[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#726817: chrony: GPL-2-only program linking GPL-3+ libreadline6 on amd64



Package: chrony
Severity: serious
Version: 1.24-3+squeeze1
X-Debbugs-Cc: team@security.debian.org, debian-release@lists.debian.org

The security update for chrony links against libreadline6 on
amd64. However chrony is licensed under GPL-2-only and libreadline6 is
GPL-3-or-later.

The buildd uploads still link against libreadline5 (GPL-2+). So it looks
like the amd64 version was built in an unclean environment.

So chrony needs either
a, a binNMU on amd64 for the next point release, leaving the current
   version on security.d.o, or
b, a sourceful upload that changes the build-depends to
   libreadline-gplv2-dev with no alternative (to require the GPL-2+
   version). This could also replace the version currently in the
   security archive.

Ansgar


Reply to: