SB2007061204 - Predictable seed in pseudo-random number generator (prng) in Linux kernel



SB2007061204 - Predictable seed in pseudo-random number generator (prng) in Linux kernel

Published: June 12, 2007

Security Bulletin ID SB2007061204
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Predictable seed in pseudo-random number generator (prng) (CVE-ID: CVE-2007-2453)

The vulnerability allows a local user to gain access to sensitive information.

The random number feature in Linux kernel 2.6 before 2.6.20.13, and 2.6.21.x before 2.6.21.4, (1) does not properly seed pools when there is no entropy, or (2) uses an incorrect cast when extracting entropy, which might cause the random number generator to provide the same values after reboots on systems without an entropy source.


Remediation

Install update from vendor's website.