The random number feature in Linux kernel 2.6 before 2.6.20.13, and 2.6.21.x before 2.6.21.4, (1) does not properly seed pools when there is no entropy, or (2) uses an incorrect cast when extracting entropy, which might cause the random number generator to provide the same values after reboots on systems without an entropy source.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 00:30
Type | Values Removed | Values Added |
---|---|---|
References | () http://marc.info/?l=linux-kernel&m=118128610219959&w=2Â - Patch | |
References | () http://marc.info/?l=linux-kernel&m=118128622431272&w=2Â - Patch | |
References | () http://osvdb.org/37114Â - | |
References | () http://secunia.com/advisories/25596Â - | |
References | () http://secunia.com/advisories/25700Â - | |
References | () http://secunia.com/advisories/25961Â - | |
References | () http://secunia.com/advisories/26133Â - | |
References | () http://secunia.com/advisories/26139Â - | |
References | () http://secunia.com/advisories/26450Â - | |
References | () http://secunia.com/advisories/26620Â - | |
References | () http://secunia.com/advisories/26664Â - | |
References | () http://www.debian.org/security/2007/dsa-1356Â - | |
References | () http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.21.4Â - | |
References | () http://www.mandriva.com/security/advisories?name=MDKSA-2007:171Â - | |
References | () http://www.mandriva.com/security/advisories?name=MDKSA-2007:196Â - | |
References | () http://www.mandriva.com/security/advisories?name=MDKSA-2007:216Â - | |
References | () http://www.novell.com/linux/security/advisories/2007_43_kernel.html - | |
References | () http://www.novell.com/linux/security/advisories/2007_51_kernel.html - | |
References | () http://www.securityfocus.com/bid/24390Â - | |
References | () http://www.securitytracker.com/id?1018248Â - | |
References | () http://www.ubuntu.com/usn/usn-470-1Â - | |
References | () http://www.ubuntu.com/usn/usn-486-1Â - | |
References | () http://www.ubuntu.com/usn/usn-489-1Â - | |
References | () http://www.vupen.com/english/advisories/2007/2105Â - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/34781Â - | |
References | () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9960Â - | |
References | () https://rhn.redhat.com/errata/RHSA-2007-0376.html - |
Information
Published : 2007-06-11 23:30
Updated : 2024-11-21 00:30
NVD link : CVE-2007-2453
Mitre link : CVE-2007-2453
CVE.ORG link : CVE-2007-2453
JSON object : View
Products Affected
linux
- linux_kernel
CWE