7.5

CVE-2021-27211

steghide 0.5.1 relies on a certain 32-bit seed value, which makes it easier for attackers to detect hidden data.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Steghide ProjectSteghide Version0.5.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.23% 0.866
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-335 Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG)

The product uses a Pseudo-Random Number Generator (PRNG) but does not correctly manage seeds.

http://packetstormsecurity.com/files/165199/Steghide-Hidden-Data-Extraction.html
Third Party Advisory
VDB Entry
https://github.com/StefanoDeVuono/steghide
Product
https://github.com/b4shfire/stegcrack
Product
https://sourceforge.net/projects/steghide/files/steghide/0.5.1/
Third Party Advisory
Release Notes