CVE-2001-1467
mkpasswd in expect 5.2.8, as used by Red Hat Linux 6.2 through 7.0, seeds its random number generator with its process ID, which limits the space of possible seeds and makes it easier for attackers to conduct brute force password attacks.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.61%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
mkpasswd in expect 5.2.8, as used by Red Hat Linux 6.2 through 7.0, seeds its random number generator with its process ID, which limits the space of possible seeds and makes it easier for attackers to conduct brute force password attacks.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 2.61% probability · 85th percentile
- CISA KEV
- Not listed
- Affected
- don libes/expect
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2001-04/0173.html
- http://archives.neohapsis.com/archives/bugtraq/2001-04/0192.html
- http://securitytracker.com/id?1001303
- http://www.kb.cert.org/vuls/id/527736US Government Resource
- http://www.securityfocus.com/bid/2632
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6382
- http://archives.neohapsis.com/archives/bugtraq/2001-04/0173.html
- http://archives.neohapsis.com/archives/bugtraq/2001-04/0192.html
- http://securitytracker.com/id?1001303
- http://www.kb.cert.org/vuls/id/527736US Government Resource
- http://www.securityfocus.com/bid/2632
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6382
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.