Package: xscreensaver
Version: 4.21-3
Severity: important

The main kde package 'kde' depends on xscreensaver. Now, if I 
understand this issue correctly, KDE has its own "randomization engine" 
for screensavers. This makes it ignore xscreensavers settings for what
screensavers should be included in 'random screensaver' and instead
randomize over all installed screensavers (at least that is how it 
seems to work per default). I *think* KDE's default setting for new 
users is to randomize screensavers; but even if it isn't, it is very 
easy for an experimenting user to flip this setting on, unaware of the
'risks' of running the web collage screensaver.

Result: without any deliberate action, a user running on a "default" debian 
install of KDE runs the risk of suddenly showing pornographic images on
the screen (fetched and shown by the 'web collage' screensaver). I have 
seen this happen.

While 'web collage' is a truly original screensaver based on a fun idea,
the thing is, there are workplace environments where this could potentially 
get people fired or sued. Hence, I think it is resonable to try to avoid any
accidental activation. Just like there is a fortune-off package for potentially 
offending fortunes, I suggest moving 'web collage' to a separate package 
'xscreensaver-off'.

However, if the maintainer feels this is not an xscreensaver 
problem, but rather an issue with kde's random screensaver
option, feel free to forward this bug report to the kde maintainers.

Also, just as a side note: another reason to avoid 'web collage' to
be activated unintentionally is that it is a significantly higher
security risk than any of the other screensavers, in that it might
pull an image from the web that exploits a buffer overflow in
the picture library.

//Rickard

-- System Information:
Debian Release: 3.1
  APT prefers testing
  APT policy: (900, 'testing'), (300, 'unstable')
Architecture: i386 (i686)
Kernel: Linux 2.4.27-2-686
Locale: LANG=en_US, LC_CTYPE=en_US (charmap=ISO-8859-1)

Versions of packages xscreensaver depends on:
ii  libatk1.0-0          1.8.0-4             The ATK accessibility toolkit
ii  libc6                2.3.2.ds1-21        GNU C Library: Shared libraries an
ii  libglade2-0          1:2.4.2-2           library to load .glade files at ru
ii  libglib2.0-0         2.6.4-1             The GLib library of C routines
ii  libgtk2.0-0          2.6.4-1             The GTK+ graphical user interface 
ii  libice6              4.3.0.dfsg.1-12.0.1 Inter-Client Exchange library
ii  libjpeg62            6b-10               The Independent JPEG Group's JPEG 
ii  libpam0g             0.76-22             Pluggable Authentication Modules l
ii  libpango1.0-0        1.8.1-1             Layout and rendering of internatio
ii  libsm6               4.3.0.dfsg.1-12.0.1 X Window System Session Management
ii  libx11-6             4.3.0.dfsg.1-12.0.1 X Window System protocol client li
ii  libxext6             4.3.0.dfsg.1-12.0.1 X Window System miscellaneous exte
ii  libxml2              2.6.16-7            GNOME XML library
ii  libxmu6              4.3.0.dfsg.1-12.0.1 X Window System miscellaneous util
ii  libxpm4              4.3.0.dfsg.1-12.0.1 X pixmap library
ii  libxrandr2           4.3.0.dfsg.1-12.0.1 X Window System Resize, Rotate and
ii  libxrender1          0.8.3-7             X Rendering Extension client libra
ii  libxt6               4.3.0.dfsg.1-12.0.1 X Toolkit Intrinsics
ii  xlibs                4.3.0.dfsg.1-12     X Keyboard Extension (XKB) configu
ii  zlib1g               1:1.2.2-4           compression library - runtime

-- no debconf information


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to