PT-2024-40045 · Unknown · Random Compat

Published

2024-05-17

·

Updated

2024-05-17

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions random compat versions prior to 2.0
Description The issue is related to the insecure usage of Cryptographically Secure Pseudo-Random Number Generators (CSPRNG). The affected versions use openssl random pseudo bytes(), which may result in insufficient entropy and compromise the security of generated random numbers.
Recommendations For versions prior to 2.0, update to version 2.0 or later to resolve the issue. As a temporary workaround, consider restricting the usage of openssl random pseudo bytes() until a patch is available.

Weakness Enumeration

Related Identifiers

GHSA-3FMQ-X9Q6-WM39

Affected Products

Random Compat