oss-sec mailing list archives

Re: CVE duplicates SA-CONTRIB-2013-075


From: Henri Salo <henri () nerv fi>
Date: Mon, 21 Oct 2013 12:37:45 +0300

On Fri, Oct 18, 2013 at 02:16:31PM -0700, Forest Monsen wrote:
On Sat, Oct 5, 2013 at 4:10 AM, Henri Salo <henri () nerv fi> wrote:

Advisory https://drupal.org/node/2087055 says:

CVE-2013-4381 (XSS)
CVE-2013-4382 (CSRF)

Are these duplicate CVEs with CVEs below or is there something I am
missing?


Henri, it certainly looks like these are duplicates. However, Kurt
facilitated CVE assignment in
http://www.openwall.com/lists/oss-security/2013/09/27/6 , so it's not clear
to me how the NVD catalogued different identifiers.

Best,
Forest

Kurt, could you REJECT (or rotate) another CVEs, thanks.

You assigned these, which are currently used by Drupal project:
CVE-2013-4381, CVE-2013-4382

From NVD:
CVE-2013-5937, CVE-2013-5938

How do we avoid this in the future?

---
Henri Salo

Attachment: signature.asc
Description: Digital signature


Current thread: