Use of insufficiently random values in Data-Entropy - CVE-2025-1860

 

Use of insufficiently random values in Data-Entropy - CVE-2025-1860

Published: March 31, 2025


Vulnerability identifier: #VU106276
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-1860
CWE-ID: CWE-330
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker to bypass implemented security restrictions.

The vulnerability exists due to software uses the rand() function as the default source of entropy, which is not cryptographically secure. A remote attacker can bypass implemented security restrictions.


Affected software

Data-Entropy
Fedora
perl-Data-Entropy

How to mitigate CVE-2025-1860

Install updates from vendor's website.

Data-Entropy - update to 0.008
perl-Data-Entropy - addressed in versions 0.008-1.el8, 0.008-1.el9, 0.008-1.fc40, 0.008-1.fc41, 0.008-1.fc42

External References

Related Security Bulletins