CVE-2000-0357: High severity redhat Linux vulnerability
ORBit and esound in Red Hat Linux 6.1 do not use sufficiently random numbers, which allows local users to guess the authentication keys.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Red Hat Linux/orbitfrom your environment.If ORBit is not required, uninstall the ORBit package from affected Red Hat Linux 6.1 systems to eliminate the vulnerable component.
- Remove
Remove
Red Hat Linux/esoundfrom your environment.If esound is not required, uninstall the esound package from affected Red Hat Linux 6.1 systems to eliminate the vulnerable component.
- Compensating control
Restrict local access to ORBit and esound interfaces and sockets to trusted accounts only (for example, tighten filesystem permissions, apply SELinux policies, or restrict execution via PAM/firewall) to reduce the risk from local users guessing authentication keys.
- Operational
Rotate or replace any authentication keys, tokens, or credentials used by ORBit and esound that may have been generated or exposed, and invalidate previously issued keys.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0357?
CVE-2000-0357 is considered a medium severity vulnerability due to the potential for local users to exploit weak authentication methods.
How do I fix CVE-2000-0357?
To fix CVE-2000-0357, users should upgrade their Red Hat Linux system to a version that addresses the key generation issue.
Who is affected by CVE-2000-0357?
CVE-2000-0357 affects local users of Red Hat Linux 6.1 who are able to exploit the weak random number generation for authentication.
What products are impacted by CVE-2000-0357?
CVE-2000-0357 specifically impacts the ORBit and esound components in Red Hat Linux 6.1.
Can CVE-2000-0357 lead to unauthorized access?
Yes, CVE-2000-0357 can potentially allow local users to guess authentication keys, which may lead to unauthorized access.