We don't normally cover security advisories here on OStatic. There's just not enough space to do them all justice, and besides,
other folks do a fine job of tracking such things. But a
recent vulnerability in the Debian version of
OpenSSL is worth spending some time on, because it's a case where the open source system failed for a long time to do its job of producing quality software.