Re: Secure Linux From Scratch

Archaic <[email protected]>
Newsgroups gmane.linux.lfs.security
Message-ID <[email protected]>
On Fri, Dec 19, 2003 at 12:53:53PM +0000, Ken Moffat wrote:
> 
>  I think that using a different version of gcc, let alone a different
> version of glibc, should be a non-starter for an LFS project.  I can
> cope with patching the version which is in LFS, obviously, but if SLFS
> becomes too far removed from the things in LFS then the amount of
> testing required will increase exponentially (and I don't mean the
> security testing people here are focussed on, I mean the "can it build
> everything correctly" testing).

Agreed. Again, if this is an addendum to the book, it should strive to
follow the package versions except for known exploits. At that point,
the decision should be made to either patch, or upgrade. After more
thought on the 2.4.22 vulnerability, I would recommend a patch instead
of upgrading to 2.4.23 because a) the next LFS book will upgrade kernels
giving up the opportunity as well, b) some people need the drivers
in 2.4.22 and c) the patch is small and trivial.

-- 
Archaic

"I hold it, that a little rebellion, now and then, is a good thing, and
as necessary in the political world as storms in the physical."

- Thomas Jefferson, Letter to James Madison, January 30, 1787

-- 
http://linuxfromscratch.org/mailman/listinfo/lfs-security
FAQ: http://www.linuxfromscratch.org/faq/
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.