Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 499
Alerts This Week
Warning Icon 1 499

Mageia 9: MGASA-2024-0304 Moderate: tgt Entropy Challenge Fix

mageia
Calendar Grey September 16, 2024
Scroller Mageia
Revised tgt packages resolve a vulnerability in Mageia, safeguarding effective entropy handling.
tgt (aka Linux target framework) before 1.0.93 attempts to achieve entropy by calling rand without srand

Summary

tgt (aka Linux target framework) before 1.0.93 attempts to achieve entropy by calling rand without srand. The PRNG seed is always 1, and thus the sequence of challenges is always identical. (CVE-2024-45751)

References

- https://bugs.mageia.org/show_bug.cgi?id=33545

- https://www.openwall.com/lists/oss-security/2024/09/07/2

- https://www.cve.org/CVERecord?id=CVE-2024-45751

Resolution

SRPMS

- 9/core/tgt-1.0.85-1.1.mga9

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 16 Sep 2024
URL: https://advisories.mageia.org/MGASA-2024-0304.html
Type: security
CVE: CVE-2024-45751

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.