[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#446405: ardour: Embeds too many libs



Package: ardour
Severity: serious

Quoting from #444518:
> That made me discover the following:
> 
> | kibi@kitty2:~/bsp2/ardour-2.1$ ls libs/
> | appleutility  ardour  clearlooks  fst  glibmm2  gtkmm2  gtkmm2ext libgnomecanvasmm  libsndfile  midi++2  pbd  sigc++2
> +soundtouch surfaces
> 
> Cc'ing the appropriate list according to [1] (although I didn't check
> which parts were actually built). Also, it seems e.g. libsndfile got
> CVE(s) this month.

This needs to be fixed if these libs are all built and linked into the binary.
If that is technically impossible we can exempt ardour from security support
as outlined in #436161.

Cheers,
        Moritz

-- System Information:
Debian Release: lenny/sid
  APT prefers unstable
  APT policy: (500, 'unstable')
Architecture: i386 (i686)

Kernel: Linux 2.6.22-2-686 (SMP w/1 CPU core)
Locale: LANG=C, LC_CTYPE=de_DE.ISO-8859-15@euro (charmap=ISO-8859-15)
Shell: /bin/sh linked to /bin/bash




Reply to: