Re: We need a new subject- bug fixes



Les Mikesell wrote:

OpenOffice is the particular thing I had in mind, but I suspect there are others. I'm not talking about additional packages - this is in reference to your comment about not deviating from upstream.

Again probably licensing reasons. I made no absolute statements that no packages ever deviate. I said that Fedora packages generally avoid patches and I stand by that.

3) Security. Daemons connecting to external ports by default is a bad idea. Well documented reasons. Configuration changes are easier to manage compared to other kind of patches too.

I suppose if you break a program's intended functionality there's not so much to maintain. That doesn't seem like a great thing to do, though, especially without providing an easy/obvious way undo it. In any case it is hard to imagine any 'upstream' version of sendmail ever delivered with that configuration

Perhaps you send to actually check instead of speculating what upstream does. Sendmail is enabled by default but not configured to connect to external ports in order to deliver local mail for root user but avoid the additional security issues with connecting to external ports by default. If there is a security hole in sendmail and it connects to external ports by default, it is remotely exploitable. If only connects to local host, then the security risk is lowered. I dont see how this is breaking any functionality since this is a well documented configuration change for security reasons. It is trivially easy to uncomment a line and configure sendmail to connect to external ports. What exactly are you suggesting?

Rahul

--
fedora-list mailing list
fedora-list@xxxxxxxxxx
To unsubscribe: https://www.redhat.com/mailman/listinfo/fedora-list



Relevant Pages

  • [Full-Disclosure] [RHSA-2003:064-01] Updated XFree86 4.1.0 packages are available
    ... security vulnerabilities have been found and fixed. ... other bug fixes, driver updates, and other enhancements have been made. ... Xterm, provided as part of the XFree86 packages, provides an escape ... Please note that this update is also available via Red Hat Network. ...
    (Full-Disclosure)
  • [Full-disclosure] [ MDVSA-2009:311 ] ghostscript
    ... Multiple security vulnerabilities has been identified and fixed ... A buffer underflow in Ghostscript's CCITTFax decoding filter allows ... Multiple interger overflows in Ghostsript's International Color ... Previousely the ghostscript packages were statically built against ...
    (Full-Disclosure)
  • [ MDVSA-2009:311 ] ghostscript
    ... Multiple security vulnerabilities has been identified and fixed ... A buffer underflow in Ghostscript's CCITTFax decoding filter allows ... Multiple interger overflows in Ghostsript's International Color ... Previousely the ghostscript packages were statically built against ...
    (Bugtraq)
  • [Full-disclosure] SUSE Security Announcement: apache, apache2 request smuggling problem (SUSE-SA:200
    ... A security flaw was found in the Apache and Apache2 web servers which ... Fixed Apache 2 server packages were released on July 26th, ... fixed Apache 1 server packages were released on August 15th. ... The preferred method for installing security updates is to use the YaST ...
    (Full-Disclosure)
  • [Full-disclosure] [USN-95-1] Linux kernel vulnerabilities
    ... Ubuntu 4.10 ... The following packages are affected: ... Georgi Guninski discovered a buffer overflow in the ATM driver. ... the previous Ubuntu security update (kernel version ...
    (Full-Disclosure)