[VIM] Sun JDK Confusion Revisited

Steven M. Christey coley at linus.mitre.org
Tue Dec 18 00:33:25 UTC 2007


On Wed, 12 Dec 2007, George A. Theall wrote:

> I posted last July about Bugtraq 24267 / CVE-2007-3004 (and
> CVE-2007-3005) duplicating Bugtraq 24004 / CVE-2007-2788 and
> CVE-2007-2789. Sun apparently confirm this:
>
>    http://www.attrition.org/pipermail/vim/2007-July/001708.html
>
> SecurityFocus retired Bugtraq 24267, but the CVE references still are
> valid. Did the clean-up get lost in the shuffle or was there some new
> info that Sun sent and I just missed?

No, the clean-up got lost in the shuffle.

Sun Alert 102934 now uses the older CVE's; CVE-2007-3004 and CVE-2007-3005
are being REJECTED.

Note that a lot of references are affected.

Sorry about the non-answer back in July :-(

- Steve


More information about the VIM mailing list