Re: [Security-Discuss] Re: [Security Announce] MDKSA-2005:113 - Updated clamav packages fix vulnerability

"Bob Puff" <bob-6dd4Sf22++lWk0Htik3J/[email protected]>
Newsgroups gmane.linux.mandrake.security.general
Message-ID <[email protected]>
I specifically purchased CS3.0 for this exact reason - so I wouldn't have to
worry about building stuff from sources each time there was an update.

I understand the logic in not doing upgrades that would break something else,
but packages like clamav, spamassassin, and amavis are extremely important to
have updated to the latest version, and I think they need to be an exception.

Right now, I am indeed disappointed that an update was done that was probably
more work to have done the back-ports than to simply give the latest version,
that is not useful to the paying community.

Bob

---------- Original Message -----------
From: Simon Oosthoek <[email protected]>
To: security-discuss-4qZELD6FgxheH41UXmfQsti2O/[email protected]
Sent: Tue, 12 Jul 2005 09:41:54 +0200
Subject: Re: [Security-Discuss] Re: [Security Announce] MDKSA-2005:113 -
Updated clamav packages fix vulnerability

> On Tue, Jul 12, 2005 at 08:17:30AM +0200, Simon Oosthoek wrote:
> > On Mon, Jul 11, 2005 at 08:20:40PM -0600, Mandriva Security Team wrote:
> > >  Mandrakelinux 10.1:
> > >  d1a61855ca50e53018e5c65ef380d8dd  10.1/RPMS/clamav-0.81-0.3.101mdk.i586.rpm
> > 
> > wouldn't it make sense in the case of this package, to update to the latest
> > stable version?
> > Clamav complains about being too old and actually lacks functionality when
> > older versions are used...
> 
> Actually, if I'd have purchased corporate server edition, I'd be offended
> that this was not the case, since the main reason to get that 
> version is to have better than "free" support. That includes proper 
> fixes to real world problems. And getting warnings like "Your 
> version of clamav is out of date, UPDATE NOW!" is something I'd not 
> put up with for very long from a paid-for OS.
> 
> Anyway, my "free" solution was to get the tarball from the clamav 
> site and build it myself outside of the rpm system. I hate to do 
> that, but in this case I couldn't get the cooker src.rpm to build on 
> 10.0 and there was no update for 10.0 anyway...
> 
> Please don't understand me wrong, I like Mandriva and the speed at which
> security updates come, usually...
> 
> As a general rule, I'd think there should be more version upgrades (upstream
> security releases) in security updates as long as they don't break
> configuration files or settings.
> 
> /Simon
> 
> PS, the sympa list still has .com and .org addresses mixed, please 
> fix that!
------- End of Original Message -------
message.footer (text/plain, 232 B)
____________________________________________________
Want to buy your Pack or Services from Mandriva? 
Go to http://store.mandriva.com
Join the Club : http://www.mandrivaclub.com
____________________________________________________
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.