|
Bad Maintainance!Bad Maintainance!Posted Dec 4, 2003 17:51 UTC (Thu) by hazelsct (subscriber, #3659)In reply to: Bad Maintainance! by AnswerGuy Parent article: The brk() vulnerability I cannot agree with you regarding this particular flaw, as the nature of the bug was not known to people maintaining the code. But I do agree regarding your earlier example. Alan's practice with 2.2 has been to make a new point release as soon as a vulnerability is discovered and patched, a release which *only* fixes the vulnerability (saving all other developments for the subsequent point release). This greatly simplifies keeping track of secure kernel releases, rather than having to know exactly which revision fixes things for each separate distribution. (For example, "You have 2.4.19-15? Is that RedHat, SuSE, Mandrake or TurboLinux? Let's see, I can't remember exactly which one fixed that problem for your particular distribution...") Marcelo has not done this, and I wish he would commit to doing so moving forward.
(Log in to post comments)
|
Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds
Powered by Rackspace Managed Hosting.