oss-sec mailing list archives

Re: CVE request: libressl before 2.0.2 under linux PRNG failure


From: cve-assign () mitre org
Date: Fri, 18 Jul 2014 17:48:01 -0400 (EDT)

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

I see a number of web pages relating to this issue are mentioning that
it has already been assigned CVE-2014-2970, can anyone throw light on this?

There are a few different groups who are potentially able to assign
CVE IDs for issues in, say, LibreSSL. On rare occasions, the
different groups don't have the same expectations about coordinating.

At MITRE, we (obviously) know where CVE-2014-2970 came from, and we'll
send information here about the resolution as soon as it happens.

- -- 
CVE assignment team, MITRE CVE Numbering Authority
M/S M300
202 Burlington Road, Bedford, MA 01730 USA
[ PGP key available through http://cve.mitre.org/cve/request_id.html ]
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (SunOS)

iQEcBAEBAgAGBQJTyZRzAAoJEKllVAevmvms7jgH/iuLmBzNvmYSlGO2Ph1quhFy
ATZnpPnHR7Ot2ufwhGpGgBDurjWNThWoRylwjHqtHUjqEMb2cTqlVVypXOoc5tZm
9//gn26kUNuXGSZyVjThjl16op4748b9VvBVuXN/4PQqUVYeB904E5lHeO83jHEN
MbN2AkCntmtTcilWgqopOPBIsrksZDXE7I21rlNtyCaqRxSSxoIBKlBZup1Siec0
5G02nqEp6mXZWKKA0YK1r3DoPD1OwP46hNG038DLHSrGBRR2Ppdpl8h4kp3rtfxB
9zIYnKo7lxvPZACgvXL9662E96knwxNBxOlBvzxihqIpd0yMbpO7NPilGdewAhA=
=ECnJ
-----END PGP SIGNATURE-----


Current thread: