[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: [DSA 694-1] New xloadimage packages fix several vulnerabilities



Bob Proulx wrote:
> But the latest security upload changed the dependencies.  Obviously
> that was unintentional.  But it is still a bad thing.
> 
> From:
>   Depends: libc6 (>= 2.2.4-4), libjpeg62, libpng2(>=1.0.12), libtiff3g, xlibs (>> 4.1.0), zlib1g (>= 1:1.1.3)
> To:
>   Depends: libc6 (>= 2.2.4-4), libjpeg62, libpng3, libtiff3g, xlibs (>> 4.1.0), zlib1g (>= 1:1.1.4)
>  
> This means that an 'apt-get upgrade' will not satisfy the dependencies
> of libpng3 and a dist-upgrade is required.

The problem is that the original package was a binary upload compiled
against libpng2 from woody.  But the build depend on libpng-dev pulls
in the libpng3 version.  So a pbuild of the binary will automatically
create a new binary bound to libpng3 instead of libpng2.

This may be fixed by installing libpng2 and libpng2-dev prior to
building the new package.  I have verified this in a woody chroot.

> > Can a new upload be made that fixes this problem?

Please?

Bob

P.S. Still a little peeved that kdelibs3 with similar problems never
got fixed.

Attachment: signature.asc
Description: Digital signature


Reply to: