Re: [Security-Discuss] Re: [Security Announce] MDKSA-2005:113 - Updated clamav packages fix vulnerability
Vincent Danen <vdanen-4qZELD6FgxhWk0Htik3J/[email protected]>
| Newsgroups | gmane.linux.mandrake.security.general |
|---|---|
| Message-ID | <[email protected]> |
On 12-Jul-05, at 12:17 AM, Simon Oosthoek wrote:
>> Mandrakelinux 10.1:
>> d1a61855ca50e53018e5c65ef380d8dd 10.1/RPMS/
>> clamav-0.81-0.3.101mdk.i586.rpm
>>
>
> wouldn't it make sense in the case of this package, to update to
> the latest
> stable version?
> Clamav complains about being too old and actually lacks
> functionality when
> older versions are used...
>
> Just a thought.
Thanks for the thought, but no. It actually wouldn't make sense. We
have an established policy that has been noted many *many* times that
we patch packages rather than update to the latest and greatest so as
to prevent regressions or rebuilds in other packages that require
what we're updating.
--
"lynx -source http://linsec.ca/vdanen.asc | gpg --import"
{FEE30AD4 : 7F6C A60C 06C2 4811 FA1C A2BC 2EBC 5E32 FEE3 0AD4}
PGP.sig
(application/pgp-signature, 186 B) - not displayed