oss-sec mailing list archives

Re: CVE Request - xlockmore 5.43 fixes a security flaw


From: mancha <mancha1 () hush com>
Date: Thu, 18 Jul 2013 10:20:26 +0000 (UTC)

Kurt Seifried <kseifried@...> writes:
I request some details, others like Drupal have security advisories that
are sufficiently detailed that i can assign based on them alone, so
until a CVE requester proves that they know what they are doing,
reliably, I'm going to need details to make sure the CVE assignment is
done correctly. Part of the issue is scale, I do 1000+ CVE assignments
a year, so if they start taking more then 5-10 minutes I won't have
time to do anything else (like my day job, or sleep).

Thank you for taking the time to provide such a detailed response.
What you say makes complete sense and helps me (and I assume list
onlookers) get a better feel for the process.

Best,

--mancha


Current thread: