|
Message-Id: <201308051927.r75JRN4b015111@linus.mitre.org> Date: Mon, 5 Aug 2013 15:27:23 -0400 (EDT) From: cve-assign@...re.org To: oss-security@...ts.openwall.com Cc: cve-assign@...re.org Subject: valid but unusual sequence of CVEs in SYM13-009 -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 There's a recent disclosure at: http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20130801_00 that has the following valid and correct sequence of CVEs: CVE-2013-4575 CVE-2013-4676 CVE-2013-4677 CVE-2013-4678 In other words, the first CVE should NOT be re-interpreted to mean a number that "fits better." CVE-2013-4575 is for software that runs on Linux but we don't know (and don't need to know) whether it is open source or might be open sourced in the future. We're mentioning it at the request of someone who has been assigned CVEs adjacent to CVE-2013-4575, with future use for open-source vulnerabilities expected. Thanks very much to that person for their help. - -- CVE assignment team, MITRE CVE Numbering Authority M/S M300 202 Burlington Road, Bedford, MA 01730 USA [ PGP key available through http://cve.mitre.org/cve/request_id.html ] -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.11 (SunOS) iQEcBAEBAgAGBQJR//l0AAoJEGvefgSNfHMdXYAH/iZbYPo5Z1mnuZ6O7l0ox7xG jU4DFThfj+pgi2RWheGiqOn9Qp6rLvjO5tPA+C53ryq+UK7LICYYxrkskTL8iol5 pi7uvMnqAkHnq/FQTjnMhVk3SD0Jo+VRCcnPk5/XleE7hBqdHNNVl7GTo8/o+QYg +Vt0PZAMahPW9DXBtlxhHlDnEfQEfFQUr8Avzi2szuDpnniTgu3c/zoYApmFhPYc Ia+092oQDS+S3AfHmSIgookzYHa6JqgelbREWkfAWOMueSCJ7ej6Dp/19l9k1eoL TFqb6JoxItrWQI08dcB2nPNfXRy9+woPLP63l6b+LWu5APRmXSSbW+JOAXpBxyc= =loS6 -----END PGP SIGNATURE-----
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.