[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Simplified Draft Counting Paper for CVE Editorial Board Review



On 2016-03-28 12:24, Common Vulnerabilities & Exposures wrote: > Please find attached to this note a copy of the draft CVE Simplified > Counting Paper. The paper was originally prepared as an internal piece > to help the CVE analysts orient their thinking, and we thought that it > would be useful to share it with the Board as background before the > Board meeting Wednesday afternoon. Comments added. At a high level, even more tolerance for assignment criteria, increased assignment (by MITRE and/or CNAs) is necessary to keep up with reality. A direct affect is an increased need for split/merge/reject cleanup. Perhaps, vaguely reminiscent of CAN/CVE days, CVE entries get a flag that can be set by MITRE or a CNA to distinguish "claimed vulnerabilities, report looks plausible, public reference" from "vendor acknowledged, or otherwise substantiated claim, public reference." - Art

Attachment:CVE_counting_cert.docx
Description:Zip archive


Page Last Updated or Reviewed:March 31, 2016