oss-sec mailing list archives
Re: MITRE is adding data intake to its CVE ID process
From: Solar Designer <solar () openwall com>
Date: Thu, 16 Feb 2017 21:16:16 +0100
On Thu, Feb 16, 2017 at 03:16:45PM -0200, Fabio Olive Leite wrote:
On 02/11/2017 09:35 PM, Solar Designer wrote:C5. I want MITRE to send the https://cveform.mitre.org form data, and the CVE ID, to the oss-security list at the same time that these are sent to the requester. R5. We have had internal discussions within MITRE about this. We are able to implement this easily if the community requires this approach. At the moment, we are expecting the requester to resend this information to oss-security once they accept their CVE ID assignment.MITRE - can you please implement that, and we'll see how it goes and whether we need it adjusted or possibly discontinued if things go wrong or if there's opposition (so far, there's almost none)?Was there any response from Mitre to this request? I believe a lot of people would feel better if they confirmed they will do it.
I saw no response from MITRE. Kurt, who is not with MITRE but who presumably knows what he's saying, implied it'd be non-trivial for MITRE to separate issues in open source vs. other software: http://www.openwall.com/lists/oss-security/2017/02/12/2 "We could also have the MITRE CVE ID feed new stuff into oss-security but it would include non open source stuff." MITRE - is this difficulty the reason for the lack of response so far? If so, should we consider workarounds such as setting up another mailing list to which all assigned CVE IDs would be posted? Alexander
Current thread:
- Re: MITRE is adding data intake to its CVE ID process, (continued)
- Re: MITRE is adding data intake to its CVE ID process Tim (Feb 10)
- Re: MITRE is adding data intake to its CVE ID process Guido Berhoerster (Feb 10)
- Re: MITRE is adding data intake to its CVE ID process cve-assign (Feb 10)
- Re: MITRE is adding data intake to its CVE ID process Solar Designer (Feb 11)
- Re: MITRE is adding data intake to its CVE ID process Kurt Seifried (Feb 12)
- Re: MITRE is adding data intake to its CVE ID process Ian Zimmerman (Feb 13)
- Re: MITRE is adding data intake to its CVE ID process Ian Zimmerman (Feb 13)
- Re: Re: MITRE is adding data intake to its CVE ID process Kurt Seifried (Feb 13)
- Re: MITRE is adding data intake to its CVE ID process Solar Designer (Feb 11)
- Re: MITRE is adding data intake to its CVE ID process Raphael Geissert (Feb 15)
- Re: MITRE is adding data intake to its CVE ID process Fabio Olive Leite (Feb 16)
- Re: MITRE is adding data intake to its CVE ID process Solar Designer (Feb 16)
- RE: MITRE is adding data intake to its CVE ID process Maier, Kurt H (Feb 13)
- Re: MITRE is adding data intake to its CVE ID process Henri Salo (Feb 15)