| |
The curl project, which became a CVE Numbering Authority (CNA) several years ago, has published 57 CVEs for security vulnerabilities but faces a dispute over one issue it declined to assign a CVE to. The project argues that while it thoroughly assesses all security reports, it should not issue CVEs for issues with minimal practical risk or extreme requirements to exploit, considering the significant ecosystem-wide cost that each CVE triggers across billions of libcurl installations worldwide.
Read Full Article →
← More Tech news