Your message dated Thu, 21 Mar 2013 07:02:06 +0000
with message-id <[email protected]>
and subject line Bug#702436: fixed in graphviz 2.26.3-5+squeeze1
has caused the Debian Bug report #702436,
regarding Ships and uses an ancient version of libtool
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
702436: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=702436
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: graphviz
Version: 2.26.3-12
Usertags: goto-cc
graphviz currently links against a shipped version of libtool that appears to be
pre-2009, and at the very least is broken when using type-checking linkers. This
was fixed in 2010:
http://git.savannah.gnu.org/cgit/libtool.git/commit/libltdl/ltdl.c?id=03feff471901aeaac97b36964f88ed4d694dff99
Furthermore, libtool has even seen security fixes since that time.
It may be worth updating the shipped libtool; preferably, however, the packaged
version of libtool should be used instead by adding --with-included-ltdl to the
configure command line.
Best,
Michael
pgpYItfiwaKPd.pgp
Description: PGP signature
--- End Message ---
--- Begin Message ---
Source: graphviz
Source-Version: 2.26.3-5+squeeze1
We believe that the bug you reported is fixed in the latest version of
graphviz, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
David Claughton <[email protected]> (supplier of updated graphviz package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Format: 1.8
Date: Tue, 19 Mar 2013 23:24:52 +0000
Source: graphviz
Binary: graphviz libgv-guile libgv-lua libgv-ocaml libgv-perl libgv-php5
libgv-python libgv-ruby libgv-tcl libgraph4 libcgraph5 libcdt4 libpathplan4
libgvc5 libgvc5-plugins-gtk libgvpr1 libxdot4 libgraphviz-dev graphviz-doc
graphviz-dev
Architecture: source all kfreebsd-amd64
Version: 2.26.3-5+squeeze1
Distribution: stable
Urgency: low
Maintainer: David Claughton <[email protected]>
Changed-By: David Claughton <[email protected]>
Description:
graphviz - rich set of graph drawing tools
graphviz-dev - transitional package for graphviz-dev rename
graphviz-doc - additional documentation for graphviz
libcdt4 - rich set of graph drawing tools - cdt library
libcgraph5 - rich set of graph drawing tools - cgraph library
libgraph4 - rich set of graph drawing tools - graph library
libgraphviz-dev - graphviz libs and headers against which to build applications
libgv-guile - Guile bindings for graphviz
libgv-lua - Lua bindings for graphviz
libgv-ocaml - OCaml bindings for graphviz
libgv-perl - Perl bindings for graphviz
libgv-php5 - Php5 bindings for graphviz
libgv-python - Python bindings for graphviz
libgv-ruby - Ruby bindings for graphviz
libgv-tcl - Tcl bindings for graphviz
libgvc5 - rich set of graph drawing tools - gvc library
libgvc5-plugins-gtk - rich set of graph drawing tools - gtk plugins
libgvpr1 - rich set of graph drawing tools - gvpr library
libpathplan4 - rich set of graph drawing tools - pathplan library
libxdot4 - rich set of graph drawing tools - xdot library
Closes: 702436
Changes:
graphviz (2.26.3-5+squeeze1) stable; urgency=low
.
* Use system ltdl in place of version in subdir (Closes: #702436)
- Currently an ancient version of libltdl is being
shipped by upstream and linked against, unnoticed until now.
Changed configure.ac to ensure system ltdl is used instead
- Security issue - shipped ltdl is susceptible to issue
described in DSA-1958-1 (CVE-2009-3736)
Checksums-Sha1:
add3b2b1d3a2b4484db3966208ca695a51edaa72 2715 graphviz_2.26.3-5+squeeze1.dsc
8ac8ac88cda829ca4e8dab4818bd73552619f6ca 49877
graphviz_2.26.3-5+squeeze1.debian.tar.gz
4821db482f221ef6ab223008bd4eb74bfa2216e2 2585174
graphviz-doc_2.26.3-5+squeeze1_all.deb
6e866239ebce2eb2cb1d752fa7d9a41dcab14b12 48184
graphviz-dev_2.26.3-5+squeeze1_all.deb
d3231b945e0f460202dadbc10dfec3d02299111f 373874
graphviz_2.26.3-5+squeeze1_kfreebsd-amd64.deb
4651b7c27b4184009bfe26af609070cb8b7f40e0 70800
libgv-guile_2.26.3-5+squeeze1_kfreebsd-amd64.deb
00df284ef30c016cad9e09a807c34849d417c966 81468
libgv-lua_2.26.3-5+squeeze1_kfreebsd-amd64.deb
680534802bd9909876070fa54faf4085ae88d751 79544
libgv-ocaml_2.26.3-5+squeeze1_kfreebsd-amd64.deb
fb18743619e20ad681b20cb6e4518a5c1e69b665 96516
libgv-perl_2.26.3-5+squeeze1_kfreebsd-amd64.deb
2f23bf9adcd8254ce1f1c30e994b1c7bf9b70544 79562
libgv-php5_2.26.3-5+squeeze1_kfreebsd-amd64.deb
caefb241e17c0810e5ab2da480ce54901db181b4 113910
libgv-python_2.26.3-5+squeeze1_kfreebsd-amd64.deb
112c2057647beb633ff8f7463e8a60bd419adb28 75732
libgv-ruby_2.26.3-5+squeeze1_kfreebsd-amd64.deb
c6bfe41c451ae086d3d6d6e2d8899de37622ffa2 664464
libgv-tcl_2.26.3-5+squeeze1_kfreebsd-amd64.deb
27373fe9b69bf3915e86970078fcdc1a72117b2a 72866
libgraph4_2.26.3-5+squeeze1_kfreebsd-amd64.deb
96ed74f673d303974b2f4eeb88d881cde3a3aed3 86796
libcgraph5_2.26.3-5+squeeze1_kfreebsd-amd64.deb
414cb3d86237e93816ed9705e52f75d9be6e8328 59752
libcdt4_2.26.3-5+squeeze1_kfreebsd-amd64.deb
d33a8ffbf5db3d4316e20328c4afa74b2b08de5f 64016
libpathplan4_2.26.3-5+squeeze1_kfreebsd-amd64.deb
47f31effb46cba86025dda5b9c59e3ebac3d4a0c 540328
libgvc5_2.26.3-5+squeeze1_kfreebsd-amd64.deb
d4ad81eb4866eb09cf31110f47616a9b10af55e8 62156
libgvc5-plugins-gtk_2.26.3-5+squeeze1_kfreebsd-amd64.deb
e183055bfcfe0a555d8bc570d49804c409345da3 244982
libgvpr1_2.26.3-5+squeeze1_kfreebsd-amd64.deb
af40a917a65c3db09e4d90bc6341639ff30e7566 53830
libxdot4_2.26.3-5+squeeze1_kfreebsd-amd64.deb
5ae80ea9032adda8633099d924ef537058e77a30 122406
libgraphviz-dev_2.26.3-5+squeeze1_kfreebsd-amd64.deb
Checksums-Sha256:
1b8fa054d94f1b2276eae8b3b61b279ccea926e3c3f50515a9ae06e1d398ac60 2715
graphviz_2.26.3-5+squeeze1.dsc
c400a0eefb18615d520365d002f5dde44c2eada06c3a54447cebd83e8000a377 49877
graphviz_2.26.3-5+squeeze1.debian.tar.gz
6ececc6b560c10894ad329c69f6c937ec82bc9fb6045a2b557ee03fc4375d5a9 2585174
graphviz-doc_2.26.3-5+squeeze1_all.deb
41f649f7723b34a9a4b620e8cbe30ebfac76c2572153340aa611d55aeded3d48 48184
graphviz-dev_2.26.3-5+squeeze1_all.deb
0f54c95d7eeaf9483ea75abab7a8786d0eff81cf6ad360d915abd08a45af39ec 373874
graphviz_2.26.3-5+squeeze1_kfreebsd-amd64.deb
8345243c6f91bb0b626d9313c78a7bb6f7aa0bba7b8d0e7862ffd3143259b5f9 70800
libgv-guile_2.26.3-5+squeeze1_kfreebsd-amd64.deb
2cd350dd0d10207a32415e841fcc6c1b5c10c8ba3b659856480a37816650b1af 81468
libgv-lua_2.26.3-5+squeeze1_kfreebsd-amd64.deb
5721902e6a43f2c85448a729eee405889b4d75d83eee45d9b90756a8b7c1ee3e 79544
libgv-ocaml_2.26.3-5+squeeze1_kfreebsd-amd64.deb
149bf0598dfff71d25854e6589438d71610c8b99565ed459b430dbd3b2ee0005 96516
libgv-perl_2.26.3-5+squeeze1_kfreebsd-amd64.deb
9ac8aa360c2aaaa5045395e91ba9fb8285fce4bfb3ed7ca9a110e7c15a6cb9ce 79562
libgv-php5_2.26.3-5+squeeze1_kfreebsd-amd64.deb
61c4cb4ddb4380edcadf94b79bb91123391d5127cebaa0918668022233384612 113910
libgv-python_2.26.3-5+squeeze1_kfreebsd-amd64.deb
d1f1f651bd31024a601bfcf52540a50fb4f9e86e1b8384e496554d549a6aa16c 75732
libgv-ruby_2.26.3-5+squeeze1_kfreebsd-amd64.deb
7e8c3e89cacf01bb1ee38928a24d325563d12bb1c823c7456c6eb52bc4faca7c 664464
libgv-tcl_2.26.3-5+squeeze1_kfreebsd-amd64.deb
d1d678371756442d8c85b5606954eb6805aa07f2c59727321ced6efb51241628 72866
libgraph4_2.26.3-5+squeeze1_kfreebsd-amd64.deb
4c03040f63b56f2bb8ce387a1e6f10809b6da6ee3fca14db7ec07fce067a2212 86796
libcgraph5_2.26.3-5+squeeze1_kfreebsd-amd64.deb
910fc89f6411106cc3718e2df32975bf81cb2b8b19892063de19557e7b00dc31 59752
libcdt4_2.26.3-5+squeeze1_kfreebsd-amd64.deb
b2a14652dbfbf5021608b0404b91f09179fbac9d04e4c9d0195b1558e9ebccc8 64016
libpathplan4_2.26.3-5+squeeze1_kfreebsd-amd64.deb
9e734cac87fe838c3dc35a55697e0d4e79b57349a405a8094ef2b8f1fc8b540c 540328
libgvc5_2.26.3-5+squeeze1_kfreebsd-amd64.deb
884b3a2993161d06cfb30c17cb20a873214d3fe5db8d9d4e5006287e3eda3634 62156
libgvc5-plugins-gtk_2.26.3-5+squeeze1_kfreebsd-amd64.deb
9e039b85d80519487bb12d0b2d2ef29c66fc1a120b179795aec49397e5cdb0cf 244982
libgvpr1_2.26.3-5+squeeze1_kfreebsd-amd64.deb
c9630c2cbf39d4980c445e6606f5779250333a0f725addb764ddfaf1c6ae4487 53830
libxdot4_2.26.3-5+squeeze1_kfreebsd-amd64.deb
e304dc2d20cfd540ba38113e7b6c3afa136bf4e50f1d94668ea327e0de3a4946 122406
libgraphviz-dev_2.26.3-5+squeeze1_kfreebsd-amd64.deb
Files:
684e031af2d67c062a009937b6547043 2715 graphics optional
graphviz_2.26.3-5+squeeze1.dsc
f1759967f3d3ac96e0575053b944281e 49877 graphics optional
graphviz_2.26.3-5+squeeze1.debian.tar.gz
64f8f4d698af6ecb3cc4179167d7c8cf 2585174 doc optional
graphviz-doc_2.26.3-5+squeeze1_all.deb
1c79801739c06c693daa557e8e42e030 48184 devel optional
graphviz-dev_2.26.3-5+squeeze1_all.deb
0f98b3e7d6f5d0a370c7fef9e210e909 373874 graphics optional
graphviz_2.26.3-5+squeeze1_kfreebsd-amd64.deb
f89a78d83d74b048016f3b92420b0437 70800 interpreters optional
libgv-guile_2.26.3-5+squeeze1_kfreebsd-amd64.deb
444ce0f5137bfb1817f77f89f2d482e6 81468 interpreters optional
libgv-lua_2.26.3-5+squeeze1_kfreebsd-amd64.deb
a9e31344c0c244d31ddff838d3e59ab0 79544 ocaml optional
libgv-ocaml_2.26.3-5+squeeze1_kfreebsd-amd64.deb
a52c4ff3f75af760c09cc67878953a24 96516 perl optional
libgv-perl_2.26.3-5+squeeze1_kfreebsd-amd64.deb
fd86038b4c174e68dc0cb94bbfda7287 79562 php optional
libgv-php5_2.26.3-5+squeeze1_kfreebsd-amd64.deb
d3f6001100f510fa76e027d75d232136 113910 python optional
libgv-python_2.26.3-5+squeeze1_kfreebsd-amd64.deb
3a120dbf129d62768a74c1925f38e10b 75732 ruby optional
libgv-ruby_2.26.3-5+squeeze1_kfreebsd-amd64.deb
202e1c5bd043eb408bb71a1e44da7670 664464 interpreters optional
libgv-tcl_2.26.3-5+squeeze1_kfreebsd-amd64.deb
63c683d77bd28ef488d89fa2d2fb5ba2 72866 libs optional
libgraph4_2.26.3-5+squeeze1_kfreebsd-amd64.deb
4e241f376027365aa434b3ed7ef29fea 86796 libs optional
libcgraph5_2.26.3-5+squeeze1_kfreebsd-amd64.deb
93132e61a4b88ece312c67eb2b3e3f62 59752 libs optional
libcdt4_2.26.3-5+squeeze1_kfreebsd-amd64.deb
8f58ec6932f292bc5494ee3ef57901c8 64016 libs optional
libpathplan4_2.26.3-5+squeeze1_kfreebsd-amd64.deb
fbe18cd79e30349b78b024c015f2a8cc 540328 libs optional
libgvc5_2.26.3-5+squeeze1_kfreebsd-amd64.deb
b589e13444851c66db20f5b5ef6b456d 62156 libs optional
libgvc5-plugins-gtk_2.26.3-5+squeeze1_kfreebsd-amd64.deb
8538765678ab198dcb07110aa044e519 244982 libs optional
libgvpr1_2.26.3-5+squeeze1_kfreebsd-amd64.deb
cdc20feb5feeae3228a842569f5e4b71 53830 libs optional
libxdot4_2.26.3-5+squeeze1_kfreebsd-amd64.deb
d84739725408f2aea3e6d112b2b49b49 122406 libdevel optional
libgraphviz-dev_2.26.3-5+squeeze1_kfreebsd-amd64.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/kFreeBSD)
iQIcBAEBCAAGBQJRSjFDAAoJEKv/7bJACMb5qC8P/RvPy3KXY3breTO21tn+4yam
WnywhjayLW8EefHIYYX6Uky9yRSwMdWQ0eXJJC8nNelBzC4g9+k08EqE32onPNsZ
i+/T6vWfxbVAIVSmDUAhJVXzYnSWl7IcjYDdfUuqNDGx038RqJGmHhbcORKUPPEE
ykK/iCokZY9gcbxUr05e3brjOPCQYOvMrx+VgVU1sa6SX8pvyTWrlcBMubsZCj3e
t0pkOcb/JJgvSQGDyIvVSM6qr2e7sAbrdZbQN5ydTl7cxjCaUsdupzEi18ngsCMq
0C3F4UCzviUzesx0vjePb4tIhMamiAGPS0t2c3xLhUVOuKC17zknnaR68vtcR5cI
QXm0hjnBxufEZzIr0v/uai9vk1/9E17r/3Ocq6khR+eM78BevL7VNK02qlIoukWo
N6+v8Hpr/6Jp3X6xqKHAizF9vezwqociJvv1DWHU6S9Y3m/UKuxws70966YLndmr
ibcYtSd66+yw8wGSgf9/rEvjhro+dHq+7jXbpPaL3BJXZJDKfSlcAN+pZcjA/t20
GmI3CsmMFKW7InWRs/AeoQSjYxqvuR6dfQBAoRCvg4WeWM3iRRNPpwNFi3lqE4n6
kuXQv/uGryTrL0DX4Ryahda9mArtziwY47Bg93ZUroB8dLNuaGBsIYkOpNjrt7Dd
JLgjm6JDzYVCp/EyMDLu
=XtgP
-----END PGP SIGNATURE-----
--- End Message ---