<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Vulnerability-Triage on krash.dev</title><link>https://krash.dev/tags/vulnerability-triage/</link><description>Recent content in Vulnerability-Triage on krash.dev</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 14 Aug 2026 08:29:09 +0530</lastBuildDate><atom:link href="https://krash.dev/tags/vulnerability-triage/rss.xml" rel="self" type="application/rss+xml"/><item><title>Investigating Reported Vulnerabilities: A Closer Look!</title><link>https://krash.dev/posts/investigating-reported-vulnerability/</link><pubDate>Sun, 30 Jul 2023 00:00:00 +0000</pubDate><guid>https://krash.dev/posts/investigating-reported-vulnerability/</guid><description>&lt;p&gt;In vulnerability scanners or penetration testing reports, you might come across statements like &lt;em&gt;&amp;ldquo;Service version x.y.z is vulnerable to CVE-YYYY-ABCD.&amp;rdquo;&lt;/em&gt; However, it&amp;rsquo;s essential to delve deeper to confirm the actual vulnerability.&lt;/p&gt;
&lt;p&gt;Let&amp;rsquo;s consider a real example:&lt;/p&gt;
&lt;p&gt;We received a vulnerability report indicating a vulnerability (&lt;a href="https://curl.se/docs/CVE-2023-23916.html" target="_blank" rel="noopener noreferrer"&gt;CVE-2023-23916&lt;/a&gt;) in curl v7.74.0 within the Debian 11 environment.&lt;/p&gt;
&lt;p&gt;The CVE documentation mentions:&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;Affected versions: curl 7.57.0 to and including 7.87.0&lt;/p&gt;
&lt;/blockquote&gt;&lt;p&gt;At first glance, it appears that v7.74.0 is indeed vulnerable. But is that really the case?&lt;/p&gt;</description></item></channel></rss>