[ Date Prev ][ Date Next ][ Thread Prev ][ Thread Next ][ Date Index ][ Thread Index ]

Re: what text is being sent to researchers re: OSS assignments?



Couple points of reference....

https://cve.mitre.org/cve/data_sources_product_coverage.html#products
https://cve.mitre.org/cve/cna.html

---
Kent Landfield
+1.817.637.8026

On 12/19/16, 8:13 AM, "owner-cve-editorial-board-list@lists.mitre.org
on behalf of Landfield, Kent B"
<owner-cve-editorial-board-list@lists.mitre.org on behalf of
kent.b.landfield@intel.com> wrote:

    Can we please post this to the appropriate place? If you have an
issue with this decision that the Board actively discussed, please as
the question there.  There is no reason to cross-post every message to
both lists.  This was a swim lane issue discussed by the Board and also
discussed at the face-to-face meeting we had in Rockville, MD in
November.

    ---
    Kent Landfield
    +1.817.637.8026

    On 12/18/16, 8:44 PM, "owner-cve-cna-list@lists.mitre.org on behalf
of jericho" <owner-cve-cna-list@lists.mitre.org on behalf of
jericho@attrition.org> wrote:

        Reference:


https://www.stevencampbell.info/2016/12/my-first-cve-2016-1000329-in-blogphp/

            I submitted my CVE request through Mitre who notified me
that open
            source software CVE requests are now processed via the
Distributed
            Weakness Filing before being sent to Mitre for inclusion in
their
            database.

        This creates an obvious disconnect and potentially duplicate
assignments
        and confusion, if researchers are being told to go to DWF for
*all* OSS
        assignments. For example, Apache is a CNA and has many OSS
projects, but
        vulnerabilities in their software should go to them, not DWF.
Could MITRE
        share the text that is being sent out currently?

        .b





Page Last Updated or Reviewed: December 19, 2016