Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Joshua Chamas Crypt::SSLeay Perl Module Insecure Entropy Source Vulnerability

Crypt::SSLeay is prone to a security vulnerability. Reports indicate that the library employs a file from a world-writable location for its fallback entropy source. The module defaults to this file if a proper entropy source is not set.

If the affected library is using the insecure file as a source of entropy, a local attacker may replace the contents of the file with known text. This known text is then employed to seed cryptographic operations. This may lead to weak cryptographic operations.







 

Privacy Statement
Copyright 2009, SecurityFocus