Multiple license issues

Bug #703896 reported by Niels Thykier
24
This bug affects 2 people
Affects Status Importance Assigned to Milestone
dropbox (Debian)
Fix Released
Unknown
dropbox (Ubuntu)
Fix Released
High
Unassigned
Natty
Fix Released
High
Unassigned

Bug Description

Binary package hint: dropbox

Hi

Debian bug #610257[1] suggests that there possibly multiple license issues in dropbox:

"""
1) ncrypt-0.6.4-*.egg/, according to its PKG-INFO (which is horribly
mangled, BTW), contains a GPL-licensed library with accompanying source.
Additionally, this library is linked to OpenSSL, but those two licenses
are incompatible.

2) netifaces-0.5*.egg/ contains the netifaces library, which is
MIT-licensed. One of the clause of the license is "The above copyright
notice and this permission notice shall be included in all copies or
substantial portions of the Software." Neither is included in dropbox.

3) _dbus*_bindings.so is the python-dbus library. It is MIT-licensed,
but copyright & permission notices are not included.

4) _librsync.so contains statically-linked librync library which is
under LGPL-2.1+ license. No source is provided.

5) _speedups.so contains (parts of) the simplejson library. It is
MIT-licensed, but copyright & permission notices are not included.

6) pyexpat.so contains statically linked Expat library. It is
MIT-licensed, but copyright & permission notices are not included.

7) libcrypto.so.0.9.8, libssl.so.0.9.8 are parts of the OpenSSL library.
Its license require that "Redistributions in binary form must reproduce
the above copyright notice, this list of conditions and the following
disclaimer in the documentation and/or other materials provided with the
distribution." Neither is reproduced in dropbox.

8) libncurses.so.5 is the ncurses library. It is MIT-licensed, but
copyright & permission notices are not included.
"""

I figured you might want to be made aware of this.

~Niels

[1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=610257

Revision history for this message
Iain Lane (laney) wrote :

Hi,

I'm subscribing ubuntu-archive so that the package can be re-reviewed and removed if it is indeed found to be un-redistributable.

Cheers,
Iain

Changed in dropbox (Ubuntu):
importance: Undecided → High
status: New → Triaged
Revision history for this message
Iain Lane (laney) wrote :

It has just been removed from Debian:

  http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=610300#25

Changed in dropbox (Debian):
status: Unknown → Fix Released
Revision history for this message
Jonathan Riddell (jr) wrote :

Deleted from archive

Changed in dropbox (Ubuntu Natty):
status: Triaged → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.