CVE-2011-0766

Published May 31, 2011
·
Updated

The random number generator in the Crypto application before 2.0.2.2, and SSH before 2.0.5, as used in the Erlang/OTP ssh library before R14B03, uses predictable seeds based on the current time, which makes it easier for remote attackers to guess DSA host and SSH session keys.

Affected Software

69 affected components
Erlang Crypto<=2.0.2.1
Erlang Erlang\/otp=r11b-5
Erlang Erlang\/otp=r12b-5
Erlang Erlang\/otp=r13b
Erlang Erlang\/otp=r13b02-1
Erlang Erlang\/otp=r13b03
Erlang Erlang\/otp=r13b04
Erlang Erlang\/otp=r14a
Erlang Erlang\/otp=r14b
Erlang Erlang\/otp=r14b01
Erlang Erlang\/otp=r14b02
SSH ssh<=2.0.4
SSH ssh=1.2.6
Erlang Crypto=1.4
SSH ssh=1.2.0
Erlang Erlang\/otp<=r14b02
Erlang Crypto=1.2.1
Erlang Crypto=1.2.3
Erlang Crypto=1.2
Erlang Crypto=2.0.1
SSH ssh=1.2.9
Erlang Crypto=1.1.3
SSH ssh=1.2.21
SSH ssh=1.2.15
Erlang Crypto=1.0
Erlang Crypto=1.1.1
SSH ssh=1.2.4
SSH ssh=1.2.14
SSH ssh=1.2.19
Erlang Crypto=2.0
Erlang Crypto=1.6.2
Erlang Crypto=1.2.2
SSH ssh=1.2.8
SSH ssh=1.2.31
SSH ssh=1.2.24
SSH ssh=1.2.18
Erlang Crypto=1.5.2.1
SSH ssh=1.2.7
SSH ssh=1.2.20
SSH ssh=1.2.3
Erlang Crypto=1.3
SSH ssh=1.2.12
SSH ssh=1.2.25
SSH ssh=1.2.17
Erlang Crypto=2.0.2
SSH ssh=1.2.30
Erlang Crypto=1.5
SSH ssh=1.2.1
Erlang Crypto=1.5.2
SSH ssh=1.2.26
Erlang Crypto=1.5.1.1
SSH ssh=1.2.27
Erlang Crypto=1.6.3
SSH ssh=1.2.16
SSH ssh=1.2.28
Erlang Crypto=1.6.4
SSH ssh=1.2.29
SSH ssh=1.2.11
SSH ssh=1.2.5
Erlang Crypto=1.1.2
Erlang Crypto=1.6
SSH ssh=1.2.13
SSH ssh=1.2.22
SSH ssh=1.2.2
Erlang Crypto=1.1
SSH ssh=1.2.23
Erlang Crypto=1.6.1
SSH ssh=1.2.10
Erlang Crypto=1.5.3

Event History

May 31, 2011
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2011-0766?

The severity of CVE-2011-0766 is rated as high due to its potential for enabling remote attackers to guess DSA host and SSH session keys.

2

How do I fix CVE-2011-0766?

To fix CVE-2011-0766, update the affected Erlang/OTP and SSH software to the latest versions that address this vulnerability.

3

What versions are affected by CVE-2011-0766?

CVE-2011-0766 affects several versions of Erlang/OTP before R14B03 and SSH before 2.0.5.

4

Can CVE-2011-0766 be exploited remotely?

Yes, CVE-2011-0766 can be exploited remotely, allowing attackers to potentially compromise keys used in SSH sessions.

5

Is CVE-2011-0766 related to weak random number generation?

Yes, CVE-2011-0766 is related to weak random number generation due to predictable seeds based on the current time.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203