[Security] advi should build-dep on hardened camlimages

Bug #602924 reported by Brian Thomason
260
This bug affects 1 person
Affects Status Importance Assigned to Milestone
advi (Ubuntu)
Invalid
Undecided
Brian Thomason
Nominated for Hardy by Brian Thomason

Bug Description

Binary package hint: advi

The build-dep for camlimages should be tightened in order to receive the fixes made there for some integer overflows.

CVE References

Changed in advi (Ubuntu):
assignee: nobody → Brian Thomason (brian-thomason)
status: New → In Progress
Revision history for this message
Brian Thomason (brian-thomason) wrote :
Revision history for this message
Jamie Strandboge (jdstrand) wrote :

I'm confused. Why is this needed? Hardy already has camlimages 1:2.2.0-2ubuntu2.1 so advi should pick this up at runtime, no?

visibility: private → public
Changed in advi (Ubuntu):
status: In Progress → Incomplete
Revision history for this message
Brian Thomason (brian-thomason) wrote :

Hi jamie,

I thought the same, but from reading the Debian changelog entry, it seems it may statically link in some bits as they saw fit to release a security update that did nothing more than change the build-deps. If you don't think it needed, that's certainly fine too.

Revision history for this message
Jamie Strandboge (jdstrand) wrote :

Since advi is in universe, would you mind researching this more? Perhaps there is a Debian bug on it or you can check the build to see if it is doing as you suggested. It's possible Debian did that as part of their unstable -> testing work.

Revision history for this message
Brian Thomason (brian-thomason) wrote :

Appears you are correct - this isn't needed in our repo. Closing it out.

Changed in advi (Ubuntu):
status: Incomplete → Invalid
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.