Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Sat, 16 Sep 2017 21:05:44 +0200
From: Solar Designer <>
To: Alexander Batischev <>
Subject: Re: Podbeuter podcast fetcher: remote code execution

On Sat, Sep 16, 2017 at 09:05:18PM +0300, Alexander Batischev wrote:
> I've requested a CVE from MITRE on August 27th, but haven't heard back 
> yet, so decided to disclose without a number.

Thanks.  Going forward, please report relevant issues in here right
away, without waiting on MITRE.  We previously had these guidelines in a
footnote, but I've just upgraded them to their own section here:

"Previously, one could request CVE IDs for issues in Open Source
software from oss-security.  This is no longer the case.  Instead, please
start by posting about the (to be made) public issue to oss-security
(without a CVE ID), request a CVE ID from MITRE directly, and finally
"reply" to your own posting when you also have the CVE ID to add.  With
the described approach you would only approach MITRE after the issue is
already public, but if you choose to do things differently and contact
MITRE about an issue that is not yet public, then please do not disclose
to them more than the absolute minimum needed for them to assign a CVE ID."

with links to:


Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.