|
Joshua Chamas Crypt::SSLeay Perl Module Insecure Entropy Source Vulnerability
Crypt::SSLeay is prone to a security vulnerability. Reports indicate that the library employs a file from a world-writable location for its fallback entropy source. The module defaults to this file if a proper entropy source is not set. If the affected library is using the insecure file as a source of entropy, a local attacker may replace the contents of the file with known text. This known text is then employed to seed cryptographic operations. This may lead to weak cryptographic operations. |
|
|
Privacy Statement |