Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2007-5502
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2007-5502

Description:
The PRNG implementation for the OpenSSL FIPS Object Module 1.1.1 does not perform auto-seeding during the FIPS self-test, which generates random data that is more predictable than expected and makes it easier for attackers to bypass protection mechanisms that rely on the randomness.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/38796

ST
  1019029

SAID
  Secunia Advisory: SA27859

CONFIRM
  http://www.openssl.org/news/secadv_20071129.txt

CERT-VN
  150249

BID
  26652


Return to the previous page.