Re: [Security-Discuss] Re: [Security Announce] MDKSA-2004:124 - Updated xorg-x11 packages fix libXpm overflow vulnerabilities

Vincent Danen <vdanen-7Aj/b8uzpy6AmYF/[email protected]>
Newsgroups gmane.linux.mandrake.security.general
Message-ID <[email protected]>
On 5-Nov-04, at 5:43 AM, Anne Wilson wrote:

>>>>                  Mandrakelinux Security Update Advisory
>>>>
>>>> ____________________________________________________________________ 
>>>> ___
>>>>
>>>>  Package name:           xorg-x11
>>>>  Advisory ID:            MDKSA-2004:124
>>>>  Date:                   November 4th, 2004
>>>>
>>>>  Affected versions:	 10.1
>>>>   
>>>> ____________________________________________________________________ 
>>>> __
>>>
>>> I can't remember exactly when (december last year?),
>
> November - some of us won't forget in a hurry
>
>>> but I believe a
>>> while back there were some problems, because of a security fix that  
>>> broke
>>> something just before a long weekend. A conclusion then was to make  
>>> sure
>>> the security updates are not sent on a friday, so problems could be  
>>> fixed
>>> quicker if they are sent at the beginning of the week...
>>
>> Well, Nov 4th is a Thursday in this part of the world anyway :)
>
> but since they go out overnight (in our time) that inevitably means  
> Friday
> install or stay without updates until after the weekend.

And there's the kicker, isn't it?  You *do* have a choice as to whether  
or not you install updates on Friday or wait until Monday.  =)

-- 
*Please note gpg keyid FE6F2AFD has been replaced with keyid FEE30AD4*
"lynx -source http://linsec.ca/vdanen.asc | gpg --import"
{FEE30AD4 : 7F6C A60C 06C2 4811 FA1C  A2BC 2EBC 5E32 FEE3 0AD4}
PGP.sig (application/pgp-signature, 186 B) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.