|
|
|
|
|
by em-bee
862 days ago
|
|
after the curl announcement i pretty much saw this one coming. as i commented there: https://news.ycombinator.com/item?id=39054152 noone should ever be able to file a CVE without the product owner having a say in this. filing a CVE should always include the party that is responsible for the vulnerability with proper checks and balances. the current process allows accusing someone without the accused having any ability to defend themselves. it was created with the expectations that only security experts who know what they are doing will file CVEs. that expectation has not held. this is pretty much why linus torvalds refused to announce when they fix security issues in the linux kernel. |
|
That's a really stupid idea. CVEs track security vulnerabilities, not 'security vulnerabilities the product owner is prepared to admit to'.
Imagine if Cisco decided they were going to be the CNA for Cisco devices just weren't going to issue any CVEs for any vulnerabilities in any Cisco devices, regardless of whether they're exploited or not.