Security Advisory

CVE-2014-0017

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2014-03-14 15:00:00
Last updated 2024-08-06 08:58:26
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

The RAND_bytes function in libssh before 0.6.3, when forking is enabled, does not properly reset the state of the OpenSSL pseudo-random number generator (PRNG), which causes the state to be shared between children processes and allows local users to obtain sensitive information by leveraging a pid collision.