CVE-2005-0106
published 2005-05-03CVE-2005-0106: SSLeay.pm in libnet-ssleay-perl before 1.25 uses the /tmp/entropy file for entropy if a source is not set in the EGD_PATH variable, which allows local users to…
PriorityP48medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
0.35%
27.5th percentile
SSLeay.pm in libnet-ssleay-perl before 1.25 uses the /tmp/entropy file for entropy if a source is not set in the EGD_PATH variable, which allows local users to reduce the cryptographic strength of certain operations by modifying the file.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libnet-ssleay-perl | < libnet-ssleay-perl 1.25-1.1 (bookworm) | libnet-ssleay-perl 1.25-1.1 (bookworm) |
| ubuntu | ubuntu_linux | — | — |
CVSS provenance
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv4.6MEDIUM
vendor_debian4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c8r4-w8p2-gf3q: SSLeay
ghsa_unreviewed·2022-05-01
CVE-2005-0106 [MEDIUM] GHSA-c8r4-w8p2-gf3q: SSLeay
SSLeay.pm in libnet-ssleay-perl before 1.25 uses the /tmp/entropy file for entropy if a source is not set in the EGD_PATH variable, which allows local users to reduce the cryptographic strength of certain operations by modifying the file.
OSV
CVE-2005-0106: SSLeay
osv·2005-05-03·CVSS 4.6
CVE-2005-0106 [MEDIUM] CVE-2005-0106: SSLeay
SSLeay.pm in libnet-ssleay-perl before 1.25 uses the /tmp/entropy file for entropy if a source is not set in the EGD_PATH variable, which allows local users to reduce the cryptographic strength of certain operations by modifying the file.
Ubuntu
libnet-ssleay-perl vulnerability
vendor_ubuntu·2005-05-03
CVE-2005-0106 libnet-ssleay-perl vulnerability
Title: libnet-ssleay-perl vulnerability
Summary: libnet-ssleay-perl vulnerability
Javier Fernandez-Sanguino Pena discovered that this library used the
file /tmp/entropy as a fallback entropy source if a proper source was
not set in the environment variable EGD_PATH. This can potentially
lead to weakened cryptographic operations if an attacker provides a
/tmp/entropy file with known content.
The updated package requires the specification of an entropy source
with EGD_PATH and also requires that the source is a socket (as
opposed to a normal file).
Please note that this only affects systems which have egd installed
from third party sources; egd is not shipped with Ubuntu.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2005-0106: libnet-ssleay-perl - SSLeay.pm in libnet-ssleay-perl before 1.25 uses the /tmp/entropy file for entro...
vendor_debian·2005·CVSS 4.6
CVE-2005-0106 [MEDIUM] CVE-2005-0106: libnet-ssleay-perl - SSLeay.pm in libnet-ssleay-perl before 1.25 uses the /tmp/entropy file for entro...
SSLeay.pm in libnet-ssleay-perl before 1.25 uses the /tmp/entropy file for entropy if a source is not set in the EGD_PATH variable, which allows local users to reduce the cryptographic strength of certain operations by modifying the file.
Scope: local
bookworm: resolved (fixed in 1.25-1.1)
bullseye: resolved (fixed in 1.25-1.1)
forky: resolved (fixed in 1.25-1.1)
sid: resolved (fixed in 1.25-1.1)
trixie: resolved (fixed in 1.25-1.1)
No detection rules found.
No public exploits indexed.
http://secunia.com/advisories/18639http://www.mandriva.com/security/advisories?name=MDKSA-2006:023http://www.securityfocus.com/bid/13471https://usn.ubuntu.com/113-1/http://secunia.com/advisories/18639http://www.mandriva.com/security/advisories?name=MDKSA-2006:023http://www.securityfocus.com/bid/13471https://usn.ubuntu.com/113-1/
2005-05-03
Published