Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Wed, 17 Aug 2016 19:05:06 +0200
From: Remi Gacogne <>
Cc: Werner Koch <>
Subject: Re: Libgcrypt and GnuPG 1.4 RNG output prediction


On 08/17/2016 06:58 PM, Solar Designer wrote:
> <@rgacogne> @gnupg @solardiz The CVE number (CVE-2016-6316) seems to have been used to track another security issue rubygem-actionview, is that correct?
> There does in fact appear to be a CVE ID clash, with:

Apparently the correct CVE number is CVE-2016-6313:

Download attachment "signature.asc" of type "application/pgp-signature" (802 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.