Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <CAOfWR+FBYDFaMWnHSs6fVeJtSthbRYpPMQTSKHaYFjFZArFEpg@mail.gmail.com>
Date: Mon, 17 Jun 2019 01:28:04 -0400
From: Robert Watson <robertcwatson1@...il.com>
To: oss-security@...ts.openwall.com
Subject: Re: Thousands of vulnerabilities, almost no CVEs: OSS-Fuzz

So Mr Gayner, which of these bugs have you fixed?

On Sat, Jun 15, 2019, 11:50 Alex Gaynor <alex.gaynor@...il.com> wrote:

>
> Today I'd like to highlight what I see as a tremendous issue: very few of
> these security bugs ever has a CVE issued for it. This is probably due to a
> few factors, a) the relative difficulty of obtaining a CVE, b) the lack of
> a human reporter who is interested in obtaining one for "credit" purposes,
> c) the sheer number of bugs that we're talking about.
>

>

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.