← Back

CVE-2011-2705

nvd nist
Published: Aug 5, 2011Modified: Apr 29, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

The SecureRandom.random_bytes function in lib/securerandom.rb in Ruby before 1.8.7-p352 and 1.9.x before 1.9.2-p290 relies on PID values for initialization, which makes it easier for context-dependent attackers to predict the result string by leveraging knowledge of random strings obtained in an earlier process with the same PID.

Affected (35)

Products: Ruby Lang: Ruby
1 product
Ruby
Configuration A
12 vulnerable
Vulnerable SoftwareAffected Versions
Ruby Lang
Up to 1.8.7-334
Version 1.8.7-160
Version 1.8.7-173
Version 1.8.7-248
Version 1.8.7-249
Version 1.8.7-299
Version 1.8.7-302
Version 1.8.7-330
Version 1.8.7-p21
Version 1.8.7 p22
Version 1.8.7 p71
Version 1.8.7 p72
Configuration B
23 vulnerable
Vulnerable SoftwareAffected Versions
Ruby Lang
Version 1.9.0-0
Version 1.9.0-1
Version 1.9.0-20060415
Version 1.9.0-20070709
Version 1.9.0-2
Version 1.9.0
Version 1.9.0 r18423
Version 1.9.1
Version 1.9.1 -p0
Version 1.9.1 -p129
Version 1.9.1 -p243
Version 1.9.1 -p376
Version 1.9.1 -p429
Version 1.9.1 -preview_1
Version 1.9.1 -preview_2
Version 1.9.1 -rc1
Version 1.9.1 -rc2
Version 1.9.2-p136
Version 1.9.2-p180
Version 1.9.2
Version 1.9.2 dev
Version 1.9
Version 1.9 r18423

References (30)

Source: secalert@redhat.com
Source: secalert@redhat.com
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch

Timeline

No history available yet.