Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 235412 - texlive-2007-r3 depends on freetype-1*, no secure freetype-1* available
Summary: texlive-2007-r3 depends on freetype-1*, no secure freetype-1* available
Status: RESOLVED DUPLICATE of bug 225851
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: All Linux
: High critical (vote)
Assignee: Gentoo Linux bug wranglers
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2008-08-21 23:07 UTC by Florian Friesdorf
Modified: 2008-08-22 18:33 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Florian Friesdorf 2008-08-21 23:07:38 UTC
texlive-2007-r3 depends on freetype-1, but there is a glsa for the most recent freetype-1*.

$ paludis --query -D texlive |grep freetype
            =media-libs/freetype-1*

$ paludis -r
* media-libs/freetype-1.4_pre20080316-r1::installed NOT OK
    This package has following security issues:
    GLSA-200806-10: "FreeType: User-assisted execution of arbitrary code"
        -> /var/paludis/repositories/gentoo/metadata/glsa/glsa-200806-10.xml

Raised severity as it seems that it is not possible to use texlive without the insecure freetype.

Reproducible: Always

Steps to Reproduce:
Comment 1 Jeroen Roovers (RETIRED) gentoo-dev 2008-08-22 18:33:32 UTC

*** This bug has been marked as a duplicate of bug 225851 ***