PT-2000-1386 · Pgp · Pgp
Publicado
2000-05-24
·
Atualizado
2008-09-10
·
CVE-2000-0445
CVSS v2.0
2.1
Baixa
| Vetor | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
PGP versions 5.x
Description
The issue is related to the pgpk command in PGP on Unix systems, which uses an insufficiently random data source for non-interactive key pair generation. This may result in the production of predictable keys.
Recommendations
For PGP version 5.x, consider using an alternative method for key pair generation that utilizes a sufficiently random data source to minimize the risk of predictable keys.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Pgp