Gentoo Archives: gentoo-user

From: Florian Philipp <lists@×××××××××××.net>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Alternatives to GLSA?
Date: Mon, 19 Sep 2011 15:21:15
Message-Id: 4E775C5E.5020105@binarywings.net
In Reply to: Re: [gentoo-user] Alternatives to GLSA? by Alan McKinnon
1 Am 17.09.2011 15:13, schrieb Alan McKinnon:
2 > On Sat, 17 Sep 2011 11:17:56 +0200
3 > Florian Philipp <lists@×××××××××××.net> wrote:
4 >
5 >> Hi list!
6 >>
7 >> Since GLSAs are in their current state of disregard, I'm searching for
8 >> another way to be informed about security fixes. What do you think is
9 >> the best approach here?
10 >>
11 >> Querying bugzilla for recently fixed security bugs like [1]?
12 >>
13 >> Searching for the term 'security bug' or something similar in
14 >> Changelogs?
15 >>
16 >> Looking at some other web site or distribution and anticipate changes
17 >> in in the portage tree?
18 >>
19 >> [1]
20 >> https://bugs.gentoo.org/buglist.cgi?list_id=428229;query_format=advanced;chfield=bug_status;chfieldfrom=2011-06-01;chfieldto=Now;chfieldvalue=RESOLVED;component=Security
21 >
22 > If you just want to be informed out the state of security of packages,
23 > subscribe to the security lists of other distros. I find RedHat and
24 > Fedora to be useful and up to date. If you see something that looks
25 > like you need to take action, find the corresponding Gentoo package and
26 > investigate further.
27 >
28 > If you need to be on the cutting edge of security issues, then you need
29 > to be on the various vuln disclosure lists around. But be warned, they
30 > can be noisy and you have to train your brain in what to ignore
31 >
32 >
33
34 Thank you for your insight. As a gentoo-specific workaround, I've
35 written a little (well, not *so* little) bash script that filters the
36 ChangeLogs of all installed packages for fixed security bugs applied
37 recently (default: one week).
38
39 Regards,
40 Florian Philipp

Attachments

File name MIME type
securitycheck.sh application/x-sh
signature.asc application/pgp-signature