Re: Is CVE-2024-30203 bogus? (Emacs)

Related Vulnerabilities: CVE-2024-30203   CVE-2024-30204  
                							

                <!--X-Body-Begin-->
<!--X-User-Header-->

oss-sec
mailing list archives
<!--X-User-Header-End-->
<!--X-TopPNI-->

By Date

By Thread

</form>

<!--X-TopPNI-End-->
<!--X-MsgBody-->
<!--X-Subject-Header-Begin-->
Re: Is CVE-2024-30203 bogus? (Emacs)

<!--X-Subject-Header-End-->
<!--X-Head-of-Message-->

From: Sean Whitton &lt;spwhitton () spwhitton name&gt;

Date: Thu, 11 Apr 2024 17:12:37 +0800

<!--X-Head-of-Message-End-->
<!--X-Head-Body-Sep-Begin-->

<!--X-Head-Body-Sep-End-->
<!--X-Body-of-Message-->
Hello,

On Wed 10 Apr 2024 at 10:07pm +07, Max Nikulin wrote:

On 10/04/2024 21:17, Salvatore Bonaccorso wrote:
On Wed, Apr 10, 2024 at 12:04:06PM +0000, Ihor Radchenko wrote:

Yes, CVE-2024-30203 title is superfluous.
And CVE-2024-30204 title is not accurate - it only applies to
certain attachments with specific (text/x-org) mime type.
[...]
If you think the CVE assignment is not valid, then you might ask for a
REJECT on https://cveform.mitre.org/ .

Do 2 CVE numbers make sense to track fixes in Emacs and Org mode? Various
versions of Org mode may be loaded to different versions of Emacs and both
parties must have fixes to avoid the issue.

My understanding is that one CVE for the same vulnerability in multiple
code bases is normal.

-- 
Sean Whitton
Attachment:
signature.asc
Description: 

<!--X-Body-of-Message-End-->
<!--X-MsgBody-End-->
<!--X-Follow-Ups-->

<!--X-Follow-Ups-End-->
<!--X-References-->
<!--X-References-End-->
<!--X-BotPNI-->

By Date

By Thread

Current thread:

Is CVE-2024-30203 bogus? (Emacs) Sean Whitton (Apr 08)

Re: Is CVE-2024-30203 bogus? (Emacs) Eli Zaretskii (Apr 08)

Re: Is CVE-2024-30203 bogus? (Emacs) Max Nikulin (Apr 08)

Re: Is CVE-2024-30203 bogus? (Emacs) Ihor Radchenko (Apr 08)

Re: Is CVE-2024-30203 bogus? (Emacs) Sean Whitton (Apr 10)

Re: Is CVE-2024-30203 bogus? (Emacs) Ihor Radchenko (Apr 10)
Re: Re: Is CVE-2024-30203 bogus? (Emacs) Salvatore Bonaccorso (Apr 10)
Re: Is CVE-2024-30203 bogus? (Emacs) Max Nikulin (Apr 10)
Re: Is CVE-2024-30203 bogus? (Emacs) Sean Whitton (Apr 11)

Re: Re: Is CVE-2024-30203 bogus? (Emacs) Sean Whitton (Apr 11)
Re: Is CVE-2024-30203 bogus? (Emacs) Max Nikulin (Apr 11)

<!--X-BotPNI-End-->
<!--X-User-Footer-->
<!--X-User-Footer-End-->