oss-sec mailing list archives

Re: using oss-security references in CVE

From: Lubomir Kundrak <lkundrak () redhat com>
Date: Fri, 28 Mar 2008 00:09:46 +0100

On Thu, 2008-03-27 at 18:59 -0400, Steven M. Christey wrote:

In CVE, we try to provide "provenance" for every detail that makes its way
into the description.  Issues like rxvt and CenterIM have some details
that are only publicly documented in oss-security, and I would like to add
these as references.

I agree. There shouldn't really be things like more public and less
public places to share security-related information.

Lubomir Kundrak (Red Hat Security Response Team)

Current thread: