With something like OpenSSL, I'd rather panic needlessly, than have someone handwringing over whether or not they should tell users to patch urgently if something COULD be reasonable exploited.
OpenSSL downgrades horror bug after week of panic, hype
OpenSSL today issued a fix for a critical-turned-high-severity vulnerability that project maintainers warned about last week. After days of speculation, infosec professionals and armchair bug hunters received more of a trick than a treat on November 1: two CVE-tagged security issues, both rated "high" severity, to patch. One …