libnet-ssleay-perl: weakened cryptographic operations
| Package(s): | libnet-ssleay-perl | CVE #(s): | CAN-2005-0106 | ||||||||
| Created: | May 3, 2005 | Updated: | January 27, 2006 | ||||||||
| Description: | Javier Fernandez-Sanguino Pena discovered that this library used the file /tmp/entropy as a fallback entropy source if a proper source was not set in the environment variable EGD_PATH. This can potentially lead to weakened cryptographic operations if an attacker provides a /tmp/entropy file with known content. | ||||||||||
| Alerts: |
| ||||||||||
