oss-sec mailing list archives

Re: MITRE is adding data intake to its CVE ID process


From: "Steven R. Loomis" <srl () icu-project org>
Date: Thu, 9 Feb 2017 08:07:49 -0800

On 2/9/17 6:54 AM, Peter Bex wrote:
In an ideal world, free software project leaders should be
able to request a CVE ID _before_ announcing a vulnerability to their
user base.  If there were some way to register people as project leaders,
the "proof" should not be necessary, they should be able to request a
CVE ID with authority.
Peter,
 I actually wondered about this very thing, if it was possible to
request an ID before the details were fully available. From your note,
it sounds like this is not the case currently.

Steven

Attachment: signature.asc
Description: OpenPGP digital signature


Current thread: