Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

ArchLinux, in its current state, is vulnerable. I suspect it will be patched soon enough.

/me sends a note to the package maintainers anyway.



arch compiles with FORTIFY_SOURCE also so it's still vulnerable, just a pain to exploit


ArchLinux doesn't have package signing, so patching sudo isn't going to get you much.


Sure it does, as of earlier this year. http://www.archlinux.org/news/pacman-4-moves-to-core/

Still in beta though. Not very stable.


Yes they do.

It is still pretty new, and from what I understand upgrading can be a bit of a pain, but pacman 4.0 has package signing.

Been using Fedora for a bit now, so haven't actually tried it yet...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: