3 ms·
Yes, all HIGH severity vulnerabilities (even MODERATE) have lead time. e.g. see https://mta.openssl.org/pipermail/openssl-announce/2021-February/000191.html ht
by bcaa7f3a8bbc 6y ago
Yes, all HIGH severity vulnerabilities (even MODERATE) have lead time.
e.g. see https://mta.openssl.org/pipermail/openssl-announce/2021-February/000191.html https://mta.openssl.org/pipermail/openssl-announce/2021-Febr...
- spockz 6y agoI really like the lead time. It gives everyone time to prepare to patch ASAP when it is released without having the vulnerability available to attackers through diffing the binary. On the other hand, it gives people that found the vulnerability independently a bit of extra time to exploit.
- koolba 6y ago> It gives everyone time to prepare to patch ASAP when it is released without having the vulnerability available to attackers through diffing the binary. It’s an open source library so the code of the patch will be available as soon as it’s published. It’s not released as a compiled library.
- spockz 6y agoYes, indeed in the case of OpenSSL indeed but I was referring to applying the practice in general. With an open source product the lead time is even more important. Even then, they could release the binaries from a private branch/repository so that packages can be updated before the source is released.