Hacker News new | past | comments | ask | show | jobs | submit login

Gee, that BIND vulnerability was made public mid-November and they're integrating that into FreeBSD on Dec 23 ?!



Not quite...

Corrected:

  2011-11-16 23:41:13 UTC (ports tree)

  2011-11-17 01:10:16 UTC (RELENG_7, 7.4-STABLE)
  2011-11-17 00:36:10 UTC (RELENG_8, 8.2-STABLE)

  2011-12-01 21:13:41 UTC (RELENG_9, 9.0-STABLE)
  2011-12-01 21:17:59 UTC (RELENG_9_0, 9.0-RC3)

  2011-12-23 15:00:37 UTC (RELENG_7_4, 7.4-RELEASE-p5)
  2011-12-23 15:00:37 UTC (RELENG_7_3, 7.3-RELEASE-p9)
  2011-12-23 15:00:37 UTC (RELENG_8_2, 8.2-RELEASE-p5)
  2011-12-23 15:00:37 UTC (RELENG_8_1, 8.1-RELEASE-p7)


We sometimes delay "non-critical" advisories in order to send them out at the same time as others. In this case -- a DoS against a daemon which most FreeBSD users install from the ports tree anyway -- there wasn't much point updating the security branches earlier.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: