Re: [Security-Discuss] Re: [Security Announce] MDKSA-2005:113 - Updated clamav packages fix vulnerability
"Bob Puff" <bob-6dd4Sf22++lWk0Htik3J/[email protected]>
| Newsgroups | gmane.linux.mandrake.security.general |
|---|---|
| Message-ID | <[email protected]> |
I specifically purchased CS3.0 for this exact reason - so I wouldn't have to worry about building stuff from sources each time there was an update. I understand the logic in not doing upgrades that would break something else, but packages like clamav, spamassassin, and amavis are extremely important to have updated to the latest version, and I think they need to be an exception. Right now, I am indeed disappointed that an update was done that was probably more work to have done the back-ports than to simply give the latest version, that is not useful to the paying community. Bob ---------- Original Message ----------- From: Simon Oosthoek <[email protected]> To: security-discuss-4qZELD6FgxheH41UXmfQsti2O/[email protected] Sent: Tue, 12 Jul 2005 09:41:54 +0200 Subject: Re: [Security-Discuss] Re: [Security Announce] MDKSA-2005:113 - Updated clamav packages fix vulnerability > On Tue, Jul 12, 2005 at 08:17:30AM +0200, Simon Oosthoek wrote: > > On Mon, Jul 11, 2005 at 08:20:40PM -0600, Mandriva Security Team wrote: > > > Mandrakelinux 10.1: > > > d1a61855ca50e53018e5c65ef380d8dd 10.1/RPMS/clamav-0.81-0.3.101mdk.i586.rpm > > > > wouldn't it make sense in the case of this package, to update to the latest > > stable version? > > Clamav complains about being too old and actually lacks functionality when > > older versions are used... > > Actually, if I'd have purchased corporate server edition, I'd be offended > that this was not the case, since the main reason to get that > version is to have better than "free" support. That includes proper > fixes to real world problems. And getting warnings like "Your > version of clamav is out of date, UPDATE NOW!" is something I'd not > put up with for very long from a paid-for OS. > > Anyway, my "free" solution was to get the tarball from the clamav > site and build it myself outside of the rpm system. I hate to do > that, but in this case I couldn't get the cooker src.rpm to build on > 10.0 and there was no update for 10.0 anyway... > > Please don't understand me wrong, I like Mandriva and the speed at which > security updates come, usually... > > As a general rule, I'd think there should be more version upgrades (upstream > security releases) in security updates as long as they don't break > configuration files or settings. > > /Simon > > PS, the sympa list still has .com and .org addresses mixed, please > fix that! ------- End of Original Message -------
message.footer
(text/plain, 232 B)
____________________________________________________ Want to buy your Pack or Services from Mandriva? Go to http://store.mandriva.com Join the Club : http://www.mandrivaclub.com ____________________________________________________