Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Message-Id: <201308051927.r75JRN4b015111@linus.mitre.org>
Date: Mon, 5 Aug 2013 15:27:23 -0400 (EDT)
From: cve-assign@...re.org
To: oss-security@...ts.openwall.com
Cc: cve-assign@...re.org
Subject: valid but unusual sequence of CVEs in SYM13-009

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

There's a recent disclosure at:

  http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20130801_00

that has the following valid and correct sequence of CVEs:

  CVE-2013-4575
  CVE-2013-4676
  CVE-2013-4677
  CVE-2013-4678

In other words, the first CVE should NOT be re-interpreted to mean a
number that "fits better."

CVE-2013-4575 is for software that runs on Linux but we don't know
(and don't need to know) whether it is open source or might be open
sourced in the future. We're mentioning it at the request of someone
who has been assigned CVEs adjacent to CVE-2013-4575, with future use
for open-source vulnerabilities expected. Thanks very much to that
person for their help.

- -- 
CVE assignment team, MITRE CVE Numbering Authority
M/S M300
202 Burlington Road, Bedford, MA 01730 USA
[ PGP key available through http://cve.mitre.org/cve/request_id.html ]
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (SunOS)

iQEcBAEBAgAGBQJR//l0AAoJEGvefgSNfHMdXYAH/iZbYPo5Z1mnuZ6O7l0ox7xG
jU4DFThfj+pgi2RWheGiqOn9Qp6rLvjO5tPA+C53ryq+UK7LICYYxrkskTL8iol5
pi7uvMnqAkHnq/FQTjnMhVk3SD0Jo+VRCcnPk5/XleE7hBqdHNNVl7GTo8/o+QYg
+Vt0PZAMahPW9DXBtlxhHlDnEfQEfFQUr8Avzi2szuDpnniTgu3c/zoYApmFhPYc
Ia+092oQDS+S3AfHmSIgookzYHa6JqgelbREWkfAWOMueSCJ7ej6Dp/19l9k1eoL
TFqb6JoxItrWQI08dcB2nPNfXRy9+woPLP63l6b+LWu5APRmXSSbW+JOAXpBxyc=
=loS6
-----END PGP SIGNATURE-----

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.