1 msgAbwesenheitsnachricht
2 msgAway from my mail
3 msgCan (non-embargoed) uploads be downloaded from ...
3 msgnet unavailable
5 msgQuestion about Debian security policy
1 msgWant some fun? Find a fuck buddy,...cynthia
1 msgWanna be more man? Check this dude
1 msgSecuring Private Keys
1 msgTop software brands and independece you can trust.
5 msgSecurity team support
8 msgsudo fix
14 msghandling private keys
1 msgJoin the thousands already saving. Save up to 5...
1 msgRolex is not for everyone, it`s for you Faustino
83 msgBad press related to (missing) Debian security

proposal: track CAN ids in changelogs
\ Filippo Giunchedi (26 Jun 2005)
. \ Javier Fernández-Sanguino Peña (26 Jun 2005)

6 msggetting the MAC address from an ip
5 msgMissing debsums and mismatches
1 msgÕîòèòå çàêàçàòü ðåêëàìó?
9 msgSpamAssassin DOS-Fix anytime soon ?
Subject:Re: proposal: track CAN ids in changelogs
Group:Debian-security
From:Javier Fernández-Sanguino Peña
Date:26 Jun 2005


 

On Sun, Jun 26, 2005 at 05:22:27PM +0200, Filippo Giunchedi wrote:
> [sorry for crossposting, but this is relevant to both ML, please cc]
>
> Hi,
> while searching bugtraq for not-yet-fixed security bugs, I found out that there
> is no reliable way (apart from testing yourself) if a package has been patched
> for a specific security advisory.

Yes there is, for stable, through the cross-references published at the web
site: www.debian.org/security/crossreferences.

> It would be fine to include as best practice for maintainers fixing security
> bugs to include something (Fixes: <CAN-ID-or-something>) in the changelog so it
> is easy to track such changes.

The security team has been asking maintainers to do so when uploading to
sid for quite some time. And that info is used by the testing security team
to keep track of CVEs not fixed in testing but fixed in sid.

Regards

Javier



© 2004-2008 readlist.com