PT-2009-5554 · Linux+1 · Linux Kernel+1
CVE-2009-3238
·
Publicado
2009-06-16
·
Atualizado
2024-02-15
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 2.6.30
Description
The issue concerns the production of insufficiently random numbers by the
get random int function, allowing attackers to predict the return value. This could potentially defeat protection mechanisms based on randomization. The function's tendency to return the same value over and over again for long stretches of time is leveraged by vectors to exploit this issue.Recommendations
For Linux kernel versions prior to 2.6.30, update to version 2.6.30 or later to resolve the issue. As a temporary workaround, consider restricting the use of the
get random int function until a patch is available.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Linux Kernel
Red Hat