lib/libc/stdlib/random.c in OpenBSD returns 0 when seeded with 0.
The product uses a Pseudo-Random Number Generator (PRNG) but does not correctly manage seeds.
Link | Tags |
---|---|
https://security-tracker.debian.org/tracker/CVE-2012-1577 | third party advisory |
http://www.openwall.com/lists/oss-security/2012/03/23/14 | third party advisory mailing list |
http://cvsweb.openbsd.org/cgi-bin/cvsweb/src/lib/libc/stdlib/random.c#rev1.16 | vendor advisory |
https://github.com/ensc/dietlibc/blob/master/CHANGES | third party advisory |