Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Wed, 19 Aug 2015 15:34:52 -0700
From: Reed Loden <reed@...dloden.com>
To: oss-security@...ts.openwall.com
Subject: Re: CVE REJECT noise

On Wed, Aug 19, 2015 at 3:06 PM, Solar Designer <solar@...nwall.com> wrote:

> So, once again, can _only_ those people who want to see non-informative
> CVE REJECT postings in here state so, please?  I don't need to hear from
> the 99%+ of people who I am sure don't want to see those postings in
> here.  That's obvious.  I also already know your preference, Kurt.
>
> And let's end this thread soon.  It isn't meant to be long, or that
> would defeat the purpose.  But for now, the thread is open in case
> anyone at all (besides Kurt) has any objections to the proposed decision
> or wants to establish another mechanism for them to receive those
> seemingly useless messages.
>

It really comes down to whether the (invalid) CVE assignment has been used
in any public capacity at all. If it has, then it's very useful to know
about it, as that has been a source of confusion in the past. If not, then
only MITRE really needs to know so they can update their records.

~reed

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.