Resurrecting DWF
Resurrecting DWF
Posted Apr 8, 2021 10:42 UTC (Thu) by jkingweb (subscriber, #113039)In reply to: Resurrecting DWF by danielthompson
Parent article: Resurrecting DWF
> Ultimately I can't agree with the assertion that CVE means vulnerability. I understand it to mean an identifier that I can look up, potentially with automatic tools in "the CVE list". Thus having identifiers that appear to be CVE numbers that are not included in the CVE list seems to be massively confusing, especially so on an identifier format that *explicitly* includes a namespace to describe the originator of an identifier.
You have identified what I've been struggling to pin down about this that I don't like. If I see CVE 1000003 and I'm not aware of DWF (I certainly wasn't before today), how do I find the particulars? Not MITRE, despite the prefix that has been well known for two decades. How do I figure out, without prior knowledge, that I should be looking for the DWF database? This uses CVE identifiers without gaining any of the practical benefits of having them, while stepping on toes in the process.
