LWN.net Logo

plexus-cipher: insufficiently random salt

Package(s):plexus-cipher CVE #(s):
Created:December 6, 2012 Updated:December 12, 2012
Description: getSalt() falls back to Random (seeded by the current time) instead of SecureRandom.

These bugs just decreases the randomness of the salt/IV, so they may not actually result in an exploitable security vulnerability. But that depends on how this class is used.

See the Red Hat bugzilla for details.

Alerts:
Fedora FEDORA-2012-19233 2012-12-06
Fedora FEDORA-2012-19267 2012-12-06

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds