Gentoo Archives: gentoo-security

From: Dan Noe <dpn@×××××××××.net>
To: gentoo-security@l.g.o
Subject: Re: [gentoo-security] US-CERT Technical Cyber Security Alert TA06-208A -- Mozilla Products Contain Multiple Vulnerabilities (fwd)
Date: Fri, 28 Jul 2006 16:01:52
Message-Id: 20060728155526.GB21644@colobus.isomerica.net
In Reply to: Re: [gentoo-security] US-CERT Technical Cyber Security Alert TA06-208A -- Mozilla Products Contain Multiple Vulnerabilities (fwd) by Rod Moffitt
1 On Fri, Jul 28, 2006 at 11:23:26AM -0400, Rod Moffitt wrote:
2 > I have complete empathy for the situation, however no distro (commercial
3 > or community based) can simply use as an excuse that the person who is
4 > responsible is gone/on vacation/insert reason for not being there. This
5 > isn't a new feature request, this is a major vulnerability we are talking
6 > about.
7
8 Problem:
9 You feel that the volunteer developers are not working fast
10 enough/well enough. You want this bug fixed as quickly as possible
11 so that it does not affect you. The volunteer developers are
12 currently working as fast as they can.
13
14 Solution:
15 Volunteer your time to fix the problem, or wait for the existing
16 volunteers to fix the problem.
17
18 If that isn't acceptable to you, you should seriously consider using a
19 commercial distribution where people *are* paid to fix security bugs.
20
21 --
22 /--------------- - - - - - -
23 | Dan Noe, freelance hacker
24 | http://isomerica.net/

Replies