Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-0017

Опубликовано: 14 мар. 2014
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 1.9

Описание

The RAND_bytes function in libssh before 0.6.3, when forking is enabled, does not properly reset the state of the OpenSSL pseudo-random number generator (PRNG), which causes the state to be shared between children processes and allows local users to obtain sensitive information by leveraging a pid collision.

РелизСтатусПримечание
devel

released

0.6.1-0ubuntu3
lucid

ignored

end of life
precise

released

0.5.2-1ubuntu0.12.04.3
quantal

released

0.5.2-1ubuntu0.12.10.3
saucy

released

0.5.4-1ubuntu0.1
upstream

released

0.6.3

Показывать по

EPSS

Процентиль: 25%
0.00088
Низкий

1.9 Low

CVSS2

Связанные уязвимости

redhat
почти 12 лет назад

The RAND_bytes function in libssh before 0.6.3, when forking is enabled, does not properly reset the state of the OpenSSL pseudo-random number generator (PRNG), which causes the state to be shared between children processes and allows local users to obtain sensitive information by leveraging a pid collision.

nvd
почти 12 лет назад

The RAND_bytes function in libssh before 0.6.3, when forking is enabled, does not properly reset the state of the OpenSSL pseudo-random number generator (PRNG), which causes the state to be shared between children processes and allows local users to obtain sensitive information by leveraging a pid collision.

debian
почти 12 лет назад

The RAND_bytes function in libssh before 0.6.3, when forking is enable ...

github
больше 3 лет назад

The RAND_bytes function in libssh before 0.6.3, when forking is enabled, does not properly reset the state of the OpenSSL pseudo-random number generator (PRNG), which causes the state to be shared between children processes and allows local users to obtain sensitive information by leveraging a pid collision.

fstec
больше 11 лет назад

Уязвимость операционной системы Gentoo Linux, позволяющая злоумышленнику нарушить конфиденциальность защищаемой информации

EPSS

Процентиль: 25%
0.00088
Низкий

1.9 Low

CVSS2