tinono wrote:
I don't use Ubuntu because cannonical doesn't support packages outside of 'main'. The Ubuntu security team only cares about 'main'.
If you need deb, use debian.
Officially true, and I believe USNs are only sent for main, but I've not yet heard of a case where a known vulnerability was not rectified in universe. An example from today would be:
http://www.ubuntu.com/usn/usn-995-1
In 10.04, this moved from main to universe, but concurrently with the fixes to 8.04/9.04/9.10, it was also updated in 10.04:
Code:
rtucker@tremens:~$ apt-cache policy libmikmod2
libmikmod2:
Installed: (none)
Candidate: 3.1.11-a-6.1ubuntu0.1
Version table:
3.1.11-a-6.1ubuntu0.1 0
500 http://security.ubuntu.com/ubuntu/ lucid-security/universe Packages
3.1.11-a-6.1 0
500 http://mirror.rit.edu/pub/ubuntu/ lucid/universe Packages
(Perhaps not the best example, but it's the one I have right here.)
_________________
Code:
/* TODO: need to add signature to posts */