Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Date: Fri, 11 Mar 2016 11:49:15 +0800
From: Paul Wise <>
To: oss-security <>, cve <>
Subject: debbugs for

Hi all,

I would like to suggest using debbugs for

debbugs is based on email so it is the lowest friction for researchers
and doesn't change their workflow except they now get an immediate CVE
after sending a detailed report to the submission address.

The Debian project doesn't have much of a problem with spam other than
spammers occasionally harvesting bug email addresses and replying to
them. This could be mitigated by not putting bug number email addresses
on the bug reports. Debian does that for transparency though. Spammers
haven't learnt to file bug reports yet though.

One thing that would need adding is support for private bugs and
authenticated commands to change bugs between public and private.

One other thing that would need adding is some support for the CVE ID
syntax. Nice URLs could be provided by mod_rewrite.

debbugs is also used by the GNU project.


Download attachment "signature.asc" of type "application/pgp-signature" (802 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.