Security Advisory

CVE-2011-2686

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2011-08-05 21:00:00
Last updated 2024-08-06 23:08:23
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

Ruby before 1.8.7-p352 does not reset the random seed upon forking, which makes it easier for context-dependent attackers to predict the values of random numbers by leveraging knowledge of the number sequence obtained in a different child process, a related issue to CVE-2003-0900. NOTE: this issue exists because of a regression during Ruby 1.8.6 development.