CVE-2011-0766

Erlang/OTP Crypto < 2.0.2.2 and SSH < 2.0.5 - Predictable Seed in Random Number Generator

Title source: llm
STIX 2.1

Description

The random number generator in the Crypto application before 2.0.2.2, and SSH before 2.0.5, as used in the Erlang/OTP ssh library before R14B03, uses predictable seeds based on the current time, which makes it easier for remote attackers to guess DSA host and SSH session keys.

References (4)

Core 4
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/44709
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/47980
Patch, Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/178990

Scores

EPSS 0.0305
EPSS Percentile 86.0%

Details

CWE
CWE-310
Status published
Products (12)
erlang/crypto < 2.0.2.1
erlang/erlang\/otp r11b-5
erlang/erlang\/otp r12b-5
erlang/erlang\/otp r13b
erlang/erlang\/otp r13b02-1
erlang/erlang\/otp r13b03
erlang/erlang\/otp r13b04
erlang/erlang\/otp r14a
erlang/erlang\/otp r14b
erlang/erlang\/otp r14b01
... and 2 more
Published May 31, 2011
Tracked Since Feb 18, 2026