Comment 39 for bug 311291

Revision history for this message
In , Kevin (kevin-redhat-bugs) wrote :

Uh, looking at the code in the SRPM, this appears to be the same code used in
clamav. The legal status of that code is not clear to me. (In fact, I
considered bringing this up with respect to clamav, but seeing the same code
used in another package makes this all the more urgent.) The file headers
say: "This code is based on the work of Alexander L. Roshal". But then isn't it
a derived work of the original unrar sources? If it is, it's illegal to
distribute this under the GPL as they're doing because the original unrar
license is non-Free and not GPL-compatible. This (libclamav unrar) code also
has a history of sharing the security vulnerabilities of the non-Free unrar,
which also sounds unlikely for a truely independent implementation. See for
example http://www.securityfocus.com/archive/1/473373/100/0/threaded .