PT-2011-4545 · Unknown · Data::Random+1

Publicado

2011-10-10

·

Atualizado

2013-09-24

·

CVE-2011-3599

CVSS v2.0

5.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Crypt::DSA module versions 1.17 and earlier
Description The issue allows remote attackers to spoof a signature or determine the signing key of a signed message via a brute-force attack when /dev/random is absent, as the module uses the Data::Random module in such cases.
Recommendations For Crypt::DSA module versions 1.17 and earlier, consider updating to a version that does not rely on the Data::Random module when /dev/random is absent, or ensure that /dev/random is present to mitigate the risk of brute-force attacks.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-3599
MGASA-2013-0289

Produtos afetados

Crypt::Dsa
Data::Random