Subject: Please use gcrypt11/gnutls11 instead of gcrypt7/gnutls10 Package: kdelibs Severity: important
'kdelibs-bin' depends on gcrypt7 or gnutls10. These packages are no longer supported by Upstream and contain serious deficiencies / bugs which may turn out to be a security problem. See [0] and followup emails, and [1] for further details. Therefore, we want to get rid of gcrypt7 and gnutls10 in Sarge. gcrypt11 and gnutls11 have an upwards-compatible API; in most cases you only have to update your debian/control file. Please upload a fixed version soon. Thank you. NB: I plan to do NMUs (on 2004-08-15) for any packages which haven't been updated at that time. [0] http://lists.debian.org/debian-release/2004/07/msg00075.html [1] http://bugs.debian.org/258975