Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Fri, 16 Mar 2012 16:40:18 -0600
From: Greg Knaddison <greg.knaddison@...uia.com>
To: security@...pal.org, Kurt Seifried <kseifried@...hat.com>
Cc: "oss-security@...ts.openwall.com" <oss-security@...ts.openwall.com>
Subject: Re: [security] Drupal CORE and Drupal Contrib

Hi Kurt,

We started considering associating CVEs with our Security Advisories
(SAs) in September of 2011. At the time we discussed it with Josh
Bressers, Jan Lieskovsky, Steven M. Christey and decided that it would
only be practical to do it for Drupal core for now and we could
considering doing it for contrib in the future. Since that discussion
there has only been one SA for Drupal core which I think has the CVEs
on it: SA-CORE-2012-001 - Drupal core multiple vulnerabilities -
http://drupal.org/node/1425084

Is there another SA for core that I'm not considering? Is there a
better way to list the CVE numbers?

There have been several SAs for contributed modules and we would
gladly update them with CVEs. If you can send an email with a link to
the SA and the CVE-id to use that would be great.

Our biggest problem with trying to integrate CVE values to the SAs for
contributed modules is that the contributed projects are all run by
individual volunteers and we don't reliably know the date we are going
to release those. My understanding is that we can ask for a 2 week
embargo on CVE requests and that would work most of the time but not
all. We're working to improve the predictability of this process, but
I think it's too early to consider getting CVE's in advance.

Thanks,
Greg

On Fri, Mar 16, 2012 at 11:51 AM, Kurt Seifried <kseifried@...hat.com> wrote:
> I was going to ask this next week but now seems topical: looking at
> http://drupal.org/security/contrib
>
> I see drupal core (at least one thing there needs a CVE), and no CVE's
> listed on that page. Would it be possible to get Drupal to list CVE's
> assigned for the issue on that page? It would make life easier for all
> concerned.
>
> Ditto for the contrib page, 41 issues so far this year, I think a bunch
> have CVE's assigned but am not sure. Would it be possible to get Drupal
> to list CVE's assigned for the issue on that page? It would make life
> easier for all concerned.
>
> I was planning to do a missing CVE assignment for Drupal this weekend
> (I'm guessing 40?).
>
>
> --
> Kurt Seifried Red Hat Security Response Team (SRT)
> --
> [ Security | http://lists.drupal.org/mailman/listinfo/security ]
> [Security team mailing list management and scheduling is documented here | https://security.drupal.org/handling-list-emails]



-- 
Director Security Services | +1-720-310-5623
Skype: greg.knaddison | http://twitter.com/greggleshttp://acquia.com

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.