LWN.net Logo

Debian & general comment

Debian & general comment

Posted Oct 6, 2011 2:56 UTC (Thu) by steffen780 (guest, #68142)
In reply to: Debian & general comment by Curan
Parent article: An odd vulnerability report for LibreOffice

3.3.4 has been in Gentoo-testing since 17Aug, stable on x86 on 4Sep *. Tho I'm not sure if Gentoo counts as a major distro.
More importantly, the LO project seriously needs to re-evaluate its policies on this. There's plenty of arguments for immediate as well as for delayed disclosure (I don't think that topic needs any further lengthy discussions), but afaik there's universal agreement that you always say when an update includes security fixes (or at least, like the kernel, say "this might include security fixes, everyone should update immediately"). Still, at least they fixed it.

Oh and if the AOO-project still can't watch its security mailbox it should probably advice people to go to LO instead until they had time to get setup with their duplicate project...

*: http://sources.gentoo.org/cgi-bin/viewvc.cgi/gentoo-x86/a...


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds