Re: traceroute root exploit
On Wed, Oct 11, 2000 at 10:24:19PM -0400, Daniel Jacobowitz wrote:
> On Wed, Oct 11, 2000 at 07:57:00PM -0400, Adam McKenna wrote:
> > A root exploit for traceroute that was verified to work on potato was posted
> > to bugtraq almost a week ago, yet no security bulletin has been published and
> > the update has not yet been released for potato. I've been told by a member
> > of the security team that the update is sitting in proposed-updates, and has
> > been for over a month. What is holding up this update?
>
> For reference, I believe this is the seventh or eighth email on this
> topic I've sent in several days, including a few to this list...
>
> We are backlogged. I am busy with my classwork, as midterms approach,
> but I'm trying to get advisories out as I can; Joey is unavailable;
> Wichert and Michael Stone are both away for a few days, I think. We're
> trying. Because I have said in several forums that the traceroute fix
> was available, it was not high on my list of priorities. It will be
> done soon.
One of the reasons I started using Debian was the frequent security updates.
I am very happy to help with this aspect of Debian because I consider it one
of the most important. However, my new-maintainer app hasn't been processed
yet.
--Adam
--
Adam McKenna <adam-sig@flounder.net> | "No matter how much it changes,
http://flounder.net/publickey.html | technology's just a bunch of wires
GPG: 17A4 11F7 5E7E C2E7 08AA | connected to a bunch of other wires."
38B0 05D0 8BF7 2C6D 110A | Joe Rogan, _NewsRadio_
10:41pm up 123 days, 19:57, 10 users, load average: 0.00, 0.02, 0.00
Reply to: