1 |
Hi, |
2 |
|
3 |
> I see now that glibc 2.4-r3 should be upgraded to 2.4-r4 (by the way, |
4 |
> where can I check the differences (Changelog) between two gentoo |
5 |
> versions (like r3 and r4)?) |
6 |
|
7 |
Check the -l flag when using emerge. For instance: |
8 |
emerge -plavuD world |
9 |
|
10 |
> So my question: If someone finds a bug in glibc that gets corrected, |
11 |
> what does the gentoo maintainers do about it? Do they backport the fix |
12 |
> in all 8 versions? Or just in some of the versions and mark the not |
13 |
> fixed ones ~? |
14 |
|
15 |
I'm sure here. |
16 |
But on the glsa-notice you'll see which versions are vulnerable and |
17 |
which are unaffected by the corrected bug. |
18 |
|
19 |
> Is there some mailinglist (like debian-security-announce) where such |
20 |
> security fixes are announced? |
21 |
|
22 |
Have a look at http://www.gentoo.org/security/en/ |
23 |
You'll find infos on the glsa-check utility and the mailinglist. |
24 |
|
25 |
|
26 |
> What is the reason that the hardened profile selects the 2.3.6 version |
27 |
> instead of the 2.4? I mean not in glibc's case only, but generally. |
28 |
> |
29 |
> Does libc 2.4 have troubles with ssp? |
30 |
|
31 |
Indeed. Not all features are ported to 2.4. |
32 |
|
33 |
|
34 |
Regards. |
35 |
|
36 |
Jean-Pierre |
37 |
|
38 |
-- |
39 |
Powered by GNU/Linux - http://schwicky.net/ |
40 |
PGP Key ID: 0xEE6F49B4 - ICQ: 4690141 - schwicky@××××××.org |
41 |
|
42 |
Nothing is impossible... Everything is relative! |
43 |
-- |
44 |
gentoo-hardened@g.o mailing list |