Sustain cover image

Sustain

Episode 203: What’s wrong with CVEs? Daniel Stenberg of cURL wants you to know

Oct 13, 2023
27:43
Snipd AI
Daniel Stenberg, founder and lead developer of the cURL project, discusses the complexities and flaws of Common Vulnerabilities and Exposures (CVEs), exploring issues with reporting, scoring, and potential impact on open-source maintainers. The conversation delves into the difficulty of fixing the CVE system, proposes short-term solutions, and addresses concerns about CVE-related DDOS attacks. The podcast also includes insights from Dan Lorenc, co-founder and CEO of Chainguard, on improving CVE quality and examines NDS's response. Tune in to learn more about the challenges and future of CVEs!
Read more

Podcast summary created with Snipd AI

Quick takeaways

  • CVEs can be filed by anyone, leading to discrepancies in quality and inflated impact of vulnerabilities.
  • The NVD system for assigning CVEs lacks effective mechanisms for evaluating vulnerabilities, causing distortion of severity scores and unnecessary fear.

Deep dives

CVEs and their Reputation

CVEs, or common vulnerabilities and exposures, are a means of identifying and addressing vulnerabilities in code. However, CVEs have received criticism due to their reputation and the way they are assigned. They can be filed by anyone, leading to discrepancies in quality, and some individuals inflate the impact of vulnerabilities to enhance their reputation. The National Vulnerability Database (NVD) is a global database that tracks these CVEs, but its scoring system, known as CVSS, has come under scrutiny. Misleading scores, like a recent CVE assigned to the curl library with a score of 9.8 (out of 10), can cause unnecessary panic and hinder development progress. The NVD relies on publicly available information, and there have been calls for more stringent filtering and evaluation of vulnerabilities to ensure accurate scores.

Get the Snipd
podcast app

Unlock the knowledge in podcasts with the podcast player of the future.
App store bannerPlay store banner

AI-powered
podcast player

Listen to all your favourite podcasts with AI-powered features

Discover
highlights

Listen to the best highlights from the podcasts you love and dive into the full episode

Save any
moment

Hear something you like? Tap your headphones to save it with AI-generated key takeaways

Share
& Export

Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more

AI-powered
podcast player

Listen to all your favourite podcasts with AI-powered features

Discover
highlights

Listen to the best highlights from the podcasts you love and dive into the full episode