Bug#762523: Multiple embedded code copies, missing sources

2014-09-23 Thread David Prévot
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, Le 23/09/2014 08:04, Craig Small a écrit : > On Tue, Sep 23, 2014 at 12:55:54AM -0400, David Prévot wrote: >> > Tags: security > Why is it a security issue? I see no security issue. For example, I just prepared a php-getid3 update yesterday to

Bug#762523: Multiple embedded code copies, missing sources

2014-09-23 Thread Craig Small
On Tue, Sep 23, 2014 at 12:55:54AM -0400, David Prévot wrote: > Tags: security Why is it a security issue? I see no security issue. > I just noticed that the wordpress package embeds since ages in > /usr/share/wordpress/wp-includes/ID3 a copy of the php-getid3 code > instead of depending on the De

Bug#762523: Multiple embedded code copies, missing sources

2014-09-22 Thread David Prévot
Source: wordpress Severity: important Tags: security Hi, I just noticed that the wordpress package embeds since ages in /usr/share/wordpress/wp-includes/ID3 a copy of the php-getid3 code instead of depending on the Debian package. Also, /usr/share/wordpress/wp-includes/js/mediaelement contains a