PT-2000-1386 · Pgp · Pgp
Published
2000-05-24
·
Updated
2008-09-10
·
CVE-2000-0445
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
PGP versions 5.x
Description
The issue is related to the pgpk command in PGP on Unix systems, which uses an insufficiently random data source for non-interactive key pair generation. This may result in the production of predictable keys.
Recommendations
For PGP version 5.x, consider using an alternative method for key pair generation that utilizes a sufficiently random data source to minimize the risk of predictable keys.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pgp