Search

Items tagged with: curl


@loke I know we are far from alone - I expect this to happen to virtually everyone. But as I work on #curl and it is a problem for us, I try to educate our audience in how this works.

I very much doubt that any CVSS change can fix this. It's an NVD problem rather than anything else as I see it.


"Alert: if you look up curl CVEs in public sources like NVD you will find they use inflated severity levels and CVSS scores. They think they know better and override our assessments. This is a systemic error that we unfortunately cannot fix. Feel free to complain to them - we keep doing it to no use - and consider using our material as the canonical sources for curl issues. "

Quote from curl.se/docs/security.html #curl

#curl


#curl


#curl


#curl


#curl


#curl


#curl


Number of announced security vulnerabilities in #curl per year, separated into high/critical vs low/medium.

These are real severity levels, not the NVD spicy versions.

#curl


#curl


#curl user survey 2023 analysis with Daniel Stenberg on video
youtu.be/eTPDNUri590
#curl


#curl


This is the Siemens EQ900.

This baby runs #curl.

#curl


#curl


#curl


#curl


I'll do my #websocket with #curl presentation on twitch twitch.tv/curlhacker starting 16:00 CEST (14:00 UTC) today



23 years of adding examples, shown as a graph #curl
#curl


#curl


#curl


#curl


#curl


#curl


#curl


The #curl CVE reports since 2010 and the share of severity high/critical among them...
#curl


#curl


#curl


#curl


I went back and provided severity levels for the 72 oldest #curl CVEs as well (assessed manually) and now every curl CVE since the dawn of time has it set. The full list is here: curl.se/docs/security.html

Let me know if anything looks wrong.

#curl