PT-2011-4545 · Unknown · Data::Random+1

Published

2011-10-10

·

Updated

2013-09-24

·

CVE-2011-3599

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Crypt::DSA module versions 1.17 and earlier
Description The issue allows remote attackers to spoof a signature or determine the signing key of a signed message via a brute-force attack when /dev/random is absent, as the module uses the Data::Random module in such cases.
Recommendations For Crypt::DSA module versions 1.17 and earlier, consider updating to a version that does not rely on the Data::Random module when /dev/random is absent, or ensure that /dev/random is present to mitigate the risk of brute-force attacks.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-3599
MGASA-2013-0289

Affected Products

Crypt::Dsa
Data::Random