|
Message-ID: <Z5DF00lM-3Q36mhh@kasco.suse.de>
Date: Wed, 22 Jan 2025 11:17:54 +0100
From: Matthias Gerstner <mgerstner@...e.de>
To: oss-security@...ts.openwall.com
Subject: issue with stuck Mitre CVE requests
Hello list,
I am currently experiencing for the second time that a CVE request
submitted via the Mitre web form [1] is not receiving a response. A
similar topic was already shortly discussed in the past [2].
I requested two CVEs on Jan 13. One got assigned within 24 hours, for
the other one I still didn't receive a reply. The same happened to me in
April 2024. Back then, after not receiving a reply for over two weeks,
the CVE has been assigned by Red Hat instead, since Red Hat developers
have been involved in the affected project.
In this instance upstream is not a CNA and it is also not closely
involved with Red Hat. Replying to the automatic CVE request mail from
Mitre does not seem to reach any human being. I don't know of any other
way to get attention from Mitre for this request.
I wonder what is the best way to recover from such a situation without
risking duplicate CVE assignments, or not assigning a CVE at all.
I have a hunch that the issue might have to do with filling out the "PGP
Key" field in the CVE request form, which I did for the one request that
has not been answered, but not for the other, which got assigned right
away.
Thanks
Matthias
[1]: https://cveform.mitre.org/
[2]: https://www.openwall.com/lists/oss-security/2024/08/06/3
--
Matthias Gerstner <matthias.gerstner@...e.de>
Security Engineer
https://www.suse.com/security
GPG Key ID: 0x14C405C971923553
SUSE Software Solutions Germany GmbH
HRB 36809, AG Nürnberg
Geschäftsführer: Ivo Totev, Andrew McDonald, Werner Knoblich
Download attachment "signature.asc" of type "application/pgp-signature" (834 bytes)
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.