Candidate: CVE-2013-4442 PublicDate: 2014-12-19 15:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4442 http://www.openwall.com/lists/oss-security/2013/10/16/15 Description: Password Generator (aka Pwgen) before 2.07 uses weak pseudo generated numbers when /dev/urandom is unavailable, which makes it easier for context-dependent attackers to guess the numbers. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=726578 https://bugs.launchpad.net/ubuntu/+source/pwgen/+bug/1183213 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=767008 Priority: low Discovered-by: Michael Samuel Assigned-to: CVSS: Patches_pwgen: other: https://launchpadlibrarian.net/140874774/randnum_c_v2.patch other: https://github.com/therealmik/pwgen/compare/securityfixes upstream_pwgen: released (2.07-1) lucid_pwgen: ignored (reached end-of-life) precise_pwgen: ignored (reached end-of-life) precise/esm_pwgen: ignored (end of ESM support, was needed) quantal_pwgen: ignored (reached end-of-life) raring_pwgen: ignored (reached end-of-life) saucy_pwgen: ignored (reached end-of-life) trusty_pwgen: ignored (reached end-of-life) trusty/esm_pwgen: DNE (trusty was needed) utopic_pwgen: ignored (reached end-of-life) vivid_pwgen: not-affected (3.3.8-3ubuntu2) vivid/stable-phone-overlay_pwgen: DNE vivid/ubuntu-core_pwgen: DNE wily_pwgen: not-affected (3.3.8-3ubuntu2) xenial_pwgen: not-affected (3.3.8-3ubuntu2) yakkety_pwgen: not-affected (3.3.8-3ubuntu2) zesty_pwgen: not-affected (3.3.8-3ubuntu2) artful_pwgen: not-affected (3.3.8-3ubuntu2) bionic_pwgen: not-affected (3.3.8-3ubuntu2) cosmic_pwgen: not-affected (3.3.8-3ubuntu2) disco_pwgen: not-affected (3.3.8-3ubuntu2) eoan_pwgen: not-affected (3.3.8-3ubuntu2) focal_pwgen: not-affected (3.3.8-3ubuntu2) groovy_pwgen: not-affected (3.3.8-3ubuntu2) hirsute_pwgen: not-affected (3.3.8-3ubuntu2) devel_pwgen: not-affected (3.3.8-3ubuntu2)