ValiCert Enterprise Validation Authority (EVA) Administration Server 3.3 through 4.2.1 uses insufficiently random data to (1) generate session tokens for HSMs using the C rand function, or (2) generate certificates or keys using /dev/urandom instead of another source which blocks when the entropy pool is low, which could make it easier for local or remote attackers to steal tokens or certificates via brute force guessing.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2002-02-02T05:00:00
Updated: 2024-08-08T04:37:07.002Z
Reserved: 2002-01-31T00:00:00
Link: CVE-2001-0950
Vulnrichment
No data.
NVD
Status : Modified
Published: 2001-12-04T05:00:00.000
Modified: 2024-11-20T23:36:30.883
Link: CVE-2001-0950
Redhat
No data.