1 |
Arturo Garcia wrote: |
2 |
>> This is now all transparent public knowledge. As such no security team |
3 |
>> worth their salt are going to leave these holes open. Remember that all |
4 |
>> the code mentioned above has been freely available for several years. |
5 |
> This is ridiculous. We are trying to bring up a service that was brought |
6 |
> down because a command-injection vulnerability, and that is the bug we are |
7 |
> trying |
8 |
> to close. The solution to this problem is what has been required to be |
9 |
> tested. Please don't deviate with arguments work that has to be done. |
10 |
> |
11 |
No the point, as I see it, is that a security _audit_ of the code is now |
12 |
being carried out. Not a fix to one bug. That's why it would be great if |
13 |
the report were submitted. Or do you think it wise to bring the service |
14 |
back up with known flaws? |
15 |
|
16 |
I didn't write the lines about the whole service needing reworking either. |
17 |
I'm just trying to explain why I think the process is being carried out |
18 |
properly. |
19 |
|
20 |
|
21 |
-- |
22 |
gentoo-project@g.o mailing list |