Sha256: fc8454edf79b2cff52a145e2b460d806059b0841fba11be2d2d27a3cece4fdf7
Contents?: true
Size: 596 Bytes
Versions: 6
Compression:
Stored size: 596 Bytes
Contents
--- engine: ruby cve: 2011-2705 url: https://redmine.ruby-lang.org/issues/4579 title: Ruby Random Number Generation Local Denial Of Service Vulnerability date: 2011-07-02 description: | The SecureRandom.random_bytes function in lib/securerandom.rb in Ruby before 1.8.7-p352 and 1.9.x before 1.9.2-p290 relies on PID values for initialization, which makes it easier for context-dependent attackers to predict the result string by leveraging knowledge of random strings obtained in an earlier process with the same PID. cvss_v2: 5.0 patched_versions: - ~> 1.8.7.352 - ">= 1.9.2.290"
Version data entries
6 entries across 6 versions & 2 rubygems