Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2007-5502

EPSS 0.38% · P60
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2007-5502

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The PRNG implementation for the OpenSSL FIPS Object Module 1.1.1 does not perform auto-seeding during the FIPS self-test, which generates random data that is more predictable than expected and makes it easier for attackers to bypass protection mechanisms that rely on the randomness.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
OpenSSL FIPS对象模块PRNG种子生成漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
OpenSSL是OpenSSL团队开发的一个开源的能够实现安全套接层(SSL v2/v3)和安全传输层(TLS v1)协议的通用加密库,它支持多种加密算法,包括对称密码、哈希算法、安全散列算法等。 OpenSSL FIPS对象模块的伪随机数生成器(PRNG)实现中存在错误,可能导致可预测的随机数。 由于FIPS自检没有正确编码,导致从不会进行自动生成种子。这意味着PRNG密钥与种子与最后一次自检相关,FIPS PRNG仅从数据时间信息获得额外的种子数据,因此所生成的随机数据比较容易预测,尤其是最初的几次调
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2007-5502

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2007-5502

Please Login to view more intelligence information

Same Patch Batch · n/a · 2007-12-01 · 9 CVEs total

CVE-2007-5742Battle for Wesnoth WML Preprocessor 目录遍历漏洞
CVE-2007-6201Wesnoth turn_cmd 未知远程拒绝服务和可执行代码漏洞
CVE-2007-6202Neocrome Seditio PLUG.PHP SQL注入漏洞
CVE-2007-6196Calacode @Mail Util.PHP 跨站脚本攻击漏洞
CVE-2007-6197BEA Plumtree Foundation及AquaLogic Interaction信息泄露漏洞
CVE-2007-6198BEA Plumtree Foundation及AquaLogic Interaction信息泄露漏洞
CVE-2007-6199Rsync Use Chroot选项创建不安全文件漏洞
CVE-2007-6200Rsync exclude守护程序非授权文件访问漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2007-5502

No comments yet


Leave a comment