[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: [SECURITY] [DSA 2939-1] chromium-browser security update



On Sat, May 31, 2014 at 10:25:28AM -0400, Michael Gilbert wrote:
> On Sat, May 31, 2014 at 5:27 AM, Georgi Naplatanov wrote:
> > When I choose "About Chromium" menu item it says:
> >
> > Version 35.0.1916.114 Built on Debian 7.1, running on Debian 7.5 (270117)
> >
> > Is that true that package for AMD64 is built on Debian 7.1?
> > If yes, is using of this package secure?
> 
> Yes, that is correct.  The reason you're seeing that is that the amd64
> package was built on one of the wheezy security build daemon chroots,
> which apparently has not been updated in a while.
> 
> It's not really a problem since only library headers are used at build
> time, and those don't change over the lifetime of the stable release.
> As long as the system libraries chromium links against on your machine
> are up to date, there is no issue at all.
> 
> It could be nice if the stable buildds were kept more up to date.
> I've CC'd amd64@buildd.debian.org to get their opinion on that.

I've just updated the chroots.  But there is reason to be
concerned that it was build against when there were some 
older packages installed.


Kurt


Reply to: