Re: Ptrace hole / Linux 2.2.25

From: Alan Cox (alan@lxorguk.ukuu.org.uk)
Date: Sun Mar 23 2003 - 17:24:49 EST


On Sun, 2003-03-23 at 20:33, Florian Weimer wrote:
> Well, this is a problem which will be fixed over time. Amorphous
> distributions such as Debian will no longer be notified first, and

Why would anyone do that. Debian is a bunch of amateurs true, but
they happen to be a bunch of extremely professional amateurs when it
comes to security.

The problem vendor-sec has is with all the tiny little groups, because
its hard to know if they are going to act securely or not. Now I trust
Russell but thats because I know him, many of the others are hard
choices.

If you get it wrong stuff leaks, take a look at the latest CERT fiasco

-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/



This archive was generated by hypermail 2b29 : Sun Mar 23 2003 - 22:00:45 EST