CVE-2011-0766 Information

Description

The random number generator in the Crypto application before 2.0.2.2 and SSH before 2.0.5 as used in the Erlang/OTP ssh library before R14B03 uses predictable seeds based on the current time which makes it easier for remote attackers to guess DSA host and SSH session keys.

Reference

http://secunia.com/advisories/44709 http://www.kb.cert.org/vuls/id/178990 http://www.securityfocus.com/bid/47980 https://github.com/erlang/otp/commit/f228601de45c5b53241b103af6616453c50885a5

Share on: