oss-sec mailing list archives

Re: Re: CVE's for SSLv2 support


From: Seth Arnold <seth.arnold () canonical com>
Date: Tue, 1 Mar 2016 12:31:38 -0800

On Tue, Mar 01, 2016 at 01:43:39PM -0500, cve-assign () mitre org wrote:
MITRE does not assign CVE IDs to track whether the universe of
products has similar or dissimilar time scales in adapting to
technology changes.

While I can appreciate that MITRE would be in an untenable position to
arbitrate trends on six-month timescales, SSLv2's replacement was released
nearly twenty years ago.

Please reconsider this position.

Thanks

Attachment: signature.asc
Description: Digital signature


Current thread: