Couldn't add a CVE reference using the web UI

Bug #241435 reported by Till Ulen
6
Affects Status Importance Assigned to Milestone
Launchpad itself
Invalid
Undecided
Unassigned

Bug Description

I couldn't add a CVE reference to several bugs (bug #240549, bug #241421 and bug #241419) using the "Link to CVE" link in the Actions menu on the left. I entered the appropriate CVE number, clicked Continue, but the CVE reference wasn't added to the "CVE references" area on the left. Neither did the bug appear when I searched for the CVE number at https://bugs.launchpad.net/bugs/cve.

I tried to add a comment with a CVE reference and it worked. So I'm using that as a work-around for now.

Tags: lp-bugs
Till Ulen (tillulen)
description: updated
Revision history for this message
Diogo Matsubara (matsubara) wrote :

Hi Alexander,

What happened when you tried to add the CVE reference? Did you get an error message? What was the value you used in the CVE Sequence Number field?

Thanks

Changed in malone:
status: New → Incomplete
Revision history for this message
Till Ulen (tillulen) wrote : Re: [Bug 241435] Re: Couldn't add a CVE reference using the web UI

On Fri, Jun 20, 2008 at 19:14, Diogo Matsubara wrote:
>
> What happened when you tried to add the CVE reference?
> Did you get an error message?

No error message. The bug page appeared just as if the CVE reference
was added successfully. I used that CVE linking feature many times
before encountering this bug, so I didn't even notice the problem the
first time it happened.

> What was the value you used in the CVE Sequence Number field?

I used the corresponding CVE numbers for each bug in the form
2008-1234, without the "CVE" prefix, because I did already know by the
time that the "Link to CVE" form doesn't accept the CVE-2008-1234
syntax (by the way, why?). On the other hand, when searching the CVE
tracker I did enter the prefix, so the queries were like
CVE-2008-1234.

Now I cannot reproduce this problem on this bug #241435. I will try to
reproduce it on more Ubuntu bugs reported by me and others as new
vulnerabilities appear. I'll update this report accordingly.

-- Alexander

Revision history for this message
Till Ulen (tillulen) wrote :

I think that the problem only occurs on the bug pages that select some package (such as https://bugs.launchpad.net/ubuntu/+source/net-snmp/+bug/239129) and does not occur on other pages (for example, at https://bugs.launchpad.net/ubuntu/+bug/239129). That's the same bug 239129 presented on two different pages. This is a wild guess though and needs more testing.

Revision history for this message
Björn Tillenius (bjornt) wrote :

Sorry, I can't reproduce this. I've tested the both URLs for bug 239129 that you provided, and it works on both.

Changed in malone:
status: Incomplete → Invalid
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.