PT-2011-4545 · Unknown · Data::Random+1
Publicado
2011-10-10
·
Atualizado
2013-09-24
·
CVE-2011-3599
CVSS v2.0
5.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Crypt::DSA module versions 1.17 and earlier
Description
The issue allows remote attackers to spoof a signature or determine the signing key of a signed message via a brute-force attack when /dev/random is absent, as the module uses the Data::Random module in such cases.
Recommendations
For Crypt::DSA module versions 1.17 and earlier, consider updating to a version that does not rely on the Data::Random module when /dev/random is absent, or ensure that /dev/random is present to mitigate the risk of brute-force attacks.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Crypt::Dsa
Data::Random