oss-sec mailing list archives

Re: How to request a CVE for open source projects


From: Kurt H Maier <khm () sciops net>
Date: Mon, 22 May 2017 12:45:26 -0700

On Mon, May 22, 2017 at 08:57:21PM +0200, Marcus Meissner wrote:

Please everyone do the distributors a favour and link to GIT commits with fixes for
the requested CVE or at least explicit single reproducers, as we have increasing trouble
of associating CVEs with the correct place in code.

This is only gonna get worse now that mitre cut the mailing list out of
the process, and third-party participants can no longer add commentary
and insight into the reported vulnerabilities.

khm


Current thread: