Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

OpenSSL FIPS Object Module PRNG Seed Vulnerability

OpenSSL is prone to a vulnerability that results in significantly weakened cryptographic security.

The OpenSSL FIPS Object Module PRNG implementation contains a serious flaw in the way the key and seed are determined. This results in a predictable PRNG output.

OpenSSL FIPS Object Module v1.1.1 is reported vulnerable.

NOTE: Changes to FIPS 140-2 validated software require official approval. The Open Source Software Institute (OSSI) has submitted patch information to the FIPS 140-2 test lab; the patches are pending approval. The estimated time to approval is currently unknown. The patches that were submitted and awaiting approval are available.







 

Privacy Statement
Copyright 2009, SecurityFocus