CVE-2007-5502

Impact:
Moderate
Public Date:
2007-11-29
Bugzilla:
390371: CVE-2007-5502 openssl FIPS module PRNG flaw

The MITRE CVE dictionary describes this issue as:

The PRNG implementation for the OpenSSL FIPS Object Module 1.1.1 does not perform auto-seeding during the FIPS self-test, which generates random data that is more predictable than expected and makes it easier for attackers to bypass protection mechanisms that rely on the randomness.

Find out more about CVE-2007-5502 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

Not vulnerable. This vulnerability only affected the OpenSSL FIPS Object Module which is not enabled or used by OpenSSL in Red Hat Enterprise Linux 2.1, 3, 4, or 5.

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.