Re: [Security-Discuss] Re: [Security Announce] MDKSA-2005:113 - Updated clamav packages fix vulnerability

Vincent Danen <vdanen-4qZELD6FgxhWk0Htik3J/[email protected]>
Newsgroups gmane.linux.mandrake.security.general
Message-ID <[email protected]>
On 12-Jul-05, at 1:41 AM, Simon Oosthoek wrote:

>>>  Mandrakelinux 10.1:
>>>  d1a61855ca50e53018e5c65ef380d8dd  10.1/RPMS/ 
>>> clamav-0.81-0.3.101mdk.i586.rpm
>>>
>>
>> wouldn't it make sense in the case of this package, to update to  
>> the latest
>> stable version?
>> Clamav complains about being too old and actually lacks  
>> functionality when
>> older versions are used...
>>
>
> Actually, if I'd have purchased corporate server edition, I'd be  
> offended
> that this was not the case, since the main reason to get that  
> version is to
> have better than "free" support. That includes proper fixes to real  
> world
> problems. And getting warnings like "Your version of clamav is out  
> of date,
> UPDATE NOW!" is something I'd not put up with for very long from a  
> paid-for
> OS.

Huh?  Since when was buying Corp Serve analogous with updating  
everything to the latest version?  You think when you buy CS that you  
get the latest apache, php, clamav, samba, etc.?  Think again, my  
friend.  Your better than free support means we support the OS for 5  
years, not that everytime something new comes out we update the OS  
with the latest version.

> Anyway, my "free" solution was to get the tarball from the clamav  
> site and
> build it myself outside of the rpm system. I hate to do that, but  
> in this
> case I couldn't get the cooker src.rpm to build on 10.0 and there  
> was no
> update for 10.0 anyway...

What an ideal solution.  Use the source, Luke!  I wish more people  
would realize that things are just that easy.

> Please don't understand me wrong, I like Mandriva and the speed at  
> which
> security updates come, usually...
>
> As a general rule, I'd think there should be more version upgrades  
> (upstream
> security releases) in security updates as long as they don't break
> configuration files or settings.

Yes, well, our general rule is patch before upgrade and there's a  
pretty good reason for it (check the archives, I'm sure it's been  
discussed a few dozen times and I really don't feel like rehashing it).

-- 
"lynx -source http://linsec.ca/vdanen.asc | gpg --import"
{FEE30AD4 : 7F6C A60C 06C2 4811 FA1C  A2BC 2EBC 5E32 FEE3 0AD4}
PGP.sig (application/pgp-signature, 186 B) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.