Re: [Security-Discuss] Re: MDKA-2005:035 - Updated clamav packages provide latest version

Vincent Danen <[email protected]> Sat, 23 Jul 2005 12:22:22 -0600
Newsgroups gmane.linux.mandrake.security.general
Message-ID <[email protected]>
On 23-Jul-05, at 1:05 AM, Simon Oosthoek wrote:

>> The policy has been changed *only* for clamav, so don't expect this
>> with other packages.  However, although I still maintain that clamav
>> was sufficiently patched so as to protect a system with it installed
>> from exploiting clamav itself, after some discussion we've determined
>> that we had two choices for our customers... the first to maintain
>> our own virus database compatible with the versions of clamav we have
>> released, or to update clamav to fully use existing virus
>> definitions... obviously we took the easy road.
>>
>> Let me stress again that the policy has been changed in respect to
>> backporting vs. updating *only* for clamav.
>>
>> Don't expect this to become a habit.  =)
>>
>
> Understood! However, it is good to know that the policy is not set  
> in stone,
> I think it would be good to define a process that can be used when  
> customers
> feel that the policy needs updating...

Well, the process is pretty much to just bring it up.

> I'm not sure NAG NAG NAG, oh alright, is a comfortable process ;-)

No, it's not.... but considering this was a special case and it's  
unlikely to be repeated too often, I think just bringing it up should  
be sufficient (ie. here or in bugzilla).

-- 
Annvix - Secure Linux Server: http://annvix.org/
"lynx -source http://linsec.ca/vdanen.asc | gpg --import"
{FEE30AD4 : 7F6C A60C 06C2 4811 FA1C  A2BC 2EBC 5E32 FEE3 0AD4}
PGP.sig (application/pgp-signature, 186 B) - not displayed