CVE-2011-2705

The SecureRandom.random_bytes function in lib/securerandom.rb in Ruby before 1.8.7-p352 and 1.9.x before 1.9.2-p290 relies on PID values for initialization, which makes it easier for context-dependent attackers to predict the result string by leveraging knowledge of random strings obtained in an earlier process with the same PID.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:N/A:N
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 78%
VendorProductVersion
ruby-langruby
𝑥
≤ 1.8.7-334
ruby-langruby
1.8.7:p22
ruby-langruby
1.8.7:p71
ruby-langruby
1.8.7:p72
ruby-langruby
1.8.7-160
ruby-langruby
1.8.7-173
ruby-langruby
1.8.7-248
ruby-langruby
1.8.7-249
ruby-langruby
1.8.7-299
ruby-langruby
1.8.7-302
ruby-langruby
1.8.7-330
ruby-langruby
1.8.7-p21
ruby-langruby
1.9
ruby-langruby
1.9:r18423
ruby-langruby
1.9.0
ruby-langruby
1.9.0:r18423
ruby-langruby
1.9.0-0
ruby-langruby
1.9.0-1
ruby-langruby
1.9.0-2
ruby-langruby
1.9.0-20060415
ruby-langruby
1.9.0-20070709
ruby-langruby
1.9.1
ruby-langruby
1.9.1:-p0
ruby-langruby
1.9.1:-p129
ruby-langruby
1.9.1:-p243
ruby-langruby
1.9.1:-p376
ruby-langruby
1.9.1:-p429
ruby-langruby
1.9.1:-preview_1
ruby-langruby
1.9.1:-preview_2
ruby-langruby
1.9.1:-rc1
ruby-langruby
1.9.1:-rc2
ruby-langruby
1.9.2
ruby-langruby
1.9.2:dev
ruby-langruby
1.9.2-p136
ruby-langruby
1.9.2-p180
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ruby1.8
saucy
not-affected
raring
not-affected
quantal
not-affected
precise
not-affected
oneiric
not-affected
natty
Fixed 1.8.7.302-2ubuntu0.1
released
maverick
Fixed 1.8.7.299-2ubuntu0.1
released
lucid
Fixed 1.8.7.249-2ubuntu0.1
released
hardy
ignored
ruby1.9
saucy
dne
raring
dne
quantal
dne
precise
dne
oneiric
dne
natty
dne
maverick
dne
lucid
ignored
hardy
ignored
ruby1.9.1
saucy
not-affected
raring
not-affected
quantal
not-affected
precise
not-affected
oneiric
not-affected
natty
ignored
maverick
ignored
lucid
ignored
hardy
dne
References