Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Thu, 3 Sep 2009 16:24:50 +0200
From: Tomas Hoger <thoger@...hat.com>
To: oss-security@...ts.openwall.com
Cc: matthias.andree@....de, "Steven M. Christey" <coley@...us.mitre.org>
Subject: Re: Re: "umbrella" CVE names (was: CVE request:
 fetchmail <= 6.3.10 SSL certificate NUL prefix verification bypass)

On Fri, 21 Aug 2009 09:28:08 +0200 "Matthias Andree"
<matthias.andree@....de> wrote:

> Mandriva Security (I think it was them - if I recall correctly) wrote
> in their fetchmail security advisory something along the lines of  
> "CVE-2009-2666, [...] related to CVE-2009-2408"

That's likely.  It seems CVE descriptions for this kind of issues all
end with "a related issue to CVE-2009-2408." (thanks, Steven!) and
Mandriva often uses CVE description with little modifications.

-- 
Tomas Hoger / Red Hat Security Response Team

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Powered by Openwall GNU/*/Linux - Powered by OpenVZ