CVE-2015-7547 Public Announcement ETA for NIST database Inclusion
Florian Weimer
fweimer@redhat.com
Thu Feb 18 06:23:00 GMT 2016
On 02/18/2016 07:13 AM, mark mark wrote:
> Hello,
>
> Since the vulnerability was disclosed, my company has already began
> patching affected servers. We've almost had that completed and the
> only show stoppers are the linux-based network devices that are
> vulnerable as per the vendor. We were told by our vendor that they
> will not initiate the patch development until the vulnerability is in
> the NIST database.
Hi Mark,
if you can share the vendor (off-list), I'm happy to explain to them why
this approach does not work.
In fact, it is so far out of the ordinary that I'm wondering if you have
relayed their position correctly.
Thanks,
Florian
More information about the Libc-alpha
mailing list