Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 18 Mar 2002 16:24:23 -0800
From:      Doug Hardie <bc979@lafn.org>
To:        stable@FreeBSD.ORG
Subject:   Security Bulletins and Related Updates
Message-ID:  <f051003a1b8bc340c3d56@[10.0.1.90]>
In-Reply-To: <20020319000703.2B06BBA05@i8k.babbleon.org>
References:  <200203180844.g2I8iwb15941@freebsd.dk> <20020318165724.GA21743@jochem.dyndns.org> <20020319000703.2B06BBA05@i8k.babbleon.org>

next in thread | previous in thread | raw e-mail | index | archive | help
I am not sure this is the right place to bring this up, but I didn't 
see one that was more obvious.

I recently received 2 security bulletins dealing with security issues 
in the releases.  These last two did not include updates for 
4.3-RELENG.  The first one was a very simple patch that obviously was 
fine with the 4.3 sources.  That was easily updated.  This last one 
with zlib double-free is not as simple or obvious.

The issue at hand is for those of us who use FreeBSD for production 
environments where down-time results in the loss of customers, having 
to update the OS 2 or 3 times a year is just not viable.  I need to 
be able to keep the OS upgrades to one per year or fewer.  Each of 
those is a severl hour down-time and really annoys my users.  I can 
justify it once a year.  The security patches generally only take a 
minute or so and that is noticed by only a couple users.  I can get 
away with that more often.  However, without the updates to the 
4.3-RELENG I have no way to keep up to date with the security issues. 
Can the security fixes be done a bit farther back?
-- 
-- Doug

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-stable" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?f051003a1b8bc340c3d56>