Hacker News new | past | comments | ask | show | jobs | submit login

What happened internally when you discovered that you were given a false severe grade CVE? I remember seeing many articles suggesting users uninstall VLC.

https://nvd.nist.gov/vuln/detail/CVE-2019-13615




> What happened internally when you discovered that you were given a false severe grade CVE?

Nothing, but we knew it was going to be a shitstorm. Clickbait articles are very annoying.

As for the CVE system, it's utterly broken and idiotic.


Hey now, CVEs are fine; it's CVSS that is totally broken.


Woah, I didn't realize it was false! I remember hearing about that at the time. I had installed VLC at work (generic office, non-tech industry that just uses windows office software) and was worried I might get in trouble, so I uninstalled it.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: