|
OpenSSL FIPS Object Module PRNG Seed Vulnerability
OpenSSL is prone to a vulnerability that results in significantly weakened cryptographic security. The OpenSSL FIPS Object Module PRNG implementation contains a serious flaw in the way the key and seed are determined. This results in a predictable PRNG output. OpenSSL FIPS Object Module v1.1.1 is reported vulnerable. NOTE: Changes to FIPS 140-2 validated software require official approval. The Open Source Software Institute (OSSI) has submitted patch information to the FIPS 140-2 test lab; the patches are pending approval. The estimated time to approval is currently unknown. The patches that were submitted and awaiting approval are available. |
|
|
Privacy Statement |