|
|
|
![]() |
Vulnerability Note VU#527736mkpasswd uses weak random number generatorOverviewMkpasswd generates passwords that are insufficiently random.I. DescriptionMkpasswd is a password generation utility included with Red Hat Linux and possibly other Linux distributions. Mkpasswd generates passwords that are not sufficiently random, which may allow an attacker to predict passwords and consequently gain unauthorized access to other accounts on the system. This vulnerability occurs because mkpasswd uses the current process ID as the seed for the random number generator. Because of this, the number of passwords is limited to the size of the process table on the operating system.II. ImpactAn attacker may be able to predict passwords and consequently gain unauthorized access to other accounts on the system.III. SolutionApply a patch from your vendor.Systems Affected
Referenceshttp://www.securitytracker.com/alerts/2001/Apr/1001303.html This vulnerability was reported by Shez <shez@molions.com>. This document was written by Ian A. Finlay.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
||||||||||||||||||||||||||||||||||||||||||||||||||||
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||