Language Selection

English French German Italian Portuguese Spanish

Debian struggling with security

Filed under
Security

Debian is facing difficulties getting timely security updates to users of its Linux distribution due to lack of manpower and software problems.

The issues recently surfaced when Debian released the latest version of its Linux distribution early in June, according to Martin Schulze, a member of the organisation's security team.

That release, Schulze wrote on his blog, caused configuration problems on the server which was responsible for distributing security updates -- and it hasn't been functioning properly since. "Several security updates aren't built on all architectures as they should be," the developer wrote only yesterday. "Currently, it's totally unreliable."

Lack of manpower also appears to be adding to Debian's security woes. Michael Stone, another member of Debian's security team, expressed his frustration to the organisation's security e-mail mailing list in mid-June, saying there was no effective tracking of security problems.

The problems have seen Debian fall behind competitors like Red Hat in releasing updates to widely-used programs. For example, although spam-filtering package SpamAssassin was updated by its creator to fix a remote denial-of-service vulnerability on 6 June, Debian provided the update on 1 July, while Novell's SuSE got the fix a week earlier on 23 June, Gentoo Linux on the 21st and Red Hat's Fedora still earlier on the 16th.

A similar situation occurred when the 'sudo' package needed an update in mid-June. In addition a number of security-related bugs are listed on Schulze's Web site as being unfixed, although the site also notes the data may be inaccurate as it is automatically generated.

Although Debian's infrastructure problems have not been as prominently discussed as the manpower issues on the project's mailing lists, giving some developers more authority is one idea that has been discussed as a way of speeding up the release of security updates.

As one developer put it: "The problem we're currently seeing isn't that the job is hard, but that only a very small number of people have the authority/ability to push the update out."

Another agreed, calling for the size of the security team to be increased from seven to 21.

Source.

More in Tux Machines

Devuan, DevOne. Here comes a fork of Debian

Ha, from ongoing discussions surrounding Systemd/Init in Debian, anybody could have predicted this was going to happen sooner or later. Well, it has happened. A fork of Debian has been announced by the “Veteran Unix Admin collective.” The name of the Debian fork is Devuan, an Italian name that’s pronounced like DevOne. The following is from the groups webpage. Read more

[Mesa-announce] Mesa 10.4.0 release candidate 3

Mesa 10.4.0 release candidate 3 is now available for testing. This is the final release candidate planned before the 10.4.0 release coming next Friday, Dec 5th. The tag in the git repository for Mesa 10.4.0-rc3 is 'mesa-10.4.0-rc3'. Mesa 10.4.0 release candidate 3 is available for download from ftp://freedesktop.org/pub/mesa/10.4.0/ Read more

Mokotów real estate dept.: ‘Open source encourages innovation’

The Department of Real Estate Management of Mokotów, a district of the city of Warsaw (Poland), is increasingly turning to free and open source software solutions to providing flexible, innovative new ICT services. “Our management values innovations, and so supports the use of open source software,” says Jacek Wolski, the IT department’s team manager, “this encourages the IT department to implement new solutions and tools.” Read more

Wine Announcement

The Wine development release 1.7.32 is now available. What's new in this release (see below for details): - New version of the Mono engine. - A few more functions implemented in MSHTML. - Improved support for restoring display mode. - Font metrics improvements in DirectWrite. - Various bug fixes. Read more