bagder, (edited )
@bagder@mastodon.social avatar

DISPUTED, not REJECTED or maybe "we simply cannot get rid of rubbish CVEs because they say so" - an update from my last few days.

https://daniel.haxx.se/blog/2024/02/21/disputed-not-rejected/

bagder,
@bagder@mastodon.social avatar

MITRE has now updated the CVE's status to REJECTED...

grishka,
@grishka@mastodon.social avatar

@bagder oh wow so they ARE actually capable of doing that?

bagder,
@bagder@mastodon.social avatar

@grishka apparently!

edyoung,
@edyoung@mastodon.online avatar

@bagder "The system is designed for good-faith reporters against bad-faith product organizations."

The tricky part is in the real world there are bad faith actors at both ends. There needs to be some way to determine ground truth of a report without fully trusting either party.

can,
@can@haz.pink avatar

@bagder I fully understand that a bogus claim like this is annoying and stupid. What I don’t fully understand is what negative consequences this has for you as a maintainer? Is it just people panicking because of a „vulnerability“ and you having to deal with it? Or is there more impact from a CVE that I’m not aware of?

bagder,
@bagder@mastodon.social avatar

@can it is A LOT of people panicking. Lots of (confused) people contacting us for help and support.

We have to spend a lot of time and effort documenting and explaining the NOT vulnerabilities sometimes even more than we spend on actual vulnerabilities.

bagder,
@bagder@mastodon.social avatar
bluGill,
bluGill avatar

@bagder At what point do we create a new vulnerability program that open source projects can live with. If the major players agree to this... Actually just the public threat that we will do this may be enough to force some change.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • ngwrru68w68
  • DreamBathrooms
  • khanakhh
  • magazineikmin
  • InstantRegret
  • tacticalgear
  • thenastyranch
  • Youngstown
  • rosin
  • slotface
  • modclub
  • everett
  • kavyap
  • Durango
  • JUstTest
  • osvaldo12
  • normalnudes
  • cubers
  • ethstaker
  • mdbf
  • tester
  • GTA5RPClips
  • cisconetworking
  • Leos
  • megavids
  • provamag3
  • anitta
  • lostlight
  • All magazines