Scheduled Maintenance: We are aware of an issue with Google, AOL, and Yahoo services as email providers which are blocking new registrations. We are trying to fix the issue and we have several internal and external support tickets in process to resolve the issue. Please see: viewtopic.php?t=158230

 

 

 

Are most or all security flaws fixed in Debian? Or is it like Ubuntu where many are not?

Here you can discuss every aspect of Debian. Note: not for support requests!
Post Reply
Message
Author
Shamak
Posts: 148
Joined: 2018-04-14 00:33
Has thanked: 12 times
Been thanked: 9 times

Are most or all security flaws fixed in Debian? Or is it like Ubuntu where many are not?

#1 Post by Shamak »

TL;DR In Ubuntu, apparently not all security issues in Universe are fixed. I was wondering if all security issues are fixed in Debian. Bearing in mind that some have lower priorities than others. Here's what got me thinking about this.

Here's a post from Wilders Security forums where Summerheat says that many security flaws in Universe in Ubuntu may not be fixed fixed whereas in Debian they all are fixed.
An article on heise.de reminds again of the fact that this LTS support only applies to the main repository (with about 7.300 packages in 16.04), not to universe (with about 45.500 packages) . This is critical as many packages therein are no longer maintained and can therefore be affected by security holes.

[Examples]

The thing is that those vulnerabilities are all fixed in Debian as all provided packages are maintained and security fixes are backported.
https://www.wilderssecurity.com/threads ... rt.385386/

Here's a post by Thomas Ward on AskUbuntu saying that the situation in Ubuntu is much the same as in Debian. He says that the more popular packages in Universe are likely to have security flaws fixed.
Even in Debian, there are many many packages that don't get regular security updates.

...

While you are not guaranteed any updates for these packages, a lot of the popular ones will have enough attention to usually have someone working to try and patch security issues.
https://askubuntu.com/questions/618727/ ... ame-packag

Here;s a post by ian-weisser saying that many less than popular packages do not get security fixes in Ubuntu Universe.
Universe packages are supposed to be provided by the community, but few volunteers do it, so generally they were not happening for many less-popular packages.
https://ubuntuforums.org/showthread.php ... st14151474

Then there's the Debian documentation which seems to indicate that indeed, if a security flaw is reported to the security team then it does get fixed.
Once the security team receives a notification of an incident, one or more members review it and consider its impact on the stable release of Debian (i.e. if it's vulnerable or not). If our system is vulnerable, we work on a fix for the problem.
https://www.debian.org/security/faq#handling

https://www.debian.org/doc/manuals/secu ... n-sec-team

The documentation claims that most security flaws are fixed by any distribution. In section 12.1.1.1 they say
Known security updates are rarely, if ever, left unfixed by a distribution vendor.
But there are too many packages to audit for security flaws. But many people are using stable packages so most will get uncovered. In section 12.1.1.8 they say
The Debian security team cannot possibly analyze all the packages included in Debian for potential security vulnerabilities, since there are just not enough resources to source code audit the whole project.

...

However, Debian users can take confidence in the fact that the stable code has a wide audience and most problems would be uncovered through use.
https://www.debian.org/doc/manuals/secu ... 12.en.html

Can anyone add any insight to this? Are most security flaws in Debian getting fixed or not? :D

User avatar
pbear
Posts: 329
Joined: 2023-08-27 15:05
Location: San Francisco
Has thanked: 1 time
Been thanked: 57 times

Re: Are most or all security flaws fixed in Debian? Or is it like Ubuntu where many are not?

#2 Post by pbear »

There's a big difference between security flaws in Debian and security flaws in apps available in Debian's repos. I'd be astonished if anyone on Team Debian is trying to keep the second stable clean.
And, do let's bear in mind, most security flaws are theoretical. Reports of such flaws causing problems on Linux desktops in the real world are exceedingly rare.

Shamak
Posts: 148
Joined: 2018-04-14 00:33
Has thanked: 12 times
Been thanked: 9 times

Re: Are most or all security flaws fixed in Debian? Or is it like Ubuntu where many are not?

#3 Post by Shamak »

pbear wrote: 2024-01-16 04:22 There's a big difference between security flaws in Debian and security flaws in apps available in Debian's repos. I'd be astonished if anyone on Team Debian is trying to keep the second stable clean.
And, do let's bear in mind, most security flaws are theoretical. Reports of such flaws causing problems on Linux desktops in the real world are exceedingly rare.
Just to clarify, by "I'd be astonished if anyone on Team Debian is trying to keep the second stable clean" do you mean that you'd be astonished if anyone on team Debian is trying to fix security flaws in the apps available in Debian's repos? Such as firejail or gnucash, for example?

User avatar
dilberts_left_nut
Administrator
Administrator
Posts: 5347
Joined: 2009-10-05 07:54
Location: enzed
Has thanked: 13 times
Been thanked: 66 times

Re: Are most or all security flaws fixed in Debian? Or is it like Ubuntu where many are not?

#4 Post by dilberts_left_nut »

AdrianTM wrote:There's no hacker in my grandma...

Shamak
Posts: 148
Joined: 2018-04-14 00:33
Has thanked: 12 times
Been thanked: 9 times

Re: Are most or all security flaws fixed in Debian? Or is it like Ubuntu where many are not?

#5 Post by Shamak »

Thanks. Yes I saw that and quoted it in the OP along with the Securing Debian Manual.

User avatar
pbear
Posts: 329
Joined: 2023-08-27 15:05
Location: San Francisco
Has thanked: 1 time
Been thanked: 57 times

Re: Are most or all security flaws fixed in Debian? Or is it like Ubuntu where many are not?

#6 Post by pbear »

Shamak wrote: 2024-01-16 05:19 ... do you mean that you'd be astonished if anyone on team Debian is trying to fix security flaws in the apps available in Debian's repos?
Right. For example, eCryptfs is in Debian repo even though it hasn't had active development in more than six years.

Still don't understand the point of the thread. The issue is well known and affects all Linux distros.
People don't worry about it much because, so far, hasn't been a significant problem in the real world.

Shamak
Posts: 148
Joined: 2018-04-14 00:33
Has thanked: 12 times
Been thanked: 9 times

Re: Are most or all security flaws fixed in Debian? Or is it like Ubuntu where many are not?

#7 Post by Shamak »

pbear wrote: 2024-01-16 16:29 Right. For example, eCryptfs is in Debian repo even though it hasn't had active development in more than six years.
Thanks.
Still don't understand the point of the thread. The issue is well known and affects all Linux distros.
I didn't really know that for sure. I had read an article about "the dirty little secret" of Linux distributions (which I had forgotten about) claiming this very point but the example it used was Ubuntu. I had seen a few posts on this regarding Ubuntu (quoted above) but the post by Summerheat said that Debian didn't do this. So I thought I'd ask.

People don't worry about it much because, so far, hasn't been a significant problem in the real world.
Good to know.

Shamak
Posts: 148
Joined: 2018-04-14 00:33
Has thanked: 12 times
Been thanked: 9 times

Re: Are most or all security flaws fixed in Debian? Or is it like Ubuntu where many are not?

#8 Post by Shamak »

Found a forum thread with a similar subject. The opinion of a couple of respected members was that perhaps this is the wrong place to ask. Being members of a Debian user forum and not security professionals members are not likely to know the answer. But here is the thread. A bit of fireworks lol.

viewtopic.php?t=150626

CwF
Global Moderator
Global Moderator
Posts: 2719
Joined: 2018-06-20 15:16
Location: Colorado
Has thanked: 41 times
Been thanked: 201 times

Re: Are most or all security flaws fixed in Debian? Or is it like Ubuntu where many are not?

#9 Post by CwF »

By nature it is a sensationalized subject often with extraneous motives.
Rarely is the one important issue mentioned;
You are a target.
You are not a target.

User avatar
pbear
Posts: 329
Joined: 2023-08-27 15:05
Location: San Francisco
Has thanked: 1 time
Been thanked: 57 times

Re: Are most or all security flaws fixed in Debian? Or is it like Ubuntu where many are not?

#10 Post by pbear »

There's a cottage industry in this FUD stuff. Anyone who wants to go down the rabbit hole can look at running Whonix (Tor in a VM) on Qubes. Personally, I've got better stuff to do. :mrgreen:

Shamak
Posts: 148
Joined: 2018-04-14 00:33
Has thanked: 12 times
Been thanked: 9 times

Re: Are most or all security flaws fixed in Debian? Or is it like Ubuntu where many are not?

#11 Post by Shamak »

So it turns out that I was aware of this. I just didn't recognize it this time. But it seems to happen more than I thought. Chromium on Debian went through the same thing for a while. The maintainer at the time, as he put it, didn't have time to maintain it so it was really out of date. I found the article that I had referred to earlier and it reminded me. Written by Chris Hoffman. I've read several of his articles and he seems to be good. Here it is.

https://www.pcworld.com/article/436288/ ... ories.html

Post Reply