Cryptocat before 2.0.22: Cryptocat.random() Function Array Key has Entropy Weakness
The product uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.
Link | Tags |
---|---|
https://www.openwall.com/lists/oss-security/2013/07/10/15 | third party advisory mailing list |
https://tobtu.com/decryptocat.php | vendor advisory |
https://vuldb.com/?id.9435 | third party advisory permissions required |
https://www.securityfocus.com/bid/61091/info | vdb entry third party advisory |