Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Tue, 13 Oct 2009 12:33:37 -0400 (EDT)
From: "Steven M. Christey" <>
To: oss-security <>
cc: "Steven M. Christey" <>
Subject: Re: Duplicate CVE assignment notification [was: CVE
 id request: django]

On Tue, 13 Oct 2009, Jan Lieskovsky wrote:

>    two CVE ids have been assigned for this issue:
> CVE-2009-3695 and CVE-2009-3610.
> Will take CVE-2009-3695 as the proper one, as it has description already.
> CVE-2009-3610 should be rejected.

I agree with this: keep CVE-2009-3695.

CVE-2009-3695 was created off a Debian advisory that didn't list a CVE.
I assume that CVE-2009-3610 was being used for pre-disclosure coordination
by the Red Hat CNA.

- Steve

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.