Author: neilm
Date: 2006-12-06 21:15:41 +0100 (Wed, 06 Dec 2006)
New Revision: 5081
Modified:
doc/narrative_introduction
Log:
add info on nvd
Modified: doc/narrative_introduction
==================================================================---
doc/narrative_introduction 2006-12-06 19:56:28 UTC (rev 5080)
+++ doc/narrative_introduction 2006-12-06 20:15:41 UTC (rev 5081)
@@ -203,7 +203,8 @@
---------------
These levels are mostly used to prioritize the order in which security
problems are resolved. Anyway, we have a rough overview on how you should
-assess these levels:
+assess these levels. These are generally based on the ''score''
from NVD
+(http://nvd.nist.gov/nvd.cfm?cvename=CVE-nnnn-nnnn)
unimportant: This problem does not affect the Debian binary package, e.g.
a vulnerable source file, which is not built or a vulnerable file