On Thu, Jun 12, 2014 at 11:15:18PM +0100, Matt Caswell wrote:
>
>
> On 12/06/14 22:43, Otto Moerbeek wrote:
> > On Thu, Jun 12, 2014 at 10:26:56PM +0200, Matt Caswell via RT wrote:
> >
> >> Patch applied:
> >> https://git.openssl.org/gitweb/?p=openssl.git;a=commit;h=abfb989fe0b749ad61f1aa4cdb0ea4f952fc13e0
> >>
> >> Many thanks for your contribution.
> >>
> >> Matt
> >
> > http://www.openbsd.org/cgi-bin/cvsweb/src/lib/libssl/src/ssl/ssl_ciph.c.diff?r1=1.38;r2=1.39
> >
> > Again no attribution in problem report and commit. Claiming
> > independent discovery is not going to be credible.
>
> The commit *is* attributed. The author is listed as Kurt Cancemi - this
> is as it is attributed in the patch supplied in the problem report.
>
> I cannot say how Kurt found this defect - that is for him to answer.
>
> All I can go on is the information supplied to me in the problem report
> and patch. I had no idea that openbsd had also discovered and fixed this
> defect until you sent the above link.
OK, let's hope Kurt shares his story and the attribution can be
retrofitted if needed.
-Otto
______________________________________________________________________
OpenSSL Project http://www.openssl.org
Development Mailing List [email protected]
Automated List Manager [email protected]