Re: Contributing Back

Related Vulnerabilities: CVE-2020-8169   CVE-2020-8177  
                							

                <!--X-Body-Begin-->
<!--X-User-Header-->

oss-sec
mailing list archives
<!--X-User-Header-End-->
<!--X-TopPNI-->

By Date

By Thread

</form>

<!--X-TopPNI-End-->
<!--X-MsgBody-->
<!--X-Subject-Header-Begin-->
Re: Contributing Back

<!--X-Subject-Header-End-->
<!--X-Head-of-Message-->

From: Zhang Xiao &lt;xiao.zhang () windriver com&gt;

Date: Fri, 3 Jul 2020 10:06:55 +0800

<!--X-Head-of-Message-End-->
<!--X-Head-Body-Sep-Begin-->

<!--X-Head-Body-Sep-End-->
<!--X-Body-of-Message-->
I haven't remind MITRE before. While they have an interface to make it:

https://cve.mitre.org/about/contactus.html

See the forth topic called "*To notify us about a vulnerability
publication*". I just remind them about CVE-2020-8169 and&nbsp; CVE-2020-8177
with it. Hope it works. :-)

I will check the status of them on CVE/NVD website these days.

Thanks

Xiao

在 2020/7/2 下午7:34, Daniel Stenberg 写道:
On Thu, 2 Jul 2020, Francis Perron wrote:

&nbsp;this delay may be possible due to many things, but the simplest
possibility that comes to mind is that Daniel (here cc'd) from H1 has
only gotten a reservation of CVE number, and he and MITRE have not
triggered the submission yet.

In the curl project we (nowadays) request and get CVE IDs from
Hackerone, and we've subsequently told them to publish these two
recent curl related CVE IDs when we made them public to the world - I
suspect this is just them being a little slow. We don't have any
direct contact with MITRE.

All details regarding the two recent curl flaws are here:

&nbsp;https://curl.haxx.se/docs/CVE-2020-8169.html
&nbsp;https://curl.haxx.se/docs/CVE-2020-8177.html

Attachment:
pEpkey.asc
Description: 

<!--X-Body-of-Message-End-->
<!--X-MsgBody-End-->
<!--X-Follow-Ups-->

<!--X-Follow-Ups-End-->
<!--X-References-->
<!--X-References-End-->
<!--X-BotPNI-->

By Date

By Thread

Current thread:

Contributing Back Zhang Xiao (Jul 02)

Re: Contributing Back Francis Perron (Jul 02)

Re: Contributing Back Daniel Stenberg (Jul 02)

Re: Contributing Back Zhang Xiao (Jul 02)

Re: Contributing Back Solar Designer (Jul 11)

Re: Contributing Back Zhang Xiao (Jul 13)

Re: Contributing Back Solar Designer (Jul 20)
Re: Contributing Back Mohammad Tausif Siddiqui (Jul 23)
Re: Contributing Back Zhang Xiao (Jul 23)

Re: Contributing Back Solar Designer (Jul 23)
Re: Contributing Back Zhang Xiao (Jul 28)

&lt;Possible follow-ups&gt;
Re: Contributing Back Solar Designer (Sep 03)

Re: Contributing Back Seth Arnold (Sep 03)

Re: Contributing Back Vincent Batts (Sep 09)

 

<!--X-BotPNI-End-->
<!--X-User-Footer-->
<!--X-User-Footer-End-->