On Thu, Jun 12, 2014 at 11:15:18PM +0100, Matt Caswell wrote: > > > On 12/06/14 22:43, Otto Moerbeek wrote: > > On Thu, Jun 12, 2014 at 10:26:56PM +0200, Matt Caswell via RT wrote: > > > >> Patch applied: > >> https://git.openssl.org/gitweb/?p=openssl.git;a=commit;h=abfb989fe0b749ad61f1aa4cdb0ea4f952fc13e0 > >> > >> Many thanks for your contribution. > >> > >> Matt > > > > http://www.openbsd.org/cgi-bin/cvsweb/src/lib/libssl/src/ssl/ssl_ciph.c.diff?r1=1.38;r2=1.39 > > > > Again no attribution in problem report and commit. Claiming > > independent discovery is not going to be credible. > > The commit *is* attributed. The author is listed as Kurt Cancemi - this > is as it is attributed in the patch supplied in the problem report. > > I cannot say how Kurt found this defect - that is for him to answer. > > All I can go on is the information supplied to me in the problem report > and patch. I had no idea that openbsd had also discovered and fixed this > defect until you sent the above link.
OK, let's hope Kurt shares his story and the attribution can be retrofitted if needed. -Otto ______________________________________________________________________ OpenSSL Project http://www.openssl.org Development Mailing List openssl-dev@openssl.org Automated List Manager majord...@openssl.org