CVE-2012-6124: Weak RNG
Published Oct 31, 2019
·Updated
A casting error in Chicken before 4.8.0 on 64-bit platform caused the random number generator to return a constant value. NOTE: the vendor states "This function wasn't used for security purposes (and is advertised as being unsuitable)."
Affected Software
2 affected componentsFixes available
debian/chicken
5.2.0-25.3.0-15.3.0-2
Call-cc Chicken<4.8.0
Remediation
Patch Available
Event History
Oct 31, 2019
CVE Published
via MITRE·08:38 PM
Data Sourced
via MITRE·08:38 PM
DescriptionWeakness
Aug 6, 2024
Data Sourced
via Debian·09:34 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2012-6124?
CVE-2012-6124 is classified as a low severity vulnerability due to its limited impact on security functionality.
2
How do I fix CVE-2012-6124?
To mitigate CVE-2012-6124, upgrade to Chicken version 5.2.0-2 or later on affected systems.
3
What type of error does CVE-2012-6124 involve?
CVE-2012-6124 involves a casting error in the random number generator on 64-bit platforms.
4
Is CVE-2012-6124 used for security purposes?
The function affected by CVE-2012-6124 was not intended for security purposes and is strongly advised against for such use.
5
Which versions of Chicken are affected by CVE-2012-6124?
CVE-2012-6124 affects all Chicken versions before 4.8.0 on 64-bit platforms.