4 ms·
I think the tone of this page is frustration that this page needs to exist. I think if I had to constantly deal with stuff like this I'd be pretty frustrated to
by stux 5y ago
I think the tone of this page is frustration that this page needs to exist. I think if I had to constantly deal with stuff like this I'd be pretty frustrated too:
> CVS-2019-19317 is an excellent example of a bogus CVE. This CVE describes a bug in an unreleased development version of SQLite. We were working on the new generated columns feature of SQLite, and a third-party hacker found an error in the code under active development, and then wrote a CVE against it. The error was fixed before the problem was ever released, and yet still there is this CVE sitting out there, unresolved, and as far as I can tell unresolveable.
Lot's of great related discussion from drh in this[0] sqlite forum thread.
[0]: https://sqlite.org/forum/forumpost/0e8b92001245dec1 https://sqlite.org/forum/forumpost/0e8b92001245dec1
- radarsat1 5y agoIt applies to a lot of software actually, I've found that one of the implications of developing in the open is that people feel free to take whatever version they want and treat it the same as a release. The DVCS appears to have exacerbated this because people so often just attach their scripts to pull from "master" instead of respecting tagged releases. I've more than once discovered an in-development version of a library I'm working on appear as a package in Debian, for example. Suddenly I'm feeling responsible to maintain backward compatibility with an unreleased version because it's now "released" as far as users go. Of course what happened is that I asked the maintainers to remove it and then they never packaged any new versions of my software because of the interpersonal friction it caused.