Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 444262 - media-video/avidemux-2.5.6-r2 has x11-libs/libva automagic
Summary: media-video/avidemux-2.5.6-r2 has x11-libs/libva automagic
Status: RESOLVED WONTFIX
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Qt Bug Alias
URL:
Whiteboard:
Keywords: PMASKED
Depends on:
Blocks:
 
Reported: 2012-11-22 08:43 UTC by Nikoli
Modified: 2013-01-20 10:29 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Nikoli 2012-11-22 08:43:36 UTC
After rebuilding world with USE="-vaapi" and running depclean revdep-rebuild found problem:
 * Checking dynamic linking consistency
[ 63% ]  *   broken /usr/lib64/libADM5avcodec.so.53 (requires libva.so.1)
[ 100% ]
 * Generated new 3_broken.rr
 * Assigning files to packages
 *   /usr/lib64/libADM5avcodec.so.53 -> media-video/avidemux
Comment 1 Michael Palimaka (kensington) gentoo-dev 2012-12-05 15:02:40 UTC
This appears to be due to the bundled ffmpeg-0.9 (which is full of security holes).

What to do?
Comment 2 Markos Chandras (RETIRED) gentoo-dev 2012-12-05 15:20:07 UTC
Maybe time to remove the ebuild?
Comment 3 Michael Palimaka (kensington) gentoo-dev 2012-12-05 15:31:08 UTC
(In reply to comment #2)
> Maybe time to remove the ebuild?

In favour of 2.6.0 (which bundles ffmpeg-0.11.1 with no reported vulnerabilities...yet) or nuke the package entirely?
Comment 4 Markos Chandras (RETIRED) gentoo-dev 2012-12-05 15:33:04 UTC
(In reply to comment #3)
> (In reply to comment #2)
> > Maybe time to remove the ebuild?
> 
> In favour of 2.6.0 (which bundles ffmpeg-0.11.1 with no reported
> vulnerabilities...yet) or nuke the package entirely?

yeah just keep 2.6.0 for now
Comment 5 Ben de Groot (RETIRED) gentoo-dev 2012-12-08 07:49:42 UTC
Mask, but keep 2.5.x in the tree please
Comment 6 Davide Pesavento (RETIRED) gentoo-dev 2012-12-08 08:11:33 UTC
(In reply to comment #5)
> Mask, but keep 2.5.x in the tree please

+1
Comment 7 Ben de Groot (RETIRED) gentoo-dev 2013-01-20 10:29:57 UTC
Package is now masked:

# Ben de Groot <yngwin@gentoo.org> (20 Jan 2013)
# 2.5* has known security and other issues due to bundled ffmpeg,
# see (bugs #446468 and #444262)
# 2.6* is masked for testing, and may have unknown issues due to bundled ffmpeg
# This package needs a new, dedicated maintainer. We voted for keeping it in
# the tree for now, so users who are willing to accept the known issues can
# still easily install it by unmasking this.
media-video/avidemux