VulnerabilityModified
CVE-2011-2683
reseed seeds random numbers from an insecure HTTP request to random.org during installation, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a man-in-the-middle attack.
MEDIUM 5.9EPSS 1.33%
Does this matter?
Lower severity and a low EPSS score (1.33%). Track it; it rarely justifies an emergency change on its own.
Description
reseed seeds random numbers from an insecure HTTP request to random.org during installation, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a man-in-the-middle attack.
- CVSS 3.0
- 5.9 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.33% probability · 69th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-254
- Affected
- reseed project/reseed
- Source
- secalert@redhat.com
References
- http://www.openwall.com/lists/oss-security/2011/07/06/8Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2014/02/08/5Mailing List, Third Party Advisory
- https://bugs.launchpad.net/ubuntu/+source/reseed/+bug/804594Third Party Advisory
- http://www.openwall.com/lists/oss-security/2011/07/06/8Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2014/02/08/5Mailing List, Third Party Advisory
- https://bugs.launchpad.net/ubuntu/+source/reseed/+bug/804594Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.