3 ms·
The conclusions about Wireshark vulnerability lifetimes look wrong to me. Average lifetimes are artificially capped around 2 years because of how Wireshark Secu
by pledess 5y ago
The conclusions about Wireshark vulnerability lifetimes look wrong to me. Average lifetimes are artificially capped around 2 years because of how Wireshark Security Advisory version reporting interacts with their support policy. Real lifetimes might be much higher.
Many Wireshark CVEs with numbers CVE-2018-16058 and lower (up until August 29, 2018) say that 2.2.0 was the lowest affected version. A bunch after that say that 2.4.0 was the lowest affected version. Is it plausible that everything discovered after August 2018 just randomly happened to be in code that was introduced on the 2.4 branch? I feel it's much more plausible that this is just an artifact of the Wireshark support policy. https://wiki.wireshark.org/Development/LifeCycle https://wiki.wireshark.org/Development/LifeCycle says the 2.2 version series hit End of Life on September 7, 2018. When Wireshark reported CVEs after then (such as CVE-2018-19622 up to CVE-2018-19627), I suspect they intentionally didn't list 2.2 affected versions because they weren't supported. So, I disagree that Wireshark advisories "have sufficiently accurate version reporting to calculate lifetime" and I feel that "Of the 509 CVEs in Wireshark, the average and median lifetimes are 1.29 and 1.4 years" may be hugely inaccurate.