Re: [Security-Discuss] Re: [Security Announce] MDKSA-2005:113 - Updated clamav packages fix vulnerability

Vincent Danen <vdanen-4qZELD6FgxhWk0Htik3J/[email protected]>
Newsgroups gmane.linux.mandrake.security.general
Message-ID <[email protected]>
On 12-Jul-05, at 12:17 AM, Simon Oosthoek wrote:

>>  Mandrakelinux 10.1:
>>  d1a61855ca50e53018e5c65ef380d8dd  10.1/RPMS/ 
>> clamav-0.81-0.3.101mdk.i586.rpm
>>
>
> wouldn't it make sense in the case of this package, to update to  
> the latest
> stable version?
> Clamav complains about being too old and actually lacks  
> functionality when
> older versions are used...
>
> Just a thought.

Thanks for the thought, but no.  It actually wouldn't make sense.  We  
have an established policy that has been noted many *many* times that  
we patch packages rather than update to the latest and greatest so as  
to prevent regressions or rebuilds in other packages that require  
what we're updating.

-- 
"lynx -source http://linsec.ca/vdanen.asc | gpg --import"
{FEE30AD4 : 7F6C A60C 06C2 4811 FA1C  A2BC 2EBC 5E32 FEE3 0AD4}
PGP.sig (application/pgp-signature, 186 B) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.