Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
Security updates and glibc (related to latest CERT advisory)
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
psp
Tux's lil' helper
Tux's lil' helper


Joined: 06 Aug 2002
Posts: 120
Location: Cape Town, South Africa

PostPosted: Tue Aug 06, 2002 11:06 am    Post subject: Security updates and glibc (related to latest CERT advisory) Reply with quote

I, like any good sysadmin, am subscribed to CERT's advisory mailing list. I read through the latest one regarding the exploitable RPC XDR buffer overflow. (http://www.cert.org/advisories/CA-2002-25.html)

I decided to check my system. So I ran: emerge rsync ; emerge --pretend --update system. The system was up-to-date. I thought this a bit strange, so I had a look in the portage tree. My version of glibc was 2.2.5-r5, but the latest was 2.2.5-r7 (which has the patch applied). I thought: "Fair enough - I don't have any RPC services installed on the box, so this might be the reason." After an: emerge --pretend nfs-utils the command returned no indication that glibc would be updated.

Perhaps the error lies with the nfs-utils ebuild package? Should it's dependancy should be bumped to the latest version of glibc? Or perhaps, the default-1.0 profile should be updated (but this feels like overkill)?

Obviously, the easy option would be to emerge the latest version of glibc, nfs-utils and be done with it (not including static compiles). But my concern is for people that are not as vigilant.

Perhaps the larger question is: How does Gentoo, as a distribution, handle essential security concerns and advisories and what is the best way to stay current with all of Gentoo/GNU/Linux's security updates?

I must state that I have only been using Gentoo Linux for 2 weeks so far and I have been tinkering and prodding at the inner workings - to see how things are done. My current desktop machine is a Linux from Scratch box - so I like to know the how and why (naze nani) of my Linux boxes. If I have missed something obvious or newbie-ish I apologise.
Back to top
View user's profile Send private message
n0n
Guru
Guru


Joined: 13 Jun 2002
Posts: 355

PostPosted: Tue Aug 06, 2002 9:39 pm    Post subject: Reply with quote

Yeah, there's a very similar discussion going on about related issues here, and also some discussion on a bug in bugs.gentoo.org. It'd be nice to have a "security" set ("emerge --update security") which would query all installed packages instead of just what's in the /var/cache/edb/world file.
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum