The OpenSSL extension of Ruby (Git trunk) versions after 2011-09-01 up to 2011-11-03 always generated an exponent value of '1' to be used for private RSA key generation. A remote attacker could use this flaw to bypass or corrupt integrity of services, depending on strong private RSA keys generation mechanism.
Advisories
Source ID Title
EUVD EUVD EUVD-2011-4069 The OpenSSL extension of Ruby (Git trunk) versions after 2011-09-01 up to 2011-11-03 always generated an exponent value of '1' to be used for private RSA key generation. A remote attacker could use this flaw to bypass or corrupt integrity of services, depending on strong private RSA keys generation mechanism.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-07T00:01:50.387Z

Reserved: 2011-10-18T00:00:00

Link: CVE-2011-4121

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-11-26T05:15:13.960

Modified: 2024-11-21T01:31:53.367

Link: CVE-2011-4121

cve-icon Redhat

Severity : Important

Publid Date: 2011-11-03T00:00:00Z

Links: CVE-2011-4121 - Bugzilla

cve-icon OpenCVE Enrichment

No data.