
oss-sec mailing list archives
Re: Is CVE-2015-4650 a duplicate, leak, or just a typo?
From: ISC Security Officer <security-officer () isc org>
Date: Wed, 12 Aug 2015 09:42:02 -0400
On 8/12/15 8:32 AM, Florian Weimer wrote:
Some documents use CVE-2015-4650 to refer to a vulnerability in BIND. Apparently, they source back to <https://www.alienvault.com/forums/discussion/5706/security-advisory-alienvault-v5-1-addresses-6-vulnerabilities> which says:
(details omitted)
That description seems to match CVE-2015-4620, so I'm leaning towards typo: <https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-4620>
Speaking for ISC on the matter, I suspect a typo as well; at any rate we have no knowledge of a CVE with that number. It is not listed in ISC's collection of BIND security advisories: https://kb.isc.org/category/74/0/10/Software-Products/BIND9/Security-Advisories/ and I can say definitely that it is not a number which we are planning to use for a pending advisory (i.e. the "leak" scenario can be dismissed.) The number appears to have been reserved for use by another party who has not yet provided MITRE with any details, as their page still shows the place-holder typical of an assigned number which has not yet been updated with details after public disclosure: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4650 A typo is the most likely explanation (and I can tell you from experience that it is very easy to err when writing communications which refer to things labeled with the CVE number format.) Michael McNally (responding for ISC Security Officer)
Current thread:
- Is CVE-2015-4650 a duplicate, leak, or just a typo? Florian Weimer (Aug 12)
- Re: Is CVE-2015-4650 a duplicate, leak, or just a typo? ISC Security Officer (Aug 12)
- Re: Is CVE-2015-4650 a duplicate, leak, or just a typo? Michael McNally (Aug 14)
- Re: Is CVE-2015-4650 a duplicate, leak, or just a typo? ISC Security Officer (Aug 12)