Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-9019

Опубликовано: 20 нояб. 2015
Источник: redhat
CVSS3: 4

Описание

In libxslt 1.1.29 and earlier, the EXSLT math.random function was not initialized with a random seed during startup, which could cause usage of this function to produce predictable outputs.

Отчет

The xslt random function provided by libxslt does not offer any security or cryptography guarantees. Applications using libxslt that rely on non-repeatable randomness should be seeding the system PRNG (srand()) themselves, as they would if calling rand() directly.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libxsltWill not fix
Red Hat Enterprise Linux 6libxsltWill not fix
Red Hat Enterprise Linux 7libxsltWill not fix
Red Hat Enterprise Linux OpenStack Platform 6 (Juno)libxsltWill not fix
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)libxsltWill not fix
Red Hat Enterprise MRG 2libxsltWill not fix
Red Hat OpenStack Platform 10 (Newton)libxsltWill not fix
Red Hat OpenStack Platform 8 (Liberty)libxsltWill not fix
Red Hat OpenStack Platform 9 (Mitaka)libxsltWill not fix
Red Hat Storage 3libxsltWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-330
https://bugzilla.redhat.com/show_bug.cgi?id=1439548libxslt: math.random() in xslt uses unseeded randomness

4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 9 лет назад

In libxslt 1.1.29 and earlier, the EXSLT math.random function was not initialized with a random seed during startup, which could cause usage of this function to produce predictable outputs.

CVSS3: 5.3
nvd
больше 9 лет назад

In libxslt 1.1.29 and earlier, the EXSLT math.random function was not initialized with a random seed during startup, which could cause usage of this function to produce predictable outputs.

CVSS3: 5.3
debian
больше 9 лет назад

In libxslt 1.1.29 and earlier, the EXSLT math.random function was not ...

CVSS3: 5.3
github
больше 4 лет назад

In libxslt 1.1.29 and earlier, the EXSLT math.random function was not initialized with a random seed during startup, which could cause usage of this function to produce predictable outputs.

suse-cvrf
около 9 лет назад

Security update for libxslt

4 Medium

CVSS3