PT-2000-1386 · Pgp · Pgp

Publicado

2000-05-24

·

Atualizado

2008-09-10

·

CVE-2000-0445

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions PGP versions 5.x
Description The issue is related to the pgpk command in PGP on Unix systems, which uses an insufficiently random data source for non-interactive key pair generation. This may result in the production of predictable keys.
Recommendations For PGP version 5.x, consider using an alternative method for key pair generation that utilizes a sufficiently random data source to minimize the risk of predictable keys.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2000-0445

Produtos afetados

Pgp