Описание
In Samba, GnuTLS gnutls_rnd() can fail and give predictable random values.
A flaw was found in Samba. When the gnutls_rnd function is called, its return value is not verified, allowing it to give predictable random values when the call to the gnutls_rnd function fails.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 6 | samba | Out of support scope | ||
Red Hat Enterprise Linux 6 | samba4 | Out of support scope | ||
Red Hat Enterprise Linux 7 | samba | Out of support scope | ||
Red Hat Storage 3 | samba | Affected | ||
Red Hat Enterprise Linux 8 | samba | Fixed | RHSA-2023:2987 | 16.05.2023 |
Red Hat Enterprise Linux 8 | samba | Fixed | RHSA-2023:2987 | 16.05.2023 |
Red Hat Enterprise Linux 8.6 Extended Update Support | samba | Fixed | RHSA-2024:0423 | 25.01.2024 |
Red Hat Enterprise Linux 9 | samba | Fixed | RHSA-2023:2519 | 09.05.2023 |
Red Hat Enterprise Linux 9 | samba | Fixed | RHSA-2023:2519 | 09.05.2023 |
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | samba | Fixed | RHSA-2024:0423 | 25.01.2024 |
Показывать по
10
Дополнительная информация
Статус:
Low
Дефект:
CWE-252->CWE-330
https://bugzilla.redhat.com/show_bug.cgi?id=2122649samba: GnuTLS gnutls_rnd() can fail and give predictable random values
EPSS
Процентиль: 32%
0.00121
Низкий
5.1 Medium
CVSS3
Связанные уязвимости
CVSS3: 5.5
ubuntu
около 3 лет назад
In Samba, GnuTLS gnutls_rnd() can fail and give predictable random values.
CVSS3: 5.5
nvd
около 3 лет назад
In Samba, GnuTLS gnutls_rnd() can fail and give predictable random values.
CVSS3: 5.5
debian
около 3 лет назад
In Samba, GnuTLS gnutls_rnd() can fail and give predictable random val ...
CVSS3: 5.5
github
около 3 лет назад
In Samba, GnuTLS gnutls_rnd() can fail and give predictable random values.
EPSS
Процентиль: 32%
0.00121
Низкий
5.1 Medium
CVSS3