public inbox for gentoo-hardened@lists.gentoo.org
 help / color / mirror / Atom feed
* [gentoo-hardened] Security updates
@ 2010-01-21 12:19 Machell, Jonathan
  2010-01-21 14:05 ` klondike
                   ` (6 more replies)
  0 siblings, 7 replies; 15+ messages in thread
From: Machell, Jonathan @ 2010-01-21 12:19 UTC (permalink / raw
  To: 'gentoo-hardened@lists.gentoo.org'

Hello there,

We're currently trialling Gentoo to possibly host some of our web-servers. I've used Gentoo for over eight years so I'm leading these trials.

I've subscribed to this mailing list but also gentoo-server and gentoo-security. I'm trying to keep up to speed with all the latest security news affecting Gentoo, GNU/Linux, Apache and MySQL. Should subscription to these mailing lists be sufficient for this or is there any other place where I should be looking to keep on top of security issues? I'm aware that this and the other two mailing lists are low traffic but I haven't heard a peep since subscribing on Tuesday. Is that normal? I was hoping to go through the archives of previous messages at some point. Are these kept somewhere?

Many thanks,

Jonathan Machell
University of Cumbria is a Company Limited by Guarantee, Registered in England & Wales No. 06033238. Registered Office: University of Cumbria, Fusehill Street, Carlisle, CA1 2HH. Telephone 01228 616234.

Confidentiality: This email and its attachments are intended for the above named only and may be confidential. If they have come to you in error you must take no action based on them, nor must you copy or show them to anyone; please reply to this email and highlight the error.

Security Warning: Please note that this email has been created in the knowledge that Internet email is not a 100% secure communications medium. We advise that you understand and observe this lack of security when emailing us.

Viruses: Although we have taken steps to ensure that this email and attachments are free from any virus, we advise that in keeping with good computing practice the recipient should ensure they are actually virus free.


^ permalink raw reply	[flat|nested] 15+ messages in thread
* [gentoo-hardened] security updates
@ 2007-02-10 16:02 Nagy Gabor Peter
  2007-02-10 16:43 ` Tom Hendrikx
                   ` (4 more replies)
  0 siblings, 5 replies; 15+ messages in thread
From: Nagy Gabor Peter @ 2007-02-10 16:02 UTC (permalink / raw
  To: gentoo-hardened

Hi list,

I have a question:

Since I am new to gentoo, I don't know how security updates work.

I know Debian. In Debian if I have stable installed on a production
server, I get regular security fixes, often backported from the current
bleeding edge version, where upstream has fixed the bug to the version
that Debian stable contains.

I have noticed that in gentoo there are many versions of a package that
are considered stable. Take glibc as an example, according to
http://packages.gentoo.org/search/?sstring=glibc, on x86 there are 8
versions available, all of them stable.

I have now two gentoo machines, one is going to be production, the
other is used to get me a little bit more familiar with the system.

On the playground machine I have 2006.1 installed, glibc 2.4-r3
On the production machine I have 2006.0, switched to hardened profile,
and then recompile, there I have glibc 2.3.6-r5

I see now that glibc 2.4-r3 should be upgraded to 2.4-r4 (by the way,
where can I check the differences (Changelog) between two gentoo
versions (like r3 and r4)?)

So my question: If someone finds a bug in glibc that gets corrected,
what does the gentoo maintainers do about it? Do they backport the fix
in all 8 versions? Or just in some of the versions and mark the not
fixed ones ~?

Is there some mailinglist (like debian-security-announce) where such
security fixes are announced?

What is the reason that the hardened profile selects the 2.3.6 version
instead of the 2.4? I mean not in glibc's case only, but generally.

Does libc 2.4 have troubles with ssp?

Cheers,
G
-- 
gentoo-hardened@gentoo.org mailing list



^ permalink raw reply	[flat|nested] 15+ messages in thread

end of thread, other threads:[~2010-01-22 18:00 UTC | newest]

Thread overview: 15+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2010-01-21 12:19 [gentoo-hardened] Security updates Machell, Jonathan
2010-01-21 14:05 ` klondike
2010-01-21 14:06 ` Kerin Millar
2010-01-21 14:12 ` Claes Gyllenswärd
2010-01-21 14:20 ` Andri Möll
2010-01-21 15:36 ` RB
2010-01-21 15:47   ` Machell, Jonathan
2010-01-22  6:36 ` Jonny Kent
2010-01-22 17:29 ` Michael Orlitzky
  -- strict thread matches above, loose matches on Subject: below --
2007-02-10 16:02 [gentoo-hardened] security updates Nagy Gabor Peter
2007-02-10 16:43 ` Tom Hendrikx
2007-02-10 17:02 ` John Schember
2007-02-10 18:21 ` Jean-Pierre Schwickerath
2007-02-11  2:17 ` Andrew Ross
2007-02-11 12:38 ` Kevin F. Quinn

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox