Date: Fri, 18 Jul 2014 17:48:01 -0400 (EDT) From: cve-assign@...re.org To: stu@...cehopper.org Cc: cve-assign@...re.org, oss-security@...ts.openwall.com, hanno@...eck.de Subject: Re: CVE request: libressl before 2.0.2 under linux PRNG failure -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 > I see a number of web pages relating to this issue are mentioning that > it has already been assigned CVE-2014-2970, can anyone throw light on this? There are a few different groups who are potentially able to assign CVE IDs for issues in, say, LibreSSL. On rare occasions, the different groups don't have the same expectations about coordinating. At MITRE, we (obviously) know where CVE-2014-2970 came from, and we'll send information here about the resolution as soon as it happens. - -- CVE assignment team, MITRE CVE Numbering Authority M/S M300 202 Burlington Road, Bedford, MA 01730 USA [ PGP key available through http://cve.mitre.org/cve/request_id.html ] -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.14 (SunOS) iQEcBAEBAgAGBQJTyZRzAAoJEKllVAevmvms7jgH/iuLmBzNvmYSlGO2Ph1quhFy ATZnpPnHR7Ot2ufwhGpGgBDurjWNThWoRylwjHqtHUjqEMb2cTqlVVypXOoc5tZm 9//gn26kUNuXGSZyVjThjl16op4748b9VvBVuXN/4PQqUVYeB904E5lHeO83jHEN MbN2AkCntmtTcilWgqopOPBIsrksZDXE7I21rlNtyCaqRxSSxoIBKlBZup1Siec0 5G02nqEp6mXZWKKA0YK1r3DoPD1OwP46hNG038DLHSrGBRR2Ppdpl8h4kp3rtfxB 9zIYnKo7lxvPZACgvXL9662E96knwxNBxOlBvzxihqIpd0yMbpO7NPilGdewAhA= =ECnJ -----END PGP SIGNATURE-----
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Powered by Openwall GNU/*/Linux - Powered by OpenVZ