CVE Vulnerabilities

CVE-2007-5502

Published: Dec 01, 2007 | Modified: Jul 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
NEGLIGIBLE

The PRNG implementation for the OpenSSL FIPS Object Module 1.1.1 does not perform auto-seeding during the FIPS self-test, which generates random data that is more predictable than expected and makes it easier for attackers to bypass protection mechanisms that rely on the randomness.

Affected Software

Name Vendor Start Version End Version
Fips_object_module Openssl 1.1.1 (including) 1.1.1 (including)

References