CVE-2017-17845: Weak RNG
Published Dec 22, 2017
·Updated
An issue was discovered in Enigmail before 1.9.9. Improper Random Secret Generation occurs because Math.Random() is used by pretty Easy privacy (pEp), aka TBE-01-001.
Affected Software
4 affected componentsFixes available
debian/enigmail
2:2.2.4-0.2~deb10u12:2.1.3+ds1-4~deb10u22:2.2.4-0.3
Enigmail Enigmail<1.9.9
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Event History
Dec 22, 2017
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-17845?
CVE-2017-17845 has a medium severity due to improper random secret generation that could compromise cryptographic operations.
2
How do I fix CVE-2017-17845?
To fix CVE-2017-17845, upgrade Enigmail to version 1.9.9 or later.
3
Which versions of Enigmail are affected by CVE-2017-17845?
Enigmail versions prior to 1.9.9 are affected by CVE-2017-17845.
4
What does CVE-2017-17845 affect in Enigmail?
CVE-2017-17845 affects the random secret generation mechanism used by pretty Easy privacy (pEp) within Enigmail.
5
Is there a specific environment where CVE-2017-17845 is a concern?
CVE-2017-17845 is a concern specifically within Debian distributions using vulnerable versions of Enigmail.