Curl is now a CVE Numbering Authority
daniel.haxx.se
daniel.haxx.se
Last year, someone got got CVE's assigned for a curl issue for code that didn't exist AND managed to get a high severity assigned to it. So curl becoming a CNA lets them provide some control to this process.
Combining this and the announcement of the same for PostgreSQL, would be even better if each was the authority for the other. I’d trust either project to classify the severity of an issue in the other.
Being able to classify your own CVEs has a bit of a fox watching the hen house vibe to it.
yes, but no. from the article:
There’s an appeals process so someone can still actually file CVEs for issues even if we say no, but at least there’s a process where both sides will argue their points.
which is how filing for CVE should have been organized to begin with.
noone should ever be able to file a CVE without the product owner having a say in this.
filing a CVE should always include the party that is responsible for the vulnerability with proper checks and balances.
the current process allows accusing someone without the accused having any ability to defend themselves. it was created with the expectations that only security experts who know what they are doing will file CVEs. that expectation has not held.
this is pretty much why linus thorvalds refused to announce when they fix security issues in the linux kernel.
If you do trust the project then why add another source of trust?