Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Mon, 21 Oct 2013 15:41:09 +0000
From: "Christey, Steven M." <coley@...re.org>
To: "oss-security@...ts.openwall.com" <oss-security@...ts.openwall.com>
CC: Forest Monsen <forest.monsen@...il.com>, Kurt Seifried
	<kseifried@...hat.com>
Subject: RE: Re: CVE duplicates SA-CONTRIB-2013-075

Note that with two CNAs handling already-public issues, there are multiple ways that duplicates can arise.  This risk grows as MITRE's output increases.  On the MITRE side, we are revisiting our procedures for reducing the number of duplicates.  We already privately identified the increased duplicate risk with Kurt and will work with him to make things more manageable.

For this specific situation: MITRE processed the Drupal advisories on September 25, creating new CVEs that were thus available in NVD at approximately 11 AM Eastern time.  Forest's request to oss-security happened on September 26.  Kurt's response to oss-security was on September 27.  So in this case, there were multiple opportunities for requesters to check for pre-existing CVEs in NVD.

The MITRE-assigned CVE-2013-5937 and CVE-2013-5938 are in more active use and were published first, so they will be kept.

REJECT CVE-2013-4381 as a duplicate of CVE-2013-5938.

REJECT CVE-2013-4382 as a duplicate of CVE-2013-5937.

Forest, please update the advisory to use the MITRE-assigned numbers.

- Steve


>-----Original Message-----
>From: Henri Salo [mailto:henri@...v.fi]
>Sent: Monday, October 21, 2013 5:38 AM
>To: oss-security@...ts.openwall.com
>Cc: Forest Monsen; Kurt Seifried
>Subject: [oss-security] Re: CVE duplicates SA-CONTRIB-2013-075
>
>On Fri, Oct 18, 2013 at 02:16:31PM -0700, Forest Monsen wrote:
>> On Sat, Oct 5, 2013 at 4:10 AM, Henri Salo <henri@...v.fi> wrote:
>>
>> > Advisory https://drupal.org/node/2087055 says:
>> >
>> > CVE-2013-4381 (XSS)
>> > CVE-2013-4382 (CSRF)
>> >
>> > Are these duplicate CVEs with CVEs below or is there something I am
>> > missing?
>> >
>>
>> Henri, it certainly looks like these are duplicates. However, Kurt
>> facilitated CVE assignment in
>> http://www.openwall.com/lists/oss-security/2013/09/27/6 , so it's not clear
>> to me how the NVD catalogued different identifiers.
>>
>> Best,
>> Forest
>
>Kurt, could you REJECT (or rotate) another CVEs, thanks.
>
>You assigned these, which are currently used by Drupal project:
>CVE-2013-4381, CVE-2013-4382
>
>>From NVD:
>CVE-2013-5937, CVE-2013-5938
>
>How do we avoid this in the future?
>
>---
>Henri Salo

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.