Date: Fri, 11 Mar 2016 11:49:15 +0800 From: Paul Wise <pabs3@...edaddy.net> To: oss-security <oss-security@...ts.openwall.com>, cve <cve@...re.org> Subject: debbugs for cve-assign@...re.org? Hi all, I would like to suggest using debbugs for cve-assign@...re.org. debbugs is based on email so it is the lowest friction for researchers and doesn't change their workflow except they now get an immediate CVE after sending a detailed report to the submission address. The Debian project doesn't have much of a problem with spam other than spammers occasionally harvesting bug email addresses and replying to them. This could be mitigated by not putting bug number email addresses on the bug reports. Debian does that for transparency though. Spammers haven't learnt to file bug reports yet though. One thing that would need adding is support for private bugs and authenticated commands to change bugs between public and private. One other thing that would need adding is some support for the CVE ID syntax. Nice URLs could be provided by mod_rewrite. debbugs is also used by the GNU project. -- bye, pabs http://bonedaddy.net/pabs3/ Download attachment "signature.asc" of type "application/pgp-signature" (802 bytes)
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Powered by Openwall GNU/*/Linux - Powered by OpenVZ