Package: libcurl3
Version: 7.21.2-1
Severity: normal

The file libcurl3/lib/security.c is derived from a file licensed with
the attribution-required BSD license.  According to clause 2,
"Redistributions in binary form must reproduce the above copyright
notice, this list of conditions and the following disclaimer in the
documentation and/or other materials provided with the distribution."

There is a brief mention at the end of /usr/share/doc/libcurl3/README:

  Curl contains pieces of source code that is Copyright (c) 1998, 1999
  Kungliga Tekniska H�gskolan. This notice is included here to comply with the
  distribution terms.

There are two problems with this:

1) Clause 2 actually requires not only the copyright notice, but also the
"list of conditions and the following disclaimer" in the documentation,
which are missing in the README.

2) This notice shouldn't actually be in /usr/share/doc/libcurl3/README --
it should be in /usr/share/doc/libcurl3/copyright, to facilitate small
debian-based distributions which often trim non-copyright information
from /usr/share/doc.
(Section 12.5 of http://www.debian.org/doc/debian-policy/ch-docs.html)


-- System Information:
Debian Release: squeeze/sid
  APT prefers unstable
  APT policy: (500, 'unstable')
Architecture: i386 (i686)

Kernel: Linux 2.6.32-5-686 (SMP w/2 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/bash

Versions of packages libcurl3 depends on:
ii  ca-certificates         20090814+nmu2    Common CA certificates
ii  libc6                   2.11.2-7         Embedded GNU C Library: Shared lib
ii  libgssapi-krb5-2        1.8.3+dfsg-2     MIT Kerberos runtime libraries - k
ii  libidn11                1.18-1           GNU Libidn library, implementation
ii  libldap-2.4-2           2.4.23-6         OpenLDAP libraries
ii  libssh2-1               1.2.6-1          SSH2 client-side library
ii  libssl0.9.8             0.9.8o-2         SSL shared libraries
ii  zlib1g                  1:1.2.3.4.dfsg-3 compression library - runtime

libcurl3 recommends no packages.

libcurl3 suggests no packages.

-- no debconf information



-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Reply via email to