Sustain

Episode 203: What’s wrong with CVEs? Daniel Stenberg of cURL wants you to know

6 snips
Oct 13, 2023
Daniel Stenberg, founder and lead developer of the cURL project, discusses the complexities and flaws of Common Vulnerabilities and Exposures (CVEs), exploring issues with reporting, scoring, and potential impact on open-source maintainers. The conversation delves into the difficulty of fixing the CVE system, proposes short-term solutions, and addresses concerns about CVE-related DDOS attacks. The podcast also includes insights from Dan Lorenc, co-founder and CEO of Chainguard, on improving CVE quality and examines NDS's response. Tune in to learn more about the challenges and future of CVEs!
Ask episode
AI Snips
Chapters
Transcript
Episode notes
ANECDOTE

Unacknowledged CVE Incident

  • An older caught bug was registered as a new CVE without the project's awareness.
  • This CVE was publicly released without cURL team's acknowledgment or their involvement initially.
INSIGHT

NVD's Overblown Severity Scores

  • NVD often assigns severity scores assuming the worst case due to sparse information.
  • This results in overly high scores for minor bugs, distorting their real impact.
INSIGHT

Problems with CVE System Quality

  • Anyone can file a CVE, leading to variable quality and inflated severity scores.
  • High-severity CVEs for popular software create noise and distract industry's focus from real issues.
Get the Snipd Podcast app to discover more snips from this episode
Get the app