VDB
CVE-2011-3009
CVE-2011-3009
PUBLISHED
Reported by mitre · Published August 5, 2011
Ruby before 1.8.6-p114 does not reset the random seed upon forking, which makes it easier for context-dependent attackers to predict the values of random numbers by leveraging knowledge of the number sequence obtained in a different child process, a related issue to CVE-2003-0900.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| n/a | n/a | *, n/a |
Timeline
- Aug 5, 2011 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 3, 2022 EPSS Score
- Dec 17, 2022 EPSS Score
- Feb 8, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 1, 2023 EPSS Score
- May 24, 2023 EPSS Score
- Jul 15, 2023 EPSS Score
References
- 49126 vdb-entryx_refsource_BID
- RHSA-2011:1581 vendor-advisoryx_refsource_REDHAT
- ruby-random-number-weak-security(69157) vdb-entryx_refsource_XF
- RHSA-2012:0070 vendor-advisoryx_refsource_REDHAT
- x_refsource_MISC
- [oss-security] 20110720 Re: CVE Request: ruby PRNG fixes mailing-listx_refsource_MLIST