Re: Mandrake & CERT advisories

From: George Burns (adr@lanline.com)
Date: 03/05/03


From: "George Burns" <adr@lanline.com>
Date: 5 Mar 2003 07:48:05 -0600

send an email to security@linux-mandrake.com with subscribe in the subject
line. They are very proactive in announcing vulnerabilities and patches to
their user community. For example,the latest announce [MDKSA-2003:028 -
Updated sendmail packages fix remotely exploitable buffer overflow
vulnerability] cites all the standard references:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-1337
http://www.kb.cert.org/vuls/id/398025
http://www.cert.org/advisories/CA-2003-07.html
and please read carefully before applying any patches. They tend to have
very specific procedures.

"Kevin" <nobody@tex.kom> wrote in message
news:cI59a.18$gz1.2215@paloalto-snr1.gtei.net...
> Why is it that Mandrake is never listed in the CERT security
> advisories in the vendors section of their postings over at
> comp.security.announce? I see Red Hat in those postings, usually
> with a "we're not vulnerable to that" comment.
>
> Anyone know?
>
> --
> Unless otherwise noted, the statements herein reflect my personal
> opinions and not those of any organization with which I may be affiliated.



Relevant Pages

  • [Full-Disclosure] RE: Internet explorer 6 execution of arbitrary code (An analysis of the 180 Soluti
    ... And again each and every one of the method caching vulnerabilities liu and ... individuals, there I many many reasons why I dislike pivx, but I don't think ... registry patches nothing more, nothing less.. ... But ask yourself how seriously can you take a company that names 5 registry ...
    (Full-Disclosure)
  • RE: Patching
    ... There seems to be at least 5 or 6 new vulnerabilities released on ... As information security people, ... at those patches you need for what you do have running. ... network analyzers. ...
    (Security-Basics)
  • Re: controversial paper
    ... > vulnerabilities not related to Blaster were still not patched. ... the same as "Microsoft hatred" as you claimed there. ... >of and has developed patches for. ... WORMS rely on publicly known issues. ...
    (sci.crypt)
  • Re: Which Router for VPN and Webhosting
    ... > hats find the vulnerabilities before the white hats do. ... > seem to get most of their holes patched before the exploits hit the net. ... patches. ... who took a one-year "web programming" course, ...
    (comp.security.firewalls)
  • Re: Which Router for VPN and Webhosting
    ... > hats find the vulnerabilities before the white hats do. ... > seem to get most of their holes patched before the exploits hit the net. ... patches. ... who took a one-year "web programming" course, ...
    (alt.computer.security)