Changes between Version 18 and Version 19 of HowTo/ManageCustomImages


Ignore:
Timestamp:
05/15/16 15:25:35 (8 years ago)
Author:
lnevers@bbn.com
Comment:

--

Legend:

Unmodified
Added
Removed
Modified
  • HowTo/ManageCustomImages

    v18 v19  
    3131
    3232
    33 As an example vulnerability announcement, here are the emails from  [https://lists.ubuntu.com/archives/ubuntu-security-announce/2016-February/003305.html Ubuntu] and [https://lists.centos.org/pipermail/centos-announce/2016-February/021668.html CentOS] Security lists regarding the libc vulnerability announced on in February 2016. Of note, these emails are only sent '''after''' a fix has been posted. How does one know there is a problem in the first place? If it's a big enough deal, [https://slashdot.org/ slashdot], or other news sites, will cover it. In most cases, the OS vendors release patches the same day as the bug is publicly announced, as they are coordinating amongst themselves and with the upstream developers.  As was the case with this libc bug in February.
     33As an example vulnerability announcement, here are the emails from  [https://lists.ubuntu.com/archives/ubuntu-security-announce/2016-February/003305.html Ubuntu] and [https://lists.centos.org/pipermail/centos-announce/2016-February/021668.html CentOS] Security lists regarding the libc vulnerability announced on in February 2016. Of note, these emails are only sent '' '''after''' '' a fix has been posted. How does one know there is a problem in the first place? If it's a big enough deal, [https://slashdot.org/ slashdot], or other news sites, will cover it. In most cases, the OS vendors release patches the same day as the bug is publicly announced, as they are coordinating amongst themselves and with the upstream developers.  As was the case with this libc bug in February.
    3434
    3535So how do we confirm that are images are affected if there is no patch immediately available?  There will probably be an article on [https://slashdot.org/ slashdot] or other news outlets.  From there they might link to a vendor's page.