Re: Vulnerability and Patch-Management in Linux (and other Unix)

Rainer Duffner <[email protected]> Fri, 20 Jun 2008 18:57:52 +0200
Newsgroups gmane.comp.security.linux
Message-ID <[email protected]>
Rados=C5=82aw Antoniuk schrieb:
> Hi,
>
> For debian/ubuntu just a simple cure:
> cron-apt - automatic update of packages using apt-get
>
>
>  =20


Well, the point is: we don't want to have automatic updates.
I'd rather like to be able to answer questions like "Which of my=20
Linux-boxes
actually does have that stupid privilege escalation bug?"

We have to plan updates very carefully, as not to break=20
customer-applications (we do managed hosting).
In theory, a yum update shouldn't create a API/ABI breakage - but "In=20
theory, this shouldn't have happened" is a bad excuse to give to the=20
customer...

So, I'd like to have a tool at hand that gives me a good overview about=20
the "state of the datacenter", patch-wise.
Pakiti looks good - I must take a closer look and see how useful it is=20
in practice.


cheers,
Rainer