A turning point for CVE numbers
A turning point for CVE numbers
Posted Feb 14, 2024 19:54 UTC (Wed) by mokki (subscriber, #33200)In reply to: A turning point for CVE numbers by jbenc
Parent article: A turning point for CVE numbers
I would hope the criteria will allow cases where companies just need to ensure there are product is safe. That can be done by locking it down or by many other means. But if there is a security breach as a result of a known bug that had a fix available, but that was not provided to the customers. Then company could be held liable.
And I think that will work transiently too. If the company in the chain did not apply the provided upstream fix, then they themselves should be liable to their customers.
