PT-2011-4545 · Unknown · Data::Random+1
Published
2011-10-10
·
Updated
2013-09-24
·
CVE-2011-3599
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Crypt::DSA module versions 1.17 and earlier
Description
The issue allows remote attackers to spoof a signature or determine the signing key of a signed message via a brute-force attack when /dev/random is absent, as the module uses the Data::Random module in such cases.
Recommendations
For Crypt::DSA module versions 1.17 and earlier, consider updating to a version that does not rely on the Data::Random module when /dev/random is absent, or ensure that /dev/random is present to mitigate the risk of brute-force attacks.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Crypt::Dsa
Data::Random