漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Data::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP
Vulnerability Description
Data::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP.
The Data::Entropy::RawSource::RandomOrg and Data::Entropy::RawSource::RandomnumbersInfo remote sources are accessed over plain HTTP.
The Data::Entropy::RawSource::RandomOrg integrity check trivially matches any non-empty byte string.
Any on-path attacker, such as open WiFi, a compromised ISP, captive portal, or a hostile egress proxy substitutes the response and thereby chooses the bytes returned by rand_bits and rand_int for every application that selected one of these sources via with_entropy_source. The _checkbuf method response is equally attacker-controlled, so the retry/sleep behaviour is steerable too.
CVSS Information
N/A
Vulnerability Type
敏感数据的明文传输
Vulnerability Title
RRWO Data::Entropy 加密问题漏洞
Vulnerability Description
RRWO Data::Entropy是RRWO个人开发者的一款提供熵数据生成与处理的软件模块。 RRWO Data::Entropy 0.010之前版本存在加密问题漏洞,该漏洞源于通过明文HTTP读取远程熵源,且完整性检查可被任意非空字节串匹配,可能导致路径攻击者替换响应并控制rand_bits和rand_int返回的字节。
CVSS Information
N/A
Vulnerability Type
N/A