CVE-2011-3599: Medium severity crypt-dsa (adam kennedy) vulnerability

Published Oct 5, 2011
·
Updated

It has been reported that Crypt::DSA, a Perl module for DSA signatures and key generation, used cryptographically weak / insecure method for random numbers generation on systems, where /dev/random file was not present. Due this flaw an attacker could be able to discover some portions of / whole secret DSA key, which has been created on such system.

References: [1] http://secunia.com/advisories/46275/ [2] https://rt.cpan.org/Public/Bug/Display.html?id=71421

Proposed upstream patch is to remove the affected fallback code part: [3] https://rt.cpan.org/Public/Bug/Display.html?id=71421#txn-984052 (though not approved yet)

Other sources

The Crypt::DSA (aka Crypt-DSA) module 1.17 and earlier for Perl, when /dev/random is absent, uses the Data::Random module, which makes it easier for remote attackers to spoof a signature, or determine the signing key of a signed message, via a brute-force attack.

Affected Software

13 affected componentsFixes available
redhat/perl-Crypt-DSA-1.17<10.
10.
Adam Kennedy Crypt-dsa<=1.17
Adam Kennedy Crypt-dsa=0.01
Adam Kennedy Crypt-dsa=0.02
Adam Kennedy Crypt-dsa=0.03
Adam Kennedy Crypt-dsa=0.10
Adam Kennedy Crypt-dsa=0.11
Adam Kennedy Crypt-dsa=0.12
Adam Kennedy Crypt-dsa=0.13
Adam Kennedy Crypt-dsa=0.14
Adam Kennedy Crypt-dsa=0.15_01
Adam Kennedy Crypt-dsa=1.16
Perl Perl

Event History

Oct 5, 2011
Data Sourced
via Red Hat·12:00 PM
DescriptionSeverityAffected Software
Oct 10, 2011
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Data Sourced
10:55 AM
DescriptionWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2011-3599?

CVE-2011-3599 is considered a high severity vulnerability due to its potential to allow attackers to compromise cryptographic security.

2

How do I fix CVE-2011-3599?

To fix CVE-2011-3599, you should upgrade the Crypt::DSA Perl module to version 1.17 or later.

3

Which versions of Crypt::DSA are affected by CVE-2011-3599?

CVE-2011-3599 affects Crypt::DSA versions prior to 1.17, including versions 0.01 through 1.16.

4

What kind of flaw is CVE-2011-3599?

CVE-2011-3599 is a cryptographic flaw involving weak random number generation.

5

Who is the vendor of the affected software in CVE-2011-3599?

The affected software, Crypt::DSA, is maintained by Adam Kennedy.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203