Bug#595171: CVE-2010-1519

Paul Wise pabs at debian.org
Fri Sep 3 04:15:09 UTC 2010


On Thu, Sep 2, 2010 at 9:08 PM, Christoph Egger <christoph at debian.org> wrote:

>    Would be probably best to get rid of glpng soon then (pabs: how's
> the status on cromium-bsu there?). Unfortunately I'm VAC for another
> week and probably offline most of the time (as well as keyless).

The SDL_Image loader released with chromium-bsu 0.9.14.1 from squeeze
works but has a minor rendering glitch that I wasn't able to fix yet.
Some details are available in the upstream bug report[1]. Help to fix
it or any of the other upstream bugs would be very much appreciated.
If the release team would accept the dependency change it I think it
would be reasonable to switch chromium-bsu to SDL_image and remove
glpng before squeeze releases instead of keeping it around. The impact
of the glpng security issue on chromium-bsu is minimal since most
people will never run it with anything other than the textures from
chromium-bsu-data.

http://sf.net/support/tracker.php?aid=2998438

-- 
bye,
pabs

http://wiki.debian.org/PaulWise





More information about the Pkg-games-devel mailing list