[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#392362: [PROPOSAL] Add should not embed code from other packages



On 10804 March 1977, Neil McGovern wrote:

> Title: 		Embedding code provided in other packages
> Synopsis: 	Packages should not include or embed code that is available in
> 			other packages.
> Rationale:	If a package contains embeded code, it becomes vulnerable
> 			to security bugs in the code it embeds. It's a) very hard to
> 			track this and b) makes it very hard to fix, as we have to
> 			issue multiple DSAs and fixed packages for any particular
> 			issue. A current list of packages we know to embed code are
> 			at [0].

Oh yeah, seconded. Its in most cases already a reject in NEW.

-- 
bye Joerg
[http://www.youam.net/stuff/info...-hosting.de/server-info.php]
"Die Anbindung des Servers: Unser Server ist mit 100 MBits/s (=12MB pro
Sekunde) an unser lokales Netzwerk angebunden, unsere Internetanbindung
sind 768 kbit/s Downstream und 128 kbit/s Upstream. Dies hört sich in
manchen Ohren langsam an, allerdings wird unsere Geschwindigkeit in der
Regel eher gelobt als kritisiert, denn der Upstream kann auch
"überzogen" werden, wenn der Server überlastet wird (wurde von uns an
Beispielen getestet, ist allerdings nicht 100%-ig zu erklären)."

Attachment: pgpLHiDT5QrPQ.pgp
Description: PGP signature


Reply to: