Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Wed, 20 Jul 2011 11:34:45 +0530
From: Huzaifa Sidhpurwala <>
CC: Ludwig Nussel <>, Marcus Rueckert <>,, Urabe Shyouhei <>,
        Joshua Bressers <>
Subject: Re: CVE Request: ruby PRNG fixes

On 07/11/2011 02:07 PM, Ludwig Nussel wrote:


Looking at the above patches, there seems to be two issues here, perhaps
it needs two CVE ids to be assigned?


This one pertains to rand returning same values in forked processes.
This is a regression, as it was fixed in 1.8.6-p114, but re-appeared in


This is an issue in the securerandom.rb module.


Can we please assign CVE-2011-2686 to one of the issues and have another
CVE id to the other issue?


Huzaifa Sidhpurwala / Red Hat Security Response Team

Powered by blists - more mailing lists

Your e-mail address:

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Powered by Openwall GNU/*/Linux - Powered by OpenVZ