Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-9019

Опубликовано: 20 нояб. 2015
Источник: redhat
CVSS3: 4
EPSS Низкий

Описание

In libxslt 1.1.29 and earlier, the EXSLT math.random function was not initialized with a random seed during startup, which could cause usage of this function to produce predictable outputs.

Отчет

The xslt random function provided by libxslt does not offer any security or cryptography guarantees. Applications using libxslt that rely on non-repeatable randomness should be seeding the system PRNG (srand()) themselves, as they would if calling rand() directly.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libxsltWill not fix
Red Hat Enterprise Linux 6libxsltWill not fix
Red Hat Enterprise Linux 7libxsltWill not fix
Red Hat Enterprise Linux OpenStack Platform 6 (Juno)libxsltWill not fix
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)libxsltWill not fix
Red Hat Enterprise MRG 2libxsltWill not fix
Red Hat Gluster Storage 3.1libxsltWill not fix
Red Hat OpenStack Platform 10 (Newton)libxsltWill not fix
Red Hat OpenStack Platform 8 (Liberty)libxsltWill not fix
Red Hat OpenStack Platform 9 (Mitaka)libxsltWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-330
https://bugzilla.redhat.com/show_bug.cgi?id=1439548libxslt: math.random() in xslt uses unseeded randomness

EPSS

Процентиль: 76%
0.00984
Низкий

4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 9 лет назад

In libxslt 1.1.29 and earlier, the EXSLT math.random function was not initialized with a random seed during startup, which could cause usage of this function to produce predictable outputs.

CVSS3: 5.3
nvd
почти 9 лет назад

In libxslt 1.1.29 and earlier, the EXSLT math.random function was not initialized with a random seed during startup, which could cause usage of this function to produce predictable outputs.

CVSS3: 5.3
debian
почти 9 лет назад

In libxslt 1.1.29 and earlier, the EXSLT math.random function was not ...

CVSS3: 5.3
github
больше 3 лет назад

In libxslt 1.1.29 and earlier, the EXSLT math.random function was not initialized with a random seed during startup, which could cause usage of this function to produce predictable outputs.

suse-cvrf
больше 8 лет назад

Security update for libxslt

EPSS

Процентиль: 76%
0.00984
Низкий

4 Medium

CVSS3