Package: apt-listchanges Version: 2.83 Severity: important Severity set as important, because not reliably doing its job partially defeats its purpose. What I've seen quit a few times on different machines is a too long changelog (like dating back to 2008 for sid), but now a package is completely missed, see the following excerpt for todays security update:
4 aktualisiert, 0 neu installiert, 0 zu entfernen und 0 nicht aktualisiert. Es müssen 1522kB an Archiven heruntergeladen werden. Nach dieser Operation werden 73,7kB Plattenplatz freigegeben. Möchten Sie fortfahren [J/n]? Hole:1 http://127.0.0.1 lenny/updates/main libfreetype6-dev 2.3.7-2+lenny2 [713kB] Hole:2 http://127.0.0.1 lenny/updates/main libfreetype6 2.3.7-2+lenny2 [386kB] Hole:3 http://127.0.0.1 lenny/updates/main libmikmod2-dev 3.1.11-a-6+lenny1 [266kB] Hole:4 http://127.0.0.1 lenny/updates/main libmikmod2 3.1.11-a-6+lenny1 [157kB] Es wurden 1522kB in 2s geholt (645kB/s) Lese Changelogs... Fertig freetype (2.3.7-2+lenny2) stable-security; urgency=high * CVE-2010-2497 freetype integer underflow #30082 #30083 * CVE-2010-2498 freetype invalid free #30106 * CVE-2010-2499 freetype buffer overflow #30248 #30249 * CVE-2010-2500 freetype integer overflow #30263 * CVE-2010-2519 freetype heap buffer overflow #30306 * CVE-2010-2520 freetype invalid realloc #30361 * CVE-2010-XXXX freetype demos buffer overflows #30054 -- Moritz Muehlenhoff <j...@debian.org> Tue, 13 Jul 2010 19:56:44 +0200 apt-listchanges: Wollen Sie fortsetzen? [J/n] There is no changelog for libmikmod2! Currently I have: ii libmikmod2 3.1.11-a-6 A portable sound library Pressing "j" (German for "y") installs both packages. After installation, I can read the changelog now: libmikmod (3.1.11-6+lenny1) stable-security; urgency=high * CVE-2009-3995 CVE-2009-3996 -- Moritz Muehlenhoff <j...@debian.org> Mon, 12 Jul 2010 19:32:07 +0200 What makes me wonder is, however, that the "-a-" is missing in the version number in libmikmod, so if this is also an error in libmikmod, please clone and reassing. If you need further information, do not hesitate to ask. -- System Information: Debian Release: 5.0.5 APT prefers stable APT policy: (500, 'stable') Architecture: amd64 (x86_64) Kernel: Linux 2.6.27.10-grsec-cz03 Locale: lang=de...@euro, lc_ctype=de...@euro (charmap=UTF-8) (ignored: LC_ALL set to de_DE.UTF-8) Shell: /bin/sh linked to /bin/bash Versions of packages apt-listchanges depends on: ii apt 0.7.20.2+lenny2 Advanced front-end for dpkg ii debconf [debconf-2.0] 1.5.24 Debian configuration management sy ii debianutils 2.30 Miscellaneous utilities specific t ii python 2.5.2-3 An interactive high-level object-o ii python-apt 0.7.7.1+nmu1 Python interface to libapt-pkg ii python-support 0.8.4lenny2 automated rebuilding support for P ii ucf 3.0016 Update Configuration File: preserv Versions of packages apt-listchanges recommends: ii exim4 4.69-9 metapackage to ease Exim MTA (v4) ii exim4-daemon-light [mail-tran 4.69-9 lightweight Exim MTA (v4) daemon Versions of packages apt-listchanges suggests: ii amaya [www-brows 9.51-2.1 Web Browser, HTML Editor and Testb ii chimera2 [www-br 2.0a19-5 Web browser for X ii elinks [www-brow 0.11.4-3 advanced text-mode WWW browser ii epiphany-gecko [ 2.22.3-9 Intuitive GNOME web browser - Geck ii iceweasel [www-b 3.0.6-3 lightweight web browser based on M ii kazehakase [www- 0.5.4-2.2+lenny1 GTK+-base web browser that allows ii konqueror [www-b 4:3.5.9.dfsg.1-6+lenny1 KDE's advanced file manager, web b ii konsole [x-termi 4:3.5.9.dfsg.1-6+lenny1 X terminal emulator for KDE ii links [www-brows 2.1pre37-1.1 Web browser running in text mode ii links2 [www-brow 2.1pre37-1.1 Web browser running in both graphi ii lynx-cur [www-br 2.8.7dev9-2.1 Text-mode WWW Browser with NLS sup ii python-glade2 2.12.1-6 GTK+ bindings: Glade support ii python-gtk2 2.12.1-6 Python bindings for the GTK+ widge ii w3m [www-browser 0.5.2-2+b1 WWW browsable pager with excellent ii xterm [x-termina 235-2 X terminal emulator -- debconf information: * apt-listchanges/confirm: true * apt-listchanges/email-address: * apt-listchanges/which: both * apt-listchanges/frontend: pager * apt-listchanges/save-seen: true -- Dr. Helge Kreutzmann deb...@helgefjell.de Dipl.-Phys. http://www.helgefjell.de/debian.php 64bit GNU powered gpg signed mail preferred Help keep free software "libre": http://www.ffii.de/
signature.asc
Description: Digital signature