mentions that one OpenSSL developer used to see defect reports from Coverity (probably through Coverity's scan project). He states:
"Coverity used to, and perhaps still do, run scans of OpenSSL, which we had (have?) access to. I used to look at them and fix relevant ones, but got irritated with the false positive level in the end.
If Coverity were interested in fixing their bugs, I might get interested in looking at their reports again."
Of course this doesn't demonstrate that Coverity found this particular problem, and since he doesn't state what the false positive rate was it's difficult to know how reasonable his statement is.
http://openssl.6102.n7.nabble.com/Coverity-coverage-of-OpenS...
mentions that one OpenSSL developer used to see defect reports from Coverity (probably through Coverity's scan project). He states:
"Coverity used to, and perhaps still do, run scans of OpenSSL, which we had (have?) access to. I used to look at them and fix relevant ones, but got irritated with the false positive level in the end.
If Coverity were interested in fixing their bugs, I might get interested in looking at their reports again."
Of course this doesn't demonstrate that Coverity found this particular problem, and since he doesn't state what the false positive rate was it's difficult to know how reasonable his statement is.