| Main Archive Page > Month Archives > oss-security archives |
On Tue, 18 Jan 2011 12:22:05 +0000, Tim Brown wrote:
> Guys,
>
> What's the best way for an open source project to request a CVE prior to
> disclosure? I'm more that happy to coordinate the disclosure with
> distributions where appropriate if that makes a difference.
You're looking for vendor-sec:
http://oss-security.openwall.org/wiki/mailing-lists/vendor-sec
Best wishes,
Mike