oss-sec mailing list archives
Re: CVE id request: busybox
From: Kurt Seifried <kseifried () redhat com>
Date: Tue, 05 Mar 2013 11:20:44 -0700
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On 03/05/2013 06:30 AM, Raphael Geissert wrote:
Hi Kurt, On 4 March 2013 03:26, Kurt Seifried <kseifried () redhat com> wrote: [...]I didn't say I;'m excluding them. I simply will require an original source, in this case the year is probably wrong.Not bikeshedding here, but sometimes those bug reports *are* the original source. And with all due respect, it has happened before that you've asked for an "original source" (upstream commit or bug report) when there exists none. All it has lead is to the CVE request becoming stalled or even abandoned.
Then say so. Basically I don't want people making lazy requests and forcing me to do the basic research.
What can we do about it? We already have a quite long list of issues without a CVE id and this is not good for anybody: https://security-tracker.debian.org/tracker/data/fake-names
So research them and post the requests here, problem solved! It's not like I'm unwilling to give out CVEs or something. I simply can't spend an hour researching each one.
(nb. some of the issues in the list might already have an id but the temporary entry hasn't been removed or it was decided that no id should be assigned)
And that's why I'm not going to deal with them myself, it would eat up all my time. I need some help here in other words.
Regards,
- -- Kurt Seifried Red Hat Security Response Team (SRT) PGP: 0x5E267993 A90B F995 7350 148F 66BF 7554 160D 4553 5E26 7993 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.13 (GNU/Linux) iQIcBAEBAgAGBQJRNjd8AAoJEBYNRVNeJnmTVGYQAKFMMAYOE7ruEg1stN7tzAQs 7tDDLCam7a8j2AHGBVogmI4I6ADfRwcqwjNBv7DOv63AQZbkw+OiVGbPADMGlKDP 8ZIdiwZvt2Z6OBprH6k0vVMGpSF9aQcirDF0qdXplGjo8sxiyXG8S8YZy0/b/y7Q QJo5qezE5+5djiG9EGNQi97VnARo514eZGLqdo8kWE2FHV+js64oSkUcH5Veu02C NAQRQziKZNpWf3ZCVZ4ByOEigbSuy8198lFqCjB3XoXrEIYk+eT2g1Fx41KdToQk ZLQ5mfAqWN/9wMLBRPRcMnojNFMHaOhCZ1AULcQyAsngu36hmvAPwFidVsDJTBwG M9UANh5Lq9Mkwu4zqF43/v3raen2Y1vQcFa7YBneHoXxtZQEDFHhK+QiZFHhLaMe TBmiuzu+N+WAhPtrGYd23BQRrOytepuFzjG2NFbxYiao8fYgFZ0rB+4Yn/W9b7t/ kCmfJttKVPwgtoS6+Oj4a/FrgVhMiWrcjonv6njxleiWvS6gsziChp4+pp+grEr3 ygFgogDtJgC2/yKlwV/ycz4rG2iiAHqkHXmebn21Nwfsxr3WnaVYQd8sJ3eOyczI pi49oU1L98678JlopgvifZhut803cqIH5sFT8hZvNIgVPH+eUfqvAGH1tI2q8ewN eA3Gc1vXdzMF19rRFlEL =b60Q -----END PGP SIGNATURE-----
Current thread:
- Re: CVE id request: busybox, (continued)
- Re: CVE id request: busybox gremlin (Mar 03)
- Re: CVE id request: busybox Michael Tokarev (Mar 03)
- Re: CVE id request: busybox Piotr Karbowski (Mar 03)
- Re: CVE id request: busybox Michael Tokarev (Mar 03)
- Re: CVE id request: busybox Kurt Seifried (Mar 03)
- Re: CVE id request: busybox Michael Gilbert (Mar 03)
- Re: CVE id request: busybox Kurt Seifried (Mar 03)
- Re: CVE id request: busybox Thomas Biege (Mar 05)
- Re: CVE id request: busybox Thomas Biege (Mar 05)
- Re: CVE id request: busybox Raphael Geissert (Mar 05)
- Re: CVE id request: busybox Kurt Seifried (Mar 05)
- Re: CVE id request: busybox Raphael Geissert (Mar 06)
- Re: CVE id request: busybox gremlin (Mar 03)