Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-3704

Опубликовано: 25 апр. 2016
Источник: redhat
CVSS3: 5.6
CVSS2: 4.6
EPSS Низкий

Описание

Pulp before 2.8.5 uses bash's $RANDOM in an unsafe way to generate passwords.

Pulp makes unsafe use of Bash's $RANDOM to generate a NSS DB password and seed resulting in insufficient randomness. An attacker could potentially guess the seed used given enough time and compute resources.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
RHUI for RHEL 6pulpNot affected
Red Hat Satellite 6.3 for RHEL 7candlepinFixedRHSA-2018:033621.02.2018
Red Hat Satellite 6.3 for RHEL 7foremanFixedRHSA-2018:033621.02.2018
Red Hat Satellite 6.3 for RHEL 7foreman-bootloaders-redhatFixedRHSA-2018:033621.02.2018
Red Hat Satellite 6.3 for RHEL 7foreman-discovery-imageFixedRHSA-2018:033621.02.2018
Red Hat Satellite 6.3 for RHEL 7foreman-installerFixedRHSA-2018:033621.02.2018
Red Hat Satellite 6.3 for RHEL 7foreman-proxyFixedRHSA-2018:033621.02.2018
Red Hat Satellite 6.3 for RHEL 7foreman-selinuxFixedRHSA-2018:033621.02.2018
Red Hat Satellite 6.3 for RHEL 7hieraFixedRHSA-2018:033621.02.2018
Red Hat Satellite 6.3 for RHEL 7katelloFixedRHSA-2018:033621.02.2018

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-330
https://bugzilla.redhat.com/show_bug.cgi?id=1330264pulp: Unsafe use of bash $RANDOM for NSS DB password and seed

EPSS

Процентиль: 67%
0.00543
Низкий

5.6 Medium

CVSS3

4.6 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.5
nvd
больше 8 лет назад

Pulp before 2.8.5 uses bash's $RANDOM in an unsafe way to generate passwords.

CVSS3: 7.5
github
больше 3 лет назад

Pulp before 2.8.5 uses bash's $RANDOM in an unsafe way to generate passwords.

EPSS

Процентиль: 67%
0.00543
Низкий

5.6 Medium

CVSS3

4.6 Medium

CVSS2