From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from pigeon.gentoo.org ([208.92.234.80] helo=lists.gentoo.org) by finch.gentoo.org with esmtp (Exim 4.60) (envelope-from ) id 1QSEBI-0003XL-BE for garchives@archives.gentoo.org; Thu, 02 Jun 2011 20:07:48 +0000 Received: from pigeon.gentoo.org (localhost [127.0.0.1]) by pigeon.gentoo.org (Postfix) with SMTP id BC1ED1C029 for ; Thu, 2 Jun 2011 20:07:47 +0000 (UTC) Received: from mail-iw0-f181.google.com (mail-iw0-f181.google.com [209.85.214.181]) by pigeon.gentoo.org (Postfix) with ESMTP id 543891C048 for ; Thu, 2 Jun 2011 19:31:39 +0000 (UTC) Received: by iwn38 with SMTP id 38so1518126iwn.40 for ; Thu, 02 Jun 2011 12:31:38 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:mime-version:sender:in-reply-to:references:date :x-google-sender-auth:message-id:subject:from:to:content-type; bh=XrGY3qRt2UrSk769+wP4qpOh5XM5FadsSSN/RwE88ks=; b=ZdvLJgBAWlmHD9By2ZLKK9iXzfIBXOS3qVehMrDAk8pYdFhhS22AqVVN5iwXXPIMVw tSfCrBM7efOpOCMBF1F44yctc+ZpWmgUs4gLX/M0TG2wxtu/8EMSQEbg5XRgJin4dfL2 L+2I7To+DKHWnU85AWn1aYd64BkI5OJufJp1M= DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=mime-version:sender:in-reply-to:references:date :x-google-sender-auth:message-id:subject:from:to:content-type; b=uXoiUKj5rCwYwSBToBgbDypL7xMoFyiDdtPjJGrDU5IsP0BtjtjFBrsk/z6rCVNzKo uORfCt4a4jwwiNnwv9ozZ05MG8x/qiJKzF13yA6PzSs7EUzYXQrJ7arLYkyJxm43ZZV1 u0LhhWCcUi+iSAiXRuOEgWrypst5xKZQLatCI= Precedence: bulk List-Post: List-Help: List-Unsubscribe: List-Subscribe: List-Id: Gentoo Linux mail X-BeenThere: gentoo-server@lists.gentoo.org Reply-to: gentoo-server@lists.gentoo.org MIME-Version: 1.0 Received: by 10.231.195.40 with SMTP id ea40mr1275084ibb.167.1307043098673; Thu, 02 Jun 2011 12:31:38 -0700 (PDT) Sender: sven.j.vermeulen@gmail.com Received: by 10.231.168.139 with HTTP; Thu, 2 Jun 2011 12:31:38 -0700 (PDT) In-Reply-To: <1306770878.29669.5.camel@localhost> References: <1306770878.29669.5.camel@localhost> Date: Thu, 2 Jun 2011 21:31:38 +0200 X-Google-Sender-Auth: 6GexIw7adJoaZBFZOSIUJHkubC8 Message-ID: Subject: Re: [gentoo-server] Managing multiple servers. From: Sven Vermeulen To: gentoo-server@lists.gentoo.org Content-Type: multipart/alternative; boundary=0016e6d42bb69a442004a4bfafa2 X-Archives-Salt: X-Archives-Hash: 75d96d81cdb7d49ec39f9d9b7a1a9cb1 --0016e6d42bb69a442004a4bfafa2 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable 2011/5/30 Jean-Fran=E7ois Maeyhieux > I think you may be use this old script as i get used several years ago: > > website: http://www.panhorst.com/glcu/ > ebuild: http://bugs.gentoo.org/show_bug.cgi?id=3D101827 > > > Hopping this script could help you... It manage daily update > (sync,build) and report via cron/mail. So you've just to install > pre-built package that have been prepared on a daily frequency when you > decide it's ok to do it without lost time. A revdep-rebuild and commit > of new configuration file using a configured dispatch-conf later, your > machine is update. > > I wrote (and still maintain) a package called cvechecker ( http://cvechecker.sourceforge.net) whose purpose is to scan the system for installed software (or you use a simple file that tells the application wha= t is installed so systemwide scans aren't needed then anymore) and pull in information from NVD about CVE entries. It then matches the CVE entries wit= h the detected software/versions on your system and report which ones might b= e affected by a known vulnerability. Wkr, Sven Vermeulen --0016e6d42bb69a442004a4bfafa2 Content-Type: text/html; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable
2011/5/30 Jean-Fran=E7ois Maeyhieux <b4b1@free.fr>
I think you may be use this old script as i get used several years ago:

website: http:/= /www.panhorst.com/glcu/
ebuild: http://bugs.gentoo.org/show_bug.cgi?id=3D101827


Hopping this script could help you... It manage daily update
(sync,build) and report via cron/mail. So you've just to install
pre-built package that have been prepared on a daily frequency when you
decide it's ok to do it without lost time. A revdep-rebuild and commit<= br> of new configuration file using a configured dispatch-conf later, your
machine is update.


I wrote (and still maintain= ) a package called cvechecker (http://cvechecker.sourceforge.net) whose purpose is to scan the syste= m for installed software (or you use a simple file that tells the applicati= on what is installed so systemwide scans aren't needed then anymore) an= d pull in information from NVD about CVE entries. It then matches the CVE e= ntries with the detected software/versions on your system and report which = ones might be affected by a known vulnerability.

Wkr,
=A0 Sven Vermeulen
--0016e6d42bb69a442004a4bfafa2--