ROCK Linux security advisory structure proposal

"Daniel Jahre" <[email protected]> Tue, 21 Mar 2006 16:38:05 +0100
Newsgroups gmane.linux.distributions.rock.devel
Message-ID <[email protected]>
After the first security announcement I send out quickly today, Netrunner
suggested the annoucements should have a structure. I agree to that and want
to make a proposal for that in this mail. I used a SuSE security annoucement
as template for that. The announcement should be sent as mail and be linked
in the Wiki. I think it is useful it have an ID for every announcement, so
it can be referenced easy. My suggestion is to use the layout RL-$date-$nr,
e.g. RL-20060321-01 for the first advisory at that date. $nr should just be
increased.

--- begin of template ---
Subject: [Security Announcement] placebo (RL-20060320-02)

Package: placebo
Announcement ID: RL-20060320-02
Date: 2006-03-20
Affected Distributions: Crystal, LiveCD
Affected Releases: Crystal ROCK CLT
Cross References:

Content of this advisory:
1) Problem Description
2) Solution or Work-Around
3) Special instructions and notes
4) Updateing your source tree
5) Source package update
6) Binary package update

--------------------------------------------------------------------------------

1) Problem Description
An attacker might use a malformed input file for getting root access.

2) Solution or Workaround
There is no known Work-Around. Please update this package.

3) Special instruction and notes
none

4) Updateing your source tree
If you are using a subversion checkout of trunk, run:
   svn up

If you are using submaster run,
  sm sync
to merge the update from trunk into your tree

5) Source package update
As a user of an affected distribution you can update this package by
rebuilding it on your machine
run
   rocket updsrc
to update your local sources and
   rocket emerge placebo
to install the updated package

6) Binary package update
there are no new binary packages available for this package yet.

--- end of template ---

Please comment on this.

_______________________________________________
rock-devel mailing list
[email protected]
http://www.rocklinux.net/mailman/listinfo/rock-devel