Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Mon, 21 Nov 2016 22:28:16 +0200
From: Henri Salo <henri@...v.fi>
To: Scott Gravelle <scottg@...rezzio.com>
Cc: oss-security@...ts.openwall.com
Subject: Re: Multiple XSS vulnerabilities affecting five
 WordPress Plugins

On Mon, Nov 21, 2016 at 04:56:13PM +0000, Scott Gravelle wrote:
> Any plans to get CVEs assigned to these vulnerabilities you guys found?  Our
> vulnerability scanner does not have a feature to filter off OVE

Maybe you should start handling OVE and other IDs too. Two reasons:

1) MITRE is not always assigning CVEs for WordPress plugin and theme
vulnerabilities for unknown reason. It's not like the CVEs are running out
2) MITRE is not assigning CVEs to all software that has previously received a
CVE, silently dropping the software to out-of-scope area. Example case:
http://www.openwall.com/lists/oss-security/2016/11/10/6

-- 
Henri Salo

Powered by blists - more mailing lists

Your e-mail address:

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Powered by Openwall GNU/*/Linux - Powered by OpenVZ