1434988 lilypond-doc-html-it_2.18.2-13_all.deb
 51ee24e9ecfb83bd0c7f92c3d2a730deae765d78 1528004 lilypond-doc-html-ja_2.18.2-13_all.deb
 e05db39558dab8e9d0c081a4cc36d33ad0d3578b 1256284 lilypond-doc-html-nl_2.18.2-13_all.deb
 05bbbfffd31cc047fa92b61fb35fb7399d42d7c1 1232996 lilypond-doc-html-zh_2.18.2-13_all.deb
 f00b0a9af662cbb662ee14481fe2c85523647377 8350544 lilypond-doc-html_2.18.2-13_all.deb
 5809d44c6d78579097677d05388369b8f14d2f6e 17407572 lilypond-doc-pdf-de_2.18.2-13_all.deb
 09d5e1afec1cd40bbcf8426af01840a822c45592 18224416 lilypond-doc-pdf-es_2.18.2-13_all.deb
 b4d707ed2a1d193eadc1af3a7b1bff0a4df7f302 17864132 lilypond-doc-pdf-fr_2.18.2-13_all.deb
 72ab44f56ec8e277cfc9ac80368738b2abb2936c 1609268 lilypond-doc-pdf-hu_2.18.2-13_all.deb
 8221ec49b32d3e787363d659578c611d2f4574c4 16272224 lilypond-doc-pdf-it_2.18.2-13_all.deb
 5bc13da5a1fa009b8985b54a7e17f8876fc80da9 2560368 lilypond-doc-pdf-nl_2.18.2-13_all.deb
 6e1943a3c41bb90da4a83c58beee12fd8ec3c51e 30290588 lilypond-doc-pdf_2.18.2-13_all.deb
 4e7610feb4476f12d56ae0f4a4cc64eed62866b5 15208340 lilypond-doc_2.18.2-13_all.deb
 9bbb53d3b120bdd8b201c9e0265354172b65b813 19843 lilypond_2.18.2-13_amd64.buildinfo
 54ce7fca65f52d50173b58048d94afc6f8232b4b 1893308 lilypond_2.18.2-13_amd64.deb
Checksums-Sha256:
 adc31dfdba6acc19344863ea586cdd19cbdf08de6a18a89c48a3107c764f1dd2 4101 lilypond_2.18.2-13.dsc
 dd706e795cdc89fad1e7edb434d374ff270ddae336563d7e07b9bbdcac60a997 58568 lilypond_2.18.2-13.debian.tar.xz
 751b5a160e9140948ac7d90f61072881a58cfde9800e01b18c693ca4a61e6c06 1816008 lilypond-data_2.18.2-13_all.deb
 38b2bef24275e8af8087347bea6bee7c5afa9eac38193c9e79dda9ae4e7f8660 23001108 lilypond-dbgsym_2.18.2-13_amd64.deb
 2dc1ac40f0d841248dab643357a596ec5cf73da6f93ae7055e29de78a456b05b 1275300 lilypond-doc-html-cs_2.18.2-13_all.deb
 829a53fc1f3741561b4ce46576504d29a953e631ab3a40645ae22b179ff79d61 1536380 lilypond-doc-html-de_2.18.2-13_all.deb
 cf215ed17a614a86d55e516368920f014aa75c11be7ff6f3e69ca0e3a57ddaf4 1601204 lilypond-doc-html-es_2.18.2-13_all.deb
 935979e073a518608b408764f36780d429d7a539536c0df09740a5c5dcd757da 1609212 lilypond-doc-html-fr_2.18.2-13_all.deb
 f247af80b48637b115be0bfdd3241d1e87dbb94688490df7ef19fe204ab19f49 1244044 lilypond-doc-html-hu_2.18.2-13_all.deb
 e1607c1e436eb6c3207ea1baba909283ccc079437747370eec3ab509a2f71b18 1434988 lilypond-doc-html-it_2.18.2-13_all.deb
 ea6dd2957cfb4bbc3cf45e91cf95c913e9e15631c11be667a87002937cf4f3da 1528004 lilypond-doc-html-ja_2.18.2-13_all.deb
 0a3b329adf3d356077dc54d20d94c8ffe39935ac16eb49c030670d60eeb62e1e 1256284 lilypond-doc-html-nl_2.18.2-13_all.deb
 2d633f33265700c5894fe63a88dfc395f0a55518024eb9c7ad80b91f26f3b58f 1232996 lilypond-doc-html-zh_2.18.2-13_all.deb
 b94d160a9768e7f50fdc78b0de1445d3a4320665b6841e3605781d8444a31b8d 8350544 lilypond-doc-html_2.18.2-13_all.deb
 95238c71d266761d22e8e72b958483702d63364f4289ebfdd795fe5ece4afc10 17407572 lilypond-doc-pdf-de_2.18.2-13_all.deb
 3d6b29baeaf3141d6102c0584f63cfecaa36575ea7a86b92b29ac375c1972a4b 18224416 lilypond-doc-pdf-es_2.18.2-13_all.deb
 479ce237b04fcde52d569b813ab918fb495b868463a5b4e0fc1c11b370db2e9c 17864132 lilypond-doc-pdf-fr_2.18.2-13_all.deb
 a49b375d5588f361315d107278c27acbdc61c1e18f1a06129c009616e8e3ccec 1609268 lilypond-doc-pdf-hu_2.18.2-13_all.deb
 90a1ef296665bcbcfcac9b9e12c704541c961812d09765a0b9010e439ee39a2b 16272224 lilypond-doc-pdf-it_2.18.2-13_all.deb
 a21718f331436657802161a50b511de60a8a8624c1d65f4579d6b04ffcf96250 2560368 lilypond-doc-pdf-nl_2.18.2-13_all.deb
 700106b4d30451457cadbc10a4026a0a66c627381c7139b8bcd0b420cf0d3a92 30290588 lilypond-doc-pdf_2.18.2-13_all.deb
 3536920cae67c52712b0bb5cdaf14e30cb6424f5e916f728404ce6de89484508 15208340 lilypond-doc_2.18.2-13_all.deb
 5bb455925e3f216694824f0346be553796bc645610fe54d341df865e609b7be8 19843 lilypond_2.18.2-13_amd64.buildinfo
 b17fa777f8b3aedfb60f7b8b5c8a24cc0037735636d0997ff422c7df86012edd 1893308 lilypond_2.18.2-13_amd64.deb
Files:
 2aeb0b28ab63993044dd5ab489e36fa7 4101 tex optional lilypond_2.18.2-13.dsc
 311cef89fb69f7d442c8bea475085aff 58568 tex optional lilypond_2.18.2-13.debian.tar.xz
 143212a0d6b4b15324f9f1a665b7cf31 1816008 tex optional lilypond-data_2.18.2-13_all.deb
 d40b42def212f5d7666a053408c7cf89 23001108 debug optional lilypond-dbgsym_2.18.2-13_amd64.deb
 20d51362d62a9df160b24f9b439a19b7 1275300 doc optional lilypond-doc-html-cs_2.18.2-13_all.deb
 2cc00fac6ea92cdb9523acdcaf3e3cf1 1536380 doc optional lilypond-doc-html-de_2.18.2-13_all.deb
 55569ae7310c69b3149856b855dee051 1601204 doc optional lilypond-doc-html-es_2.18.2-13_all.deb
 6e4a7e7d5e6d930423aba719fb9faf2f 1609212 doc optional lilypond-doc-html-fr_2.18.2-13_all.deb
 3bbffab4d5856d559ae6ab8691696022 1244044 doc optional lilypond-doc-html-hu_2.18.2-13_all.deb
 b3b90a6522742f407e462ac7a51e4d98 1434988 doc optional lilypond-doc-html-it_2.18.2-13_all.deb
 abe271fda3ec8145932e52496d3da56b 1528004 doc optional lilypond-doc-html-ja_2.18.2-13_all.deb
 08406c7cb9ca99860d4435bded327781 1256284 doc optional lilypond-doc-html-nl_2.18.2-13_all.deb
 1a5e2be9fb747881daf13cba18cb7fa1 1232996 doc optional lilypond-doc-html-zh_2.18.2-13_all.deb
 08e7f878beb9ae447955778226c20613 8350544 doc optional lilypond-doc-html_2.18.2-13_all.deb
 6d91aa5132600f6bf627ee6427bf029d 17407572 doc optional lilypond-doc-pdf-de_2.18.2-13_all.deb
 45544780d70b99e300997f0686f16247 18224416 doc optional lilypond-doc-pdf-es_2.18.2-13_all.deb
 588e6eb45e470734a379454ecd2e7ede 17864132 doc optional lilypond-doc-pdf-fr_2.18.2-13_all.deb
 867562f76cce0202c6610d083b5717f6 1609268 doc optional lilypond-doc-pdf-hu_2.18.2-13_all.deb
 dbd40d3577007d5a091ec29bcd2c2f15 16272224 doc optional lilypond-doc-pdf-it_2.18.2-13_all.deb
 f0bcd2136f915f5cd0fa78209fbfe1d0 2560368 doc optional lilypond-doc-pdf-nl_2.18.2-13_all.deb
 4dc3812797a1e170e10e5e9380236008 30290588 doc optional lilypond-doc-pdf_2.18.2-13_all.deb
 e820b33a66fdedf35b0e32301be23dc0 15208340 doc optional lilypond-doc_2.18.2-13_all.deb
 16178f19f7c14ea765b282de28745daf 19843 tex optional lilypond_2.18.2-13_amd64.buildinfo
 588cf1f239e62aa0a0e3890869bbc7b3 1893308 tex optional lilypond_2.18.2-13_amd64.deb

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEN5QgYeBoIEyihVyW9VAlZYpmvz8FAlr1wVMACgkQ9VAlZYpm
vz8Qkw/8CQGdNbJD0eoouBGpHDH/YfNly8iXclfjqDsGSsIAkdg6DetneX/zDrly
fcApsy4tAaKiwXcaG/HLizHgPnxKeYnhhBu1OC/wQ37YQjnQyLTO7XyDHmJo08z3
23kZPM50nQ8OuMQUbtq3U/rABtr0q6XXjLzbp1NmtnQ6MOLAjVoJeMZEb6jtE61O
6fIEsBKrGAFCQrxdFCD1vByv9+w0iqXKTnuuDMkcH9sBXb+M9P+QgyxXUITnqzfo
kPwj+3B/nQ5lvMJdWkYDdIIi9yZU+xti4xnfJAeJ/fjV9Be8ZCgkQhP3fh5l/Au7
5rjZZoTSOslN0+ZgAxkNM7x6EKDLUGRx6fD6BftNDiKecKDX4tz4/wkQNbqNw8ni
MXEL8+eJbY3lz/grUWeWKSjGaqur63AFhd7GEeimcwMihzP7dUdSxuwEd6A2LPyQ
RUlCKbiY3cm4eD8O7+jn2K8c+G8W85LZB/XA6Pt0WEI1UKLkkc6FB6wmfZPvMQcb
oTQlDyTk/xs0XElO4GlxqAMlVlxw5UJDAL91b6Nb0fINFFK+oP29Q/ABBAbewWRG
m09/KtUl7NL+AxrKJkGR+Q9beNnQd9zLkVlDMtEWIsECIZ3TSCqkSLeaybnpscSd
0IyU5V9cEw3o1MgG6GENE7L1lpXQOozVTZ+zPZYVhxJtI5D/TlE=
=TNlx
-----END PGP SIGNATURE-----




Reply sent to Don Armstrong <don@debian.org>:
You have taken responsibility. (Fri, 11 May 2018 16:39:04 GMT) (full text, mbox, link).


Notification sent to Gabriel Corona <gabriel.corona@enst-bretagne.fr>:
Bug acknowledged by developer. (Fri, 11 May 2018 16:39:04 GMT) (full text, mbox, link).


Reply sent to Don Armstrong <don@debian.org>:
You have taken responsibility. (Fri, 11 May 2018 20:51:06 GMT) (full text, mbox, link).


Notification sent to Salvatore Bonaccorso <carnil@debian.org>:
Bug acknowledged by developer. (Fri, 11 May 2018 20:51:06 GMT) (full text, mbox, link).


Message #44 received at 884136-close@bugs.debian.org (full text, mbox, reply):

From: Don Armstrong <don@debian.org>
To: 884136-close@bugs.debian.org
Subject: Bug#884136: fixed in lilypond 2.19.81-1~exp2
Date: Fri, 11 May 2018 20:48:14 +0000
Source: lilypond
Source-Version: 2.19.81-1~exp2

We believe that the bug you reported is fixed in the latest version of
lilypond, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 884136@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Don Armstrong <don@debian.org> (supplier of updated lilypond package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Thu, 10 May 2018 17:24:03 -0700
Source: lilypond
Binary: lilypond lilypond-data lilypond-doc lilypond-doc-pdf lilypond-doc-html lilypond-doc-html-ca lilypond-doc-html-cs lilypond-doc-html-de lilypond-doc-html-es lilypond-doc-html-fr lilypond-doc-html-hu lilypond-doc-html-it lilypond-doc-html-ja lilypond-doc-html-nl lilypond-doc-html-zh lilypond-doc-pdf-ca lilypond-doc-pdf-de lilypond-doc-pdf-es lilypond-doc-pdf-fr lilypond-doc-pdf-hu lilypond-doc-pdf-it lilypond-doc-pdf-nl
Architecture: source all amd64
Version: 2.19.81-1~exp2
Distribution: unstable
Urgency: medium
Maintainer: Don Armstrong <don@debian.org>
Changed-By: Don Armstrong <don@debian.org>
Description:
 lilypond   - program for typesetting sheet music
 lilypond-data - LilyPond music typesetter (data files)
 lilypond-doc - LilyPond Documentation in info format (and metapackage)
 lilypond-doc-html - LilyPond HTML Documentation
 lilypond-doc-html-ca - LilyPond HTML Documentation in Catalan
 lilypond-doc-html-cs - LilyPond HTML Documentation in Czech
 lilypond-doc-html-de - LilyPond HTML Documentation in German
 lilypond-doc-html-es - LilyPond HTML Documentation in Spanish
 lilypond-doc-html-fr - LilyPond HTML Documentation in French
 lilypond-doc-html-hu - LilyPond HTML Documentation in Hungarian
 lilypond-doc-html-it - LilyPond HTML Documentation in Italian
 lilypond-doc-html-ja - LilyPond HTML Documentation in Japanese
 lilypond-doc-html-nl - LilyPond HTML Documentation in Dutch
 lilypond-doc-html-zh - LilyPond HTML Documentation in Chinese
 lilypond-doc-pdf - LilyPond PDF Documentation
 lilypond-doc-pdf-ca - LilyPond PDF Documentation in Catalan
 lilypond-doc-pdf-de - LilyPond PDF Documentation in German
 lilypond-doc-pdf-es - LilyPond PDF Documentation in Spanish
 lilypond-doc-pdf-fr - LilyPond PDF Documentation in French
 lilypond-doc-pdf-hu - LilyPond PDF Documentation in Hungarian
 lilypond-doc-pdf-it - LilyPond PDF Documentation in Italian
 lilypond-doc-pdf-nl - LilyPond PDF Documentation in Dutch
Closes: 884136
Changes:
 lilypond (2.19.81-1~exp2) unstable; urgency=medium
 .
   * Switch lilypond-invoke-editor to use system* instead of system to fix
     CVE-2017-17523 for non textedit:// URIs. (Closes: #884136)
Checksums-Sha1:
 4bba1c4765174119d193fbbee22ebe6401add746 4296 lilypond_2.19.81-1~exp2.dsc
 f1acc806cf785af604398d68363f3e8e6eefc581 54032 lilypond_2.19.81-1~exp2.debian.tar.xz
 cb656a821932147c6f15d49740341fbaaaf5beaf 2298976 lilypond-data_2.19.81-1~exp2_all.deb
 353063431c3fe7e0f3d8fc56b267debd382b7580 31718844 lilypond-dbgsym_2.19.81-1~exp2_amd64.deb
 6231b70c6ec0c19ae578e35996a34c1d6bb96d71 1608552 lilypond-doc-html-ca_2.19.81-1~exp2_all.deb
 a12c0a165788380da620924d15eadc3dfa284316 1335180 lilypond-doc-html-cs_2.19.81-1~exp2_all.deb
 b28b14837d2e2e70e20442d8f17381a97c5697ba 1647824 lilypond-doc-html-de_2.19.81-1~exp2_all.deb
 e1cb96ac277639ddf8979ea7846266a1e7d190b0 1746796 lilypond-doc-html-es_2.19.81-1~exp2_all.deb
 0dfac2b759d4879ebca066803dccc3aae0b8fc4b 1764848 lilypond-doc-html-fr_2.19.81-1~exp2_all.deb
 1507f2af560b35ff3ea63905a937d4a3bb73e4dc 1311720 lilypond-doc-html-hu_2.19.81-1~exp2_all.deb
 61cb7c66b85ee2aa49dbd196d2db7eff1e537268 1584476 lilypond-doc-html-it_2.19.81-1~exp2_all.deb
 65dfd0be276026c0fdb4afcec739303d28df660f 1671412 lilypond-doc-html-ja_2.19.81-1~exp2_all.deb
 2d81b40044f58fb61ebfe56ad21d8f90a6caebaf 1314800 lilypond-doc-html-nl_2.19.81-1~exp2_all.deb
 d2f8899198fe8989e4b3b40966bc05aac4a0c0d0 1292172 lilypond-doc-html-zh_2.19.81-1~exp2_all.deb
 51d39a2f2cbba552fcecf2be64c501732ddbf45b 8877384 lilypond-doc-html_2.19.81-1~exp2_all.deb
 53d59777c76daa21f8d0006c908cc87bfd0ae0d6 8859680 lilypond-doc-pdf-ca_2.19.81-1~exp2_all.deb
 92edfc48f8b58ab662fe439f89f752d393c1252d 10228080 lilypond-doc-pdf-de_2.19.81-1~exp2_all.deb
 8362c25ab6c737b30d448aca38453e2825339ec4 10741912 lilypond-doc-pdf-es_2.19.81-1~exp2_all.deb
 7f8c7f1c230192d3760aba6243e557dd139d0818 10782272 lilypond-doc-pdf-fr_2.19.81-1~exp2_all.deb
 fb7b8b459de990441d4e1e392127cb3bb350c7cf 4233484 lilypond-doc-pdf-hu_2.19.81-1~exp2_all.deb
 b53d8d6c7f75811374d8d8b38fae83481da087a3 10454696 lilypond-doc-pdf-it_2.19.81-1~exp2_all.deb
 32a7d6cad4ae36971e65558a9aaeedaa2bd0f53a 3116012 lilypond-doc-pdf-nl_2.19.81-1~exp2_all.deb
 5a733d122a99ac1bcd50408ae9491121fff9ce01 18250168 lilypond-doc-pdf_2.19.81-1~exp2_all.deb
 06ae1dc766eca50f75ddb1514a97ccb9f7529a9b 16606712 lilypond-doc_2.19.81-1~exp2_all.deb
 8b8924869223e94c843eb43ea4599c1d553b0251 20953 lilypond_2.19.81-1~exp2_amd64.buildinfo
 a5c43bf489a6d5cf6d7f38dda46c5d31382f8a84 2136000 lilypond_2.19.81-1~exp2_amd64.deb
Checksums-Sha256:
 4ca4132c530158cdc648453906cf28370784afefa9ddf073a53a558677ec8885 4296 lilypond_2.19.81-1~exp2.dsc
 ca84f327512fac59baaf002487b32a430caf60abcba059e442d02ac3c0516098 54032 lilypond_2.19.81-1~exp2.debian.tar.xz
 d039b2d519a3df29249436115cca2fefad24f1a51b93328eccd579a3c807653e 2298976 lilypond-data_2.19.81-1~exp2_all.deb
 03729a88995f9a7d19f73039f9b79a7744d3f9c4504da4766e1e41d3e5d8f8e8 31718844 lilypond-dbgsym_2.19.81-1~exp2_amd64.deb
 4a542913ff33d393ad0902487a04b90ea8a7e2b5795914d71d6bc1d891b1cfdd 1608552 lilypond-doc-html-ca_2.19.81-1~exp2_all.deb
 07134eda8a3e76fed6fa36e1c95cd57da58a26b789067c6e8e08625e3dfd25fa 1335180 lilypond-doc-html-cs_2.19.81-1~exp2_all.deb
 37ddace8d29493f9a0f740f7b87d7739e8ba3da925d7331294507ce24423251a 1647824 lilypond-doc-html-de_2.19.81-1~exp2_all.deb
 6e3a062301f765464636ae2adc797ed0f66529a78dc25125e09798e363952d0f 1746796 lilypond-doc-html-es_2.19.81-1~exp2_all.deb
 8d4e00e5cb4f1a63fc50b6fe3b46dd794aa9ff2d95801ec436fe47707dbcdc4e 1764848 lilypond-doc-html-fr_2.19.81-1~exp2_all.deb
 bb8f8d087ea6c2407e3f40f8f735e65cf3579ef7dfa519fb9918f85ef4e19108 1311720 lilypond-doc-html-hu_2.19.81-1~exp2_all.deb
 653f3cf9a7e69478f1edb6f77c049b496eb23fa24a758f9845604aa5cf2f4609 1584476 lilypond-doc-html-it_2.19.81-1~exp2_all.deb
 a1397577fce6a0dd5266423064db215d5e18e5ce10b24359d06d94078506cfd9 1671412 lilypond-doc-html-ja_2.19.81-1~exp2_all.deb
 de4834d4c83b2ac899c881078a6fb457c8f04de1fb63c0a9f795f61bf1b6e594 1314800 lilypond-doc-html-nl_2.19.81-1~exp2_all.deb
 db2e508a725d3415513c40f02e92b9deb2d4f11146549d2eb5c8e27993f7a3cf 1292172 lilypond-doc-html-zh_2.19.81-1~exp2_all.deb
 c23f5ee75ac09503d6f9686b4fa7f034d89b353aa964ad6ed45da69bcb5eb51d 8877384 lilypond-doc-html_2.19.81-1~exp2_all.deb
 de7bb851e671aaa751159e9b9a5d786d2b95ba64b0873c3c7daf34ebe7080943 8859680 lilypond-doc-pdf-ca_2.19.81-1~exp2_all.deb
 7cbc05d9fc13c2eaa153ecb0381216df940466033ac7e5b97a69f42a673d0d48 10228080 lilypond-doc-pdf-de_2.19.81-1~exp2_all.deb
 b5641c1063750dcbaa48e4c984e5424bc4554fb81f13bf1c03eca486795c7afd 10741912 lilypond-doc-pdf-es_2.19.81-1~exp2_all.deb
 e04acad040822d6a44d1a7d16471020b3dce7591993ed8e69b12082e86ac84e8 10782272 lilypond-doc-pdf-fr_2.19.81-1~exp2_all.deb
 b64cdfe7a478df6b7f65320f619b5a303cf243627db08467e7d1da425e313b43 4233484 lilypond-doc-pdf-hu_2.19.81-1~exp2_all.deb
 7bfde9e97c9bd3253cba5e21606046912963d823f2684f4b5ea558506041e1e3 10454696 lilypond-doc-pdf-it_2.19.81-1~exp2_all.deb
 3cbccd9804b7132ce1a3e30eb1ef893681bc8c7ff395c5a1a24c5253c5acd0be 3116012 lilypond-doc-pdf-nl_2.19.81-1~exp2_all.deb
 e5ab358f6d437df70f0a27da5f8a9be40f06519d1d218fd0927498a84c109739 18250168 lilypond-doc-pdf_2.19.81-1~exp2_all.deb
 fc34ff30f8e14c0f3e4ebe077576bdf5350425b02b369560e0d685eb2f6df86d 16606712 lilypond-doc_2.19.81-1~exp2_all.deb
 a9e9ce4845010bd6bdb645ef30d2630fa981bbb8c6a39fe06b035a549028081e 20953 lilypond_2.19.81-1~exp2_amd64.buildinfo
 5b6714fc56070ce3eda8bfc8ab9115d1c20c866d0577075acc8b23305d942baa 2136000 lilypond_2.19.81-1~exp2_amd64.deb
Files:
 05f3fd897e17522293ef43f4bf663a51 4296 tex optional lilypond_2.19.81-1~exp2.dsc
 809aa0ea20c6dcb6fb2571d6a6854e9c 54032 tex optional lilypond_2.19.81-1~exp2.debian.tar.xz
 73bcda0b59b246872160585affdbf3d9 2298976 tex optional lilypond-data_2.19.81-1~exp2_all.deb
 343bfa671d90ec8f389892ce4b5a6303 31718844 debug optional lilypond-dbgsym_2.19.81-1~exp2_amd64.deb
 bdd4e832aaba6dcddafb405da0ac8456 1608552 doc optional lilypond-doc-html-ca_2.19.81-1~exp2_all.deb
 b3ce206b0a3aeb8fbe465f64d61b2a09 1335180 doc optional lilypond-doc-html-cs_2.19.81-1~exp2_all.deb
 e9a2fcdb67f723eee08c0b50d2be671a 1647824 doc optional lilypond-doc-html-de_2.19.81-1~exp2_all.deb
 0efdda2d39cd37a748f700fa77e7bfa1 1746796 doc optional lilypond-doc-html-es_2.19.81-1~exp2_all.deb
 f4a14b494fe7d05d7a9d61ef102fc4f5 1764848 doc optional lilypond-doc-html-fr_2.19.81-1~exp2_all.deb
 c27cb73b29174642b4f163a76f76b1bc 1311720 doc optional lilypond-doc-html-hu_2.19.81-1~exp2_all.deb
 0772b5a244dd7deadaf7cbc3ac39c2d8 1584476 doc optional lilypond-doc-html-it_2.19.81-1~exp2_all.deb
 8f792208ba0e8c3c2f5599efdd831007 1671412 doc optional lilypond-doc-html-ja_2.19.81-1~exp2_all.deb
 05b85d143148cbf21d1f5d0c2a811ce6 1314800 doc optional lilypond-doc-html-nl_2.19.81-1~exp2_all.deb
 9f09ccf77ac836a38f639cbe0a48f96c 1292172 doc optional lilypond-doc-html-zh_2.19.81-1~exp2_all.deb
 6a59e7b24e2d471a44300450a959521b 8877384 doc optional lilypond-doc-html_2.19.81-1~exp2_all.deb
 a487fe3b2135f61177b6416ec16b8b40 8859680 doc optional lilypond-doc-pdf-ca_2.19.81-1~exp2_all.deb
 2bd4cde5701fc6d9052861ad8f0480fd 10228080 doc optional lilypond-doc-pdf-de_2.19.81-1~exp2_all.deb
 215981fdea5deaed21a5ae34683ec576 10741912 doc optional lilypond-doc-pdf-es_2.19.81-1~exp2_all.deb
 928bc8e89383ecbf53186dca80cb467a 10782272 doc optional lilypond-doc-pdf-fr_2.19.81-1~exp2_all.deb
 906ee915f1160911630e33db59ee8bbc 4233484 doc optional lilypond-doc-pdf-hu_2.19.81-1~exp2_all.deb
 b1573b2e22d24c286e77e36654cdc4aa 10454696 doc optional lilypond-doc-pdf-it_2.19.81-1~exp2_all.deb
 87725600c876d42fee5690dd6e0b1ed9 3116012 doc optional lilypond-doc-pdf-nl_2.19.81-1~exp2_all.deb
 8beffd7f302935aba106a2c16eb7a89c 18250168 doc optional lilypond-doc-pdf_2.19.81-1~exp2_all.deb
 73b158f84516977bcb8fdddfd293264e 16606712 doc optional lilypond-doc_2.19.81-1~exp2_all.deb
 61e78a9c2a6a237159260806eefacef7 20953 tex optional lilypond_2.19.81-1~exp2_amd64.buildinfo
 f4b1adf0a12e1c58adfc42db53d2a365 2136000 tex optional lilypond_2.19.81-1~exp2_amd64.deb

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEN5QgYeBoIEyihVyW9VAlZYpmvz8FAlr19swACgkQ9VAlZYpm
vz+L4Q/+NBCLxosXKoQNOr7ILxZzypW4irjwJ4ucCGTUy7nzUdBjl+mQ2xWehmdn
UgmgiG9EhFDqrNTBKPltda03xqqAVeDIZ7hp7nZSI/g10TC1OSt4CY2m4c5aIA+k
XijjPuc3WgrwTGuQm4F4JtsorU2M9pfPa/+HJE9nEEflWxrKIAtACwNt6z0FTdcN
9U8Y2mtdHJbWgEXuJ/Tp7ipmXArbrpjFyEoNTpeNfXqb8Cz6Vj2/rvXd8RWXEIbr
sXA2ZrrvOHf9h0p62eGClpGOHiRjArbVQcaXAiDHHwS9zBIuZTM7GfEjjr91eyRV
bTFkD04Ft6Bwoqps2x5Q/r0Rdte29H1yZc6USnAsiKJWb/jivvWBRGfbJAz8Nx5Q
KFjCkE0vSSS+kAJ+l0OzxEbGR9o+Tb4uxxqY1drY308kFIecFk5z7zggXRDXzvpg
NOQAzUDbPCJPn2wI3su4fJhRfqRu4r9Z9+ePV3vZzmhv4mGt21MAAoTJ1ScW4zno
bz3FKFHgRQ+xPe+I4WAoUNjU/cxtpcJHOuWqniMpz1Xok/sbrkmGceYUrrRxHdYG
+yWbcNRH2b5EVjhRgU9t1Xk5s77jHJZt8pNy9ZMoxgTYjbjdRLp4LhTwmgjONLwB
uZokIDxB7Oc+bigpGbBwdk1yYC5JO9KPksa0RiRfNfQ0U+ytyv0=
=qq/e
-----END PGP SIGNATURE-----




Reply sent to Don Armstrong <don@debian.org>:
You have taken responsibility. (Fri, 11 May 2018 20:51:06 GMT) (full text, mbox, link).


Notification sent to Gabriel Corona <gabriel.corona@enst-bretagne.fr>:
Bug acknowledged by developer. (Fri, 11 May 2018 20:51:07 GMT) (full text, mbox, link).


Disconnected #898373 from all other report(s). Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Sat, 12 May 2018 06:27:03 GMT) (full text, mbox, link).


Marked as fixed in versions lilypond/2.18.2-12. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Sat, 12 May 2018 06:27:04 GMT) (full text, mbox, link).


Marked as fixed in versions lilypond/2.19.81-1~exp1. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Sat, 12 May 2018 06:27:04 GMT) (full text, mbox, link).


Message sent on to Salvatore Bonaccorso <carnil@debian.org>:
Bug#884136. (Sat, 12 May 2018 06:27:07 GMT) (full text, mbox, link).


Message #57 received at 884136-submitter@bugs.debian.org (full text, mbox, reply):

From: Salvatore Bonaccorso <carnil@debian.org>
To: control@bugs.debian.org
Cc: 884136-submitter@bugs.debian.org, 898373-submitter@bugs.debian.org
Subject: unmerging 898373, retitle 884136 to lilypond: CVE-2017-17523, found 884136 in 2.18.2-4 ...
Date: Sat, 12 May 2018 08:21:35 +0200
unmerge 898373
retitle 884136 lilypond: CVE-2017-17523
found 884136 2.18.2-4
close 884136 2.18.2-12
close 884136 2.19.81-1~exp1
retitle 898373 lilypond: CVE-2018-10992
found 898373 2.18.2-12
found 898373 2.19.81-1~exp1
close 898373 2.18.2-13
close 898373 2.19.81-1~exp2
thanks

CVE-2018-10992 was assigned separately to #898373 as incomplete fix for CVE-2017-17523 (#884136).




No longer marked as found in versions lilypond/2.19.81-1~exp1. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Sat, 12 May 2018 06:39:02 GMT) (full text, mbox, link).


Reply sent to toddy@debian.org (Dr. Tobias Quathamer):
You have taken responsibility. (Sat, 12 May 2018 21:24:04 GMT) (full text, mbox, link).


Notification sent to Salvatore Bonaccorso <carnil@debian.org>:
Bug acknowledged by developer. (Sat, 12 May 2018 21:24:04 GMT) (full text, mbox, link).


Message #64 received at 884136-close@bugs.debian.org (full text, mbox, reply):

From: toddy@debian.org (Dr. Tobias Quathamer)
To: 884136-close@bugs.debian.org
Subject: Bug#884136: fixed in lilypond 2.19.81+really-2.18.2-13
Date: Sat, 12 May 2018 21:20:39 +0000
Source: lilypond
Source-Version: 2.19.81+really-2.18.2-13

We believe that the bug you reported is fixed in the latest version of
lilypond, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 884136@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Dr. Tobias Quathamer <toddy@debian.org> (supplier of updated lilypond package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Sat, 12 May 2018 21:22:39 +0200
Source: lilypond
Binary: lilypond lilypond-data lilypond-doc lilypond-doc-pdf lilypond-doc-html lilypond-doc-html-cs lilypond-doc-html-de lilypond-doc-html-es lilypond-doc-html-fr lilypond-doc-html-hu lilypond-doc-html-it lilypond-doc-html-ja lilypond-doc-html-nl lilypond-doc-html-zh lilypond-doc-pdf-de lilypond-doc-pdf-es lilypond-doc-pdf-fr lilypond-doc-pdf-hu lilypond-doc-pdf-it lilypond-doc-pdf-nl
Architecture: source
Version: 2.19.81+really-2.18.2-13
Distribution: unstable
Urgency: medium
Maintainer: Don Armstrong <don@debian.org>
Changed-By: Dr. Tobias Quathamer <toddy@debian.org>
Description:
 lilypond   - program for typesetting sheet music
 lilypond-data - LilyPond music typesetter (data files)
 lilypond-doc - LilyPond Documentation in info format (and metapackage)
 lilypond-doc-html - LilyPond HTML Documentation
 lilypond-doc-html-cs - LilyPond HTML Documentation in Czech
 lilypond-doc-html-de - LilyPond HTML Documentation in German
 lilypond-doc-html-es - LilyPond HTML Documentation in Spanish
 lilypond-doc-html-fr - LilyPond HTML Documentation in French
 lilypond-doc-html-hu - LilyPond HTML Documentation in Hungarian
 lilypond-doc-html-it - LilyPond HTML Documentation in Italian
 lilypond-doc-html-ja - LilyPond HTML Documentation in Japanese
 lilypond-doc-html-nl - LilyPond HTML Documentation in Dutch
 lilypond-doc-html-zh - LilyPond HTML Documentation in Chinese
 lilypond-doc-pdf - LilyPond PDF Documentation
 lilypond-doc-pdf-de - LilyPond PDF Documentation in German
 lilypond-doc-pdf-es - LilyPond PDF Documentation in Spanish
 lilypond-doc-pdf-fr - LilyPond PDF Documentation in French
 lilypond-doc-pdf-hu - LilyPond PDF Documentation in Hungarian
 lilypond-doc-pdf-it - LilyPond PDF Documentation in Italian
 lilypond-doc-pdf-nl - LilyPond PDF Documentation in Dutch
Closes: 884136
Changes:
 lilypond (2.19.81+really-2.18.2-13) unstable; urgency=medium
 .
   * New upload to override the accidental upload of the
     experimental version to unstable, effectivly canceling the
     2.18.2-13 upload two days ago.
     We avoid using an epoch because lilypond is expected to release
     their stable version 2.20 before the freeze of buster. The
     "+really" workaround in the Debian version number could be
     removed then.
   * Update script for doc packages
   * Add Multi-Arch: foreign to pdf packages
   * Run wrap-and-sort and cme fix dpkg
   * Update Standards-Version to 4.1.4, no changes needed
   * Use debhelper v11
   * Fix lintian warning: Remove '--with quilt' from debhelper call
     in debian/rules. The package is already using the 3.0 (quilt)
     source format.
   * Remove unneeded patches
 .
 lilypond (2.18.2-13) unstable; urgency=medium
 .
   * Switch lilypond-invoke-editor to use system* instead of system to fix
     CVE-2017-17523 for non textedit:// URIs. (Closes: #884136)
     This fixes the newly assigned CVE-2018-10992.
Checksums-Sha1:
 e18455a50764a35cc33e0d4cf02c9ebac7bee155 4230 lilypond_2.19.81+really-2.18.2-13.dsc
 13b37383e69d96123630fc7519af4cd8b0feadb0 2510038 lilypond_2.19.81+really-2.18.2.orig-guile18.tar.gz
 09d3a1e0e9fadeb8ef6e279227a2b30812c7ee9b 16027977 lilypond_2.19.81+really-2.18.2.orig.tar.gz
 aaf9d16892de2426aec3837bfe0506b938eb17ca 56688 lilypond_2.19.81+really-2.18.2-13.debian.tar.xz
 702f4867977cae28dd2b492a1b8b4939d27ddf5b 20664 lilypond_2.19.81+really-2.18.2-13_amd64.buildinfo
Checksums-Sha256:
 af6be7d4eef8c2a1dc9ca40d426742d82dd80919bed9408c265ff90d624dc532 4230 lilypond_2.19.81+really-2.18.2-13.dsc
 55ff45dd426c58ef7a5530b4e701c2a6a1e54043c2b69c64206fc105ddd247db 2510038 lilypond_2.19.81+really-2.18.2.orig-guile18.tar.gz
 329d733765b0ba7be1878ae3f457dbbb875cc2840d2b75af4afc48c9454fba07 16027977 lilypond_2.19.81+really-2.18.2.orig.tar.gz
 128ea3e3f6a7dbba74c8b2ac96d49e35c87d3cd1ac18ce6196885bec02013f23 56688 lilypond_2.19.81+really-2.18.2-13.debian.tar.xz
 b8e4dcbab5f7721967fc1d63bca50d0e16e874712d714816c682a5728411388e 20664 lilypond_2.19.81+really-2.18.2-13_amd64.buildinfo
Files:
 bb99bd9150c9fe547d3acfe782ab0651 4230 tex optional lilypond_2.19.81+really-2.18.2-13.dsc
 2863f46023dd38e33ac37978302c078f 2510038 tex optional lilypond_2.19.81+really-2.18.2.orig-guile18.tar.gz
 3c4bcbb708d12644668b32bfe82ebf25 16027977 tex optional lilypond_2.19.81+really-2.18.2.orig.tar.gz
 380a283e24bfe87bf1bc7fb9ebe3f6a7 56688 tex optional lilypond_2.19.81+really-2.18.2-13.debian.tar.xz
 b3c0116657356c5e22f1465beb0e6047 20664 tex optional lilypond_2.19.81+really-2.18.2-13_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEE0cuPObxd7STF0seMEwLx8Dbr6xkFAlr3Vk4ACgkQEwLx8Dbr
6xkjkg/+NokeFZclCpiAzDa1PFAr1cEB5oC83GwOBH+uslPkZTTI/BtxtAqibcfB
k1P6/s4mjPmoq1rXEsH0IK/ppQisOq5VzrQsDRSyrg1igRkgr3JkXzXnUv6wdeV/
5tet7Ivi2M9aMyN4a0f8pVdKg9Z54Yttx5Xu8CvCCJSqP9UWpdoiNtJw41AyNn7l
M6joE5i4u1n/vmwNLmzyk81yUmxiAcabybnVtvZdND3draZVqqbwSmObs2PfOHvR
K8wLC+gsMQWP/tKY9iB1mYM913v4pSwZIjwVvRls6CpnNtL50wy9rOh7Hu9954AU
2iRwRc3Bq/8320Kkyylly80t7Bj0WqxZ/Ppvf+7Sned1Ai8qyu9dNfLaCDx6CGB7
ACXBtfckSvAZczHrwSSwfLe/SP9CTc0mEMbQU89ciovRcmkOnl12esj9r9QR6Z1u
sKFSXh9gfv6vhjvuaVhMut65gPCVnzydf++1FP10gZcffamrpkj549y7hhczByCf
Zafu8qMeEy2ERsEW2wUtudvfRAXOBtazf2r4VmiXpFMQM3NvkrPLYcPHH4WtvZJ5
JTYA0q4R2QijzkDskn0Y62n1ixk9SkkT5yoU267AhNtDWjXGMPdWGGouPKQ3n4bw
x2P3eZHaJyeg0Nz8KmNf470PZLPGMPQdJ7huF0DsNTpWzkqFWCM=
=h/WT
-----END PGP SIGNATURE-----




No longer marked as found in versions lilypond/2.18.2-12. Request was from Andreas Beckmann <anbe@debian.org> to control@bugs.debian.org. (Tue, 22 May 2018 00:18:03 GMT) (full text, mbox, link).


No longer marked as fixed in versions lilypond/2.19.81-1~exp2. Request was from Andreas Beckmann <anbe@debian.org> to control@bugs.debian.org. (Tue, 22 May 2018 00:18:03 GMT) (full text, mbox, link).


No longer marked as fixed in versions lilypond/2.19.81+really-2.18.2-13. Request was from Andreas Beckmann <anbe@debian.org> to control@bugs.debian.org. (Tue, 22 May 2018 00:18:04 GMT) (full text, mbox, link).


Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Tue, 19 Jun 2018 07:28:30 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jun 19 17:05:49 2019; Machine Name: beach

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.