Use of insufficiently random values in Data-Entropy - CVE-2025-1860
Published: March 31, 2025
Vulnerability identifier: #VU106276
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-1860
CWE-ID: CWE-330
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows an attacker to bypass implemented security restrictions.
The vulnerability exists due to software uses the rand() function as the default source of entropy, which is not cryptographically secure. A remote attacker can bypass implemented security restrictions.
Affected software
Data-Entropy
Fedora
perl-Data-Entropy
Fedora
perl-Data-Entropy
How to mitigate CVE-2025-1860
Install updates from vendor's website.
Data-Entropy - update to 0.008
perl-Data-Entropy - addressed in versions 0.008-1.el8, 0.008-1.el9, 0.008-1.fc40, 0.008-1.fc41, 0.008-1.fc42
perl-Data-Entropy - addressed in versions 0.008-1.el8, 0.008-1.el9, 0.008-1.fc40, 0.008-1.fc41, 0.008-1.fc42