5 ms·
> The reporter is using Ubuntu 18.04, which is an old version of Ubuntu, and clearly has not all the updated libraries. It's not a "old" version of Ubuntu its
by codewithcheese 7y ago
> The reporter is using Ubuntu 18.04, which is an old version of Ubuntu, and clearly has not all the updated libraries.
It's not a "old" version of Ubuntu its the latest LTS.
- M2Ys4U 7y agoLTS == old. That's the point of LTS.
- pgeorgi 7y agoJust that Ubuntu apparently forgot about the "S" part of "LTS", or they could have updated that package. Alternatively (because libebml is "universe", that is, unsupported), stop ripping out maintained components from projects to "use system packages instead" which are not maintained. It's stuff like this that makes Firefox and Pale Moon play hardball with distros that mess up their software. (nevermind that the Pale Moon devs aren't even trying to solve such things amicably)
- Mathnerd314 7y agoThe actual packages are from Debian, and Debian keeps them updated. Debian stretch (2017) is vulnerable, buster is not. Ubuntu 18.04 LTS is based on buster (https://askubuntu.com/questions/445487/what-debian-version-are-the-different-ubuntu-versions-based-on https://askubuntu.com/questions/445487/what-debian-version-a...) so compatibility isn't the problem. Judging from bugs like https://bugs.launchpad.net/ubuntu/+source/libebml/+bug/1412054 https://bugs.launchpad.net/ubuntu/+source/libebml/+bug/14120... the problem is just that nobody at Ubuntu is responsible for keeping it updated in LTS releases. tl;dr Avoid Ubuntu LTS because they don't maintain their packages properly.
- parliament32 7y agoStretch is supposed to keep getting security fixes until June 2022 but this particular library doesn't have the fix backported yet: https://security-tracker.debian.org/tracker/CVE-2019-13615 https://security-tracker.debian.org/tracker/CVE-2019-13615
- rlpb 7y agoThe package in Debian was updated four days before Ubuntu 18.04 was released. That's why the update didn't make 18.04 "automatically". Since then, both Debian and Ubuntu have acted the same: not knowing about the vulnerability, neither updated their [release] packages. Buster happened to have been updated before it was frozen for release. Stretch was not, and neither was 18.04. > tl;dr Avoid Ubuntu LTS because they don't maintain their packages properly. By your logic, you should also avoid Debian then, since they followed the same process here. What got updated and what didn't was merely an accident of calendar freeze dates. At the time I write this, Debian stretch is still on 1.3.4-1 and hasn't been updated. Ubuntu 18.04 has now been updated.
- Mathnerd314 7y ago> By your logic, you should also avoid Debian then It's true, I was looking at Debian testing & sid as possibilities but apparently they can't handle mass rebuilds very well and the recommended workaround is to just not update. So rolling distros only for me. (current NixOS)
- gsich 7y agoThe library is not the newest one, so it is by definition, old.
- yjftsjthsd-h 7y agoSorta, but most people mean "obsolete, shouldn't use" when they say old. For instance, postgres currently has 5 in-support versions going back to 9.4; are 9.4-10 "old"?
- couchand 7y agoA library version with unfixed security vulnerabilities absolutely should be classified as "shouldn't use".
- Redoubts 7y agoPostgres without upsert is definitely old.
- justinclift 7y ago9.4 is definitely "old". You can use it if you want, and it has support (for now), but it's not a good idea to base new projects on it unless they're likely short term. ;)
- deleted 7y ago[deleted]