oss-sec mailing list archives

Re: Contributing Back


From: Daniel Stenberg <daniel () haxx se>
Date: Thu, 2 Jul 2020 13:34:03 +0200 (CEST)

On Thu, 2 Jul 2020, Francis Perron wrote:

this delay may be possible due to many things, but the simplest possibility that comes to mind is that Daniel (here cc'd) from H1 has only gotten a reservation of CVE number, and he and MITRE have not triggered the submission yet.

In the curl project we (nowadays) request and get CVE IDs from Hackerone, and we've subsequently told them to publish these two recent curl related CVE IDs when we made them public to the world - I suspect this is just them being a little slow. We don't have any direct contact with MITRE.

All details regarding the two recent curl flaws are here:

 https://curl.haxx.se/docs/CVE-2020-8169.html
 https://curl.haxx.se/docs/CVE-2020-8177.html

--

 / daniel.haxx.se


Current thread: