oss-sec mailing list archives

Re: Is CVE-2015-4650 a duplicate, leak, or just a typo?


From: ISC Security Officer <security-officer () isc org>
Date: Wed, 12 Aug 2015 09:42:02 -0400

On 8/12/15 8:32 AM, Florian Weimer wrote:
Some documents use CVE-2015-4650 to refer to a vulnerability in BIND.
Apparently, they source back to

<https://www.alienvault.com/forums/discussion/5706/security-advisory-alienvault-v5-1-addresses-6-vulnerabilities>

which says:

(details omitted)

That description seems to match CVE-2015-4620, so I'm leaning towards typo:

<https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-4620>

Speaking for ISC on the matter, I suspect a typo as well; at any rate
we have no knowledge of a CVE with that number.  It is not listed in
ISC's collection of BIND security advisories:


https://kb.isc.org/category/74/0/10/Software-Products/BIND9/Security-Advisories/

and I can say definitely that it is not a number which we are planning
to use for a pending advisory (i.e. the "leak" scenario can be dismissed.)

The number appears to have been reserved for use by another party
who has not yet provided MITRE with any details, as their page still
shows the place-holder typical of an assigned number which has not
yet been updated with details after public disclosure:

   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4650

A typo is the most likely explanation (and I can tell you from
experience that it is very easy to err when writing communications
which refer to things labeled with the CVE number format.)

Michael McNally
(responding for ISC Security Officer)


Current thread: