[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Sat, 23 Feb 2008 04:34:29 +0300
From: Solar Designer <solar@...nwall.com>
To: oss-security@...ts.openwall.com
Cc: "Steven M. Christey" <coley@...us.mitre.org>
Subject: Re: CVE Help
> > Jamie Strandboge wrote:
> > You'll probably want to CC Steve on such emails... I don't think he's
> > actually subscribed to the list (Steve, feel free to correct me if I'm
> > wrong here... I assumed it would be the same as vendor-sec).
On Thu, Feb 21, 2008 at 05:12:15PM -0500, Josh Bressers wrote:
> Steve,
>
> I think this is a good opportunity to ask you how we can use this list to
> make your life easier. Perhaps it's worth thinking about ways some of the
> subscribed CNAs can dish out CVE ids to reduce your load a little bit for
> these public issues that obviously lack a proper id.
IIRC, Steve's reason for not being on vendor-sec was that he did not
want to be exposed to more non-public security issues (and detailed info
on them) than is necessary for assigning CVE ids. If so, this reason
does not apply for oss-security, because this is a public list. Steve -
you're welcome to join us on oss-security, although this is, of course,
up to you. :-)
Thanks,
Alexander
Powered by blists - more mailing lists
Please check out the
Open Source Software Security Wiki, which is counterpart to this
mailing list.
Powered by Openwall GNU/*/Linux -
Powered by OpenVZ