Gentoo Archives: gentoo-hardened

From: Nagy Gabor Peter <linux42@××××××××.hu>
To: gentoo-hardened@l.g.o
Subject: [gentoo-hardened] security updates
Date: Sat, 10 Feb 2007 16:05:23
Message-Id: 20070210160237.GB5317@swordfish.capgemini.hu
1 Hi list,
2
3 I have a question:
4
5 Since I am new to gentoo, I don't know how security updates work.
6
7 I know Debian. In Debian if I have stable installed on a production
8 server, I get regular security fixes, often backported from the current
9 bleeding edge version, where upstream has fixed the bug to the version
10 that Debian stable contains.
11
12 I have noticed that in gentoo there are many versions of a package that
13 are considered stable. Take glibc as an example, according to
14 http://packages.gentoo.org/search/?sstring=glibc, on x86 there are 8
15 versions available, all of them stable.
16
17 I have now two gentoo machines, one is going to be production, the
18 other is used to get me a little bit more familiar with the system.
19
20 On the playground machine I have 2006.1 installed, glibc 2.4-r3
21 On the production machine I have 2006.0, switched to hardened profile,
22 and then recompile, there I have glibc 2.3.6-r5
23
24 I see now that glibc 2.4-r3 should be upgraded to 2.4-r4 (by the way,
25 where can I check the differences (Changelog) between two gentoo
26 versions (like r3 and r4)?)
27
28 So my question: If someone finds a bug in glibc that gets corrected,
29 what does the gentoo maintainers do about it? Do they backport the fix
30 in all 8 versions? Or just in some of the versions and mark the not
31 fixed ones ~?
32
33 Is there some mailinglist (like debian-security-announce) where such
34 security fixes are announced?
35
36 What is the reason that the hardened profile selects the 2.3.6 version
37 instead of the 2.4? I mean not in glibc's case only, but generally.
38
39 Does libc 2.4 have troubles with ssp?
40
41 Cheers,
42 G
43 --
44 gentoo-hardened@g.o mailing list

Replies

Subject Author
Re: [gentoo-hardened] security updates Tom Hendrikx <tom@×××××××××.net>
Re: [gentoo-hardened] security updates John Schember <j5483@×××××.com>
Re: [gentoo-hardened] security updates Jean-Pierre Schwickerath <gentoo@××××××××.net>
Re: [gentoo-hardened] security updates Andrew Ross <aross@g.o>
Re: [gentoo-hardened] security updates "Kevin F. Quinn" <kevquinn@g.o>