Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Fri, 14 Jul 2017 20:07:42 +0200
From: Kristian Fiskerstrand <>
To:, Javantea <>
Subject: Re: Estimate for the total number of exploitable bugs
 in large linux distro?

On 07/14/2017 07:52 PM, Javantea wrote:
> This shows that GLSAs are neither increasing nor decreasing within the margin of error over the past 10 years.

As a metric it likely doesn't provide much though; a high number of
tracked issues are fixed without GLSA, depending on severity and
expected install base of the package, and multiple fixes are combined
into single GLSAs if related to same package etc, so as a metric it is
probably quite bad and number depending on factors such as available
manpower from year to year.

Kristian Fiskerstrand
OpenPGP keyblock reachable at hkp://
fpr:94CB AFDD 3034 5109 5618 35AA 0B7F 8B60 E3ED FAE3

Download attachment "signature.asc" of type "application/pgp-signature" (489 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.