CVE-2006-1833: Low severity NetBSD NetBSD vulnerability
Published Apr 19, 2006
·Updated
Intel RNG Driver in NetBSD 1.6 through 3.0 may incorrectly detect the presence of the pchb interface, which will cause it to always generate the same random number, which allows remote attackers to more easily crack encryption keys generated from the interface.
Affected Software
10 affected components
NetBSD NetBSD=1.6
NetBSD NetBSD=1.6-beta
NetBSD NetBSD=1.6.1
NetBSD NetBSD=1.6.2
NetBSD NetBSD=2.0
NetBSD NetBSD=2.0.1
NetBSD NetBSD=2.0.2
NetBSD NetBSD=2.0.3
NetBSD NetBSD=2.1
NetBSD NetBSD=3.0
Event History
Apr 19, 2006
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-1833?
CVE-2006-1833 has a high severity rating due to its potential to allow remote attackers to crack encryption keys.
2
How do I fix CVE-2006-1833?
To fix CVE-2006-1833, upgrade to a later version of NetBSD that addresses this vulnerability.
3
What versions of NetBSD are affected by CVE-2006-1833?
CVE-2006-1833 affects NetBSD versions 1.6 through 3.0.
4
What is the impact of CVE-2006-1833 on encryption?
CVE-2006-1833 can allow attackers to exploit predictable random number generation, making it easier to crack encryption.
5
Can CVE-2006-1833 be exploited remotely?
Yes, CVE-2006-1833 can be exploited by remote attackers due to the flawed random number generation.