First Slackware Security Advisory in year 2005
This morning i just finished download some packages from slackware ftp site to update/upgrade my Slackware 10.1 box, although i know that Pat released it on March 27. It's about security issues and bugs on Mozilla packages. You can read the advisory from slackware.com. See the Subject? [slackware-security] Mozilla/Firefox/Thunderbird (SSA: 2005-085-01).
This distro also added Firefox 1.0.2, Thunderbird 1.0.2 in Slackware -current and GAIM 1.2.0 in Slackware 9.1, 10.0, 10.1.
I like _this_ slack-guy's saying in the advisory:
Just a little note on Slackware security -- I believe the state of Slackwareright now is quite secure. I know there have been issues announced and fixed elsewhere, and I am assessing the reality of them (to be honest, it seems the level of proof needed to announce a security hole these days has fallen close to zero -- where are the proof-of-concept exploits?) It is, as always, my firm intent to keep Slackware as secure as it can possibly be. I'm still getting back up to speed (and I do not believe that anything exploitable in real life is being allowed to slide), but I'm continuing to look over the various reports and would welcome input at security@slackware.com if you feel anything important has been overlooked and is in need of attention. Please remember that I do read BugTraq and many other security lists. I am not asking for duplicates of BugTraq posts unless you have additional proof or information on the issues, or can explain how an issue affects your own servers. This will help me to priorite any work that remains to be done. Thanks in advance for any helpful comment.
This distro also added Firefox 1.0.2, Thunderbird 1.0.2 in Slackware -current and GAIM 1.2.0 in Slackware 9.1, 10.0, 10.1.
I like _this_ slack-guy's saying in the advisory:
Just a little note on Slackware security -- I believe the state of Slackwareright now is quite secure. I know there have been issues announced and fixed elsewhere, and I am assessing the reality of them (to be honest, it seems the level of proof needed to announce a security hole these days has fallen close to zero -- where are the proof-of-concept exploits?) It is, as always, my firm intent to keep Slackware as secure as it can possibly be. I'm still getting back up to speed (and I do not believe that anything exploitable in real life is being allowed to slide), but I'm continuing to look over the various reports and would welcome input at security@slackware.com if you feel anything important has been overlooked and is in need of attention. Please remember that I do read BugTraq and many other security lists. I am not asking for duplicates of BugTraq posts unless you have additional proof or information on the issues, or can explain how an issue affects your own servers. This will help me to priorite any work that remains to be done. Thanks in advance for any helpful comment.
0 Comments:
Posting Komentar
<< Home