Re: [Security-Discuss] Re: [Security Announce] MDKSA-2005:113 - Updated clamav packages fix vulnerability

Vincent Danen <vdanen-4qZELD6FgxhWk0Htik3J/[email protected]>
Newsgroups gmane.linux.mandrake.security.general
Message-ID <[email protected]>
On 12-Jul-05, at 9:34 AM, Oden Eriksson wrote:

>>> Actually, if I'd have purchased corporate server edition, I'd be
>>> offended
>>> that this was not the case, since the main reason to get that
>>> version is to
>>> have better than "free" support. That includes proper fixes to real
>>> world
>>> problems. And getting warnings like "Your version of clamav is out
>>> of date,
>>> UPDATE NOW!" is something I'd not put up with for very long from a
>>> paid-for
>>> OS.
>>>
>>
>> Huh?  Since when was buying Corp Serve analogous with updating
>> everything to the latest version?  You think when you buy CS that you
>> get the latest apache, php, clamav, samba, etc.?  Think again, my
>> friend.  Your better than free support means we support the OS for 5
>> years, not that everytime something new comes out we update the OS
>> with the latest version.
>>
>
> Good reasoning. For this particular package it won't apply as easy.
>
> As a fact with this software is that sometimes the clamav authors  
> change the
> database structure (the database engine routines) as in 0.81 -> 0.85.x
> rendering it totally useless in protecting for new viruses.  
> Vincent, I am
> sure I have told you about this. So in my opinion Simon Oosthoek is  
> right
> about this particular software. So, fixing a bug in this 0.81  
> version is
> wasting time. Sure, it plugs the hole, but the software itself remains
> useless. Sorry...

I'm glad you just volunteered to build all future updates and test  
for regressions in this package.

Thanks, Oden!  We'll be counting on your work from now on.

-- 
"lynx -source http://linsec.ca/vdanen.asc | gpg --import"
{FEE30AD4 : 7F6C A60C 06C2 4811 FA1C  A2BC 2EBC 5E32 FEE3 0AD4}
PGP.sig (application/pgp-signature, 186 B) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.