oss-sec mailing list archives

On anonymous CVE assignments


From: Lior Kaplan <kaplanlior () gmail com>
Date: Fri, 8 Jul 2016 15:39:03 +0200

Hi,

I'm sorry for sending this to the cve-assign mail, but I think this is
important to how CVE assignment process should work and the importance of
cooperating with the upstream projects.

In the past year+ I've been dealing with CVE assignment and the PHP
project. During this period we managed to work closer with the Linux
distributions and also to improve the internal process regarding CVE
requests.

I've blogged about a recent problem I encountered with is request and
assignment of CVE for issues almost a year old without any public info
about this ("anonymous requests"). Meaning that me, being part of upstream
(incl. the security team), don't even know we've got CVE assigned and can
update things on our side (and also other relevant upstreams such as libgd).

More details at
https://liorkaplan.wordpress.com/2016/07/07/anonymous-cve-requests/

I'll be happy to be referred to the right forum to further discuss this.
Till then, I hope you'll take these remakes into consideration, so the
whole eco system could work more smoothly.

Kaplan
The PHP project

Current thread: