Unrated severityNVD Advisory· Published Mar 14, 2014· Updated May 6, 2026
CVE-2014-0017
CVE-2014-0017
Description
The RAND_bytes function in libssh before 0.6.3, when forking is enabled, does not properly reset the state of the OpenSSL pseudo-random number generator (PRNG), which causes the state to be shared between children processes and allows local users to obtain sensitive information by leveraging a pid collision.
Affected products
12cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:*+ 11 more
- cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:*range: <=0.6.2
- cpe:2.3:a:libssh:libssh:0.4.7:*:*:*:*:*:*:*
- cpe:2.3:a:libssh:libssh:0.4.8:*:*:*:*:*:*:*
- cpe:2.3:a:libssh:libssh:0.5.0:*:*:*:*:*:*:*
- cpe:2.3:a:libssh:libssh:0.5.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:libssh:libssh:0.5.1:*:*:*:*:*:*:*
- cpe:2.3:a:libssh:libssh:0.5.2:*:*:*:*:*:*:*
- cpe:2.3:a:libssh:libssh:0.5.3:*:*:*:*:*:*:*
- cpe:2.3:a:libssh:libssh:0.5.4:*:*:*:*:*:*:*
- cpe:2.3:a:libssh:libssh:0.5.5:*:*:*:*:*:*:*
- cpe:2.3:a:libssh:libssh:0.6.0:*:*:*:*:*:*:*
- cpe:2.3:a:libssh:libssh:0.6.1:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- www.libssh.org/2014/03/04/libssh-0-6-3-security-release/nvdPatchVendor Advisory
- secunia.com/advisories/57407nvdVendor Advisory
- lists.opensuse.org/opensuse-updates/2014-03/msg00036.htmlnvd
- lists.opensuse.org/opensuse-updates/2014-03/msg00040.htmlnvd
- www.debian.org/security/2014/dsa-2879nvd
- www.openwall.com/lists/oss-security/2014/03/05/1nvd
- www.ubuntu.com/usn/USN-2145-1nvd
- bugzilla.redhat.com/show_bug.cginvd
News mentions
0No linked articles in our index yet.