Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2010-3400

Опубликовано: 15 сент. 2010
Источник: ubuntu
Приоритет: medium
CVSS2: 5.8

Описание

The js_InitRandom function in the JavaScript implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, uses the current time for seeding of a random number generator, which makes it easier for remote attackers to guess the seed value via a brute-force attack, a different vulnerability than CVE-2008-5913.

РелизСтатусПримечание
dapper

ignored

end of life
devel

not-affected

4.0+nobinonly-0ubuntu1
hardy

ignored

end of life
jaunty

DNE

karmic

DNE

lucid

not-affected

3.6.16+build1+nobinonly-0ubuntu0.10.04.1
maverick

not-affected

3.6.16+build1+nobinonly-0ubuntu0.10.10.1
natty

not-affected

4.0+nobinonly-0ubuntu1
upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

DNE

hardy

not-affected

3.6.16+build1+nobinonly-0ubuntu0.8.04.1
jaunty

ignored

end of life
karmic

DNE

lucid

DNE

maverick

DNE

natty

DNE

upstream

needs-triage

Ubuntu source uses 3.6.x

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

DNE

hardy

DNE

jaunty

ignored

karmic

not-affected

3.6.16+build1+nobinonly-0ubuntu0.9.10.1
lucid

DNE

maverick

DNE

natty

DNE

upstream

needs-triage

Ubuntu source uses 3.6.x

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

not-affected

hardy

not-affected

2.0.11+build1+nobinonly-0ubuntu0.8.04.1
jaunty

ignored

end of life
karmic

not-affected

lucid

not-affected

maverick

not-affected

natty

not-affected

upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

not-affected

hardy

ignored

end of life
jaunty

ignored

end of life
karmic

ignored

end of life
lucid

not-affected

3.1.8+build3+nobinonly-0ubuntu0.10.04.1
maverick

not-affected

natty

not-affected

upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

not-affected

1.9.2.15+build1+nobinonly-0ubuntu1
hardy

not-affected

1.9.2.16+build1+nobinonly-0ubuntu0.8.04.1
jaunty

ignored

end of life
karmic

not-affected

lucid

not-affected

maverick

not-affected

natty

not-affected

1.9.2.15+build1+nobinonly-0ubuntu1
upstream

needs-triage

Показывать по

Ссылки на источники

5.8 Medium

CVSS2

Связанные уязвимости

nvd
больше 15 лет назад

The js_InitRandom function in the JavaScript implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, uses the current time for seeding of a random number generator, which makes it easier for remote attackers to guess the seed value via a brute-force attack, a different vulnerability than CVE-2008-5913.

debian
больше 15 лет назад

The js_InitRandom function in the JavaScript implementation in Mozilla ...

github
больше 3 лет назад

The js_InitRandom function in the JavaScript implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, uses the current time for seeding of a random number generator, which makes it easier for remote attackers to guess the seed value via a brute-force attack, a different vulnerability than CVE-2008-5913.

5.8 Medium

CVSS2