LWN.net Logo

Vulnerability window may not start with disclosure

Vulnerability window may not start with disclosure

Posted Nov 17, 2011 16:57 UTC (Thu) by raven667 (subscriber, #5198)
In reply to: Vulnerability window may not start with disclosure by epa
Parent article: Security response: how are we doing?

I imagine that information is harder to compile as it would mean analyzing the revision information for each bug and those results aren't already compiled whereas the disclosure date is well published. Also, it would probably be very depressing. It might be useful to get an average or median number of how many vulnerabilities are likely to be present in any system of a sufficient complexity level.


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds