Quote:
Originally Posted by simond
|
On the other hand, it is a standard practice (standard, not necessarily the good/best one)to only publish vulnerabilities when a correction is available.
It also is standard practice to publish corrections in a major/minor release rather than as a quick patch.
(On the Other hand, the previous Vulnerability had been fixed via a sub-minor release... 2.0-->2.0.1 cf
http://web.nvd.nist.gov/view/vuln/de...013-1377&cid=7 )