|
Message-ID: <Z5Q9VKUg_v3MBrmh@aeon>
Date: Sat, 25 Jan 2025 01:24:36 +0000
From: Mark Esler <mark.esler@...onical.com>
To: oss-security@...ts.openwall.com
Subject: Re: issue with stuck Mitre CVE requests
On Wed, Jan 22, 2025 at 03:18:10PM +0100, Johannes Segitz wrote:
> We're not empowered to do this. We are a CNA for code that we own (e.g.
> zypper), but not for arbitrary open source projects.
The text of SUSE's scope [0] is similar to Canonical's [1]. We
understand "All Canonical issues (including Ubuntu Linux) only" as
including all software we distribute. It does not require us to be the
author of that code.
Mark
[0] https://www.cve.org/PartnerInformation/ListofPartners/partner/canonical
[1] https://www.cve.org/PartnerInformation/ListofPartners/partner/suse
Download attachment "signature.asc" of type "application/pgp-signature" (834 bytes)
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.