Re: Security Audit

Alan Cox (alan@lxorguk.ukuu.org.uk)
Mon, 22 Jun 1998 19:32:50 +0100 (BST)


> > We just tell Alan, and he tells RedHat :)
>
> I hope all of the stuff is getting to everyone actually.
>
> I'm a bit concerned that while it's certainly great for the Red Hat and Debian
> distributions to get these security bug fixes, it is very important that they
> make it back to the original packages, wherever they came from, and that new
> versions of those packages are released, so that the entire community using the
> packages receives the benefit.

Every package I've fixed or merged diffs into for Red Hat they have gone
to the maintainer if there is one. Often there isnt. Metamail has no maintainer
and the nmh maintainers didnt seem at all interested in the holes in nmh. It
varies. They _are_ going back however.

I believe the Debian policy is identical on this issue

Alan

-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.rutgers.edu