[engineering.redhat.com #278019] Insufficient salting in the net-ldap Ruby gem

Red Hat Security Response Team <[email protected]> Thu, 13 Feb 2014 11:44:49 -0500
Newsgroups gmane.os.freebsd.bugbusters
Message-ID <[email protected]>
On Thu Feb 13 00:11:15 2014, [email protected] wrote:
> On Wed, Feb 12, 2014 at 10:01 PM, Red Hat Security Response Team
> <[email protected]> wrote:
> > Please use CVE-2014-0083 for this issue. Also can an issue be opened
> upstream if it hasn't already been done? Thanks.
> 
> My understanding from a naive search is that the current active
> project is github.com/ruby-ldap/ruby-net-ldap, and
> [email protected] has been merging all pull requests there in
> recent times, so I included them in the original email as the presumed
> current upstream.
> 

Excellent, thanks. Also can someone post this to oss-security? I suspect quite a few people are using this gem. If needed I can do the posting. 

-- 
Kurt Seifried Red Hat Security Response Team (SRT)
PGP: 0x5E267993 A90B F995 7350 148F 66BF 7554 160D 4553 5E26 7993

_______________________________________________
[email protected] mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-bugbusters
To unsubscribe, send any mail to "[email protected]"