Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Sat, 23 Feb 2008 04:34:29 +0300
From: Solar Designer <>
Cc: "Steven M. Christey" <>
Subject: Re: CVE Help

> > Jamie Strandboge wrote:
> > You'll probably want to CC Steve on such emails... I don't think he's
> > actually subscribed to the list (Steve, feel free to correct me if I'm
> > wrong here... I assumed it would be the same as vendor-sec).

On Thu, Feb 21, 2008 at 05:12:15PM -0500, Josh Bressers wrote:
> Steve,
> I think this is a good opportunity to ask you how we can use this list to
> make your life easier.  Perhaps it's worth thinking about ways some of the
> subscribed CNAs can dish out CVE ids to reduce your load a little bit for
> these public issues that obviously lack a proper id.

IIRC, Steve's reason for not being on vendor-sec was that he did not
want to be exposed to more non-public security issues (and detailed info
on them) than is necessary for assigning CVE ids.  If so, this reason
does not apply for oss-security, because this is a public list.  Steve -
you're welcome to join us on oss-security, although this is, of course,
up to you. :-)



Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.