oss-sec mailing list archives

Re: CVE REJECT noise


From: David Walser <luigiwalser () yahoo com>
Date: Wed, 19 Aug 2015 21:59:01 +0000 (UTC)

Solar Designer <solar@...> writes:
Can we please agree that CVE REJECT postings such as those Kurt has been
occasionally making in here for a while are not to be made anymore?

I am fine with postings that talk in some detail about issues that are
already public and also mention that a CVE ID should be rejected.  I am
not fine with postings the only purpose of which is to announce that a
CVE ID is being rejected, especially if those postings fail to mention
the product and the vulnerability.

If there's no likelihood that any open-source software vendor has already
used the rejected CVE in an existing advisory (or a pending one), then these
posts are useless.  As the security team leader for the Mageia distribution,
I always check our Bugzilla when Kurt sends these posts to see if we've used
the CVE(s) in question, and I cannot recall a case where I've ever found that
we had.  It would be a lot more helpful if he would state at least the
software that the CVE was associated with; it drives me crazy when he does
not.  If he's not able to give this information, then it's very unlikely that
anyone has already used the CVE.  If he is able to give at least the software,
then it *might* be helpful to someone.  So, long story short, I agree with
Solar Designer.


Current thread: