4.6
CVSSv2

CVE-2005-0106

Published: 03/05/2005 Updated: 03/10/2018
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SSLeay.pm in libnet-ssleay-perl prior to 1.25 uses the /tmp/entropy file for entropy if a source is not set in the EGD_PATH variable, which allows local users to reduce the cryptographic strength of certain operations by modifying the file.

Vulnerable Product Search on Vulmon Subscribe to Product

ubuntu ubuntu linux 5.04

Vendor Advisories

Javier Fernandez-Sanguino Pena discovered that this library used the file /tmp/entropy as a fallback entropy source if a proper source was not set in the environment variable EGD_PATH This can potentially lead to weakened cryptographic operations if an attacker provides a /tmp/entropy file with known content ...