logoalt Hacker News

PunchyHamstertoday at 1:34 PM1 replyview on HN

if the tool isn't ran it can't be exploited

CVE should just be far more granular instead of flagging alert for anything using zlib


Replies

pixl97today at 4:20 PM

And when you chain another weak CVE to run the tool in a method that would have previously been a noop?

Security can be a major pain in the ass, and it's pretty often we see CVEs that were low valued suddenly become more urgent when someone finds a better way to use them as an exploit.