Daniel Stenberg says the scores are “security misinformation”.

  • BestBouclettes@jlai.lu
    link
    fedilink
    English
    arrow-up
    6
    ·
    edit-2
    2 days ago

    Nah, the last few high scoring CVEs curl got were really niche buffer overflows or potential security issues.
    He’s been very vocal about this. Yeah it’s a bug, and usually an easy fix, but they scored like 8 or 9 on CVSS. Which is disproportionate compared to a lot of other 8s or 9s.
    I can understand the frustration there.