On BNET: How to turbocharge Firefox
BNET Business Network:
BNET
TechRepublic
ZDNet

By Renai LeMay
Posted on ZDNet News: Jun 8, 2005 5:38:00 PM

A configuration mistake in the new Debian Linux distribution has forced a fix less than 24 hours after the software was released.

"New installations (of Debian 3.1 from CD and DVD) will not get security updates by default," Debian developer Colin Watson wrote in an e-mail warning. Installations from floppy disks or network servers were not affected.

Watson apologized and asked vendors to delay burning CDs or DVDs of Debian 3.1, saying that an update would be available shortly. However, Steve Langasek--another member of the release team--said on his blog that it would probably be a day or two before the updated CDs and DVDs were available everywhere.

"Whoops," Langasek wrote. "Don't go pressing those 10,000 copies of (3.1) just yet."

The good news for those who have already installed the operating system is that fixing the problem is a simple matter of replacing an entry in a configuration file.

Version 3.1 has been long anticipated by the Debian community, as it's been three years since the last major release of the software. This cycle is significantly slower than that followed by competing Linux vendors such as Red Hat.

Debian is not the only high-profile software project to be forced to fix a security flaw shortly after the time of release.

Netscape fixed two critical flaws in the new version of its browser in a similarly short time frame after it was released late last month. Ironically, Netscape marketed the release as being able to provide users with additional security features not found elsewhere.

Renai LeMay of ZDNet Australia reported from Sydney.

  • Talkback
  • Most Recent of 28 Talkback(s)
FHS, not Debian
Sounds like you're bashing your head against the FHS, the File Heirarchy Standard, not necessarily Debian per-se. FHS, although it goes against "tradition", is designed with NFS portability in mind, ... (Read the rest)
Posted by: chewie_z Posted on: 06/10/05 You are currently: Logged In as: a Guest  | Login | Terms of Use
Debian drops ball on security updates  Loverock Davidson | 06/08/05
Hey knuckle head...  Linux User 147560 | 06/08/05
A flaw is a flaw  Loverock Davidson | 06/08/05
Flaw?  Linux User 147560 | 06/09/05
Wow really?  Zinoron | 06/08/05
Really!  Loverock Davidson | 06/08/05
I wasn't changing the subject.  Zinoron | 06/08/05
I seriously don't understand the maliciousness over OS choice.  hipparchus2000 | 06/08/05
Debian FreeBSD  Loverock Davidson | 06/08/05
debian/kfreebsd  hipparchus2000 | 06/08/05
Why would this make you happy  duclod | 06/08/05
Re: Debian drops ball on security updates  nightshade0143 | 06/08/05
Very diserving  Roger Ramjet | 06/08/05
Examples?  toadlife | 06/08/05
Sounds like M$  Roger Ramjet | 06/09/05
Economics.  doe_z | 06/09/05
FHS, not Debian  chewie_z | 06/10/05
What is more concerning  osreinstall | 06/08/05
Just guessing...  doe_z | 06/08/05
All install methods must be identical  osreinstall | 06/08/05
Oops  node357 | 06/08/05
Well..  d_jedi | 06/08/05
To much time on ones hand  nizzach | 06/08/05
installed nicely, works great, free  pesky_z | 06/08/05
storm in a teacup  hipparchus2000 | 06/08/05
Debian Drops Ball  asqarin | 06/09/05
Security Updates  Scrat | 06/09/05
It's not a security flaw until....  Dr.C | 06/09/05

What do you think?

advertisement
advertisement

Fusion

advertisement
Click Here