oss-sec mailing list archives

debbugs for cve-assign () mitre org?


From: Paul Wise <pabs3 () bonedaddy net>
Date: Fri, 11 Mar 2016 11:49:15 +0800

Hi all,

I would like to suggest using debbugs for cve-assign () mitre org.

debbugs is based on email so it is the lowest friction for researchers
and doesn't change their workflow except they now get an immediate CVE
after sending a detailed report to the submission address.

The Debian project doesn't have much of a problem with spam other than
spammers occasionally harvesting bug email addresses and replying to
them. This could be mitigated by not putting bug number email addresses
on the bug reports. Debian does that for transparency though. Spammers
haven't learnt to file bug reports yet though.

One thing that would need adding is support for private bugs and
authenticated commands to change bugs between public and private.

One other thing that would need adding is some support for the CVE ID
syntax. Nice URLs could be provided by mod_rewrite.

debbugs is also used by the GNU project.

-- 
bye,
pabs

http://bonedaddy.net/pabs3/

Attachment: signature.asc
Description: This is a digitally signed message part


Current thread: