#VU22999 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in NetBSD


Published: 2019-11-26

Vulnerability identifier: #VU22999

Vulnerability risk: Low

CVSSv3.1: 4.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C]

CVE-ID: N/A

CWE-ID: CWE-338

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
NetBSD
Operating systems & Components / Operating system

Vendor: NetBSD Foundation, Inc

Description

The vulnerability allows a local user to predict values of random generator.

The vulnerability exists due to en error in kern.arandom implementation. A local user that can obtain kernel PRNG state used by kern.arandom can predict future outputs of kern.arandom.

Mitigation
Install updates from vendor's website.

Vulnerable software versions

NetBSD: 7.1 - 8.0


External links
http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2019-005.txt.asc


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability