Re: replacing misleading debian.org/security claims

2022-01-09 Thread Salvatore Bonaccorso
Hi, On Wed, Jan 05, 2022 at 02:20:46PM +0800, Paul Wise wrote: > > (Side note: It seems that NVD tends to assign "medium" severity to > > vulnerabilities initially, but upgrades them to "high" or "critical" > > later. However, Debian keeps showing the initial severity rating) > > Please send a pa

Incorrect NVD severity ratings: (was: replacing misleading debian.org/security claims)

2022-01-09 Thread max
January 5, 2022 7:20:46 AM CET Paul Wise wrote: > Please send a patch, issue or mail about that separately. Please see below: The security tracker is listing incorrect NVD severity ratings. It looks like NVD tends to assign "medium" severity and later upgrades them, while Debian doesn't. Fo

Re: replacing misleading debian.org/security claims

2022-01-09 Thread max
(Added: CC: secur...@debian.org as requested. Please see the mailing list archive if you need context) January 5, 2022 7:20:46 AM CET Paul Wise wrote: > This isn't entirely factual either. How about this (added "largely"): """ Debian's security updates are largely created by volunteers work