News SuSEFAQ Howtos Using Wordnet(New) VNC(New) Bash Initialization CD Ripping Apt for RPM PAM Sendmail Mailboxes RPM OpenSSH YOU local(Changed) Fixed packages Wine Clock Grub Graphire Guides Project About |
Is my package fixed? Or: How to look into RPMsSometimes on the SuSE list folks express doubts whether a package contains a certain fix or not. Even if the security announcements say the packages are not vulnerable, they want to know for sure. Looking at the version number of the package is most likely not enough to be sure... but how then? How to look "into" the packages? I thought I'd write up a short howto and post it here. Procedure 1. How to find out what HAS been changed:
Procedure 2. How to find out what SHOULD have been changed:
Taking this even further, to really verify that the vulnerability is gone, you need a testcase (an exploit). Anyway, your picture about the packages should be complete by then, and all your doubts hopefully gone. For remaining questions you could contact this list (<suse-security@suse.com>). In case of serious concerns you should contact the SuSE Security Team directly, writing to <security@suse.de>. |