Re: [Security-Discuss] Re: MDKA-2005:035 - Updated clamav packages provide latest version
"Bob Puff" <bob-6dd4Sf22++lWk0Htik3J/[email protected]> Sat, 23 Jul 2005 13:56:11 -0400
| Newsgroups | gmane.linux.mandrake.security.general |
|---|---|
| Message-ID | <[email protected]> |
I believe I remember seeing SpamAssassin also updated to the 3.x line for 10.1, unfortunately not 10.0. This policy must be causing much more work for poor Vincent, having to track down all the security-related patches for a product, and integrate it into the source of an older version. A good example of this is the latest Firefox update. It must be a nightmare trying to make sure that you don't break the program in some odd way doing all this patching. Allow me to ask this: how unique are the source RPMs to their distribution? In other words, is it possible (or could it be possible, with a small modification) to take a 10.2 SRPM, rebuild it for a 10.0 machine, and use it? I realize that there are some things that are fixed: libc, X, etc... But there are many other programs that I would like to be able to keep up with the latest version... examples: postfix, spamassassin, clamav, amavis, maybe Perl. Bob ---------- Original Message ----------- From: Vincent Danen <vdanen-4qZELD6FgxhWk0Htik3J/[email protected]> To: security-discuss-4qZELD6FgxheH41UXmfQsti2O/[email protected] Sent: Sat, 23 Jul 2005 00:25:28 -0600 Subject: Re: [Security-Discuss] Re: MDKA-2005:035 - Updated clamav packages provide latest version > On 22-Jul-05, at 10:40 PM, Anthony Brooks wrote: > > >>> Aha!!! A big THANK-YOU to whoever at Mandrake saw the light about > >>> this! > >>> > >> > >> You're welcome. > > > > Vincent..is this a change in policy about some packages or you guys > > just got > > tired of us complaining about it :) Either way, thanks for doing it. > > Both. =) > > The policy has been changed *only* for clamav, so don't expect this > with other packages. However, although I still maintain that clamav > was sufficiently patched so as to protect a system with it > installed from exploiting clamav itself, after some discussion > we've determined that we had two choices for our customers... the > first to maintain our own virus database compatible with the > versions of clamav we have released, or to update clamav to fully > use existing virus definitions... obviously we took the easy road. > > Let me stress again that the policy has been changed in respect to > backporting vs. updating *only* for clamav. > > Don't expect this to become a habit. =) > > -- > "lynx -source http://linsec.ca/vdanen.asc | gpg --import" > {FEE30AD4 : 7F6C A60C 06C2 4811 FA1C A2BC 2EBC 5E32 FEE3 0AD4} ------- End of Original Message -------
message.footer
(text/plain, 232 B)
____________________________________________________ Want to buy your Pack or Services from Mandriva? Go to http://store.mandriva.com Join the Club : http://www.mandrivaclub.com ____________________________________________________