Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2013-4347

Опубликовано: 20 мая 2014
Источник: ubuntu
Приоритет: medium
CVSS2: 5.8

Описание

The (1) make_nonce, (2) generate_nonce, and (3) generate_verifier functions in SimpleGeo python-oauth2 uses weak random numbers to generate nonces, which makes it easier for remote attackers to guess the nonce via a brute force attack.

РелизСтатусПримечание
artful

DNE

bionic

DNE

cosmic

DNE

devel

DNE

disco

DNE

esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was needed]
lucid

DNE

precise

ignored

end of life
precise/esm

DNE

precise was needed
quantal

ignored

end of life

Показывать по

5.8 Medium

CVSS2

Связанные уязвимости

redhat
почти 13 лет назад

The (1) make_nonce, (2) generate_nonce, and (3) generate_verifier functions in SimpleGeo python-oauth2 uses weak random numbers to generate nonces, which makes it easier for remote attackers to guess the nonce via a brute force attack.

nvd
больше 11 лет назад

The (1) make_nonce, (2) generate_nonce, and (3) generate_verifier functions in SimpleGeo python-oauth2 uses weak random numbers to generate nonces, which makes it easier for remote attackers to guess the nonce via a brute force attack.

debian
больше 11 лет назад

The (1) make_nonce, (2) generate_nonce, and (3) generate_verifier func ...

CVSS3: 3.7
github
больше 3 лет назад

SimpleGeo python-oauth2 vulnerable to the use of Insufficiently Random Values to generate nonces

5.8 Medium

CVSS2