|
|
Log in / Subscribe / Register

Linux Mint downloads (briefly) compromised

Linux Mint downloads (briefly) compromised

Posted Feb 22, 2016 20:57 UTC (Mon) by glaubitz (subscriber, #96452)
In reply to: Linux Mint downloads (briefly) compromised by welinder
Parent article: Linux Mint downloads (briefly) compromised

> That is really just scare mongering.

No, it's not. It's based on actual facts.

> I have yet to encounter a situation where a cve report has had Debian and Ubuntu responses, but no patch for Mint has shown up in my patch queue immediately or very soon thereafter. (I know about the "banned" packages and I have flipped the switch so I can see them and decide; I am not worried over local attacks, so grub can wait.)

You may be aware of blacklisted package updates, but many users are not. I'm sorry, but making security updates *optional* is not up for discussion, on any operating system. Period.

And, as I have explained before, Linux Mint does not issue security advisories, so you - as a Linux Mint user - have no immediate and easy way to quickly verify whether your particular version of Linux Mint is affected by a certain CVE.

On Debian, I open up Google and type "Debian CVE-2015-7547" and I am immediately presented with a website which shows me which versions of Debian are affected by the recent glibc vulnerability and which are not. You *cannot* do that on Linux Mint which therefore disqualifies itself for any professional use. End of discussion.

> Now, compare that non-situation to Debian's years of dragging feet regarding fixing the package management's trust in the network and its resultant vulnerability to man-in-the-middle attacks -- including those unintentional ones known as captive portals -- which would *disable* security updates entirely. (Debian 710229; Launchpad 1055614; and many others.)

Did you actually read the bug reports you linked? The original report for Debian's #710229 was filed on May 29, 2013 and on September, 01 2014, David Kalniskies [1] comments:

> As said, this isn't the fix for the problem of the initial reporter, though. This problem should be solved with earlier versions we released since the last Debian stable release, so I am closing this bug anyhow. I can't pin-point a specific version as there are many cornercases and we had various iterations fixing some (and opening new venues in the process).

So your argument is a strawman. And, even if it was valid, the problem would affect Linux Mint as since Mint uses most of Debian's packages unmodified, including apt, so I don't really understand why you would bring up in the first place.

> [1] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=710229#17


The LWN site is currently under high scraper load, so comment display has been suppressed for anonymous users. If you are a human, you may read the comments by clicking the button below:

Note: you can avoid this step in the future by logging into your LWN account.


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds