| |||||||||||||
| Test ID: | 1.3.6.1.4.1.25623.1.0.69757 |
| Category: | FreeBSD Local Security Checks |
| Title: | FreeBSD Ports: erlang |
| Summary: | FreeBSD Ports: erlang |
| Description: | The remote host is missing an update to the system as announced in the referenced advisory. The following package is affected: erlang CVE-2011-0766 The random number generator in the Crypto application before 2.0.2.2, and SSH before 2.0.5, as used in the Erlang/OTP ssh library before R14B03, uses predictable seeds based on the current time, which makes it easier for remote attackers to guess DSA host and SSH session keys. Solution: Update your system with the appropriate patches or software upgrades. http://www.erlang.org/download/otp_src_R14B03.readme https://github.com/erlang/otp/commit/f228601de45c5b53241b103af6616453c50885a5 http://www.vuxml.org/freebsd/e4833927-86e5-11e0-a6b4-000a5e1e33c6.html |
| Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2011-0766 CERT/CC vulnerability note: VU#178990 http://www.kb.cert.org/vuls/id/178990 BugTraq ID: 47980 http://www.securityfocus.com/bid/47980 http://secunia.com/advisories/44709 |
| Copyright | Copyright (c) 2011 E-Soft Inc. http://www.securityspace.com |
| This is only one of 32582 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |
|