Gentoo Archives: gentoo-user

From: Urs Schutz <u.schutz@×××××××.ch>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] GLSA «201110-01 / openssl» and acroread-9.4.2
Date: Tue, 17 Jan 2012 12:15:29
Message-Id: 20120117101340.64d400cd@bluewin.ch
In Reply to: Re: [gentoo-user] GLSA «201110-01 / openssl» and acroread-9.4.2 by Alan McKinnon
1 On Tue, 17 Jan 2012 12:35:50 +0200
2 Alan McKinnon <alan.mckinnon@×××××.com> wrote:
3
4 > On Mon, 16 Jan 2012 20:29:28 -0200
5 > Urs Schutz <u.schutz@×××××××.ch> wrote:
6 >
7 > > As far as I know acroread is not unmasked in this
8 > > installation, nor is openssl
9 > > > # grep -i acro /etc/portage/*
10 > > > # grep -i ssl /etc/portage/*
11 > > shows nothing, so acroread and ssl is «stable».
12 > >
13 > > For now I just uninstalled acroread to prevent the
14 > > installation of a buggy openssl version, but this seems
15 > > wrong for a mostly stable installation...
16 > >
17 > > Any hints how to proceed? Is there any danger to have an
18 > > old (and apparently buggy) openssl lib installed in
19 > > parallel with the recent one?
20 >
21 > That's always a tricky one.
22 >
23 > Users want Adobe's shiny stuff and Adobe is notorious for
24 > releasing crap software. For whatever reason, acroread on
25 > x86 profile requires openssl in the 0.9.8 series and that
26 > can't be worked around.
27 >
28 > The answer to your question is "are you prepared to live
29 > with it?"
30 >
31 > The GLSA indicates that this is quite a severe issue so
32 > maybe it should be hard masked. However, that will break
33 > acroread and there's only one version in the tree.
34 > Hardmask openssl:0.9.8 means hardmask acroread and that
35 > means thousands of whinging users.
36 >
37 > So the devs are between a rock and a hard place where all
38 > the issues are out of their control. The only middle path
39 > left is to inform all the users as much as possible and
40 > let them decide for themselves.
41 >
42 > Personally, I would deep-six acroread and use any one of
43 > the many PDF readers out there.
44 >
45 > The tax authority in my country uses new funky PDF
46 > features in Reader for on-line tax returns so I need
47 > access to Reader once a year. For that, there's wine,
48 > Windows in VirtualBox or the wife's computer.
49 >
50 >
51
52 Thanks for the reply. I switched to app-text/evince , this
53 seems fine for just reading pdf.
54
55 Urs