SSLeay.pm in libnet-ssleay-perl prior to 1.25 uses the /tmp/entropy file for entropy if a source is not set in the EGD_PATH variable, which allows local users to reduce the cryptographic strength of certain operations by modifying the file.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
ubuntu ubuntu linux 5.04 |