Re: [Security-Discuss] Re: MDKA-2005:035 - Updated clamav packages provide latest version

Simon Oosthoek <[email protected]> Sat, 23 Jul 2005 09:05:07 +0200
Newsgroups gmane.linux.mandrake.security.general
Message-ID <[email protected]>
Hi Vincent

thanks for listening!

On Sat, Jul 23, 2005 at 12:25:28AM -0600, Vincent Danen wrote:
> 
> The policy has been changed *only* for clamav, so don't expect this  
> with other packages.  However, although I still maintain that clamav  
> was sufficiently patched so as to protect a system with it installed  
> from exploiting clamav itself, after some discussion we've determined  
> that we had two choices for our customers... the first to maintain  
> our own virus database compatible with the versions of clamav we have  
> released, or to update clamav to fully use existing virus  
> definitions... obviously we took the easy road.
> 
> Let me stress again that the policy has been changed in respect to  
> backporting vs. updating *only* for clamav.
> 
> Don't expect this to become a habit.  =)

Understood! However, it is good to know that the policy is not set in stone,
I think it would be good to define a process that can be used when customers
feel that the policy needs updating...

I'm not sure NAG NAG NAG, oh alright, is a comfortable process ;-)

Cheers

Simon
message.footer (text/plain, 232 B)
____________________________________________________
Want to buy your Pack or Services from Mandriva? 
Go to http://store.mandriva.com
Join the Club : http://www.mandrivaclub.com
____________________________________________________