Re: Secure Linux From Scratch
Archaic <[email protected]>
| Newsgroups | gmane.linux.lfs.security |
|---|---|
| Message-ID | <[email protected]> |
On Fri, Dec 19, 2003 at 12:53:53PM +0000, Ken Moffat wrote: > > I think that using a different version of gcc, let alone a different > version of glibc, should be a non-starter for an LFS project. I can > cope with patching the version which is in LFS, obviously, but if SLFS > becomes too far removed from the things in LFS then the amount of > testing required will increase exponentially (and I don't mean the > security testing people here are focussed on, I mean the "can it build > everything correctly" testing). Agreed. Again, if this is an addendum to the book, it should strive to follow the package versions except for known exploits. At that point, the decision should be made to either patch, or upgrade. After more thought on the 2.4.22 vulnerability, I would recommend a patch instead of upgrading to 2.4.23 because a) the next LFS book will upgrade kernels giving up the opportunity as well, b) some people need the drivers in 2.4.22 and c) the patch is small and trivial. -- Archaic "I hold it, that a little rebellion, now and then, is a good thing, and as necessary in the political world as storms in the physical." - Thomas Jefferson, Letter to James Madison, January 30, 1787 -- http://linuxfromscratch.org/mailman/listinfo/lfs-security FAQ: http://www.linuxfromscratch.org/faq/ Unsubscribe: See the above information page