Lucene search

K
nvd[email protected]NVD:CVE-2014-0017
HistoryMar 14, 2014 - 3:55 p.m.

CVE-2014-0017

2014-03-1415:55:05
CWE-310
web.nvd.nist.gov
6

CVSS2

1.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:N/A:N

AI Score

8

Confidence

High

EPSS

0

Percentile

5.1%

The RAND_bytes function in libssh before 0.6.3, when forking is enabled, does not properly reset the state of the OpenSSL pseudo-random number generator (PRNG), which causes the state to be shared between children processes and allows local users to obtain sensitive information by leveraging a pid collision.

Affected configurations

Nvd
Node
libsshlibsshRange≀0.6.2
OR
libsshlibsshMatch0.4.7
OR
libsshlibsshMatch0.4.8
OR
libsshlibsshMatch0.5.0
OR
libsshlibsshMatch0.5.0rc1
OR
libsshlibsshMatch0.5.1
OR
libsshlibsshMatch0.5.2
OR
libsshlibsshMatch0.5.3
OR
libsshlibsshMatch0.5.4
OR
libsshlibsshMatch0.5.5
OR
libsshlibsshMatch0.6.0
OR
libsshlibsshMatch0.6.1
VendorProductVersionCPE
libsshlibssh*cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:*
libsshlibssh0.4.7cpe:2.3:a:libssh:libssh:0.4.7:*:*:*:*:*:*:*
libsshlibssh0.4.8cpe:2.3:a:libssh:libssh:0.4.8:*:*:*:*:*:*:*
libsshlibssh0.5.0cpe:2.3:a:libssh:libssh:0.5.0:*:*:*:*:*:*:*
libsshlibssh0.5.0cpe:2.3:a:libssh:libssh:0.5.0:rc1:*:*:*:*:*:*
libsshlibssh0.5.1cpe:2.3:a:libssh:libssh:0.5.1:*:*:*:*:*:*:*
libsshlibssh0.5.2cpe:2.3:a:libssh:libssh:0.5.2:*:*:*:*:*:*:*
libsshlibssh0.5.3cpe:2.3:a:libssh:libssh:0.5.3:*:*:*:*:*:*:*
libsshlibssh0.5.4cpe:2.3:a:libssh:libssh:0.5.4:*:*:*:*:*:*:*
libsshlibssh0.5.5cpe:2.3:a:libssh:libssh:0.5.5:*:*:*:*:*:*:*
Rows per page:
1-10 of 121

CVSS2

1.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:N/A:N

AI Score

8

Confidence

High

EPSS

0

Percentile

5.1%