Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Tor before 0.1.1.20 uses OpenSSL pseudo-random bytes (RAND_pseudo_bytes) instead of cryptographically strong RAND_bytes, and seeds the entropy value at start-up with 160-bit chunks without reseeding, which makes it easier for attackers to conduct brute force guessing attacks.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Tor before OpenSSL伪随机暴力破解漏洞
Vulnerability Description
Tor before 0.1.1.20 使用 OpenSSL伪随机字节(RAND_pseudo_bytes)而非强密码RAND_字节,并在以160位组块起动时播种entropy值而不重复播种,可以使攻击者更易于进行强力的猜测攻击。
CVSS Information
N/A
Vulnerability Type
N/A