Gentoo Archives: gentoo-user

From: Urs Schutz <u.schutz@×××××××.ch>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] GLSA management
Date: Tue, 06 Mar 2012 23:15:02
Message-Id: 20120306201339.3a0bf160@bluewin.ch
In Reply to: [gentoo-user] GLSA management by Grant
1 On Tue, 6 Mar 2012 10:32:35 -0800
2 Grant <emailgrant@×××××.com> wrote:
3
4 > I've been checking this daily for a while:
5 >
6 > http://www.gentoo.org/security/en/glsa/index.xml
7 >
8 > but every time there's a vulnerability in a package I
9 > know I have installed, my installed version is
10 > unaffected. If I emerge world daily, do I need to check
11 > on GLSA's?
12 >
13 > - Grant
14 >
15
16 I run a cron job that does glsa-check -t all daily, and had
17 one glsa showing up lately (201201-09). This was an old
18 slot of media-libs/freetype, pulled in by emerge because of
19 obscure useflags in luatex. This was with stable packages.
20 Another one showed up because of app-text/acroread, and
21 was resolved by replacing acroread with evince.
22
23 So in my opinion it is necessary to run glsa-check
24 regularly to show the detected problems within the system.
25 Run as a cron job there is little work to do, checking the
26 mail takes less than 10 seconds.
27
28 And: A big thanks to the people who invest their time and
29 use their brains to write the Gentoo Linux Security Advices!
30
31 Urs