Re: New sendmail and missing /usr/lib/sendmail

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Quoting David Eisner <cradle@xxxxxxx>:

Eric Rostetter wrote:
This sounds like what happens when we rush the QA processes...

Other distros had advance warning about this vulnerability,

So did FL technically.

and hence
more time to apply patches and do testing.

They didn't have more time to apply patches.  They did have more time
to do testing, as they have professional (internal) QA testers.

Is there a way Fedora
Legacy could be added to the list of vendors that are notified in this
type of situation?

It is.

Who decides whom to notify in advance. Sendmail, Inc.? I imagine they
want vendors to keep the information under wraps until the official
announcement is made. (I could be wrong.)  How would this work with
Fedora Legacy?  Is it possible?

We were notified.  We didn't act because it was "bad timing" for FL.
But that isn't the issue IMHO.  We had an update-testing version out
fast.  We just shouldn't have pushed it to updates so fast IMHO.

-David

--
Eric Rostetter
The Department of Physics
The University of Texas at Austin

Go Longhorns!

--

fedora-legacy-list@xxxxxxxxxx
https://www.redhat.com/mailman/listinfo/fedora-legacy-list

[Index of Archives]     [Fedora Development]     [Fedora Announce]     [Fedora Legacy Announce]     [Fedora Config]     [PAM]     [Fedora General Discussion]     [Big List of Linux Books]     [Gimp]     [Yosemite Questions]

  Powered by Linux