[Pkg-utopia-maintainers] Bug#658541: upower: Shouldn't depend on libimobiledevice (that depends on usbmuxd) causing security issue and bloat

Touko Korpela touko.korpela at iki.fi
Fri Feb 3 20:47:43 UTC 2012


Package: upower
Version: 0.9.15-1
Severity: normal


What is the reason upower depends on libimobiledevice2? That library depends
on usbmuxd (daemon which was vulnerable to malicious USB devices,
CVE-2012-0065).

In my opinion, upower shouldn't require installation of Apple-specific
libraries and daemons for all users. So recommends at most, or suggest.

PS: You should look also other bugs that aren't answered





More information about the Pkg-utopia-maintainers mailing list