April 28, 2024, 10:48 a.m. | /u/dkarlovi

cybersecurity www.reddit.com

Latest PHP still has obsolete/invalid CVEs from 2007 open: https://github.com/php/php-src/issues/14050

The maintainers claim "there's nothing that can be done" and it seems they're fine with these CVEs being open in perpetuity even though they're obsolete / invalid.

Is there really no way an obsolete/invalid CVE to be closed, what organization / person would the PHP foundation need to contact and what procedure to follow to get this closed? It seems quite unlikely there is just no way to do this …

can claim cve cves cybersecurity foundation maintainers nothing organization php procedure

Information Security Engineers

@ D. E. Shaw Research | New York City

Technology Security Analyst

@ Halton Region | Oakville, Ontario, Canada

Senior Cyber Security Analyst

@ Valley Water | San Jose, CA

Senior - Penetration Tester

@ Deloitte | Madrid, España

Associate Cyber Incident Responder

@ Highmark Health | PA, Working at Home - Pennsylvania

Senior Insider Threat Analyst

@ IT Concepts Inc. | Woodlawn, Maryland, United States