PublicDate: 2005-05-03 04:00:00 UTC Candidate: CVE-2005-0106 References: https://ubuntu.com/security/notices/USN-113-1 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0106 Description: SSLeay.pm in libnet-ssleay-perl before 1.25 uses the /tmp/entropy file for entropy if a source is not set in the EGD_PATH variable, which allows local users to reduce the cryptographic strength of certain operations by modifying the file. Ubuntu-Description: Notes: Priority: untriaged Discovered-by: Assigned-to: CVSS: Bugs: dapper_libnet-ssleay-perl: released (1.25-2build1) edgy_libnet-ssleay-perl: released (1.25-2build1) feisty_libnet-ssleay-perl: released (1.25-2build1) devel_libnet-ssleay-perl: released (1.25-2build1) upstream_libnet-ssleay-perl: needs-triage