oss-sec mailing list archives
Re: CVE Requests
From: Mark Stanislav <mark.stanislav () gmail com>
Date: Fri, 16 Mar 2012 14:30:35 -0400
On Fri, Mar 16, 2012 at 1:46 PM, Kurt Seifried <kseifried () redhat com> wrote:
On 03/16/2012 09:53 AM, Solar Designer wrote:On Fri, Mar 16, 2012 at 12:20:37AM -0400, Mark Stanislav wrote:None of the details of these issues have been publicly discussed orreleased as I am trying (without much success) to allocate a CVE prior to sending out a coordinated advisory including that identifier as I always have done and as the mitre site indicates to do.There are no reference links to provide and I am not publicizingdetails on this list before the developer can be informed of the CVE.I'm happy to take this off list as I am sure no one cares about any ofthis discussion In which case you can ask for them on VS@ list where the issue will remain embargoed. If the issue is so sensitive you cannot leak details/etc then you need to contact Mitre directly (this will also ensure no duplicates/etc.).
Is "VS@" supposed to be vendor-sec; the defunct list? Or is there another list I am not aware of? If so, can you please give me the *full* address? Thanks.
No, please keep this on the list. Discussions on how to handle vulnerability disclosure (including the CVE ID assignment step) are definitely on topic for oss-security.Yes and I need to finish documenting this stuff (it's become obvious we need to educate people on how the system works and why it works that way, we're not insane, we have good reasons for doing it the way we do, honest =).
I'd say you may want to coordinate that documentation with Steve Christy as the nine times he allocated CVEs for me directly, this sort of conversation never came up. I can understand frustration on your part that people may not be educated, but realize that if CNAs handle this process differently, it may not be a matter of education on how 'the system works' but rather consistency within the entire process, agnostic of whom is allocating a CVE. I again, do appreciate your time but I suppose I'll just wait for Steve or whomever is manning cve@mitre to contact me back. Best, -Mark
Thanks, Alexander (a moderator for oss-security)-- Kurt Seifried Red Hat Security Response Team (SRT)
Current thread:
- CVE Requests Mark Stanislav (Mar 15)
- Re: CVE Requests Kurt Seifried (Mar 15)
- Re: CVE Requests Mark Stanislav (Mar 15)
- Re: CVE Requests Kurt Seifried (Mar 15)
- Re: CVE Requests Mark Stanislav (Mar 15)
- Re: CVE Requests Kurt Seifried (Mar 15)
- Re: CVE Requests Mark Stanislav (Mar 15)
- Re: CVE Requests Solar Designer (Mar 16)
- Re: CVE Requests Kurt Seifried (Mar 16)
- Re: CVE Requests Mark Stanislav (Mar 16)
- Re: CVE Requests Kurt Seifried (Mar 16)
- Re: CVE Requests Mark Stanislav (Mar 15)
- Re: CVE Requests Kurt Seifried (Mar 15)
- Re: CVE Requests Andreas Ericsson (Mar 16)
- Re: CVE Requests Adam D. Barratt (Mar 16)
- Re: CVE Requests Mark Stanislav (Mar 16)
- Re: CVE Requests Tim Brown (Mar 16)
- Re: CVE Requests Mark Stanislav (Mar 16)
- Re: CVE Requests Kurt Seifried (Mar 16)
- Re: CVE Requests Tim Brown (Mar 16)
- Re: CVE Requests Eugene Teo (Mar 18)
- Re: CVE Requests Kurt Seifried (Mar 16)