Re: [Security-Discuss] Re: [Security Announce] MDKSA-2005:113 - Updated clamav packages fix vulnerability
Vincent Danen <vdanen-4qZELD6FgxhWk0Htik3J/[email protected]>
| Newsgroups | gmane.linux.mandrake.security.general |
|---|---|
| Message-ID | <[email protected]> |
On 12-Jul-05, at 8:58 AM, Simon Oosthoek wrote:
>>>> Mandrakelinux 10.1:
>>>> d1a61855ca50e53018e5c65ef380d8dd 10.1/RPMS/
>>>> clamav-0.81-0.3.101mdk.i586.rpm
>>>>
>>>>
>>>
>>> wouldn't it make sense in the case of this package, to update to
>>> the latest
>>> stable version?
>>> Clamav complains about being too old and actually lacks
>>> functionality when
>>> older versions are used...
>>>
>>> Just a thought.
>>>
>>
>> Thanks for the thought, but no. It actually wouldn't make sense. We
>> have an established policy that has been noted many *many* times that
>> we patch packages rather than update to the latest and greatest so as
>> to prevent regressions or rebuilds in other packages that require
>> what we're updating.
>>
>
> Obviously, I'm questioning the validity of the policy ;-)
Fair enough, but I don't see a problem with it.
> Seriously, things changed when clamav was taken from contrib and
> put into
> main. I'm sure most policies develop exceptions as the world
> changes from
> what it was at the time the policy was defined to what it is now.
Unfortunately, once we make one exception, then we're pretty much
expected to make the same exception for other packages. clamav isn't
the only package people would like to see updated to the latest and
greatest. So if we make an exception for clamav, what grounds do we
have to refuse every other request to upgrade package XYZ to version
ABC rather than patch it? Pretty much none.
This is why we don't patch contribs. Even if someone inside the
company asks. As soon as we make one exception, all of a sudden
we're supporting the whole contribs. It's the same principle.
Policy is there for a reason, and it's a good reason. It lowers our
costs and increases our delivery time. I think I can speak for
everyone when I say that with the higher increase of security
updates, delaying updates to do very heavy regression testing is not
appealing to anyone.
--
"lynx -source http://linsec.ca/vdanen.asc | gpg --import"
{FEE30AD4 : 7F6C A60C 06C2 4811 FA1C A2BC 2EBC 5E32 FEE3 0AD4}
PGP.sig
(application/pgp-signature, 186 B) - not displayed