The xfer_secondary_pool function in drivers/char/random.c in the Linux kernel 2.4 before 2.4.35 performs reseed operations on only the first few bytes of a buffer, which might make it easier for attackers to predict the output of the random number generator, related to incorrect use of the sizeof operator.
References
Configurations
Information
Published : 2007-08-13 14:17
Updated : 2011-05-24 21:00
NVD link : CVE-2007-4311
Mitre link : CVE-2007-4311
JSON object : View
CWE
CWE-310
Cryptographic Issues
Products Affected
linux
- linux_kernel