CVE-2015-5276
Severity
5.0MEDIUM
EPSS
0.4%
top 36.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 17
Latest updateMay 14
Description
The std::random_device class in libstdc++ in the GNU Compiler Collection (aka GCC) before 4.9.4 does not properly handle short reads from blocking sources, which makes it easier for context-dependent attackers to predict the random values via unspecified vectors.
CVSS vector
AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9
Affected Packages1 packages
š“Vulnerability Details
3GHSAā¶
GHSA-rq8f-f9q7-5x24: The std::random_device class in libstdc++ in the GNU Compiler Collection (aka GCC) before 4ā2022-05-14
OSVā¶
CVE-2015-5276: The std::random_device class in libstdc++ in the GNU Compiler Collection (aka GCC) before 4ā2015-11-17
CVEListā¶
CVE-2015-5276: The std::random_device class in libstdc++ in the GNU Compiler Collection (aka GCC) before 4ā2015-11-17