security advisorysoftware updatedebian
The perl module Data::Entropy was using the cryptographically insecure rand() function as default entropy source. For Debian 11 bullseye, this problem has been fixed in version . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4100-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Adrian Bunk March 31, 2025 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : libdata-entropy-perl Version : 0.007-3.1+deb11u1 CVE ID : CVE-2025-1860 Debian Bug : 1101503 The perl module Data::Entropy was using the cryptographically insecure rand() function as default entropy source. For Debian 11 bullseye, this problem has been fixed in version 0.007-3.1+deb11u1. We recommend that you upgrade your libdata-entropy-perl packages. For the detailed security status of libdata-entropy-perl please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/libdata-entropy-perl Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Fix for the libdata-entropy-perl module's security issue in Debian 11 bullseye to enhance application security.. module, entropy, using, cryptographically, insecure, rand(), function, default. . Severity: Important. LinuxSecurity.com Team
Mar 31, 2025
•Important
Debian LTS