←back to thread

277 points jwilk | 1 comments | | HN request time: 0.211s | source
Show context
DeepYogurt ◴[] No.44382139[source]
It'd be great if some of these open source security initiatives could dial up the quality of reports. I've seen so so many reports for some totally unreachable code and get a cve for causing a crash. Maintainers will argue that user input is filtered elsewhere and the "vuln" isn't real, but mitre don't care.
replies(3): >>44382170 #>>44382407 #>>44382413 #
1. selfhoster11 ◴[] No.44382413[source]
Better yet - they could contribute a patch that fixes the issue.