Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <20260518100248.52b532c1.freebsd-listen@fabiankeil.de>
Date: Mon, 18 May 2026 10:02:48 +0200
From: Fabian Keil <freebsd-listen@...iankeil.de>
To: oss-security@...ts.openwall.com
Subject: Re: CVE request experience

Fabian Keil <freebsd-listen@...iankeil.de> wrote on 2021-01-31 at 13:13:29:

> Nick Tait <ntait@...hat.com> wrote on 2020-12-23:
> 
> > That is a rather poor experience Fabian, sorry! Took a look at that
> > incident number and no encrypted message appears on our end. I believe
> > you did actually send a message but not sure what went wrong. While I
> > can't directly help, did request the appropriate people follow up with
> > you.
> 
> Thanks a lot for your help, Nick.
> 
> I was contacted by someone from Red Hat Product Security
> on 2020-12-24 and received a CVE.
> 
> I replied and requested CVEs for the other issues fixed in
> Privoxy 3.0.29 but did not receive a reply yet. I just
> forwarded the request to <secalert@...hat.com>.

Privoxy 4.2.0, which is supposed to be released around 2026-05-30,
will contain fixes for two security issues that are currently
tracked as OVE-20260515-0001 and OVE-20260515-0002.

I tried to get two CVEs from Redhat yesterday by sending an encrypted
mail to the address above, which is still listed at [0], but so far only
received what looks like an automated response which claims that I
need an "Atlassian" account to "finish" the request.

For various reasons I don't want an "Atlassian" or any other account ...

Fabian

[0]: <https://access.redhat.com/security/team/contact/>

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.