Counting vulnerabilities
Posted Jun 25, 2007 14:14 UTC (Mon) by
nix (subscriber, #2304)
In reply to:
Counting vulnerabilities by Randakar
Parent article:
Counting vulnerabilities
But everyone does that.
To be specific: everyone quietly fixes bugs which *might potentially* be considered security vulnerabilities, if just because they don't realise that they're vulnerabilities at the time they fix them.
You don't need to be nefarious to do that.
(Equally, known vulnerabilities in unreleased or released-as-development versions of free software are often fixed without formal vulnerability announcements, on the basis that anyone who was bitable by this bug is going to be upgrading often anyway, or why else would they be running a development release?)
(
Log in to post comments)