The bogus CVE problem [LWN.net]
Without subscribers, LWN would simply not exist. Please consider signing up for a subscription and helping to keep LWN publishing The "Common Vulnerabilities and Exposures" (CVE) system was launched late in the previous century (September 1999) to track vulnerabilities in software. Over the years since, it has had a somewhat checkered reputation, along with some some attempts to replace it, but CVE numbers are still the only effective way to track vulnerabilities. While that can certainly be useful, the CVE-assignment (and severity scoring) process is not without its problems. The prominence of CVE numbers, and the consequent increase in "reputation" for a reporter, have combined to create a system that can be—and is—actively gamed. Meanwhile, the organizations that oversee the system are ultimately not doing a particularly stellar job. A recent incident highlights some of the problems inherent in the system. CVE-2020-19909, which is an integer-overflow bug in the curl tool and library
The bogus CVE problem [LWN.net] LWN .net News from the source Content Weekly Edition Archives Search Kernel Security Events calendar Unread comments LWN FAQ Write for us Edition Return to the Front page User: Password: | | Log in / Subscribe / Register The bogus CVE problem We're bad at marketing We can admit it, marketing is not our strong suit. Our strength is writing the kind of articles that developers, administrators, and free-software supporters depend on to know what is going on in the Linux world. Please subscribe today to help us keep doing that, and so we don’t have to get good at ma
Explore this link on the map →related reading
- Assessing Claude Mythos Preview’s cybersecurity capabilities \ Anthropicred.anthropic.com
- FIRST Mid-Year Vulnerability Forecast Confirms Historic Surge, Projects ~66,000 CVEs in 2026first.org
- Project Glasswing: Securing critical software for the AI era \ Anthropicanthropic.com
- Mediumstephenshaffer.io
- Why I attacknicholas.carlini.com
- Significant raise of reports [LWN.net]lwn.net
- The Letter - Stop Hacklore!hacklore.org
- Measuring LLMs' impact on N-day exploits \ Anthropicred.anthropic.com
- Pwnie Award Winners 2023 – Pwniespwnies.com
- Mediumstephenshaffer.io
- Twenty years of Valgrind | Nicholas Nethercotennethercote.github.io
- Sub-Venture Scale Security Problemstldrsec.com