Scaling/domain knowledge
Scaling/domain knowledge
Posted Dec 6, 2023 7:40 UTC (Wed) by epa (subscriber, #39769)In reply to: Scaling/domain knowledge by nickodell
Parent article: Supplementing CVEs with !CVEs
Perhaps they would do better to declare that a NotCVE simply represents a “bug”. Thus avoiding the whole circus about what counts as a vulnerability, the expected uses of the software, where the trust boundary lies and so on.
Calling something a “bug” is also open to debate—the developer may argue that a segmentation fault on invalid input is not a bug because by design the program is meant to work only on valid input—but without the additional politics brought in by the word “vulnerability” it may be easier to resolve.