Skip to content
Snippets Groups Projects
  1. Nov 19, 2024
  2. Jan 09, 2024
    • Siddhesh Poyarekar's avatar
      SECURITY.txt: Drop "exploitable" in reference to hardening issues · e9f2c6d2
      Siddhesh Poyarekar authored
      
      The "exploitable vulnerability" may lead to a misunderstanding that
      missed hardening issues are considered vulnerabilities, just that
      they're not exploitable.  This is not true, since while hardening bugs
      may be security-relevant, the absence of hardening does not make a
      program any more vulnerable to exploits than without.
      
      Drop the "exploitable" word to make it clear that missed hardening is
      not considered a vulnerability.
      
      Signed-off-by: default avatarSiddhesh Poyarekar <siddhesh@gotplt.org>
      
      ChangeLog:
      
      	* SECURITY.txt: Drop "exploitable" in the hardening section.
      e9f2c6d2
  3. Oct 05, 2023
  4. Oct 04, 2023
Loading