oss-sec mailing list archives

Re: CVE request experience


From: Fabian Keil <freebsd-listen () fabiankeil de>
Date: Mon, 18 May 2026 10:02:48 +0200

Fabian Keil <freebsd-listen () fabiankeil de> wrote on 2021-01-31 at 13:13:29:

Nick Tait <ntait () redhat com> wrote on 2020-12-23:

That is a rather poor experience Fabian, sorry! Took a look at that
incident number and no encrypted message appears on our end. I believe
you did actually send a message but not sure what went wrong. While I
can't directly help, did request the appropriate people follow up with
you.

Thanks a lot for your help, Nick.

I was contacted by someone from Red Hat Product Security
on 2020-12-24 and received a CVE.

I replied and requested CVEs for the other issues fixed in
Privoxy 3.0.29 but did not receive a reply yet. I just
forwarded the request to <secalert () redhat com>.

Privoxy 4.2.0, which is supposed to be released around 2026-05-30,
will contain fixes for two security issues that are currently
tracked as OVE-20260515-0001 and OVE-20260515-0002.

I tried to get two CVEs from Redhat yesterday by sending an encrypted
mail to the address above, which is still listed at [0], but so far only
received what looks like an automated response which claims that I
need an "Atlassian" account to "finish" the request.

For various reasons I don't want an "Atlassian" or any other account ...

Fabian

[0]: <https://access.redhat.com/security/team/contact/>


Current thread: