oss-sec mailing list archives

Re: using oss-security references in CVE


From: Lubomir Kundrak <lkundrak () redhat com>
Date: Fri, 28 Mar 2008 00:09:46 +0100


On Thu, 2008-03-27 at 18:59 -0400, Steven M. Christey wrote:
All,

In CVE, we try to provide "provenance" for every detail that makes its way
into the description.  Issues like rxvt and CenterIM have some details
that are only publicly documented in oss-security, and I would like to add
these as references.

I agree. There shouldn't really be things like more public and less
public places to share security-related information.

-- 
Lubomir Kundrak (Red Hat Security Response Team)



Current thread: