V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2007-4311
DEB
MediumConfirmedExploit available

The xfer_secondary_pool function in drivers/char/random.c in the Linux kernel 2.4 before 2.4.35 performs reseed operations on only the firs…

CVSS
6.8
Medium
EPSS
0.01
p71
Published
2007-01-01
Updated
2007-01-01
Description

The xfer_secondary_pool function in drivers/char/random.c in the Linux kernel 2.4 before 2.4.35 performs reseed operations on only the first few bytes of a buffer, which might make it easier for attackers to predict the output of the random number generator, related to incorrect use of the sizeof operator.

Tags · CWE
CWE-310
Affected products
Linux_kernel ≤ 2.4.34
CVSS vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Timeline
2007-01-01
Published
2007-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: M
Medium
Authentication
Au: N
None (N)
Confidentiality Impact
C: P
Partial
Integrity Impact
I: P
Partial
Availability Impact
A: P
Partial
Exploit indicators
EPSS
0.007 · p71
Known exploited (KEV)
No
Known exploits — Сканер-ВС
30080
exploitdb · https://www.exploit-db.com/exploits/30080
Enterprise
30604
exploitdb · https://www.exploit-db.com/exploits/30604
Enterprise
30605
exploitdb · https://www.exploit-db.com/exploits/30605
Enterprise
4460
exploitdb · https://www.exploit-db.com/exploits/4460
Enterprise
6851
exploitdb · https://www.exploit-db.com/exploits/6851
Enterprise
7618
exploitdb · https://www.exploit-db.com/exploits/7618
Enterprise
CVE-2006-4814
github-poc · https://github.com/tagatac/linux-CVE-2006-4814
Enterprise
Affected software
ProductVendorStatus
linux-2.6Tracked
linux_kernel*Tracked