unhinge to [email protected]English • 1 year agoHow do you track security vulnerabilities?message-square34fedilinkarrow-up180
arrow-up180message-squareHow do you track security vulnerabilities?unhinge to [email protected]English • 1 year agomessage-square34fedilink
Do you rely on mailing lists or news articles for security vulnerabilities? Please share. I only got to know about xz/liblzma [1] and curl [2] [3] vulnerabilities through lemmy (maybe because of high severity?). 1 ↩︎ 2 ↩︎ 3 ↩︎
minus-square@[email protected]linkfedilink5•1 year agoSeeing my colleagues, I fear that the answer from them is “That’s the neat part, you don’t!”
minus-squareLastlinkfedilink3•1 year agoSame here. Our servers are so out of date that we might not have a version of xz with any commits from Jia Tan at all.
minus-square@[email protected]linkfedilink1•1 year agoI don’t think up-to-date Debian stable even got it before it was discovered. No prod servers should be affected
Seeing my colleagues, I fear that the answer from them is “That’s the neat part, you don’t!”
Same here. Our servers are so out of date that we might not have a version of xz with any commits from Jia Tan at all.
I don’t think up-to-date Debian stable even got it before it was discovered. No prod servers should be affected