rngatherd@1.0 vulnerabilities

Random number gathering daemon which creates a /dev/hwrandom

Direct Vulnerabilities

Known vulnerabilities in the rngatherd package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Replay Attack

rngatherd is a Random number gathering daemon which creates a /dev/hwrandom

Affected versions of this package are vulnerable to Replay Attack due to an insecure implementation of session verification.

How to fix Replay Attack?

Upgrade rngatherd to version 2.0 or higher.

[,2.0)