Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.project > #13490

Re: Fwd: CVE-2023-38545 security fix not listed on NVD databse

From Moritz Mühlenhoff <jmm@inutil.org>
Newsgroups linux.debian.project
Subject Re: Fwd: CVE-2023-38545 security fix not listed on NVD databse
Date 2024-02-02 20:10 +0100
Message-ID <I375f-7qGI-7@gated-at.bofh.it> (permalink)
References <I2hJn-6OX9-15@gated-at.bofh.it> <I375f-7qGI-9@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


Amar Adadande wrote:
> As part of our organization's security measures, we regularly conduct
> security scans using the National Vulnerability Database (NVD). We have
> noticed that the NVD database used by Debian may not be up to date with the
> latest vulnerabilities.

You seem to be mistaken. We don't use the NVD database for anything and
triage vulnerabilities ourselves.

If any external provider (like apparently the security feed you seem to
be using) uses incorrect/stale data which differs from what we publish
via the Debian Security Tracker you should report this disprepancy to
them, not us.

If you believe to have found incorrect, please see here:
https://security-tracker.debian.org/tracker/data/report

Cheers,
        Moritz

Back to linux.debian.project | Previous | NextPrevious in thread | Find similar | Unroll thread


Thread

CVE-2023-38545 security fix not listed on NVD databse Amar Adadande <amarstjit@gmail.com> - 2024-01-31 13:20 +0100
  Re: Fwd: CVE-2023-38545 security fix not listed on NVD databse Moritz Mühlenhoff <jmm@inutil.org> - 2024-02-02 20:10 +0100

csiph-web