Bug#601181: openscenegraph uses an embedded copy of vulnerable lib3ds

2010-10-26 Thread Alberto Luaces
This will take some time. As I expect we all feared :) , the embedded copy of lib3ds in OSG is modified in order to address endianess issues and things like that. I will get a patch as soon as I can. -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsub

Bug#601181: openscenegraph uses an embedded copy of vulnerable lib3ds

2010-10-23 Thread Silvio Cesare
Package: libopenscenegraph7 Version: 2.4.0-1.1 Severity: important Tags: security openscenegraph uses an embedded copy of lib3ds 1.1. This version of lib3ds is vulnerable to http://security-tracker.debian.org/tracker/CVE-2010-0280. The desired outcome is that openscenegraph use the system wide lib