CVE-2011-0766

The random number generator in the Crypto application before 2.0.2.2, and SSH before 2.0.5, as used in the Erlang/OTP ssh library before R14B03, uses predictable seeds based on the current time, which makes it easier for remote attackers to guess DSA host and SSH session keys.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:erlang:crypto:*:*:*:*:*:*:*:*
cpe:2.3:a:erlang:erlang\/otp:r11b-5:*:*:*:*:*:*:*
cpe:2.3:a:erlang:erlang\/otp:r12b-5:*:*:*:*:*:*:*
cpe:2.3:a:erlang:erlang\/otp:r13b:*:*:*:*:*:*:*
cpe:2.3:a:erlang:erlang\/otp:r13b02-1:*:*:*:*:*:*:*
cpe:2.3:a:erlang:erlang\/otp:r13b03:*:*:*:*:*:*:*
cpe:2.3:a:erlang:erlang\/otp:r13b04:*:*:*:*:*:*:*
cpe:2.3:a:erlang:erlang\/otp:r14a:*:*:*:*:*:*:*
cpe:2.3:a:erlang:erlang\/otp:r14b:*:*:*:*:*:*:*
cpe:2.3:a:erlang:erlang\/otp:r14b01:*:*:*:*:*:*:*
cpe:2.3:a:erlang:erlang\/otp:r14b02:*:*:*:*:*:*:*
cpe:2.3:a:ssh:ssh:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2011-05-31 20:55

Updated : 2025-04-11 00:51


NVD link : CVE-2011-0766

Mitre link : CVE-2011-0766

CVE.ORG link : CVE-2011-0766


JSON object : View

Products Affected

ssh

  • ssh

erlang

  • erlang\/otp
  • crypto
CWE
CWE-310

Cryptographic Issues