Re: [Security-Discuss] Re: MDKA-2005:035 - Updated clamav packages provide latest version

Vincent Danen <vdanen-4qZELD6FgxhWk0Htik3J/[email protected]> Sat, 23 Jul 2005 00:25:28 -0600
Newsgroups gmane.linux.mandrake.security.general
Message-ID <[email protected]>
On 22-Jul-05, at 10:40 PM, Anthony Brooks wrote:

>>> Aha!!!  A big THANK-YOU to whoever at Mandrake saw the light about
>>> this!
>>>
>>
>> You're welcome.
>
> Vincent..is this a change in policy about some packages or you guys  
> just got
> tired of us complaining about it :) Either way, thanks for doing it.

Both.  =)

The policy has been changed *only* for clamav, so don't expect this  
with other packages.  However, although I still maintain that clamav  
was sufficiently patched so as to protect a system with it installed  
from exploiting clamav itself, after some discussion we've determined  
that we had two choices for our customers... the first to maintain  
our own virus database compatible with the versions of clamav we have  
released, or to update clamav to fully use existing virus  
definitions... obviously we took the easy road.

Let me stress again that the policy has been changed in respect to  
backporting vs. updating *only* for clamav.

Don't expect this to become a habit.  =)

-- 
"lynx -source http://linsec.ca/vdanen.asc | gpg --import"
{FEE30AD4 : 7F6C A60C 06C2 4811 FA1C  A2BC 2EBC 5E32 FEE3 0AD4}
PGP.sig (application/pgp-signature, 186 B) - not displayed