oss-sec mailing list archives
Re: Thousands of vulnerabilities, almost no CVEs: OSS-Fuzz
From: Bob Friesenhahn <bfriesen () simple dallas tx us>
Date: Sat, 15 Jun 2019 11:21:41 -0500 (CDT)
On Sat, 15 Jun 2019, Alex Gaynor wrote:
Today I'd like to highlight what I see as a tremendous issue: very few of these security bugs ever has a CVE issued for it. This is probably due to a few factors, a) the relative difficulty of obtaining a CVE, b) the lack of a human reporter who is interested in obtaining one for "credit" purposes, c) the sheer number of bugs that we're talking about.
Many oss-fuzz "security" issues are not CVE-worthy although they are bugs worthy to spend time fixing.
At least as pertains to the Debian project, I do feel that someone is looking at each security issue I fix and creating CVEs for serious issues. A CVE summary page for GraphicsMagick is maintained at https://security-tracker.debian.org/tracker/source-package/graphicsmagick.
This is in addition to the >100 security bugs OSS-Fuzz found and publicly disclosed due to hitting their disclosure deadline, and which still have not been fixed [3].
Security bugs are often very hard to diagnose and fix. The community has become much better at producing bug reports than with helping to solve the problems found. Help with actually fixing issues is appreciated. I think that the objective should be open source software which lacks bugs and still provides a useful purpose. Finding bugs is just part of the effort.
Bob -- Bob Friesenhahn bfriesen () simple dallas tx us, http://www.simplesystems.org/users/bfriesen/ GraphicsMagick Maintainer, http://www.GraphicsMagick.org/ Public Key, http://www.simplesystems.org/users/bfriesen/public-key.txt
Current thread:
- Thousands of vulnerabilities, almost no CVEs: OSS-Fuzz Alex Gaynor (Jun 15)
- Re: Thousands of vulnerabilities, almost no CVEs: OSS-Fuzz Greg KH (Jun 15)
- Re: Thousands of vulnerabilities, almost no CVEs: OSS-Fuzz Yves-Alexis Perez (Jun 21)
- Re: Thousands of vulnerabilities, almost no CVEs: OSS-Fuzz Simon McVittie (Jun 21)
- Re: Thousands of vulnerabilities, almost no CVEs: OSS-Fuzz Moritz Muehlenhoff (Jun 21)
- Re: Thousands of vulnerabilities, almost no CVEs: OSS-Fuzz Ian Zimmerman (Jun 21)
- Re: Re: Thousands of vulnerabilities, almost no CVEs: OSS-Fuzz Simon McVittie (Jun 21)
- Re: Thousands of vulnerabilities, almost no CVEs: OSS-Fuzz Yves-Alexis Perez (Jun 21)
- Re: Thousands of vulnerabilities, almost no CVEs: OSS-Fuzz Greg KH (Jun 21)
- Re: Thousands of vulnerabilities, almost no CVEs: OSS-Fuzz Yves-Alexis Perez (Jun 21)
- Re: Thousands of vulnerabilities, almost no CVEs: OSS-Fuzz Greg KH (Jun 15)
- Re: Thousands of vulnerabilities, almost no CVEs: OSS-Fuzz Alex Gaynor (Jun 15)
- Re: Thousands of vulnerabilities, almost no CVEs: OSS-Fuzz Bob Friesenhahn (Jun 15)
- Re: Thousands of vulnerabilities, almost no CVEs: OSS-Fuzz David A. Wheeler (Jun 15)
- Re: Thousands of vulnerabilities, almost no CVEs: OSS-Fuzz Alan Coopersmith (Jun 15)
- Re: Thousands of vulnerabilities, almost no CVEs: OSS-Fuzz Bob Friesenhahn (Jun 16)
- Re: Thousands of vulnerabilities, almost no CVEs: OSS-Fuzz Solar Designer (Jun 16)
- Re: Thousands of vulnerabilities, almost no CVEs: OSS-Fuzz Alexander Potapenko (Jun 17)
