Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-Id: <20141121002225.5A1DB52E0ED@smtpvbsrv1.mitre.org>
Date: Thu, 20 Nov 2014 19:22:25 -0500 (EST)
From: cve-assign@...re.org
To: pwolanin@...il.com
Cc: cve-assign@...re.org, oss-security@...ts.openwall.com, security@...pal.org, gwolf@...lf.org, team@...urity.debian.org, carnil@...ian.org
Subject: Re: [security] Pending CVE assignments for SA-CORE-2014-006?

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

> Since it's identical code, should I use the same CVE number, or since
> it's a contributed project, there will be a distinct one issued?

The former. In other words, the CVE-2014-9016 ID originally assigned
for the second issue in SA-CORE-2014-006 should also be used for
SA-CONTRIB-2014-113 (i.e., the https://www.drupal.org/node/2378367
report).

- -- 
CVE assignment team, MITRE CVE Numbering Authority
M/S M300
202 Burlington Road, Bedford, MA 01730 USA
[ PGP key available through http://cve.mitre.org/cve/request_id.html ]
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (SunOS)

iQEcBAEBAgAGBQJUboU1AAoJEKllVAevmvms/DAIAKE/ID/3JcqO6Ks2Q0tjXV8G
PtWg/ZiiCsaPejCkx1GmTd+2mxOezYWtwoxzSfYS29XMvj4RbdHUNWXrkihzY1EA
BgFC2Uc9reqF+BqlQIQng52lJGQBPf6VV/mejtBfYHv+WOFogQPGqPFgZLTGxLvf
Yd2Am8yiArTOoZNJxmkDju2L4Z7EWtGdMh3md4jgKB4A1eFjgmIl7be0vktAC1QI
f9pg1lqMlIYrlgNlIKap8kf0F45wpLJxru7DNJgpNDoDHtFkcFa8i3/iVwjlzq26
+PyQe1iF3IxCtlxZ6fFF6ObnBxrrv2iKjcebyVfYqdTK6Sbr959tXeCruNAUW7k=
=CbgI
-----END PGP SIGNATURE-----

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.