latest security patch

From: Bob Vickers (bobv@cs.rhul.ac.uk)
Date: Thu Mar 27 2003 - 05:24:29 EST


I do despair at the lack of communication skills of the people who send
out the patch announcements. A recent e-mail says

TITLE: SSRT0845U - HP Tru64 UNIX Potential stdio Security Vulnerability
New Kit Date: 12-MAR-2003
Modification Date: 27-MAR-2003
Modification Type: Kit Updated with correct links
Copyright (c) Hewlett-Packard Company 2003. All rights reserved.

What on earth does 'updated with correct links' mean? There is one
question which will be on the lips of nearly all 4.0G admins receiving
this e-mail:

"I have already successfully installed the original version of this patch.
Do I now have to repeat all the work and service disruption to install
this new version?"

I have seen more or less identical announcements where the answer was No
because the reissue was for some minor reason but obviously
I can't take any chances.

There are a lot of great Tru64 people at Compaq but I get the impression
the authors of these announcements get beaten over the head by lawyers
the moment they reveal any information of the slightest value.

Sorry this has turned into a rant on a non-ranting list: really I just
want an answer to the question about whether I need to install the patch
(as I'm sure do lots of others).

Bob
==============================================================
Bob Vickers R.Vickers@cs.rhul.ac.uk
Dept of Computer Science, Royal Holloway, University of London
WWW: http://www.cs.rhul.ac.uk/home/bobv
Phone: +44 1784 443691



This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 10:49:13 EDT