Skip to main content


Again NVD lists the wrong info for a #curl advisory in nvd.nist.gov/vuln/detail/CVE-2… which now has the ripple effect that #Debian also lists the wrong versions as affected, in security-tracker.debian.org/tr…

I wish more orgs just read our canonical sources instead.

This entry was edited (1 year ago)
in reply to daniel:// stenberg://

I've complained at NVD, I've submitted an update request of the CVE metadata to MITRE. What a broken system this is.
in reply to daniel:// stenberg://

someone, somewhere, obviously just manually edited the description that we provided for this flaw, and that manual edit was incorrect and inserted this error into the text.
Unknown parent

daniel:// stenberg://
@beekir yet we somehow fool ourselves into believing we have systems nowadays to better handle these things...