Re: [Security-Discuss] Re: [Security Announce] MDKSA-2005:113 - Updated clamav packages fix vulnerability
Vincent Danen <vdanen-4qZELD6FgxhWk0Htik3J/[email protected]>
| Newsgroups | gmane.linux.mandrake.security.general |
|---|---|
| Message-ID | <[email protected]> |
On 12-Jul-05, at 9:34 AM, Oden Eriksson wrote:
>>> Actually, if I'd have purchased corporate server edition, I'd be
>>> offended
>>> that this was not the case, since the main reason to get that
>>> version is to
>>> have better than "free" support. That includes proper fixes to real
>>> world
>>> problems. And getting warnings like "Your version of clamav is out
>>> of date,
>>> UPDATE NOW!" is something I'd not put up with for very long from a
>>> paid-for
>>> OS.
>>>
>>
>> Huh? Since when was buying Corp Serve analogous with updating
>> everything to the latest version? You think when you buy CS that you
>> get the latest apache, php, clamav, samba, etc.? Think again, my
>> friend. Your better than free support means we support the OS for 5
>> years, not that everytime something new comes out we update the OS
>> with the latest version.
>>
>
> Good reasoning. For this particular package it won't apply as easy.
>
> As a fact with this software is that sometimes the clamav authors
> change the
> database structure (the database engine routines) as in 0.81 -> 0.85.x
> rendering it totally useless in protecting for new viruses.
> Vincent, I am
> sure I have told you about this. So in my opinion Simon Oosthoek is
> right
> about this particular software. So, fixing a bug in this 0.81
> version is
> wasting time. Sure, it plugs the hole, but the software itself remains
> useless. Sorry...
I'm glad you just volunteered to build all future updates and test
for regressions in this package.
Thanks, Oden! We'll be counting on your work from now on.
--
"lynx -source http://linsec.ca/vdanen.asc | gpg --import"
{FEE30AD4 : 7F6C A60C 06C2 4811 FA1C A2BC 2EBC 5E32 FEE3 0AD4}
PGP.sig
(application/pgp-signature, 186 B) - not displayed