
Recent security update email from Ubuntu had me wondering.
“Stefan Cornelius discovered that GIMP did not correctly handle certain
malformed PSD files. If a user were tricked into opening a specially
crafted PSD file, an attacker could execute arbitrary code with the user’s
privileges. This issue only applied to Ubuntu 8.10, 9.04 and 9.10.
(CVE-2009-3909)
Updated packages for Ubuntu 8.04 LTS:
Source archives:…”
OK so Ubuntu 8.04 didn’t have the problem but you updated the 8.04 package anyway? What’s the point of that? If I were Ubuntu I would error on the side of not updating a package that doesn’t need to be. Reason? Not screwing up something is easier if you don’t mess with it. Plus a zillion people update Ubuntu’s LTS, save the bandwidth.