Bug#732147: libtk-img: uses internal copies of libpng and libtiff

2013-12-14 Thread Julien Cristau
Source: libtk-img
Version: 1:1.4.2-1
Severity: serious
Tags: security

The latest changelog entry says you're now using internal copies of
libpng and libtiff.  Considering the security history of those two libs,
that is not acceptable.  Please find a way to use the standalong
versions.

Cheers,
Julien


signature.asc
Description: Digital signature


Bug#732147: libtk-img: uses internal copies of libpng and libtiff

2013-12-14 Thread Sergei Golovan
Hi Julien,

On Sat, Dec 14, 2013 at 10:53 PM, Julien Cristau jcris...@debian.org wrote:

 The latest changelog entry says you're now using internal copies of
 libpng and libtiff.  Considering the security history of those two libs,
 that is not acceptable.  Please find a way to use the standalong
 versions.

I did that until I could. As for now, to use the system-wide libpng
I'd have to revert to libtk-img 1.3 (and lose quite a few useful
changes including support for new image formats). And I don't know a
way how to use new libtiff 4.0 (libtk-img supports only 3.something
and uses libtiff internals, so porting isn't feasible for me).

Cheers!
-- 
Sergei Golovan


-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org