|
Message-ID: <4F61F9E9.9040003@gmail.com> Date: Thu, 15 Mar 2012 10:17:13 -0400 From: Dan Rosenberg <dan.j.rosenberg@...il.com> To: security@...roid.com, cve@...re.org CC: "Steven M. Christey" <coley@...us.mitre.org>, oss-security@...ts.openwall.com Subject: Android CVE identifiers Hi Android Security Team and CVE folks, The assignment of CVE identifiers to Android security issues appears to be sporadic at best, because to my knowledge none of the major Android OEMs (HTC, Motorola, Samsung, LG) assign CVEs to Android security issues affecting their builds or publish any information about this. Is there any official policy followed by the Android security team on assigning CVE identifiers to OEM-specific vulnerabilities? If it would be helpful to anyone, I have a detailed list of about 20 local privilege escalation vulnerabilities that have been patched in the last year or two, most of which affect specific devices. If there is interest in assigning CVEs to these issues, I can follow up with a formal CVE request. Additionally, there are at least a few Google-authored vulnerabilities that are missing identifiers. Regards, Dan
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.