Perl Crypt-DSA Module Random Number Values Security Weakness
BID:49928
Info
Perl Crypt-DSA Module Random Number Values Security Weakness
| Bugtraq ID: | 49928 |
| Class: | Design Error |
| CVE: |
CVE-2011-3599 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 04 2011 12:00AM |
| Updated: | Sep 26 2013 12:13AM |
| Credit: | Harlan Lieberman-Berg |
| Vulnerable: |
MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 CPAN Crypt-DSA Module 1.17 |
| Not Vulnerable: | |
Discussion
Perl Crypt-DSA Module Random Number Values Security Weakness
Perl Crypt-DSA Module is prone to a security weakness.
An attacker can exploit this weakness to predict random number values and bypass certain security restrictions.
Perl Crypt-DSA Module 1.17 is vulnerable; other versions may also be affected.
NOTE: Exploits will only succeed if '/dev/random' is not available on the targeted system.
Perl Crypt-DSA Module is prone to a security weakness.
An attacker can exploit this weakness to predict random number values and bypass certain security restrictions.
Perl Crypt-DSA Module 1.17 is vulnerable; other versions may also be affected.
NOTE: Exploits will only succeed if '/dev/random' is not available on the targeted system.
Exploit / POC
Perl Crypt-DSA Module Random Number Values Security Weakness
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Perl Crypt-DSA Module Random Number Values Security Weakness
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].,Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].,Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Perl Crypt-DSA Module Random Number Values Security Weakness
References:
References: