Lucene search

K
freebsdFreeBSDF8C88D50-5FB3-11E4-81BD-5453ED2E2B49
HistoryMar 05, 2014 - 12:00 a.m.

libssh -- PRNG state reuse on forking servers

2014-03-0500:00:00
vuxml.freebsd.org
22

CVSS2

1.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:N/A:N

EPSS

0

Percentile

5.1%

Aris Adamantiadis reports:

When accepting a new connection, the server forks and the
child process handles the request. The RAND_bytes() function
of openssl doesn’t reset its state after the fork, but
simply adds the current process id (getpid) to the PRNG
state, which is not guaranteed to be unique.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchlibssh<Β 0.6.3UNKNOWN

CVSS2

1.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:N/A:N

EPSS

0

Percentile

5.1%