Gentoo 'ssl-cert' eclass Information Disclosure Vulnerability
BID:28350
Info
Gentoo 'ssl-cert' eclass Information Disclosure Vulnerability
| Bugtraq ID: | 28350 |
| Class: | Design Error |
| CVE: |
CVE-2008-1383 |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 20 2008 12:00AM |
| Updated: | Mar 25 2008 01:10PM |
| Credit: | Robin Johnson is credited with the discovery of this issue. |
| Vulnerable: |
Gentoo Linux |
| Not Vulnerable: | |
Discussion
Gentoo 'ssl-cert' eclass Information Disclosure Vulnerability
Gentoo is prone to an information-disclosure vulnerability.
An attacker can exploit this issue to obtain sensitive information and gain access to SSL private encryption keys. Information obtained may aid in further attacks.
The issue affects multiple ebuilds included in Gentoo Linux.
Gentoo is prone to an information-disclosure vulnerability.
An attacker can exploit this issue to obtain sensitive information and gain access to SSL private encryption keys. Information obtained may aid in further attacks.
The issue affects multiple ebuilds included in Gentoo Linux.
Exploit / POC
Gentoo 'ssl-cert' eclass Information Disclosure Vulnerability
To exploit this issue an attacker can use readily available tools or standard commands.
To exploit this issue an attacker can use readily available tools or standard commands.
Solution / Fix
Gentoo 'ssl-cert' eclass Information Disclosure Vulnerability
Solution:
The vendor has released an advisory and fixes. Please see the references for more information.
Solution:
The vendor has released an advisory and fixes. Please see the references for more information.
References
Gentoo 'ssl-cert' eclass Information Disclosure Vulnerability
References:
References:
- CVE-2015-7513 Kernel: kvm: divide by zero issue leads to DoS (Prasad J Pandit)