Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Thu, 27 Apr 2017 11:46:49 -0400
From: Kash Pande <kash@...pleback.net>
To: oss-security@...ts.openwall.com
Subject: Re: MITRE is adding data intake to its CVE ID process


On 27/04/17 11:31 AM, Solar Designer wrote:
> I am a bit concerned that MITRE's change may
> result in us getting notified in fewer cases, especially if we continue
> to redirect to MITRE those CVE requests that still arrive in here.  This
> is going to result in not only fewer CVE requests sent in here, but also
> in fewer vulnerabilities being disclosed in here - or at least in them
> being brought in here with an extra delay (after MITRE has assigned a
> CVE ID and reminded the person that they should notify oss-security,
> which thankfully they do).

I share with you these concerns, thank you for articulating them.


Kash Pande

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.