mkpasswd in expect 5.2.8, as used by Red Hat Linux 6.2 through 7.0, seeds its random number generator with its process ID, which limits the space of possible seeds and makes it easier for attackers to conduct brute force password attacks.
References
Configurations
Information
Published : 2001-04-10 21:00
Updated : 2017-07-10 18:29
NVD link : CVE-2001-1467
Mitre link : CVE-2001-1467
JSON object : View
CWE
Products Affected
don_libes
- expect