Freexian Security Policy
Freexian relies on the Common Vulnerabilities and Exposures (CVE) system and the coordination with vendors across the ecosystem to track and triage all the different security issues that have been identified in the packages shipped in our supported Debian releases.
Freexian provides information about CVEs in its own Security Tracker, which is based on the Debian Security Tracker but amended with additional information. Besides the human-readable information in the Security Tracker, Freexian also provides machine-readable information in the CSAF/VEX standard format.
Severity Categorization
After becoming aware of a CVE the first step is to evaluate the severity of this issue. Freexian uses the following severity categorization: Critical, High, Medium, Low, None and Undetermined.
Overview
Critical: All issues that can be easily exploited by a remote attacker to gain root privileges, or that result in remote data theft or remotely induced data loss, are ranked here. All issues that require authentication, local, or physical access to a system are not ranked Critical.
High: All issues exploitable in the default installation of the package (the package as configured with its default options on a standard Debian system) are ranked here, as is any local root privilege escalation regardless of configuration. Local data theft and local data loss also fall into this category. Issues requiring physical access or non-default configurations are ranked Medium or lower.
Medium: All issues that are difficult to exploit but could still compromise the confidentiality, integrity, or availability of resources are ranked here. Examples include remotely triggered Denial of Service (DoS) with high impact on service availability, stored cross-site scripting (XSS, affecting users without targeted interaction by the attacker), or gaining non-root user privileges.
Low: All issues that are very unlikely to be exploitable, or whose security impact has minimal consequences, are ranked here. As a general rule, such issues are only addressed when higher-severity issues require an update of the package, or when many pile up for a package. Examples include low-impact DoS (e.g. ReDoS or a clean crash of a respawning process), reflected XSS (requiring targeted social engineering), or issues that can be easily mitigated.
None: All issues that do not affect the maintained version of the software are ranked here. For example, an issue affecting a feature that does not exist in the older version: the newest version of the software will be rated Critical, High, Medium or Low, whereas the older (maintained) version will be rated None.
Undetermined: All issues whose impact is not yet known are ranked here, including those for which not enough information has been published.
CVSS Base Score
The Severity Categorization is complemented by the Common Vulnerability Scoring System (CVSS) base score, an industry standard rating system for security vulnerabilities. This score is initially based on the National Vulnerability Database (NVD) assessment. For more information regarding this score please have a look at CVSS.
The base score of any vulnerability depends not only on criteria related to the corresponding software but also on how this software is configured and used. In some cases, Freexian may consider providing a more accurate CVSS score considering the standard distribution / configuration of the related package in Debian. Further it is not always possible to know how third-party software uses, for example, certain libraries. In this case the calculated base score from Freexian might also be different from the score calculated by the vendor of this third-party software.
It is very important to recognize that this CVSS base score is not a measure of risk. For example a vulnerability with a high CVSS score that only affects an internal test server without any user data, might not require an urgent fix. In contrast, a vulnerability with a medium CVSS score that affects a public facing server which processes user data, might take priority over the higher CVSS of the vulnerability mentioned before.
The CVSS score just rates how bad a vulnerability is. But you still need to combine this with your knowledge of the affected servers to decide on the risk that the vulnerability represents, and decide how fast you want to deploy the corresponding security update.
Machine-Readable Information
Freexian sticks to RFC 9116 and implements the security.txt standard.
The starting point is reachable under the well-known URL, that includes metadata about provided machine-readable CSAF/VEX documents, following ISO/IEC 20153:2025.