[CentOS-devel] CVE-2011-3192 rpms for CentOS 5 still pending?
dfrg.msc at gmail.com
Wed Sep 7 13:11:55 UTC 2011
2011/9/7 Ned Slider <ned at unixmail.co.uk>:
> On 07/09/11 05:20, dfrg.msc wrote:
>> According to the CentOS-CR-Announce list, there is recently an update
>> for httpd in CentOS 5 CR repo. But the announcement
>> refers to upstream RHBA-2011-1067, which is the version released with
>> 5.7 base packages. Upstream has an update for CVE-2011-3192 whose
>> announcement is RHSA-2011-1245, and this update of httpd has version
>> number 2.2.3-53.el5_7.1, which is higher than that in C5 CR repo
>> (2.2.3-53.el5.centos). Maybe there should be another update for httpd
>> in CentOS 5 CR repo.
>> BTW, any update on C6.1 (or 6.0 CR packages)?
> Please see this extremely lengthy thread for an explanation as to why
> this is confusing:
> You can not go by the package name-version-release string alone as
> CentOS change this. Try examining the changelog and look for the above
> CentOS-devel mailing list
> CentOS-devel at centos.org
I understand. So there is already CVE-2011-3192 rpms uploaded to
CentOS 5 CR repo, but no announcement posted yet.
More information about the CentOS-devel