[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#452399: marked as done (luatex needs to be rebuilt against libpoppler2)



Your message dated Fri, 23 Nov 2007 17:47:05 +0000
with message-id <E1IvccL-0001pk-2k@ries.debian.org>
and subject line Bug#452399: fixed in luatex 0.15-1
has caused the attached Bug report to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what I am
talking about this indicates a serious mail system misconfiguration
somewhere.  Please contact me immediately.)

Debian bug tracking system administrator
(administrator, Debian Bugs database)

--- Begin Message ---
Package: luatex
Version: 0.11.2-1
Severity: grave
Justification: renders package unusable

luatex is currently uninstallable in sid because it depends on the obsoleted
libpoppler1 which has been removed from sid.

If a user works around this problem by installing libpoppler1 from another
archive, they then introduce a several security holes into their system
(CVE-2007-4352, CVE-2007-5392, CVE-2007-5393) that are present in libpoppler1.

Please rebuild luatex against libpoppler2.


-- System Information:
Debian Release: lenny/sid
  APT prefers unstable
  APT policy: (990, 'unstable'), (1, 'experimental')
Architecture: amd64 (x86_64)

Kernel: Linux 2.6.23.1-amd64 (SMP w/2 CPU cores; PREEMPT)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/bash

Versions of packages luatex depends on:
ii  libc6                   2.6.1-6          GNU C Library: Shared libraries
ii  libpng12-0              1.2.15~beta5-3   PNG library - runtime
ii  libpoppler1             0.5.4-6.2        PDF rendering library
ii  texlive-base-bin        2007.dfsg.1-2    TeX Live: Essential binaries
ii  zlib1g                  1:1.2.3.3.dfsg-7 compression library - runtime

luatex recommends no packages.

-- no debconf information



--- End Message ---
--- Begin Message ---
Source: luatex
Source-Version: 0.15-1

We believe that the bug you reported is fixed in the latest version of
luatex, which is due to be installed in the Debian FTP archive:

luatex_0.15-1.diff.gz
  to pool/main/l/luatex/luatex_0.15-1.diff.gz
luatex_0.15-1.dsc
  to pool/main/l/luatex/luatex_0.15-1.dsc
luatex_0.15-1_i386.deb
  to pool/main/l/luatex/luatex_0.15-1_i386.deb
luatex_0.15.orig.tar.gz
  to pool/main/l/luatex/luatex_0.15.orig.tar.gz



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 452399@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Norbert Preining <preining@debian.org> (supplier of updated luatex package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.7
Date: Thu, 22 Nov 2007 18:05:15 +0100
Source: luatex
Binary: luatex
Architecture: source i386
Version: 0.15-1
Distribution: unstable
Urgency: low
Maintainer: Debian TeX Maintainers <debian-tex-maint@lists.debian.org>
Changed-By: Norbert Preining <preining@debian.org>
Description: 
 luatex     - next generation TeX engine
Closes: 448726 452399
Changes: 
 luatex (0.15-1) unstable; urgency=low
 .
   * switch to libpoppler 0.6 (adjusting build-deps and patch)
     (Closes: #452399)
   * add README.Debian containing some remarks on luatex based latex format
     thanks to Stefano Zacchiroli <zack@debian.org>
   * add one example files, and call dh_installexamples
   * register the luatex manual with doc-base, thanks again Stefano
     (Closes: #448726)
   * add Homepage, Vcs-Svn, and Vcs-Browser fields to debian/control
   * install texdoclua(.1) and a diversion from texdoc (addint preinst and
     postrm files), patch texdoclua for the lfs.tmpname vs mkdir bug
   * new upstream
     - Completely overhauled hyphenation and ligkern application.
     - the interface of the pre_linebreak_filter,hpack_filter,
       vpack_filter, and pre_output_filter has changed slightly.
     - lpeg is now at version 0.7
     - a whole series of exotic bugs and compiler warnings are
       fixed thanks to the watchful eye of Fabrice.
     - texio.print now accepts multiple strings as arguments.
     - The lua function os.sleep() is added
Files: 
 17de6aca4fddfc47e2be02e120bc3c8d 924 tex optional luatex_0.15-1.dsc
 f7209827d996a8d3d41edf36bf1acbc8 6128268 tex optional luatex_0.15.orig.tar.gz
 0411d94c38653139c0889cd4e0da2cce 21145 tex optional luatex_0.15-1.diff.gz
 cf7aae58f65eeeaaec83122422b60a3e 1640914 tex optional luatex_0.15-1_i386.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFHRbki0r9KownFsJQRAnIIAJ9npYVJTPK/ZKTxg+bIA4yzhpwYTQCgjOaU
//5qupIozOZ7N+ZmdUczsLo=
=QoHJ
-----END PGP SIGNATURE-----



--- End Message ---

Reply to: