Package: security.debian.org
Severity: important

Hello,

the recent DSA-1292-1 for qt4-x11 says:

> For the stable distribution (etch), this problem has been fixed in
> version 4.2.1-2etch1

However, this seems to be lower than the current version in etch:

| silencer:~# apt-cache policy libqt4-core
| libqt4-core:
|   Installed: 4.2.1-2+b1
|   Candidate: 4.2.1-2+b1
|   Version table:
|      4.2.3-1+b1 0
|          -1 http://ftp.de.debian.org sid/main Packages
|  *** 4.2.1-2+b1 0
|         500 http://ftp2.de.debian.org etch/main Packages
|         100 /var/lib/dpkg/status
|      4.2.1-2etch1 0
|         500 http://security.debian.org etch/updates/main Packages

| silencer:~# dpkg --compare-versions 4.2.1-2+b1 \> 4.2.1-2etch1 && echo true
| true

As a result, the security upgrade won't be installed automatically using
APT.


The higher version number seems to originate from an automatic buildd
rebuild; from the changelog:

| qt4-x11 (4.2.1-2+b1) unstable; urgency=low
| 
|   * Binary-only non-maintainer upload for i386; no source changes.
|   * Rebuild against libmysqlclient15off (>= 5.0.27-1)
| 
|  -- Debian/i386 Build Daemon <buildd_i386-saens>  Sun, 18 Feb 2007 17:40:30 
-0600
| 
| qt4-x11 (4.2.1-2) unstable; urgency=low
| 
| [...]
| 
|  -- Brian Nelson <[EMAIL PROTECTED]>  Tue, 31 Oct 2006 02:42:02 -0500

So this seems to be a systematic problem here that will cause trouble
again with further security upgrades or NMUs; the '+' in the appended
version strings seems to be rather high, perhaps it should be changed to
something lower for the future.

Regards, Fabian

-- 
Fabian "zzz" Pietsch - http://zzz.arara.de/


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to