7.5

CVE-2008-5659

The gnu.java.security.util.PRNG class in GNU Classpath 0.97.2 and earlier uses a predictable seed based on the system time, which makes it easier for context-dependent attackers to conduct brute force attacks against cryptographic routines that use this class for randomness, as demonstrated against DSA private keys.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GnuClasspath Version <= 0.97.2
GnuClasspath Version0.6
GnuClasspath Version0.7
GnuClasspath Version0.8
GnuClasspath Version0.9
GnuClasspath Version0.10
GnuClasspath Version0.11
GnuClasspath Version0.12
GnuClasspath Version0.13
GnuClasspath Version0.14
GnuClasspath Version0.15
GnuClasspath Version0.16
GnuClasspath Version0.17
GnuClasspath Version0.18
GnuClasspath Version0.19
GnuClasspath Version0.20
GnuClasspath Version0.90
GnuClasspath Version0.91
GnuClasspath Version0.92
GnuClasspath Version0.93
GnuClasspath Version0.95
GnuClasspath Version0.96
GnuClasspath Version0.96.1
GnuClasspath Version0.97
GnuClasspath Version0.97.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.75% 0.818
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P