Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE for encryptor 2.0.0 #30

Open
tarcieri opened this issue Oct 13, 2017 · 4 comments
Open

CVE for encryptor 2.0.0 #30

tarcieri opened this issue Oct 13, 2017 · 4 comments

Comments

@tarcieri
Copy link

tarcieri commented Oct 13, 2017

I opened a ruby-advisory-db issue for the GCM nonce reuse issue in encryptor 2.0.0:

rubysec/ruby-advisory-db#305

The first step is to obtain a CVE. Are you interested in doing that?

https://iwantacve.org

If not I can get one on your behalf.

@saghaulor
Copy link
Contributor

@tarcieri This is the best course of action. I should have done that when the issue was exposed. Thanks for bringing it to my attention.

I've added a comment to your rubysec PR pointing to the issue where the bug was originally reported.

I'll try to open a CVE myself, if I am unable to figure it out I'll reach out for you help. Thank you.

@tarcieri
Copy link
Author

Awesome, thanks!

@reedloden
Copy link

Did a CVE ever get assigned to this? If not, can assign one...

@jasnow
Copy link

jasnow commented Jun 13, 2023

@tarcieri, @saghaulor,

As part of my ruby-advisory-db repo work, I would like to offer my help to work with you in applying for a CVE for the Encryptor 2.0.0 issue covered by rubysec/ruby-advisory-db#305 and this issue.

To start this process, I have collected all of the data I could find. It is in a format similar to ruby-advisory-db advisories.

Feel free to use the data or replace it as needed. I will help out as I can.

Thanks

CC: @reedloden @postmodern

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants