oss-sec mailing list archives

CVE oops in GLSA 201308-05 (wireshark)


From: Vincent Danen <vdanen () redhat com>
Date: Wed, 28 Aug 2013 09:24:44 -0600

I just saw via a Gentoo bug report that their GLSA 201308-05 advisory
mentioned some CVEs as related to wireshark that were incorrect.

Instead of mentioning CVE-2013-{3560,3561,3562} they mentioned
CVE-2013-{3540,3541,3542}.  I checked on MITRE's site and those three
are still reserved.

I don't know who those three (354[012]) are assigned to, but you might
want to see if they've been used already or not and dupe them against
356[012] if they have not.

See:

http://www.net-security.org/advisory.php?id=16517
https://bugs.gentoo.org/show_bug.cgi?id=482794

Thanks.

--
Vincent Danen / Red Hat Security Response Team

Current thread: