[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: How up-to-date is Debian's stable release kept to fix published kernel security vulnerabilities?



On Sun, May 08, 2011 at 10:08:31PM +0200, Florian Weimer wrote:
> * Kelly Dean:
> 
> > http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-2943 was
> > published Sept 30, 2010, and says that Linux 2.6.32.5 is
> > vulnerable. Squeeze uses 2.6.32-5, built on Jan 12, 2011. Is
> > Squeeze's kernel fixed, or does it have the vulnerability?
> 
> According to our records, this issue was addressed in version
> 2.6.32-31 of the linux-2.6 package, which is also the version
> currently in sqeeze.

If so, why is my squeeze installation, fully updated, showing 2.6.32-5?

-- 
Bob Holtzman
Key ID: 8D549279
"If you think you're getting free lunch,
 check the price of the beer"

Attachment: signature.asc
Description: Digital signature


Reply to: