5 ms·
Flash security has gotten so bad that security analysts can fully disclose a vulnerability patched only 2 months ago. There's been ~5 0day events since then so.
by jdangu 11y ago
Flash security has gotten so bad that security analysts can fully disclose a vulnerability patched only 2 months ago. There's been ~5 0day events since then so...
- bitmapbrother 11y agoAnd how many Windows 0 days has there been?
- adestefan 11y agoThere have been 10 Linux kernel CVEs issued in the last 2 months. That includes 4 code execution and/or privilege escalation vulnerabilities. That's not even counting any 0 day's that are (probably) sitting in someone's toolbox. The point being that this isn't a Flash/Microsoft/pick your target problem, but it's an industry wide, software engineering problem.
- jdangu 11y agoWhat do you mean a "pick-your-target problem"? I was referring to responsible disclosure.
- arielby 11y agoCould you be more specific? The last Debian security update was in April, which is more than 2 months ago.
- rictic 11y agoI'm not the parent, but this is the place to look I believe: https://web.nvd.nist.gov/view/vuln/search-results?query=linux+kernel&search_type=last3months&cves=on https://web.nvd.nist.gov/view/vuln/search-results?query=linu...