Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Fri, 18 Jul 2014 17:48:01 -0400 (EDT)
From: cve-assign@...re.org
To: stu@...cehopper.org
Cc: cve-assign@...re.org, oss-security@...ts.openwall.com, hanno@...eck.de
Subject: Re: CVE request: libressl before 2.0.2 under linux PRNG failure

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

> I see a number of web pages relating to this issue are mentioning that
> it has already been assigned CVE-2014-2970, can anyone throw light on this?

There are a few different groups who are potentially able to assign
CVE IDs for issues in, say, LibreSSL. On rare occasions, the
different groups don't have the same expectations about coordinating.

At MITRE, we (obviously) know where CVE-2014-2970 came from, and we'll
send information here about the resolution as soon as it happens.

- -- 
CVE assignment team, MITRE CVE Numbering Authority
M/S M300
202 Burlington Road, Bedford, MA 01730 USA
[ PGP key available through http://cve.mitre.org/cve/request_id.html ]
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (SunOS)

iQEcBAEBAgAGBQJTyZRzAAoJEKllVAevmvms7jgH/iuLmBzNvmYSlGO2Ph1quhFy
ATZnpPnHR7Ot2ufwhGpGgBDurjWNThWoRylwjHqtHUjqEMb2cTqlVVypXOoc5tZm
9//gn26kUNuXGSZyVjThjl16op4748b9VvBVuXN/4PQqUVYeB904E5lHeO83jHEN
MbN2AkCntmtTcilWgqopOPBIsrksZDXE7I21rlNtyCaqRxSSxoIBKlBZup1Siec0
5G02nqEp6mXZWKKA0YK1r3DoPD1OwP46hNG038DLHSrGBRR2Ppdpl8h4kp3rtfxB
9zIYnKo7lxvPZACgvXL9662E96knwxNBxOlBvzxihqIpd0yMbpO7NPilGdewAhA=
=ECnJ
-----END PGP SIGNATURE-----

Powered by blists - more mailing lists

Your e-mail address:

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Powered by Openwall GNU/*/Linux - Powered by OpenVZ