Gentoo Archives: gentoo-security

From: Vincent Rivellino <vince@×××××××××.org>
To: gentoo-security@l.g.o
Subject: Re: [gentoo-security] SearchSecurity.com: 'Linux patch problems: Your distro may vary'
Date: Mon, 07 Aug 2006 16:27:30
Message-Id: 49041.71.16.82.82.1154967436.squirrel@mail.valentsol.com
In Reply to: [gentoo-security] SearchSecurity.com: "Linux patch problems: Your distro may vary" by Wolfram Schlich
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 Interesting study. I like the premise of it. However, I'm not sure I
5 agree with their method. From the article:
6
7 "For instance, if a distribution fixed an issue on the earliest date, it
8 would receive a score of 100 for that issue; if it was the last vendor to
9 fix the issue, it would get a score of 0. One can then average the scores
10 after evaluating the 30 issues."
11
12 So this is just a ranking, with no quantitative results. What I'd really
13 like to know are the distributions' average response times for the High
14 and Moderate vulnerabilities.
15
16 While Gentoo might be 6th, I'd like to know how much slower Gentoo gets
17 out patches than Ubuntu, Fedora, and/or RHEL.
18
19
20 - -Vince
21
22
23 - --
24 Vincent Rivellino
25 GPG Key ID: 62BFEBE4
26 https://cuz.cx/gpg
27
28
29 On Mon, August 7, 2006 07:42, Wolfram Schlich wrote:
30 > Hi,
31 >
32 >
33 > I just stumbled over an article from SearchSecurity.com which was linked
34 > to in a heise newsticker posting that tries to analyze how fast
35 > distributions react to security vulnerabilities:
36 >
37 > http://tinyurl.com/lplfb
38 >
39 >
40 > Quick chart:
41 >
42 >
43 > Rank Distro Points/100
44 > ---- ------------------------- ----------
45 > 1. Ubuntu 76
46 > 2. Fedora Core 70
47 > 3. Red Hat Enterprise Linux 63
48 > 4. Debian GNU/Linux 61
49 > 5. Mandriva Linux 54
50 > 6. Gentoo Linux 39
51 > 7. Trustix Secure Linux 32
52 > 8. SUSE Linux Enterprise 32
53 > 9. Slackware Linux 30
54 >
55 >
56 > Rank 6 out of 10 is not a great result -- at least we beat SUSE ;)
57 >
58 >
59 > Any comments or thoughts about this?
60 > Can we become better?
61 > Are we maybe better than the author pretends?
62 > Does the security team currently face serious problems that need to be
63 > solved, be it inside or outside the security team?
64 >
65 > I am just curious and would be glad to get some feedback :)
66 > --
67 > Regards,
68 > Wolfram Schlich <wschlich@g.o>
69 > Gentoo Linux * http://dev.gentoo.org/~wschlich/
70 > --
71 > gentoo-security@g.o mailing list
72 >
73 >
74
75
76 -----BEGIN PGP SIGNATURE-----
77 Version: GnuPG v1.4.4 (GNU/Linux)
78
79 iD8DBQFE12eKhUAfdmK/6+QRAm4sAJ9U4hDbql8b5Du7ELWTclnBdwXONACghkRk
80 PLfad2L0hjQZ99puzngf4nU=
81 =/aSm
82 -----END PGP SIGNATURE-----
83
84 --
85 gentoo-security@g.o mailing list

Replies

Subject Author
Re: [gentoo-security] SearchSecurity.com: 'Linux patch problems: Your distro may vary' Eilverijus Kondratas <eilwerijus@×××××.com>