RETIRED: LibreSSL PRNG Entropy Weakness
BID:68667
Info
RETIRED: LibreSSL PRNG Entropy Weakness
| Bugtraq ID: | 68667 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 16 2014 12:00AM |
| Updated: | Aug 19 2014 12:52AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
RETIRED: LibreSSL PRNG Entropy Weakness
LibreSSL is prone to a weakness that may result in weaker cryptographic security.
Attackers can exploit this issue with brute-force techniques to obtain sensitive information that can aid in further attacks.
Libressl 2.0.0 and 2.0.1 are vulnerable.
Note: This BID is being retired as CVE-2014-2970 is rejected.
LibreSSL is prone to a weakness that may result in weaker cryptographic security.
Attackers can exploit this issue with brute-force techniques to obtain sensitive information that can aid in further attacks.
Libressl 2.0.0 and 2.0.1 are vulnerable.
Note: This BID is being retired as CVE-2014-2970 is rejected.
Exploit / POC
RETIRED: LibreSSL PRNG Entropy Weakness
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
Solution / Fix
RETIRED: LibreSSL PRNG Entropy Weakness
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
RETIRED: LibreSSL PRNG Entropy Weakness
References:
References: