On Tue, Sep 23, 2014 at 12:55:54AM -0400, David Prévot wrote:
> Tags: security
Why is it a security issue? I see no security issue.

> I just noticed that the wordpress package embeds since ages in
> /usr/share/wordpress/wp-includes/ID3 a copy of the php-getid3 code
> instead of depending on the Debian package.
> 
> Also, /usr/share/wordpress/wp-includes/js/mediaelement contains a copy
> of the recently uploaded libjs-mediaelement, and that copy includes
> sourceless (and a priori even unbuildable) Flash and Silverlight
> binaries.
> 
> Maybe a complete review would be worth it before Jessie gets released
> (I saw other JS bits, some seemed to be handled via dh-linktree, not
> sure all were, just focused on some parts I’m currently packaging).
It embeds a lot, generally because the versions that Debian ships are
not the same that come with wordpress. It's almost getting to the stage
where its plainly not worthwhile packaging the Debian package.
I'm really not inclined to play find the embedded js that is almost but
not quite the same as shipped in Debian game.

 - Craig

-- 
Craig Small (@smallsees)   http://enc.com.au/       csmall at : enc.com.au
Debian GNU/Linux           http://www.debian.org/   csmall at : debian.org
GPG fingerprint:        5D2F B320 B825 D939 04D2  0519 3938 F96B DF50 FEA5


-- 
To UNSUBSCRIBE, email to [email protected]
with a subject of "unsubscribe". Trouble? Contact [email protected]

Reply via email to