LWN.net Logo

ruby: predictable random numbers

Package(s):ruby CVE #(s):CVE-2011-2686 CVE-2011-2705
Created:July 26, 2011 Updated:January 31, 2012
Description: From the Red Hat bugzilla:

It was found that Ruby did not properly reinitialize the random number generator, when forking new Ruby process. A local attacker could use this flaw to easier predict random numbers.

Alerts:
Scientific Linux SL-ruby-20111206 2011-12-06
Red Hat RHSA-2011:1581-03 2011-12-06
Fedora FEDORA-2011-9374 2011-07-16
Fedora FEDORA-2011-9359 2011-07-16
Pardus 2011-101 2011-08-03
Red Hat RHSA-2012:0070-01 2012-01-30
CentOS CESA-2012:0070 2012-01-30
CentOS CESA-2012:0070 2012-01-30
Oracle ELSA-2012-0070 2012-01-31
Oracle ELSA-2012-0070 2012-01-31
Scientific Linux SL-ruby-20120130 2012-01-30
openSUSE openSUSE-SU-2012:0228-1 2012-02-09
Ubuntu USN-1377-1 2012-02-27

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds