Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-Id: <201407110840.s6B8egJF018309@linus.mitre.org>
Date: Fri, 11 Jul 2014 04:40:42 -0400 (EDT)
From: cve-assign@...re.org
To: carnil@...ian.org, mmcallis@...hat.com, vkaigoro@...hat.com
Cc: cve-assign@...re.org, oss-security@...ts.openwall.com
Subject: Re: CVE request: XSS in PNP4Nagios

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

> I noticed that on Red Hat's Bugzilla these two are aliased to
> CVE-2014-4740. Should thus CVE-2014-4740 be rejected, or is
> CVE-204-4740 used for something different?

> https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-4740 i.e.
> https://bugzilla.redhat.com/show_bug.cgi?id=1115983 .

We need to REJECT CVE-2014-4740 because of the multiple conflicting
uses.

http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-4740 says
that CVE-2014-4740 is only about
f846a6c9d007ca2bee05359af747619151195fc9. The correct CVE ID for
f846a6c9d007ca2bee05359af747619151195fc9 is CVE-2014-4907.

However, https://bugzilla.redhat.com/show_bug.cgi?id=1115983 says that
CVE-2014-4740 is only about e4a19768a5c5e5b1276caf3dd5bb721a540ec014
and cb925073edeeb97eb4ce61a86cdafccc9b87f9bb. The correct CVE ID for
those two is CVE-2014-4908.

- -- 
CVE assignment team, MITRE CVE Numbering Authority
M/S M300
202 Burlington Road, Bedford, MA 01730 USA
[ PGP key available through http://cve.mitre.org/cve/request_id.html ]
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (SunOS)

iQEcBAEBAgAGBQJTv6KzAAoJEKllVAevmvmsQhsIAJbbGeIR6ym+m7CaNTJT0J4T
1pYnvPXkTXn6C7g7Dn1vCZqWISry6XAamP3OTIk8iXEkY+hJkQUKf6FiAsBP3uST
RjKy9Gs96hXxKtC4Ym5O+DcXyhWQYrOBqmfsidYGY8dH3L4aHFUAlGAAGNsJrIQp
bwc7VEfCqnRLhC4tyQ0YYBQKWOPO7BKKBBn0gQD/gJ2h98efknGYeEhNoVaAzzA/
jqBuh7ob2b4MwkOJlcpo5zHMd+b10L5R7hSu6VHvr81WY5JcQ4gXFKoXIZcjp6ZH
uda6OZrKE5DScie8e1yQkT+EhDSGcDSqAXpLJdklC0aoH8GDIPe4sdmCwhoRvTU=
=74N8
-----END PGP SIGNATURE-----

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.