Date: Wed, 12 Aug 2015 09:42:02 -0400 From: ISC Security Officer <security-officer@....org> To: Florian Weimer <fweimer@...hat.com>, Assign a CVE Identifier <cve-assign@...re.org> CC: oss-security@...ts.openwall.com, "security-officer@....org" <security-officer@....org> Subject: Re: Is CVE-2015-4650 a duplicate, leak, or just a typo? On 8/12/15 8:32 AM, Florian Weimer wrote: > Some documents use CVE-2015-4650 to refer to a vulnerability in BIND. > Apparently, they source back to > > <https://www.alienvault.com/forums/discussion/5706/security-advisory-alienvault-v5-1-addresses-6-vulnerabilities> > > which says: (details omitted) > That description seems to match CVE-2015-4620, so I'm leaning towards typo: > > <https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-4620> Speaking for ISC on the matter, I suspect a typo as well; at any rate we have no knowledge of a CVE with that number. It is not listed in ISC's collection of BIND security advisories: https://kb.isc.org/category/74/0/10/Software-Products/BIND9/Security-Advisories/ and I can say definitely that it is not a number which we are planning to use for a pending advisory (i.e. the "leak" scenario can be dismissed.) The number appears to have been reserved for use by another party who has not yet provided MITRE with any details, as their page still shows the place-holder typical of an assigned number which has not yet been updated with details after public disclosure: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4650 A typo is the most likely explanation (and I can tell you from experience that it is very easy to err when writing communications which refer to things labeled with the CVE number format.) Michael McNally (responding for ISC Security Officer)
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.