Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Wed, 20 Jul 2011 11:34:45 +0530
From: Huzaifa Sidhpurwala <>
CC: Ludwig Nussel <>, Marcus Rueckert <>,, Urabe Shyouhei <>,
        Joshua Bressers <>
Subject: Re: CVE Request: ruby PRNG fixes

On 07/11/2011 02:07 PM, Ludwig Nussel wrote:


Looking at the above patches, there seems to be two issues here, perhaps
it needs two CVE ids to be assigned?


This one pertains to rand returning same values in forked processes.
This is a regression, as it was fixed in 1.8.6-p114, but re-appeared in


This is an issue in the securerandom.rb module.


Can we please assign CVE-2011-2686 to one of the issues and have another
CVE id to the other issue?


Huzaifa Sidhpurwala / Red Hat Security Response Team

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.