7 ms·
libebml is in the Ubuntu universe repository which means that it is not supported by Canonical. And in the Debian changelog for this package I don't see any men
by hs86 7y ago
libebml is in the Ubuntu universe repository which means that it is not supported by Canonical. And in the Debian changelog for this package I don't see any mentions of a security issue that was fixed 16 months ago: https://metadata.ftp-master.debian.org/changelogs//main/libe/libebml/libebml_1.3.9-2_changelog https://metadata.ftp-master.debian.org/changelogs//main/libe...
I am loosing more and more confidence that these "package the world and freeze everything in place" distros are the right choice for end users.
- yrro 7y agoFYI given a CVE or package name, you can view the state of a particular issue across all Debian versions using the Security Bug Tracker. For instance https://security-tracker.debian.org/tracker/CVE-2019-13615 https://security-tracker.debian.org/tracker/CVE-2019-13615 In this case, this hasn't yet been updated with the info from the VLC team, I expect it'll be marked ignore or not-vulnerable once that happens. I don't know the real CVE for the libebml issue but it doesn't appear to be listed at https://security-tracker.debian.org/tracker/source-package/libebml https://security-tracker.debian.org/tracker/source-package/l... which means that the Debian security team aren't aware of it.
- thegeomaster 7y ago> I am loosing more and more confidence that these "package the world and freeze everything in place" distros are the right choice for end users. I'm there with you. I use a rolling distro (Arch) and I update all packages to the latest versions whenever I'm bored. I do this because I can't remember the last time something broke this way. I've been doing that for ~6 years on 3 different machines. On the other hand, a lot of my friends use Ubuntu as their main OS and they constantly have mysterious issues with software, trouble installing stuff (a ton of things require binary-only vendor-run PPAs which then often have out-of-date versions), etc. So I'm wondering, at least for desktop use-cases, what exactly is gained there? I would've thought that freezing all packages and issuing a release would allow a much more rigorous QA process and make the system rock solid. But somehow a huge company (Canonical) cannot make a system that is as stable as orders of magnitude less popular, volunteer-run rolling distribution. Something just doesn't add up to me there. It could be a bias of my sample, or Canonical just not caring much about the desktop experience anymore. (I run a lot of machines on Ubuntu LTS and for the server-side it's pretty good.)
- effie 7y agoCanonical probably does care less than in their desktop golden years, now they are perhaps focusing on the server os market (cloud). The distribution model has the advantage of single click install. Great for basic users, but you run outdated software, sometimes with well known security holes. For power users who can take some work in maintaining their system, it seems to me that your way - keeping up with the latest version of all software - gives you better security.
- mort96 7y agoWhat do you mean? Arch works the same way as Ubuntu; there's a package manager, you use it to install software from the system repositories. `apt-get install vlc` is no easier or more user friendly than `pacman -S vlc`. I imagine gnome-software even works it does in Ubuntu, though I haven't tried using it. The only difference is that Arch updates their repos' packages as soon as a new version is available upstream (after some testing of course), while Ubuntu doesn't.
- effie 7y agoI meant the LTS model such as Ubuntu 18.04 gives you old version software with the possibility of worse functionality and more security holes. Arch may be more up-to-date than Ubuntu, but it isn't in the same category; it is not LTS, and it is not as widespread.
- mort96 7y agoI was mostly responding to the part about how "The distribution model has the advantage of single click install". What's the difference in how "single click" installation can be between rolling and LTS?
- effie 7y agoThe point is classic distributions which support their product for a long time (Debian, Ubuntu,RHEL,Centos) are easier to use for basic users you can meet on street. With Arch or Gentoo, you are right that there is a package manager which makes installation of software easier, but the system is not easy to use for BFUs. When problems with installation/upgrades arise (which is more likely for Arch/Gentoo), you are expected to spend some time becoming proficient GNU/Linux user who resolves things in command line.
- fulafel 7y agoUbuntu badly needs a mechanism for blacklisting vulnerable "universe" categorised software that handle untrusted data from the network. Or some other way of protecting users in these cases. This is by far not the first time this happens, though good that there is a public outcry this time...
- bzbarsky 7y agoIs VLC also in the universe repository? Because it sounds like the VLC binary Ubuntu provides is linked against this unsupported and out-of-date library, whereas the VLC binaries the VLC folks themselves provide are linked against a fixed version of the library...
- flukus 7y agoIt looks like the problem is that their is no stable version with any long term commitments to security fixes, at least I couldn't find any mention of one on the website or github page. I'm can't see any release branches on github. So the problem is VLC using unstable dependencies without a mature release cycle.