* Matt Zimmerman: >> <http://cve.mitre.org/cve/cna.html#cnas> lists organizations, not >> individuals. The requirements are clearly geared towards >> organizations, too. > > Unless things have changed since I went through the process, the authority > involved does not extend to Debian in general but only to specific > individuals.
Certainly, at Debian, only certain individuals issue CVEs. I can't tell if this is Debian's choice, or a result of MITRE's rules. _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
