Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Date: Thu, 15 Mar 2012 10:17:13 -0400
From: Dan Rosenberg <dan.j.rosenberg@...il.com>
To: security@...roid.com, cve@...re.org
CC: "Steven M. Christey" <coley@...us.mitre.org>, 
 oss-security@...ts.openwall.com
Subject: Android CVE identifiers

Hi Android Security Team and CVE folks,

The assignment of CVE identifiers to Android security issues appears to
be sporadic at best, because to my knowledge none of the major Android
OEMs (HTC, Motorola, Samsung, LG) assign CVEs to Android security issues
affecting their builds or publish any information about this.  Is there
any official policy followed by the Android security team on assigning
CVE identifiers to OEM-specific vulnerabilities?

If it would be helpful to anyone, I have a detailed list of about 20
local privilege escalation vulnerabilities that have been patched in the
last year or two, most of which affect specific devices.  If there is
interest in assigning CVEs to these issues, I can follow up with a
formal CVE request.  Additionally, there are at least a few
Google-authored vulnerabilities that are missing identifiers.

Regards,
Dan

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.