VulnerabilityModified
CVE-2008-3168
The files utility in Empire Server before 4.3.15 discloses the world creation time, which makes it easier for attackers to determine the PRNG seed.
MEDIUM 5.0EPSS 1.04%
Does this matter?
Lower severity and a low EPSS score (1.04%). Track it; it rarely justifies an emergency change on its own.
Description
The files utility in Empire Server before 4.3.15 discloses the world creation time, which makes it easier for attackers to determine the PRNG seed.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.04% probability · 62th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- empire server/empire server
- Source
- cve@mitre.org
References
- http://freshmeat.net/projects/empserver/?branch_id=22267&release_id=280745Patch
- http://sourceforge.net/project/shownotes.php?group_id=24031&release_id=600111Patch
- http://www.securityfocus.com/bid/30152
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43653
- http://freshmeat.net/projects/empserver/?branch_id=22267&release_id=280745Patch
- http://sourceforge.net/project/shownotes.php?group_id=24031&release_id=600111Patch
- http://www.securityfocus.com/bid/30152
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43653
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.