4 ms·
I'm technically aware, but do I really have the expertise and bandwidth to tell the difference between an actual CVE and one that isn't, for the whole database?
by TomSwirly 3y ago
I'm technically aware, but do I really have the expertise and bandwidth to tell the difference between an actual CVE and one that isn't, for the whole database?
The database isn't really much use unless it's pretty accurate, as few of us have the ability to evaluate correctness.
In this case, where there's an anonymous report, and a clear, near-elementary level explanation of how the code in question cannot be a security violation and has since been removed, the CVE should just be deleted, to save bandwidth for everyone.
- deleted 3y ago[deleted]
- grepknfss 3y ago> I'm technically aware, but do I really have the expertise and bandwidth to tell the difference between an actual CVE and one that isn't, for the whole database? I sure don’t. But who does? Who gets paid by whom to make this all work? Apparently whatever is happening now ain’t it.