CVE Vulnerabilities

CVE-2011-0766

Published: May 31, 2011 | Modified: Jul 13, 2011
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.8 HIGH
AV:N/AC:L/Au:N/C:C/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

The random number generator in the Crypto application before 2.0.2.2, and SSH before 2.0.5, as used in the Erlang/OTP ssh library before R14B03, uses predictable seeds based on the current time, which makes it easier for remote attackers to guess DSA host and SSH session keys.

Affected Software

Name Vendor Start Version End Version
Crypto Erlang 1.0 1.0
Crypto Erlang 1.1 1.1
Crypto Erlang 1.1.1 1.1.1
Crypto Erlang 1.1.2 1.1.2
Crypto Erlang 1.1.3 1.1.3
Crypto Erlang 1.2 1.2
Crypto Erlang 1.2.1 1.2.1
Crypto Erlang 1.2.2 1.2.2
Crypto Erlang 1.2.3 1.2.3
Crypto Erlang 1.3 1.3
Crypto Erlang 1.4 1.4
Crypto Erlang 1.5 1.5
Crypto Erlang 1.5.1.1 1.5.1.1
Crypto Erlang 1.5.2 1.5.2
Crypto Erlang 1.5.2.1 1.5.2.1
Crypto Erlang 1.5.3 1.5.3
Crypto Erlang 1.6 1.6
Crypto Erlang 1.6.1 1.6.1
Crypto Erlang 1.6.2 1.6.2
Crypto Erlang 1.6.3 1.6.3
Crypto Erlang 1.6.4 1.6.4
Crypto Erlang 2.0 2.0
Crypto Erlang 2.0.1 2.0.1
Crypto Erlang 2.0.2 2.0.2
Crypto Erlang * 2.0.2.1
Erlang/otp Erlang r11b-5 r11b-5
Erlang/otp Erlang r12b-5 r12b-5
Erlang/otp Erlang r13b r13b
Erlang/otp Erlang r13b02-1 r13b02-1
Erlang/otp Erlang r13b03 r13b03
Erlang/otp Erlang r13b04 r13b04
Erlang/otp Erlang r14a r14a
Erlang/otp Erlang r14b r14b
Erlang/otp Erlang r14b01 r14b01
Erlang/otp Erlang * r14b02
Ssh Ssh 1.2.0 1.2.0
Ssh Ssh 1.2.1 1.2.1
Ssh Ssh 1.2.2 1.2.2
Ssh Ssh 1.2.3 1.2.3
Ssh Ssh 1.2.4 1.2.4
Ssh Ssh 1.2.5 1.2.5
Ssh Ssh 1.2.6 1.2.6
Ssh Ssh 1.2.7 1.2.7
Ssh Ssh 1.2.8 1.2.8
Ssh Ssh 1.2.9 1.2.9
Ssh Ssh 1.2.10 1.2.10
Ssh Ssh 1.2.11 1.2.11
Ssh Ssh 1.2.12 1.2.12
Ssh Ssh 1.2.13 1.2.13
Ssh Ssh 1.2.14 1.2.14
Ssh Ssh 1.2.15 1.2.15
Ssh Ssh 1.2.16 1.2.16
Ssh Ssh 1.2.17 1.2.17
Ssh Ssh 1.2.18 1.2.18
Ssh Ssh 1.2.19 1.2.19
Ssh Ssh 1.2.20 1.2.20
Ssh Ssh 1.2.21 1.2.21
Ssh Ssh 1.2.22 1.2.22
Ssh Ssh 1.2.23 1.2.23
Ssh Ssh 1.2.24 1.2.24
Ssh Ssh 1.2.25 1.2.25
Ssh Ssh 1.2.26 1.2.26
Ssh Ssh 1.2.27 1.2.27
Ssh Ssh 1.2.28 1.2.28
Ssh Ssh 1.2.29 1.2.29
Ssh Ssh 1.2.30 1.2.30
Ssh Ssh 1.2.31 1.2.31
Ssh Ssh * 2.0.4
Erlang Ubuntu hardy *
Erlang Ubuntu lucid *
Erlang Ubuntu maverick *
Erlang Ubuntu natty *
Erlang Ubuntu oneiric *
Erlang Ubuntu upstream *

References