Re: Security response: how are we doing?
In article <i2qVj-21Q-5@gated-at.bofh.it>,
Andrew Alderwick <alderwick@fsfe.org> wrote:
>Hi Carlos,
>
>On Tue, Nov 29, 2011 at 03:53:04AM +0100, Carlos Alberto Lopez Perez wrote:
>>https://lwn.net/Articles/467615/
>
>It's certainly worth mentioning the errata that zack has posted:
>https://lwn.net/Articles/468117/
>
>â??Depending on how you read the above data, the â??noneâ?? count for Debian
>would go down to either 3 or 4, the most common value for the columns of
>your table. Considering that, I think it'd be fair to reconsider your
>â??it is, in particular, sadâ?? comment.â??
On the other hand, at least from my point of view, things are not looking so
bright. I have on my watchlist 4 buffer overflows (CVE-2011-3193,
CVE-2011-3194, CVE-2011-1071, CVE-2011-1097), one DoS (CVE-2011-1659) and a
number of lesser problems (#628843, #615118, CVE-2011-1521), most of which
I have at least pinged once, most are around for at least 3 months, some
for more than 6 months. And my selection is a quite limited one.
cu
AW
--
[...] If you don't want to be restricted, don't agree to it. If you are
coerced, comply as much as you must to protect yourself, just don't support
it. Noone can free you but yourself. (crag, on Debian Planet)
Arne Wichmann (aw@linux.de)
Reply to: