Vulnerability   
Search   
    Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.702781
Category:Debian Local Security Checks
Title:Debian Security Advisory DSA 2781-1 (python-crypto - PRNG not correctly reseeded in some situations)
Summary:A cryptographic vulnerability was discovered in the pseudo random number;generator in python-crypto.;;In some situations, a race condition could prevent the reseeding of the;generator when multiple processes are forked from the same parent. This would;lead it to generate identical output on all processes, which might leak;sensitive values like cryptographic keys.
Description:Summary:
A cryptographic vulnerability was discovered in the pseudo random number
generator in python-crypto.

In some situations, a race condition could prevent the reseeding of the
generator when multiple processes are forked from the same parent. This would
lead it to generate identical output on all processes, which might leak
sensitive values like cryptographic keys.

Affected Software/OS:
python-crypto on Debian Linux

Solution:
For the oldstable distribution (squeeze), this problem has been fixed in
version 2.1.0-2+squeeze2.

For the stable distribution (wheezy), this problem has been fixed in
version 2.6-4+deb7u3.

For the testing distribution (jessie), this problem has been fixed in
version 2.6.1-2.

For the unstable distribution (sid), this problem has been fixed in
version 2.6.1-1.

We recommend that you upgrade your python-crypto packages.

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:N/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2013-1445
Debian Security Information: DSA-2781 (Google Search)
http://www.debian.org/security/2013/dsa-2781
http://www.openwall.com/lists/oss-security/2013/10/17/3
CopyrightCopyright (C) 2013 Greenbone Networks GmbH http://greenbone.net

This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2024 E-Soft Inc. All rights reserved.