Bug#726817: chrony: GPL-2-only program linking GPL-3+ libreadline6 on amd64
Package: chrony
Severity: serious
Version: 1.24-3+squeeze1
X-Debbugs-Cc: team@security.debian.org, debian-release@lists.debian.org
The security update for chrony links against libreadline6 on
amd64. However chrony is licensed under GPL-2-only and libreadline6 is
GPL-3-or-later.
The buildd uploads still link against libreadline5 (GPL-2+). So it looks
like the amd64 version was built in an unclean environment.
So chrony needs either
a, a binNMU on amd64 for the next point release, leaving the current
version on security.d.o, or
b, a sourceful upload that changes the build-depends to
libreadline-gplv2-dev with no alternative (to require the GPL-2+
version). This could also replace the version currently in the
security archive.
Ansgar
Reply to: