Date: Wed, 20 Jul 2011 11:34:45 +0530 From: Huzaifa Sidhpurwala <huzaifas@...hat.com> To: oss-security@...ts.openwall.com CC: Ludwig Nussel <ludwig.nussel@...e.de>, Marcus Rueckert <mrueckert@...e.de>, security@...y-lang.org, Urabe Shyouhei <shyouhei@...y-lang.org>, Joshua Bressers <bressers@...hat.com> Subject: Re: CVE Request: ruby PRNG fixes On 07/11/2011 02:07 PM, Ludwig Nussel wrote: > http://www.ruby-lang.org/en/news/2011/07/02/ruby-1-8-7-p352-released/ > http://redmine.ruby-lang.org/issues/4579 > http://svn.ruby-lang.org/cgi-bin/viewvc.cgi?view=revision&revision=31713 > http://svn.ruby-lang.org/cgi-bin/viewvc.cgi?view=revision&revision=32050 Looking at the above patches, there seems to be two issues here, perhaps it needs two CVE ids to be assigned? 1. http://svn.ruby-lang.org/cgi-bin/viewvc.cgi?view=revision&revision=31713 This one pertains to rand returning same values in forked processes. http://redmine.ruby-lang.org/issues/show/4338 This is a regression, as it was fixed in 1.8.6-p114, but re-appeared in 1.8.6-p399. 2. http://svn.ruby-lang.org/cgi-bin/viewvc.cgi?view=revision&revision=32050 This is an issue in the securerandom.rb module. http://redmine.ruby-lang.org/issues/4579 Josh, Can we please assign CVE-2011-2686 to one of the issues and have another CVE id to the other issue? Thanks. -- Huzaifa Sidhpurwala / Red Hat Security Response Team
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.