User: Password:
Subscribe / Log in / New account

Security response: how are we doing?

Security response: how are we doing?

Posted Nov 17, 2011 16:05 UTC (Thu) by paravoid (subscriber, #32869)
Parent article: Security response: how are we doing?

I'd say that to be fair in comparison, you should probably account for the severity of each vulnerability as well, esp. compared to the response time. It's a serious problem if a zero-day remote vulnerability with an exploit in the wild is fixed in 42 days but not so if a minor potential local DoS is not fixed yet.

Debian, for example┬╣, is frequently postponing minor vulnerabilities to stable point releases instead of pushing them as security updates.

┬╣: Disclaimer: I'm a Debian Developer.

(Log in to post comments)

Copyright © 2017, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds