oss-sec mailing list archives
Android CVE identifiers
From: Dan Rosenberg <dan.j.rosenberg () gmail com>
Date: Thu, 15 Mar 2012 10:17:13 -0400
Hi Android Security Team and CVE folks, The assignment of CVE identifiers to Android security issues appears to be sporadic at best, because to my knowledge none of the major Android OEMs (HTC, Motorola, Samsung, LG) assign CVEs to Android security issues affecting their builds or publish any information about this. Is there any official policy followed by the Android security team on assigning CVE identifiers to OEM-specific vulnerabilities? If it would be helpful to anyone, I have a detailed list of about 20 local privilege escalation vulnerabilities that have been patched in the last year or two, most of which affect specific devices. If there is interest in assigning CVEs to these issues, I can follow up with a formal CVE request. Additionally, there are at least a few Google-authored vulnerabilities that are missing identifiers. Regards, Dan
Current thread:
- Android CVE identifiers Dan Rosenberg (Mar 15)