oss-sec mailing list archives
Re: CVE duplicates SA-CONTRIB-2013-075
From: Henri Salo <henri () nerv fi>
Date: Mon, 21 Oct 2013 12:37:45 +0300
On Fri, Oct 18, 2013 at 02:16:31PM -0700, Forest Monsen wrote:
On Sat, Oct 5, 2013 at 4:10 AM, Henri Salo <henri () nerv fi> wrote:Advisory https://drupal.org/node/2087055 says: CVE-2013-4381 (XSS) CVE-2013-4382 (CSRF) Are these duplicate CVEs with CVEs below or is there something I am missing?Henri, it certainly looks like these are duplicates. However, Kurt facilitated CVE assignment in http://www.openwall.com/lists/oss-security/2013/09/27/6 , so it's not clear to me how the NVD catalogued different identifiers. Best, Forest
Kurt, could you REJECT (or rotate) another CVEs, thanks. You assigned these, which are currently used by Drupal project: CVE-2013-4381, CVE-2013-4382 From NVD: CVE-2013-5937, CVE-2013-5938 How do we avoid this in the future? --- Henri Salo
Attachment:
signature.asc
Description: Digital signature
Current thread:
- CVE duplicates SA-CONTRIB-2013-075 Henri Salo (Oct 05)
- Re: CVE duplicates SA-CONTRIB-2013-075 Forest Monsen (Oct 18)
- Re: CVE duplicates SA-CONTRIB-2013-075 Henri Salo (Oct 21)
- RE: Re: CVE duplicates SA-CONTRIB-2013-075 Christey, Steven M. (Oct 21)
- Re: Re: CVE duplicates SA-CONTRIB-2013-075 Kurt Seifried (Oct 21)
- Re: Re: CVE duplicates SA-CONTRIB-2013-075 Forest Monsen (Oct 22)
- Re: CVE duplicates SA-CONTRIB-2013-075 Henri Salo (Oct 21)
- Re: CVE duplicates SA-CONTRIB-2013-075 Forest Monsen (Oct 18)