CVE-2011-0766
The random number generator in the Crypto application before 2.0.2.2, and SSH before 2.0.5, as used in the Erlang/OTP ssh library before R14B03, uses predictable seeds based on the current time, which makes it easier for remote attackers to guess DSA host and SSH session keys.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-0766?
The severity of CVE-2011-0766 is rated as high due to its potential for enabling remote attackers to guess DSA host and SSH session keys.
How do I fix CVE-2011-0766?
To fix CVE-2011-0766, update the affected Erlang/OTP and SSH software to the latest versions that address this vulnerability.
What versions are affected by CVE-2011-0766?
CVE-2011-0766 affects several versions of Erlang/OTP before R14B03 and SSH before 2.0.5.
Can CVE-2011-0766 be exploited remotely?
Yes, CVE-2011-0766 can be exploited remotely, allowing attackers to potentially compromise keys used in SSH sessions.
Is CVE-2011-0766 related to weak random number generation?
Yes, CVE-2011-0766 is related to weak random number generation due to predictable seeds based on the current time.