CVE-2005-0106
N/A
N/A
Summary
SSLeay.pm in libnet-ssleay-perl before 1.25 uses the /tmp/entropy file for entropy if a source is not set in the EGD_PATH variable, which allows local users to reduce the cryptographic strength of certain operations by modifying the file.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- https://usn.ubuntu.com/113-1/
- http://secunia.com/advisories/18639
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:023
- http://www.securityfocus.com/bid/13471
References
- https://usn.ubuntu.com/113-1/
- http://secunia.com/advisories/18639
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:023
- http://www.securityfocus.com/bid/13471
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.