CVE-2012-6661: High severity Plone plone vulnerability
Zope before 2.13.19, as used in Plone before 4.2.3 and 4.3 before beta 1, does not reseed the pseudo-random number generator (PRNG), which makes it easier for remote attackers to guess the value via unspecified vectors. NOTE: this issue was SPLIT from CVE-2012-5508 due to different vulnerability types (ADT2).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-6661?
CVE-2012-6661 has a medium severity level due to the potential for attackers to guess random values, impacting system security.
How do I fix CVE-2012-6661?
To resolve CVE-2012-6661, upgrade Plone to version 4.2.3 or later or Zope to version 2.13.19 or later.
Which versions of Plone are affected by CVE-2012-6661?
Plone versions prior to 4.2.3 are affected by CVE-2012-6661.
Which versions of Zope are affected by CVE-2012-6661?
Zope versions before 2.13.19 are impacted by CVE-2012-6661.
Can CVE-2012-6661 be exploited remotely?
Yes, CVE-2012-6661 can be exploited by remote attackers, allowing them to guess values through unspecified vectors.