Debian Developers - Re: RFC: allow new upstream into stable when it's the only way tofix security issues.

This is Interesting: Free IT Magazines  
Home > Archive > Debian Developers > August 2005 > Re: RFC: allow new upstream into stable when it's the only way tofix security issues.





You are viewing an archived Text-only version of the thread. To view this thread in it's original format and/or if you want to reply to this thread please [click here]

Author Re: RFC: allow new upstream into stable when it's the only way tofix security issues.
Anthony DeRobertis

2005-08-03, 7:51 am

Joe Smith wrote:
> How about if it meets the folowing critieria:
>
> 1. it has been in testing for 10 days (been in sid at least 20 days)


This means the security hole was disclosed at least 20 days ago,
probably more.

> 2. Iff it fixes a critical security problem, uploaded to security (This
> requires security team and/or stable RM approval).


Requiring more manual action, give this at least a few days I'd say.

So we're looking at leaving our users exploitable for the better part of
a month, before we even release an update, in the *best case* under this
procedure.

I think we can generally expect that a package like Mozilla Firefox will
take more than 10 days to get into testing, especially if we're in the
middle of, say, a C++ transition. Also, its quite possible the
maintainer convincing the security team to release the update, and then
the security team actually doing so, could take another week (remember,
Mozilla takes a while to autobuild, too).

This could easily leave our users vulnerable for over a month. Is that
really acceptable on today's Internet? It doesn't take long at all for
exploit code to be written and released into the wild.


--
To UNSUBSCRIBE, email to debian-devel-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Sponsored Links






Free braindumps | Software forum | Database administration forum

Copyright 2003 - 2008 webservertalk.com