security_fixes

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revisionBoth sides next revision
security_fixes [2015/12/14 07:57] stassecurity_fixes [2015/12/16 12:37] kaplan
Line 35: Line 35:
 ===== CVEs ===== ===== CVEs =====
  
-CVE handling procedures TBD. +CVE handling procedures TBD. 
 + 
 +Some useful info: 
 + 
 +Request a CVE Identifier - https://cve.mitre.org/cve/request_id.html 
 + 
 +Introduction to CVE Identifier Reservation 
 +The basic process is: 
 +  - There is a request for one or more CVE-ID number(s). 
 +  - MITRE reserves the CVE-ID number(s) and provides the number(s) to the requester, and creates "blank," content-free CVE(s) on the CVE Web site. 
 +  - The requester shares the CVE-ID number(s) with all parties involved in the disclosure. 
 +  - The requester includes the CVE-ID number(s) in the vulnerability advisory. 
 +  - The requester makes the CVE-ID(s) public and notifies MITRE. 
 +  - MITRE updates the CVE-ID(s) on the CVE Web site to provide the details. 
 + 
security_fixes.txt · Last modified: 2017/09/22 13:28 by 127.0.0.1