oss-sec mailing list archives
Re: CVEs, Crypto and "vulnerabilities"
From: Michael Samuel <mik () miknet net>
Date: Mon, 31 Mar 2014 20:31:18 +1100
On 31 March 2014 17:26, Kurt Seifried <kseifried () redhat com> wrote:
So the line in the sand is moving currently, I think this issue is another good example of something that may qualify for a CVE, or maybe not, depends where we draw the line. https://github.com/opencart/opencart/issues/1279 So if someone has strong opinions either way please speak up.
This looks like an easily exploitable bug. What possible reason could there be for it not qualifying? If somebody wrote an exploit would it be disqualified just because the author doesn't understand? Regards, Michael
Current thread:
- CVEs, Crypto and "vulnerabilities" Kurt Seifried (Mar 30)
- Re: CVEs, Crypto and "vulnerabilities" Donald Stufft (Mar 31)
- Re: CVEs, Crypto and "vulnerabilities" Michael Samuel (Mar 31)
- Re: CVEs, Crypto and "vulnerabilities" Marcus Meissner (Mar 31)
- Re: CVEs, Crypto and "vulnerabilities" Tim (Mar 31)
- Re: CVEs, Crypto and "vulnerabilities" Marcus Meissner (Mar 31)