Lucene search

K
cveMitreCVE-2006-3419
HistoryJul 07, 2006 - 12:05 a.m.

CVE-2006-3419

2006-07-0700:05:00
mitre
web.nvd.nist.gov
26
cve-2006-3419
tor
openssl
rand_bytes
entropy
brute force
nvd

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.5

Confidence

Low

EPSS

0.004

Percentile

73.4%

Tor before 0.1.1.20 uses OpenSSL pseudo-random bytes (RAND_pseudo_bytes) instead of cryptographically strong RAND_bytes, and seeds the entropy value at start-up with 160-bit chunks without reseeding, which makes it easier for attackers to conduct brute force guessing attacks.

Affected configurations

Nvd
Node
tortorMatch0.0.2
OR
tortorMatch0.0.2_pre13
OR
tortorMatch0.0.2_pre14
OR
tortorMatch0.0.2_pre15
OR
tortorMatch0.0.2_pre16
OR
tortorMatch0.0.2_pre17
OR
tortorMatch0.0.2_pre18
OR
tortorMatch0.0.2_pre19
OR
tortorMatch0.0.2_pre20
OR
tortorMatch0.0.2_pre21
OR
tortorMatch0.0.2_pre22
OR
tortorMatch0.0.2_pre23
OR
tortorMatch0.0.2_pre24
OR
tortorMatch0.0.2_pre25
OR
tortorMatch0.0.2_pre26
OR
tortorMatch0.0.2_pre27
OR
tortorMatch0.0.3
OR
tortorMatch0.0.4
OR
tortorMatch0.0.5
OR
tortorMatch0.0.6
OR
tortorMatch0.0.6.1
OR
tortorMatch0.0.6.2
OR
tortorMatch0.0.7
OR
tortorMatch0.0.7.1
OR
tortorMatch0.0.7.2
OR
tortorMatch0.0.7.3
OR
tortorMatch0.0.8
OR
tortorMatch0.0.8.1
OR
tortorMatch0.0.9
OR
tortorMatch0.0.9.1
OR
tortorMatch0.0.9.2
OR
tortorMatch0.0.9.3
OR
tortorMatch0.0.9.4
OR
tortorMatch0.0.9.5
OR
tortorMatch0.0.9.6
OR
tortorMatch0.0.9.7
OR
tortorMatch0.0.9.8
OR
tortorMatch0.0.9.9
OR
tortorMatch0.0.9.10
OR
tortorMatch0.1.0.1
OR
tortorMatch0.1.0.2
OR
tortorMatch0.1.0.3
OR
tortorMatch0.1.0.4
OR
tortorMatch0.1.0.5
OR
tortorMatch0.1.0.6
OR
tortorMatch0.1.0.7
OR
tortorMatch0.1.0.8
OR
tortorMatch0.1.0.9
OR
tortorMatch0.1.0.10
OR
tortorMatch0.1.0.11
OR
tortorMatch0.1.0.12
OR
tortorMatch0.1.0.13
OR
tortorMatch0.1.0.14
OR
tortorMatch0.1.0.15
OR
tortorMatch0.1.0.16
OR
tortorMatch0.1.0.17
OR
tortorMatch0.1.0.18
OR
tortorMatch0.1.0.19
OR
tortorMatch0.1.1.1_alpha
OR
tortorMatch0.1.1.2_alpha
OR
tortorMatch0.1.1.3_alpha
OR
tortorMatch0.1.1.4_alpha
OR
tortorMatch0.1.1.5_alpha
OR
tortorMatch0.1.1.6_alpha
OR
tortorMatch0.1.1.7_alpha
OR
tortorMatch0.1.1.8_alpha
OR
tortorMatch0.1.1.9_alpha
OR
tortorMatch0.1.1.10_alpha
VendorProductVersionCPE
tortor0.0.2cpe:2.3:a:tor:tor:0.0.2:*:*:*:*:*:*:*
tortor0.0.2_pre13cpe:2.3:a:tor:tor:0.0.2_pre13:*:*:*:*:*:*:*
tortor0.0.2_pre14cpe:2.3:a:tor:tor:0.0.2_pre14:*:*:*:*:*:*:*
tortor0.0.2_pre15cpe:2.3:a:tor:tor:0.0.2_pre15:*:*:*:*:*:*:*
tortor0.0.2_pre16cpe:2.3:a:tor:tor:0.0.2_pre16:*:*:*:*:*:*:*
tortor0.0.2_pre17cpe:2.3:a:tor:tor:0.0.2_pre17:*:*:*:*:*:*:*
tortor0.0.2_pre18cpe:2.3:a:tor:tor:0.0.2_pre18:*:*:*:*:*:*:*
tortor0.0.2_pre19cpe:2.3:a:tor:tor:0.0.2_pre19:*:*:*:*:*:*:*
tortor0.0.2_pre20cpe:2.3:a:tor:tor:0.0.2_pre20:*:*:*:*:*:*:*
tortor0.0.2_pre21cpe:2.3:a:tor:tor:0.0.2_pre21:*:*:*:*:*:*:*
Rows per page:
1-10 of 681

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.5

Confidence

Low

EPSS

0.004

Percentile

73.4%

Related for CVE-2006-3419