Sustain cover image

Sustain

Episode 203: What’s wrong with CVEs? Daniel Stenberg of cURL wants you to know

Oct 13, 2023
Daniel Stenberg, founder and lead developer of the cURL project, discusses the complexities and flaws of Common Vulnerabilities and Exposures (CVEs), exploring issues with reporting, scoring, and potential impact on open-source maintainers. The conversation delves into the difficulty of fixing the CVE system, proposes short-term solutions, and addresses concerns about CVE-related DDOS attacks. The podcast also includes insights from Dan Lorenc, co-founder and CEO of Chainguard, on improving CVE quality and examines NDS's response. Tune in to learn more about the challenges and future of CVEs!
27:43

Episode guests

Podcast summary created with Snipd AI

Quick takeaways

  • CVEs can be filed by anyone, leading to discrepancies in quality and inflated impact of vulnerabilities.
  • The NVD system for assigning CVEs lacks effective mechanisms for evaluating vulnerabilities, causing distortion of severity scores and unnecessary fear.

Deep dives

CVEs and their Reputation

CVEs, or common vulnerabilities and exposures, are a means of identifying and addressing vulnerabilities in code. However, CVEs have received criticism due to their reputation and the way they are assigned. They can be filed by anyone, leading to discrepancies in quality, and some individuals inflate the impact of vulnerabilities to enhance their reputation. The National Vulnerability Database (NVD) is a global database that tracks these CVEs, but its scoring system, known as CVSS, has come under scrutiny. Misleading scores, like a recent CVE assigned to the curl library with a score of 9.8 (out of 10), can cause unnecessary panic and hinder development progress. The NVD relies on publicly available information, and there have been calls for more stringent filtering and evaluation of vulnerabilities to ensure accurate scores.

Remember Everything You Learn from Podcasts

Save insights instantly, chat with episodes, and build lasting knowledge - all powered by AI.
App store bannerPlay store banner