oss-sec mailing list archives

Android CVE identifiers


From: Dan Rosenberg <dan.j.rosenberg () gmail com>
Date: Thu, 15 Mar 2012 10:17:13 -0400

Hi Android Security Team and CVE folks,

The assignment of CVE identifiers to Android security issues appears to
be sporadic at best, because to my knowledge none of the major Android
OEMs (HTC, Motorola, Samsung, LG) assign CVEs to Android security issues
affecting their builds or publish any information about this.  Is there
any official policy followed by the Android security team on assigning
CVE identifiers to OEM-specific vulnerabilities?

If it would be helpful to anyone, I have a detailed list of about 20
local privilege escalation vulnerabilities that have been patched in the
last year or two, most of which affect specific devices.  If there is
interest in assigning CVEs to these issues, I can follow up with a
formal CVE request.  Additionally, there are at least a few
Google-authored vulnerabilities that are missing identifiers.

Regards,
Dan


Current thread: