Security Advisory

CVE-2011-0766

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2011-05-31 20:00:00
Last updated 2024-09-17 04:29:25
Assigner certcc
CVSS score not scored
State PUBLISHED

Description

The random number generator in the Crypto application before 2.0.2.2, and SSH before 2.0.5, as used in the Erlang/OTP ssh library before R14B03, uses predictable seeds based on the current time, which makes it easier for remote attackers to guess DSA host and SSH session keys.