Gentoo Archives: gentoo-hardened

From: Jean-Pierre Schwickerath <gentoo@××××××××.net>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] security updates
Date: Sat, 10 Feb 2007 18:24:10
Message-Id: 20070210192144.3144fb74@ws001.ch.schwicky.lan
In Reply to: [gentoo-hardened] security updates by Nagy Gabor Peter
1 Hi,
2
3 > I see now that glibc 2.4-r3 should be upgraded to 2.4-r4 (by the way,
4 > where can I check the differences (Changelog) between two gentoo
5 > versions (like r3 and r4)?)
6
7 Check the -l flag when using emerge. For instance:
8 emerge -plavuD world
9
10 > So my question: If someone finds a bug in glibc that gets corrected,
11 > what does the gentoo maintainers do about it? Do they backport the fix
12 > in all 8 versions? Or just in some of the versions and mark the not
13 > fixed ones ~?
14
15 I'm sure here.
16 But on the glsa-notice you'll see which versions are vulnerable and
17 which are unaffected by the corrected bug.
18
19 > Is there some mailinglist (like debian-security-announce) where such
20 > security fixes are announced?
21
22 Have a look at http://www.gentoo.org/security/en/
23 You'll find infos on the glsa-check utility and the mailinglist.
24
25
26 > What is the reason that the hardened profile selects the 2.3.6 version
27 > instead of the 2.4? I mean not in glibc's case only, but generally.
28 >
29 > Does libc 2.4 have troubles with ssp?
30
31 Indeed. Not all features are ported to 2.4.
32
33
34 Regards.
35
36 Jean-Pierre
37
38 --
39 Powered by GNU/Linux - http://schwicky.net/
40 PGP Key ID: 0xEE6F49B4 - ICQ: 4690141 - schwicky@××××××.org
41
42 Nothing is impossible... Everything is relative!
43 --
44 gentoo-hardened@g.o mailing list