Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Crypt::DSA versions before 1.22 for Perl draw the DSA signing nonce and private key from a biased random generator, leading to private-key recovery
Vulnerability Description
Crypt::DSA versions before 1.22 for Perl draw the DSA signing nonce and private key from a biased random generator, leading to private-key recovery.
"Crypt::DSA::Util::makerandom forces the high bit of every value it returns to obtain an exactly N-bit integer for prime search. The signing nonce and the private key are drawn from makerandom. Because the high bit is always set, the result is not uniform: its top bit is fixed, producing insecure values."
An attacker who collects a modest number of signatures under an affected key, together with the public key, can recover the private key with a lattice attack.
Keys used to sign with an affected version should be considered compromised and new keys should be generated.
CVSS Information
N/A
Vulnerability Type
使用不充分的随机数
Vulnerability Title
TIMLEGGE Crypt::DSA 加密问题漏洞
Vulnerability Description
timlegge Crypt::DSA是timlegge的数字签名库。 TIMLEGGE Crypt::DSA 1.22之前版本存在加密问题漏洞,该漏洞源于使用有偏见的随机生成器生成DSA签名随机数和私钥,导致私钥可被恢复。
CVSS Information
N/A
Vulnerability Type
N/A