Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Tue, 7 Oct 2008 17:35:15 -0400 (EDT)
From: "Steven M. Christey" <coley@...us.mitre.org>
To: oss-security@...ts.openwall.com
Subject: Re: Mozilla CVE duplicate


On Tue, 7 Oct 2008, Moritz Muehlenhoff wrote:

> CVE-2008-4067 is a duplicate of CVE-2007-3073, both reference
> https://bugzilla.mozilla.org/show_bug.cgi?id=380994 and the
> reporter is identical.

This seems to be the case.  Josh Bressers, can you confirm? CVE-2007-3073
is associated with comment #16 in bug 367428, but later comments for bug
367428 seem to suggest it's the same (or almost the same) as bug 380994.

If these are dupes, then CVE-2008-4067 would be preferred due to usage by
more authoritative sources, and more commonly referenced.

- Steve

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.