Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Tue, 16 Dec 2008 21:18:20 -0500 (EST)
From: "Steven M. Christey" <coley@...us.mitre.org>
To: Jan Lieskovsky <jlieskov@...hat.com>
cc: Andreas Ericsson <ae@....se>, Eygene Ryabinkin <rea-sec@...elabs.ru>,
        oss-security@...ts.openwall.com, coley@...re.org
Subject: Re: CVE Request (nagios)


On Thu, 11 Dec 2008, Jan Lieskovsky wrote:

>   I can't follow this. Nagios 3.0.5 should fix two issues:

Neither can I.  I'm not sure if we need to clean up the CVE descriptions
or not.

Note that general CVE practice is - if you have vuln X in version 1, and
you don't completely fix X, then we give a separate CVE for version 2.

In this case, I'd probably want to modify CVE-2008-5028 to say it's
related to "submission of external commands" which is in the 3.0.6
changelog, then refer to the original, pre-3.0.5 CSRF as the "Tim
Starling" bug or something like that.

- Steve

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.