curl의 CVE 발급 여부에 대한 분쟁과 MITRE의 동의 내용.
curl은 CNA로서 CVE를 발급해 왔으나, 특정 조건에서 발생하는 인증서 호스트명 검사 버그는 CVE 대상으로 판단하지 않았습니다. MITRE 역시 curl의 판단에 동의했습니다. 이는 점으로 시작하는 불법 DNS 호스트명, 와일드카드 인증서 및 특정 TLS 백엔드와 관련된 문제를 포함합니다.
Dispute over curl's CVE issuance and agreement with MITRE.
curl, as a CNA, has been issuing CVEs but has determined that a bug in certificate hostname verification occurring under extreme conditions does not warrant a CVE. MITRE has agreed with this assessment. This issue involves illegal DNS hostnames starting with a dot, wildcard certificates, and certain TLS backends.