Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.10.2014.0535
Category:Mageia Linux Local Security Checks
Title:Mageia: Security Advisory (MGASA-2014-0535)
Summary:The remote host is missing an update for the 'pwgen' package(s) announced via the MGASA-2014-0535 advisory.
Description:Summary:
The remote host is missing an update for the 'pwgen' package(s) announced via the MGASA-2014-0535 advisory.

Vulnerability Insight:
Updated pwgen package fixes security vulnerabilities:

Pwgen was found to generate weak non-tty passwords by default, which could
be brute-forced with a commendable success rate, which could raise security
concerns (CVE-2013-4440).

Pwgen was found to silently falling back to use standard pseudo generated
numbers on the systems that heavily use entropy. Systems, such as those with
a lot of daemons providing encryption services, the entropy was found to be
exhausted, which forces pwgen to fall back to use standard pseudo generated
numbers (CVE-2013-4442).

Affected Software/OS:
'pwgen' package(s) on Mageia 4.

Solution:
Please install the updated package(s).

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:P/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2013-4440
FEDORA-2014-16368
http://lists.fedoraproject.org/pipermail/package-announce/2014-December/146015.html
FEDORA-2014-16406
http://lists.fedoraproject.org/pipermail/package-announce/2014-December/146237.html
FEDORA-2014-16473
http://lists.fedoraproject.org/pipermail/package-announce/2014-December/146285.html
MDVSA-2015:008
http://www.mandriva.com/security/advisories?name=MDVSA-2015:008
[oss-security] 20140606 Re: CVE Request: pwgen
http://www.openwall.com/lists/oss-security/2013/06/06/1
[oss-security] 20141015 Re: RESEND: CVE Request: pwgen
http://www.openwall.com/lists/oss-security/2013/10/16/15
http://advisories.mageia.org/MGASA-2014-0535.html
http://sourceforge.net/p/pwgen/code/ci/00118ccac4656adb028504639b313d7b09e62b79/
Common Vulnerability Exposure (CVE) ID: CVE-2013-4442
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=672241
CopyrightCopyright (C) 2022 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.