Bug#789256: cmus: Pulls in unwanted and potentially dangerous DECnet packages through libroar2

Tobias Frost tobi at debian.org
Sat Jun 20 19:49:04 UTC 2015


On Sat, 20 Jun 2015 20:46:17 +0200 John Paul Adrian Glaubitz <glaubitz at physik.fu-berlin.de> wrote:

> >> Currently cmus is definitely getting stuck on a _fresh_ install,
> >> simply by installing with "apt-get install cmus".
> > 
> > On those systems where you experience cmus being stuck, is the
> > package "dnet-common" also installed (or was it ever)?
>

I cannot reproduce this in a clean sid chroot:
Can you please describe how you get your quoted behaviour?

root at edoras:/home/tobi# LANG=C apt-get install cmus 
Reading package lists... Done 
Building dependency tree
Reading state information... Done 
The following extra packages will be installed:  
cmus-plugin-ffmpeg i965-va-driver libao-common libao4 libasound2
libasyncns0 libavcodec56 libavformat56   libavresample2 libavutil54
libcddb2 libcdio-cdda1 libcdio13 libcue1 libdnet libdrm-intel1
libdrm-nouveau2   libdrm-radeon1 libdrm2 libelf1 libfaad2 libflac8
libgl1-mesa-dri libgl1-mesa-glx libglapi-mesa libgsm1   libice6
libjson-c2 libllvm3.5 libmad0 libmodplug1 libmp3lame0 libmpcdec6
libnuma1 libogg0 libopenjpeg5   libopus0 liborc-0.4-0 libpciaccess0
libpulse0 libroar2 libschroedinger-1.0-0 libslp1 libsm6 libsndfile1  
libspeex1 libspeexdsp1 libtheora0 libtxc-dxtn-s2tc0 libva1 libvdpau1
libvorbis0a libvorbisenc2   libvorbisfile3 libvpx2 libwavpack1 libx11-6
libx11-xcb1 libx264-146 libx265-59 libxau6 libxcb-dri2-0  
libxcb-dri3-0 libxcb-glx0 libxcb-present0 libxcb-sync1 libxcb1
libxdamage1 libxdmcp6 libxext6 libxfixes3   libxi6 libxshmfence1
libxtst6 libxvidcore4 libxxf86vm1 va-driver-all vdpau-va-driver

Suggested packages: 
libaudio2 libesd0 libesd-alsa0 libasound2-plugins dnet-common
opus-tools pciutils pulseaudio   libroar-plugins-universal
roaraudio-server libmuroar0 slpd socat openslp-doc speex
nvidia-vdpau-driver vdpau-driver libx265-59-dbg xvba-va-driver 

The following NEW packages will be installed:
cmus cmus-plugin-ffmpeg i965-va-driver libao-common libao4
libasound2 libasyncns0 libavcodec56 libavformat56 libavresample2
libavutil54 libcddb2 libcdio-cdda1 libcdio13 libcue1 libdnet
libdrm-intel1   libdrm-nouveau2 libdrm-radeon1 libdrm2 libelf1 libfaad2
libflac8 libgl1-mesa-dri libgl1-mesa-glx   libglapi-mesa libgsm1
libice6 libjson-c2 libllvm3.5 libmad0 libmodplug1 libmp3lame0
libmpcdec6 libnuma1   libogg0 libopenjpeg5 libopus0 liborc-0.4-0
libpciaccess0 libpulse0 libroar2 libschroedinger-1.0-0 libslp1   libsm6
libsndfile1 libspeex1 libspeexdsp1 libtheora0 libtxc-dxtn-s2tc0 libva1
libvdpau1 libvorbis0a   libvorbisenc2 libvorbisfile3 libvpx2
libwavpack1 libx11-6 libx11-xcb1 libx264-146 libx265-59 libxau6  
libxcb-dri2-0 libxcb-dri3-0 libxcb-glx0 libxcb-present0 libxcb-sync1
libxcb1 libxdamage1 libxdmcp6 libxext6   libxfixes3 libxi6
libxshmfence1 libxtst6 libxvidcore4 libxxf86vm1 va-driver-all
vdpau-va-driver 0 upgraded, 79 newly installed, 0 to remove and 0 not
upgraded.

LANG=C dpkg -l cmus dnet-common libroar2
Desired=Unknown/Install/Remove/Purge/Hold
|
Status=Not/Inst/Conf-files/Unpacked/halF-conf/Half-inst/trig-aWait/Trig-pend
|/ Err?=(none)/Reinst-required (Status,Err: uppercase=bad)
||/ Name                  Version         Architecture    Description
+++-=====================-===============-===============-================================================
ii  cmus                  2.5.0-7+b1      amd64           lightweight
ncurses audio player
un  dnet-common           <none>          <none>          (no
description available)
ii  libroar2              1.0~beta11-1    amd64           foundation
libraries for the RoarAudio sound ser

root at edoras:/home/tobi# su - tobi
tobi at edoras:~$ cmus
(cmus interface starts up apperantly fine)

--
tobi
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 819 bytes
Desc: This is a digitally signed message part
URL: <http://lists.alioth.debian.org/pipermail/pkg-multimedia-maintainers/attachments/20150620/beba566a/attachment.sig>


More information about the pkg-multimedia-maintainers mailing list