Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

In the event of slow uptake of the fix, additional effort might be warranted to call attention the vulnerability (for example, using social media), as discussed in Section 4.6.1.

It is also possible that the remediation advice is incorrect, or may not apply to all scenarios. Therefore the vendor and reporter should monitor for public discussion or reports of problems, so that the disclosure advisory and remediation information can be updated as necessary. Remember, the goal for remediation is to fix vulnerable product instances or at least reduce the impact of the vulnerability. Consequently, if a significant portion of the vulnerable product instances have not been remediated, that goal has not been achieved.