Security Advisory

CVE-2011-3599

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2011-10-10 10:00:00
Last updated 2024-08-06 23:37:48
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

The Crypt::DSA (aka Crypt-DSA) module 1.17 and earlier for Perl, when /dev/random is absent, uses the Data::Random module, which makes it easier for remote attackers to spoof a signature, or determine the signing key of a signed message, via a brute-force attack.