CVE-2003-0094
Last modified
CVE-2003-0094 is a vulnerability of currently unknown severity. A patch for mcookie in the util-linux package for Mandrake Linux 8.2 and 9.0 uses /dev/urandom instead of /dev/random, which causes mcookie to use an entropy source that is more predictable than expected, which may make it easier for certain types of attacks to succeed.. EPSS estimates a 1.55% chance of exploitation in the next 30 days.
Description
A patch for mcookie in the util-linux package for Mandrake Linux 8.2 and 9.0 uses /dev/urandom instead of /dev/random, which causes mcookie to use an entropy source that is more predictable than expected, which may make it easier for certain types of attacks to succeed.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Andries Brouwer | Util-Linux | 2.11n |
| Andries Brouwer | Util-Linux | 2.11u |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2003-0094?
How severe is CVE-2003-0094?
How do I fix CVE-2003-0094?
Are you affected by CVE-2003-0094?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
