Friendica
daniel:// stenberg://
daniel:// stenberg://

daniel:// stenberg://

bagder@mastodon.social

daniel:// stenberg://

bagder@mastodon.social
I write curl. I don't know anything.
ActivityPub
2024-07-13 15:58:41 2024-07-11 22:02:13 2024-07-11 22:02:08 5187305

daniel:// stenberg://
daniel:// stenberg://
mastodon - Link to source

daniel:// stenberg://

1 year ago • •

daniel:// stenberg://

1 year ago • •


CVE-2024-5535 is an #OpenSSL problem that cannot be triggered by #curl

OpenSSL calls it it a low severity flaw. openssl.org/news/vulnerabiliti…

GitHub lists it as "critical" at 9.1 out of 10: github.com/advisories/GHSA-4fc…


CVE-2024-5535 - GitHub Advisory Database

Issue summary: Calling the OpenSSL API function...
GitHub
#OpenSSL #curl
This entry was edited (1 year ago)
  •  Languages
  •  Search Text
  •  Share via ...
in reply to daniel:// stenberg://

daniel:// stenberg://
mastodon - Link to source

daniel:// stenberg://

in reply to daniel:// stenberg:// • 1 year ago • •
It is time we realize and accept that there can never be a single nor objective criticality score for a CVE.
  •  Languages
  •  Search Text
  •  Share via ...
in reply to daniel:// stenberg://

p
mastodon - Link to source

p

in reply to daniel:// stenberg:// • 1 year ago • •
there is no ultimate authority, it's a recurring problem (see politics)
@bagder
@daniel:// stenberg://
  •  Languages
  •  Search Text
  •  Share via ...
in reply to daniel:// stenberg://

Bernard Quatermass
mastodon - Link to source

Bernard Quatermass

in reply to daniel:// stenberg:// • 1 year ago • •

Speaking as someone who is dealing with that as a OSS project member live-and-direct-this-instant, I couldn't agree more.

We're not a CNA (nor are we particularly bothered in becoming one), and as you've noted that doesn't do much to stop the garbage.

  •  Languages
  •  Search Text
  •  Share via ...
in reply to daniel:// stenberg://

Jim Fuller
mastodon - Link to source

Jim Fuller

in reply to daniel:// stenberg:// • 1 year ago • •
ya, I have been fighting the battle that a CVE has a community context (general) and a specific context to any bit of software .. its the main issue with CVE that someone else's 9.1 will be one's 0 ... a community score vs a specific software score is needed to provide context
  •  Languages
  •  Search Text
  •  Share via ...
in reply to daniel:// stenberg://

Tim Yates
mastodon - Link to source

Tim Yates

in reply to daniel:// stenberg:// • 1 year ago • •
love that GitHub includes the "low severity" paragraph 🙄
  •  Languages
  •  Search Text
  •  Share via ...
in reply to daniel:// stenberg://

Clemens
mastodon - Link to source

Clemens

in reply to daniel:// stenberg:// • 1 year ago • •
imported from NVD again, without critical review...
  •  Languages
  •  Search Text
  •  Share via ...
⇧