Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <55CB4D2A.1070404@isc.org>
Date: Wed, 12 Aug 2015 09:42:02 -0400
From: ISC Security Officer <security-officer@....org>
To: Florian Weimer <fweimer@...hat.com>, 
 Assign a CVE Identifier <cve-assign@...re.org>
CC: oss-security@...ts.openwall.com, 
 "security-officer@....org" <security-officer@....org>
Subject: Re: Is CVE-2015-4650 a duplicate, leak, or just a typo?

On 8/12/15 8:32 AM, Florian Weimer wrote:
> Some documents use CVE-2015-4650 to refer to a vulnerability in BIND.
> Apparently, they source back to
> 
> <https://www.alienvault.com/forums/discussion/5706/security-advisory-alienvault-v5-1-addresses-6-vulnerabilities>
> 
> which says:

(details omitted)

> That description seems to match CVE-2015-4620, so I'm leaning towards typo:
> 
> <https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-4620>

Speaking for ISC on the matter, I suspect a typo as well; at any rate
we have no knowledge of a CVE with that number.  It is not listed in
ISC's collection of BIND security advisories:


https://kb.isc.org/category/74/0/10/Software-Products/BIND9/Security-Advisories/

and I can say definitely that it is not a number which we are planning
to use for a pending advisory (i.e. the "leak" scenario can be dismissed.)

The number appears to have been reserved for use by another party
who has not yet provided MITRE with any details, as their page still
shows the place-holder typical of an assigned number which has not
yet been updated with details after public disclosure:

   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4650

A typo is the most likely explanation (and I can tell you from
experience that it is very easy to err when writing communications
which refer to things labeled with the CVE number format.)

Michael McNally
(responding for ISC Security Officer)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.