1 |
On Tue, 6 Mar 2012 10:32:35 -0800 |
2 |
Grant <emailgrant@×××××.com> wrote: |
3 |
|
4 |
> I've been checking this daily for a while: |
5 |
> |
6 |
> http://www.gentoo.org/security/en/glsa/index.xml |
7 |
> |
8 |
> but every time there's a vulnerability in a package I |
9 |
> know I have installed, my installed version is |
10 |
> unaffected. If I emerge world daily, do I need to check |
11 |
> on GLSA's? |
12 |
> |
13 |
> - Grant |
14 |
> |
15 |
|
16 |
I run a cron job that does glsa-check -t all daily, and had |
17 |
one glsa showing up lately (201201-09). This was an old |
18 |
slot of media-libs/freetype, pulled in by emerge because of |
19 |
obscure useflags in luatex. This was with stable packages. |
20 |
Another one showed up because of app-text/acroread, and |
21 |
was resolved by replacing acroread with evince. |
22 |
|
23 |
So in my opinion it is necessary to run glsa-check |
24 |
regularly to show the detected problems within the system. |
25 |
Run as a cron job there is little work to do, checking the |
26 |
mail takes less than 10 seconds. |
27 |
|
28 |
And: A big thanks to the people who invest their time and |
29 |
use their brains to write the Gentoo Linux Security Advices! |
30 |
|
31 |
Urs |