oss-sec mailing list archives
Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies
From: Markus Vervier <markus.vervier () x41-dsec de>
Date: Mon, 7 Mar 2016 09:10:46 +0100
On 03/04/2016 07:24 PM, Kurt Seifried wrote:
So I've now heard from several security researchers that they are unable to get CVEs for issues that need CVEs (e.g. widely used hardware/software with flaws that have real world impacts and need to be properly tracked. This has definitely resulted in issues being publicized with no CVE that then makes it much harder to track and deal with these issues.
Hi, just in order to second that: We have had similar experience with delays and with rejections that seemed random. Especially regarding vulnerabilities that did not fit into existing vulnerability classes or would require some amount of work to validate. It seems to me MITRE currently wants to improve CVE quality but does not have the resources to do a real and fair validation. In my mind having a globally accepted enumeration systems and unique vulnerability identifiers is more important than a small curated but outdated list of selected vulnerabilities. Therefore I would appreciate to move back to the old process where you would request a CVE, get it assigned - but with the possibility of revocation later. Or move to a fully automated process like OVE as proposed here before. Markus -- Markus Vervier (Managing Director) X41 D-SEC GmbH, Dennewartstr. 25-27, D-52068 Aachen Unternehmenssitz: Aachen, Amtsgericht Aachen: HRB19989 Geschäftsführer: Markus Vervier
Attachment:
smime.p7s
Description: S/MIME Cryptographic Signature
Current thread:
- Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies, (continued)
- Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies Reed Loden (Mar 09)
- Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies Timothy D. Morgan (Mar 09)
- Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies Kurt Seifried (Mar 09)
- Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies Timothy D. Morgan (Mar 10)
- Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies Kurt Seifried (Mar 10)
- Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies Tim (Mar 10)
- Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies Zach W. (Mar 10)
- Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies Kurt Seifried (Mar 10)
- Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies halfdog (Mar 10)
- Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies Carlos Alberto Lopez Perez (Mar 11)
- Re: Concerns about CVE coverage shrinking - direct impact to researchers/companies Kurt Seifried (Mar 11)