Re: [Security-Discuss] Wine & Security upgrades: move it to contribs?

Vincent Danen <vdanen-4qZELD6FgxhWk0Htik3J/[email protected]> Tue, 10 Jan 2006 16:29:43 -0700
Newsgroups gmane.linux.mandrake.security.general
Organization Mandriva
Message-ID <[email protected]>
* Frederik Himpe <[email protected]> [2006-01-10 22:27:59 +0100]:

> It seems that even Wine is vulnerable to the dreaded WMF vulnerability
> Windows suffered lately. Now, Wine in fact, is in main. So that means it
> should get security updates too.
> 
> On the other hand, I can imagine that wine is such a moving target that
> it's almost impossible to follow security issues and fix them, without
> switching to a complete new version. Furthermore, Wine can be perfectly
> fine for running some applications, but for a lot of Windows programs,
> it is hardly usable. This makes me wonder: does Wine really belong in
> Main? Seems like these characteristics make it much more suitable for
> contribs...

This is something you may want to bring up on the cooker list.  We
can't, in mid-release, decide to move something from main to contribs
because it's uncomfortable for us to update (although I completely agree
with you here).

Having said that, I can't ever recall doing a wine update in the past.

> I attached the patch which is included in Ubuntu's Wine 0.9.5 package
> which fixes this vulnerability.
> http://packages.ubuntu.com/dapper/otherosfs/wine

Thanks.  This was on our TODO list but a few things had higher priority.

-- 
"lynx -source http://linsec.ca/vdanen.asc | gpg --import"
{FEE30AD4 : 7F6C A60C 06C2 4811 FA1C  A2BC 2EBC 5E32 FEE3 0AD4}
Wasting time like it was free...
signature.asc (application/pgp-signature, 186 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.1 (Darwin)

iD8DBQFDxENmLrxeMv7jCtQRAnONAKCW5fezHzk+OhLPZYGUsiCvksEEvwCgwLP6
DFfvR5Nz2WwEIhPP4UbAX3s=
=jhli
-----END PGP SIGNATURE-----