oss-sec mailing list archives
Re: CVE-2022-21449 and version reporting
From: Christian Fischer <christian.fischer () greenbone net>
Date: Sat, 30 Apr 2022 13:24:36 +0200
> It’s not that they didn’t/can’t verify, it’s already verified, they’re claiming those versions no longer being officially supported means they can seemingly omit them from CVE reporting.
> > Which is dangerous, misleading, and nonsensical.While i fully agree with this be aware that CVE entries could generally contain incomplete information:
After requesting an update of a CVE entry via the MITRE CVE forum in the past to add additional affected products for a different vendor (which wasn't even the assigning CNA like it is the case for Oracle here) my request was rejected by MITRE with the following rationale given:
> A CVE description does not necessarily contain all the affected products or versions and is not part of CVE ID requirements. The products are documented in the CVE references.
This is also matching my experiences with various other products / vendors and related CVE entries for these.
On 29.04.22 01:34, Seaman, Chad wrote:
Exactly this. It’s not that they didn’t/can’t verify, it’s already verified, they’re claiming those versions no longer being officially supported means they can seemingly omit them from CVE reporting. Which is dangerous, misleading, and nonsensical. Regards, Chad On Apr 28, 2022, at 5:36 PM, Sven Schwedas <sven.schwedas () tao at> wrote: On 28.04.22 22:10, Seth Arnold wrote: On Thu, Apr 28, 2022 at 02:12:04PM +0000, Seaman, Chad wrote: In what universe exactly are versions omitted from vulnerability reporting because a vendor “no longer supports that version”… this non-supported version is still vulnerable? A large part of software maintenance is managing technical debt -- and being able to walk away from no-longer-supported products is an important part of that. Would you expect Microsoft to evaluate Windows 3.11, Windows 95, Windows 98, Windows ME, Windows NT 3.51, Windows NT 4.0. Windows XP, etc for every single vulnerability discovered in newest products? You and Jeremy arguing in bad faith here, OP didn't ask about anything like that. The problem at hand is, someone *already did all that work*, and Oracle is *actively intervening* to have it dropped from CVE reports. So the question is: Why is vulnerability information that already exists being censored?
Current thread:
- CVE-2022-21449 and version reporting Seaman, Chad (Apr 28)
- Re: CVE-2022-21449 and version reporting Brian Behlendorf (Apr 28)
- Re: CVE-2022-21449 and version reporting Jeremy Stanley (Apr 28)
- Re: CVE-2022-21449 and version reporting Seth Arnold (Apr 28)
- Re: CVE-2022-21449 and version reporting Sven Schwedas (Apr 28)
- Re: CVE-2022-21449 and version reporting Seaman, Chad (Apr 28)
- Re: CVE-2022-21449 and version reporting Christian Fischer (Apr 30)
- Re: CVE-2022-21449 and version reporting John Helmert III (Apr 30)
- Re: CVE-2022-21449 and version reporting David A. Wheeler (Apr 30)
- Re: CVE-2022-21449 and version reporting Christian Fischer (Apr 30)
- Re: CVE-2022-21449 and version reporting John Helmert III (May 01)
- Re: CVE-2022-21449 and version reporting Christian Fischer (May 02)
- Re: CVE-2022-21449 and version reporting Sven Schwedas (Apr 28)
- Re: CVE-2022-21449 and version reporting Iron-Bound (Apr 29)
- Re: CVE-2022-21449 and version reporting Jeremy Stanley (Apr 30)