MEDIUM · 5.0

CVE-2001-1141

The Pseudo-Random Number Generator (PRNG) in SSLeay and OpenSSL before 0.9.6b allows attackers to use the output of small PRNG requests to determine the internal state information, which could be used...

Vulnerability Description

The Pseudo-Random Number Generator (PRNG) in SSLeay and OpenSSL before 0.9.6b allows attackers to use the output of small PRNG requests to determine the internal state information, which could be used by attackers to predict future pseudo-random numbers.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
OpensslOpenssl0.9.1c
SsleaySsleay0.8.1

References

FAQ

What is CVE-2001-1141?

CVE-2001-1141 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The Pseudo-Random Number Generator (PRNG) in SSLeay and OpenSSL before 0.9.6b allows attackers to use the output of small PRNG requests to determine the internal state information, which could be used...

How severe is CVE-2001-1141?

CVE-2001-1141 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2001-1141?

Check the references section above for vendor advisories and patch information. Affected products include: Openssl Openssl, Ssleay Ssleay.