|
CVE Reference: CVE-2006-3419
|
|
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.
|
|
Original Page at CVE MITRE:
CVE-2006-3419
|
|
Description:
Tor before 0.1.1.20 uses OpenSSL pseudo-random bytes (RAND_pseudo_bytes) instead of cryptographically strong RAND_bytes, and seeds the entropy value at start-up with 160-bit chunks without reseeding, which makes it easier for attackers to conduct brute force guessing attacks.
|
|
CVE Status:
Candidate
|
|
References:
SAID Secunia Advisory: SA20514
OSVDB 25880
GENTOO http://security.gentoo.org/glsa/glsa-200606-04.xml
CONFIRM http://tor.eff.org/cvs/tor/ChangeLog
|
|
|
Return to the previous page.
|