oss-sec mailing list archives
Current CVE policy on missing-hardening bugs
From: Florian Weimer <fweimer () redhat com>
Date: Mon, 05 Aug 2019 13:36:54 +0200
What's the current policy on assinging CVE IDs for bugs that are merely missed hardening opportunities? One example is lack of full ASLR due to address space limits (47 or fewer bits instead of the theoretical limit of 64 bits). Are they eligible for CVE assignment? Should we DISPUTE them if we encounter them? Thanks, Florian
Current thread:
- Current CVE policy on missing-hardening bugs Florian Weimer (Aug 05)