Re: apt-listbugs and security



On Thu, Jan 12, 2006 at 09:25:24AM +0100, Mauro Sanna wrote:
> > I'm not trying to discourage you from using Debian, it's great, but
> > you may want to look at the next release of Ubuntu Server, which will
> > have security support for five years.
>
> But using debian sarge for servers is secure or not?
>
Using Debian is as secure as using any other Linux. Debian has an
active security team and fixes bugs. Your degree of risk depends
on what services you run and on how you configure your servers.
If your services are open to others - e.g. selling web hosting -
your risk increases to how insecure they are :(

The next release of Ubuntu Server, which is scheduled to have
five years security support, isn't due out until October.
Debian "stable" / Sarge shuld be fine for most purposes -
_you_ need to assess _your_ risk, look at the applications you're
running and, potentially, screen apt-listbugs and similar output
to see what affects you.

Read a security related mailing list if it will help: the RISKS Forum
digest (Google for it) is quite useful.

HTH,

Andy


--
To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx
with a subject of "unsubscribe". Trouble? Contact listmaster@xxxxxxxxxxxxxxxx



Relevant Pages

  • Re: apt-listbugs and security
    ... > five years security support, ... > running and, potentially, screen apt-listbugs and similar output ... Yes ok but why you suggest ubuntu server rather than debian stable? ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
    (Debian-User)
  • [Full-disclosure] [SECURITY] [DSA 2336-1] ffmpeg security update
    ... Multiple vulnerabilities were found in the ffmpeg, a multimedia player, ... Security support for ffmpeg has been discontinued for the oldstable ... Further information about Debian Security Advisories, ...
    (Full-Disclosure)
  • [SECURITY] [DSA 2336-1] ffmpeg security update
    ... Multiple vulnerabilities were found in the ffmpeg, a multimedia player, ... Security support for ffmpeg has been discontinued for the oldstable ... Further information about Debian Security Advisories, ...
    (Bugtraq)
  • Re: Lenny security support dropped
    ... Well, just for those who have missed the official notice, Lenny is not ... Security Support for Debian GNU/Linux 5.0 terminated on February 6th ... One year after the release of Debian 6.0 alias "Squeeze" and nearly three ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
    (Debian-User)
  • Re: Debian breaks commitment to support Lenny until after Wheezy is released
    ... Now Debian announcesthat it stops security support for Lenny. ... announcement about the Lenny extended support until Wheezy is released. ...
    (Debian-User)