RSS   Vulnerabilities for 'Crypto'   RSS

2011-05-31
 
CVE-2011-0766

CWE-310
 

 
The random number generator in the Crypto application before 2.0.2.2, and SSH before 2.0.5, as used in the Erlang/OTP ssh library before R14B03, uses predictable seeds based on the current time, which makes it easier for remote attackers to guess DSA host and SSH session keys.

 

 >>> Vendor: Erlang 6 Products
Erlang
Crypto
Erlang/otp
OTP
Rebar3
Erlang\/otp


Copyright 2024, cxsecurity.com

 

Back to Top