Gentoo Archives: gentoo-security

From: Rod Moffitt <rodlist@×××.info>
To: gentoo-security@l.g.o
Subject: Re: [gentoo-security] US-CERT Technical Cyber Security Alert TA06-208A -- Mozilla Products Contain Multiple Vulnerabilities (fwd)
Date: Fri, 28 Jul 2006 15:30:01
Message-Id: Pine.LNX.4.64.0607281109230.9356@crystal.nuked.org
In Reply to: Re: [gentoo-security] US-CERT Technical Cyber Security Alert TA06-208A -- Mozilla Products Contain Multiple Vulnerabilities (fwd) by Andrew Gaffney
1 >> For the first time in 3 years I am installing firefox from the moz site
2 >> and uninstalling the ebuild - I recommand everyone do that ASAP until the
3 >> gentoo devel wake up and realize how serious this is and fix the ebuild.
4 >
5 > You know, you are more than welcome to contribute an ebuild for the new
6 > firefox rather than bitching that we're too slow. As for why we're so slow
7 > (as you put it...didn't the new version just come out yesterday?), the
8 > primary maintainer for all of the Mozilla stuff (firefox, mozilla, seamonkey,
9 > thunderbird, etc.) quit about 2 weeks ago. We've been trying to find someone
10 > to step up and take permanent maintainership, but until then, the "backup
11 > maintainers" are busy people and will get to it when they have time.
12
13 I don't believe that I was 'bitching'. I was merely stating that this was
14 a serious issue and that it should be addressed as soon as possible.
15
16 I have complete empathy for the situation, however no distro (commercial
17 or community based) can simply use as an excuse that the person who is
18 responsible is gone/on vacation/insert reason for not being there. This
19 isn't a new feature request, this is a major vulnerability we are talking
20 about.
21
22 Not only will gentoo suffer because the users will be affected by this,
23 yet one of the major benefits of an open-source os such as gentoo/linux is
24 that responses to security holes are generally very quick (this is often a
25 comparison point between linux and windows).
26
27 - Rod
28 --
29 gentoo-security@g.o mailing list

Replies