Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Fri, 16 Mar 2012 14:41:38 -0400
From: Mark Stanislav <mark.stanislav@...il.com>
To: Tim Brown <tmb@...35.com>
Cc: oss-security@...ts.openwall.com, 
	"Adam D. Barratt" <adam@...m-barratt.org.uk>, Kurt Seifried <kseifried@...hat.com>
Subject: Re: CVE Requests

On Fri, Mar 16, 2012 at 2:37 PM, Tim Brown <tmb@...35.com> wrote:

> On Friday 16 Mar 2012 16:11:04 Mark Stanislav wrote:
> > All points being made are very much valid and I certainly understand how
> > contextually oss-sec may be used to allocation requests under different
> > circumstances.
> >
> > So here's my situation, I'm up for suggestions (of which, "wait longer",
> is
> > perfectly viable!)...
> >
> > 1) March 1st, I sent 2 of these CVEs over to Steve Christy at MITRE who
> had
> > previously allocated 9 prior CVEs in a day or two generally
> > 2) March 8th, after not hearing back from Steve, I contacted
> > cve@...redirectly with all 5
> > 3) March 15th, after not hearing back from MITRE, I contacted Kurt off
> list
> > as I've noted his helpfulness doing allocations
> > 3a) Kurt pointed me to email the list, rather than him directly (which is
> > perfectly fine, but perhaps not the context I was aiming for initially)
>
> Josh Bressers (Josh, correct me if I'm using your name in vain) used to be
> quite happy to assign CVEs for undisclosed (embargoed) F/OSS issues
> providing
> details were forthcoming with the request.   If Josh is no longer able to
> fulfil that role due to a change of circumstance at Redhat it would be
> nice if
> someone stepped into the breach -  be that Redhat, Debian or one of the
> other
> CNAs.  There is definately a place for "disclosed to project, being/been
> fixed,
> not public - can I have a CVE?" without deferring to the distros list or
> MITRE
> - most of the time projects can respond in a timely fashion, so a minimum
> effort approach is ideal.
>
> As an aside, the public address for MITRE on the web site is wrong AFAIK.
> Quoting Steve Christey:
>
> "Apologies for the delay.  In the future, please use cve-assign@...re.org
> for requests related to CVE reservation."
>

Thank you, Tim. I've forwarded them over to that address instead.

-Mark


>
> From last time I went to MITRE (for a closed source product).
>
> Tim
> --
> Tim Brown
> <mailto:tmb@...35.com>
>

Powered by blists - more mailing lists

Your e-mail address:

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.