CVE-2012-6124
published 2019-10-31CVE-2012-6124: A casting error in Chicken before 4.8.0 on 64-bit platform caused the random number generator to return a constant value. NOTE: the vendor states "This…
PriorityP421medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
1.25%
66.4th percentile
A casting error in Chicken before 4.8.0 on 64-bit platform caused the random number generator to return a constant value. NOTE: the vendor states "This function wasn't used for security purposes (and is advertised as being unsuitable)."
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| call-cc | chicken | < 4.8.0 | 4.8.0 |
| chicken | chicken | — | — |
| chicken | chicken | >= 0 < 4.8.0-1 | 4.8.0-1 |
| chicken | chicken | >= 0 < 4.8.0-1 | 4.8.0-1 |
| chicken | chicken | >= 0 < 4.8.0-1 | 4.8.0-1 |
| chicken | chicken | >= 0 < 4.8.0-1 | 4.8.0-1 |
| debian | chicken | < chicken 4.8.0-1 (bookworm) | chicken 4.8.0-1 (bookworm) |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.3MEDIUM
vendor_debian5.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-59j9-qv68-3xx5: A casting error in Chicken before 4
ghsa_unreviewed·2022-04-23
CVE-2012-6124 [MEDIUM] CWE-338 GHSA-59j9-qv68-3xx5: A casting error in Chicken before 4
A casting error in Chicken before 4.8.0 on 64-bit platform caused the random number generator to return a constant value. NOTE: the vendor states "This function wasn't used for security purposes (and is advertised as being unsuitable)."
OSV
CVE-2012-6124: A casting error in Chicken before 4
osv·2019-10-31·CVSS 5.3
CVE-2012-6124 [MEDIUM] CVE-2012-6124: A casting error in Chicken before 4
A casting error in Chicken before 4.8.0 on 64-bit platform caused the random number generator to return a constant value. NOTE: the vendor states "This function wasn't used for security purposes (and is advertised as being unsuitable)."
Debian
CVE-2012-6124: chicken - A casting error in Chicken before 4.8.0 on 64-bit platform caused the random num...
vendor_debian·2012·CVSS 5.3
CVE-2012-6124 [MEDIUM] CVE-2012-6124: chicken - A casting error in Chicken before 4.8.0 on 64-bit platform caused the random num...
A casting error in Chicken before 4.8.0 on 64-bit platform caused the random number generator to return a constant value. NOTE: the vendor states "This function wasn't used for security purposes (and is advertised as being unsuitable)."
Scope: local
bookworm: resolved (fixed in 4.8.0-1)
bullseye: resolved (fixed in 4.8.0-1)
forky: resolved (fixed in 4.8.0-1)
sid: resolved (fixed in 4.8.0-1)
trixie: resolved (fixed in 4.8.0-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2013/02/08/2https://access.redhat.com/security/cve/cve-2012-6124https://lists.nongnu.org/archive/html/chicken-hackers/2012-02/msg00084.htmlhttps://security-tracker.debian.org/tracker/CVE-2012-6124http://www.openwall.com/lists/oss-security/2013/02/08/2https://access.redhat.com/security/cve/cve-2012-6124https://lists.nongnu.org/archive/html/chicken-hackers/2012-02/msg00084.htmlhttps://security-tracker.debian.org/tracker/CVE-2012-6124
2019-10-31
Published