barkas,
Ubuntu's also famous for blowing stuff out the door at a fast pace without doing as much QA as they probably should. SUSE/SLES, RHEL/CentOS won't patch within 24hours as they do a bunch of testing before release, but also often times backport changes to earlier versions.
A couple of days is reasonable for a major enterprise Linux vendor to respond to a vulnerability. Add in an extra day for trickle down to companies like Sophos that rebuild those distros, SLES in this case, and it gets fixed.
Then the end user spends weeks sitting on the patch. [:)] (tongue in cheek snark)
For this patch, I can not wait a couple of days, it is too critical. Better to rush it out and break something than leave all your installations open for days.
I can not shut down every system, nor can I regenerate the certificates of certain systems.
Owner: Emmanuel Technology Consulting
Former Sophos SG(Astaro) advocate/researcher/Silver Partner
PfSense w/Suricata, ntopng,
Other addons to follow
not at the expense of downing your security device...that's just shortsighted and NOT the way to run a security appliance.
I couldn't disagree more. I'd rather want my security devices offline than vulnerable to this flaw.
CTO, Convergent Information Security Solutions, LLC
https://www.convergesecurity.com
Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries. Use the advice given at your own risk.
I couldn't disagree more. I'd rather want my security devices offline than vulnerable to this flaw.
I'm certain that automated attacks are either already happening or are about to happen that make use of this bug.
Owner: Emmanuel Technology Consulting
Former Sophos SG(Astaro) advocate/researcher/Silver Partner
PfSense w/Suricata, ntopng,
Other addons to follow
I couldn't disagree more. I'd rather want my security devices offline than vulnerable to this flaw.
I'm certain that automated attacks are either already happening or are about to happen that make use of this bug.
Owner: Emmanuel Technology Consulting
Former Sophos SG(Astaro) advocate/researcher/Silver Partner
PfSense w/Suricata, ntopng,
Other addons to follow