Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <d3992a258f5cf32230b873f133879054173e928c.camel@orlitzky.com>
Date: Wed, 14 Aug 2024 17:45:04 -0400
From: Michael Orlitzky <michael@...itzky.com>
To: oss-security@...ts.openwall.com
Subject: Re: Tracking down a lost CVE request (MITRE)

On Wed, 2024-08-14 at 15:55 -0500, Mark Esler wrote:
> MITRE is not required to assign CVEs.
> 
> It is always best to work with upstream (if possible). MITRE is more
> likely to respond if upstream replies to your email ticket ACKing the
> CVE request. Otherwise, you may want to ask Red Hat's CNA to assign a
> CVE [0].

Thanks, with some off-list help from Red Hat and MITRE I was able to
get this resolved and CVE-2024-43199 has been published.

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.