Re: Vulnerability and Patch-Management in Linux (and other Unix)
Rainer Duffner <[email protected]> Fri, 20 Jun 2008 18:57:52 +0200
| Newsgroups | gmane.comp.security.linux |
|---|---|
| Message-ID | <[email protected]> |
Rados=C5=82aw Antoniuk schrieb: > Hi, > > For debian/ubuntu just a simple cure: > cron-apt - automatic update of packages using apt-get > > > =20 Well, the point is: we don't want to have automatic updates. I'd rather like to be able to answer questions like "Which of my=20 Linux-boxes actually does have that stupid privilege escalation bug?" We have to plan updates very carefully, as not to break=20 customer-applications (we do managed hosting). In theory, a yum update shouldn't create a API/ABI breakage - but "In=20 theory, this shouldn't have happened" is a bad excuse to give to the=20 customer... So, I'd like to have a tool at hand that gives me a good overview about=20 the "state of the datacenter", patch-wise. Pakiti looks good - I must take a closer look and see how useful it is=20 in practice. cheers, Rainer