Bugzilla – Bug 875192
VUL-0: CVE-2014-2734: ruby: openssl private key spoofing
Last modified: 2020-04-01 22:11:02 UTC
Via: seclists.org http://seclists.org/fulldisclosure/2014/Apr/231 Ruby openssl has a vulnerability when a public key is a issued prior writing to private key and is reopened during a script it spoofs a CA private key. PoC script https://gist.github.com/10446549 CVE-2014-2734 was assigned to this issue. References: http://people.canonical.com/~ubuntu-security/cve/2014/CVE-2014-2734.html http://seclists.org/fulldisclosure/2014/Apr/231
bugbot adjusting priority