Gentoo Archives: gentoo-project

From: Steve Long <slong@××××××××××××××××××.uk>
To: gentoo-project@l.g.o
Subject: [gentoo-project] Re: Re: gentoo security and packages.gentoo.org
Date: Thu, 27 Sep 2007 15:52:23
Message-Id: fdgim6$3g9$2@sea.gmane.org
In Reply to: Re: [gentoo-project] Re: gentoo security and packages.gentoo.org by Arturo Garcia
1 Arturo Garcia wrote:
2 >> This is now all transparent public knowledge. As such no security team
3 >> worth their salt are going to leave these holes open. Remember that all
4 >> the code mentioned above has been freely available for several years.
5 > This is ridiculous. We are trying to bring up a service that was brought
6 > down because a command-injection vulnerability, and that is the bug we are
7 > trying
8 > to close. The solution to this problem is what has been required to be
9 > tested. Please don't deviate with arguments work that has to be done.
10 >
11 No the point, as I see it, is that a security _audit_ of the code is now
12 being carried out. Not a fix to one bug. That's why it would be great if
13 the report were submitted. Or do you think it wise to bring the service
14 back up with known flaws?
15
16 I didn't write the lines about the whole service needing reworking either.
17 I'm just trying to explain why I think the process is being carried out
18 properly.
19
20
21 --
22 gentoo-project@g.o mailing list

Replies

Subject Author
Re: [gentoo-project] gentoo security and packages.gentoo.org Arturo Garcia <arturo.g.arturo@×××××.com>