Re: Re: [RHSA-2004:003-01] Updated CVS packages fix minor security issue
[email protected] Mon, 12 Jan 2004 17:10:15 -0500
| Newsgroups | gmane.comp.security.full-disclosure,gmane.comp.security.bugtraq,gmane.linux.redhat.security.watch |
|---|---|
| Message-ID | <[email protected]> |
--==_Exmh_-1472254839P Content-Type: text/plain; charset=us-ascii On Mon, 12 Jan 2004 12:22:01 CST, Caylan Larson said: > Minor... let's not worry about it. No one uses cvs anyways. I'm sure that the guys at Sourceforge and Savannah are overjoyed to hear that attitude. So tell me - at what point are there enough users to worry? 100K? 10K? I'm sure there's over 10K machines running a CVS server - a *lot* of ISPs and hosting companies use it to track config changes. Now, for whatever value of N you chose - are you running *any* software that has less than N users, but *you* would be worried if there was a vulnerability found in it? --==_Exmh_-1472254839P Content-Type: application/pgp-signature -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.3 (GNU/Linux) Comment: Exmh version 2.5 07/13/2001 iD8DBQFAAxtHcC3lWbTT17ARAtwxAJ9ykVwCavf79EsIXV3+E880V22IUgCfe2DL j5jAsrO6eqLo/28pEpoMk9Y= =1fqh -----END PGP SIGNATURE----- --==_Exmh_-1472254839P-- _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html