Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-45751

Опубликовано: 06 сент. 2024
Источник: debian
EPSS Низкий

Описание

tgt (aka Linux target framework) before 1.0.93 attempts to achieve entropy by calling rand without srand. The PRNG seed is always 1, and thus the sequence of challenges is always identical.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tgtfixed1:1.0.85-1.3package
tgtfixed1:1.0.85-1+deb12u1bookwormpackage

Примечания

  • https://github.com/fujita/tgt/pull/67

  • https://github.com/fujita/tgt/commit/abd8e0d987ab56013d360077202bf2aca20a42dd (v1.0.93)

  • https://www.openwall.com/lists/oss-security/2024/09/07/2

EPSS

Процентиль: 45%
0.00551
Низкий

Связанные уязвимости

CVSS3: 5.9
ubuntu
около 2 лет назад

tgt (aka Linux target framework) before 1.0.93 attempts to achieve entropy by calling rand without srand. The PRNG seed is always 1, and thus the sequence of challenges is always identical.

CVSS3: 5.9
nvd
около 2 лет назад

tgt (aka Linux target framework) before 1.0.93 attempts to achieve entropy by calling rand without srand. The PRNG seed is always 1, and thus the sequence of challenges is always identical.

suse-cvrf
около 1 года назад

Security update for tgt

CVSS3: 5.9
github
около 2 лет назад

tgt (aka Linux target framework) before 1.0.93 attempts to achieve entropy by calling rand without srand. The PRNG seed is always 1, and thus the sequence of challenges is always identical.

EPSS

Процентиль: 45%
0.00551
Низкий