[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247862

 
 

909

 
 

194603

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2014-0016Date: (C)2015-12-16   (M)2023-12-22


stunnel before 5.00, when using fork threading, does not properly update the state of the OpenSSL pseudo-random number generator (PRNG), which causes subsequent children with the same process ID to use the same entropy pool and allows remote attackers to obtain private keys for EC (ECDSA) or DSA certificates.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 4.3
Exploit Score: 8.6
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: PARTIAL
Integrity: NONE
Availability: NONE
  
Reference:
BID-65964
http://www.openwall.com/lists/oss-security/2014/03/05/1
https://bugzilla.redhat.com/attachment.cgi?id=870826&action=diff
https://bugzilla.redhat.com/show_bug.cgi?id=1072180
https://www.stunnel.org/sdf_ChangeLog.html

CPE    2
cpe:/a:stunnel:stunnel
cpe:/a:stunnel:stunnel:4.55
CWE    1
CWE-332
OVAL    3
oval:org.secpod.oval:def:2100729
oval:org.secpod.oval:def:106866
oval:org.secpod.oval:def:106873

© SecPod Technologies