True-Random Number Generation Bugs (TRN) Examples
CVE-2008-0141
BF Taxonomy
Cause:
Inadequate Entropy Sources (current date/time and user name)
Attributes:
Used For: Generation (of password)
Randomness Requirement: Non-Inferable (time known from password reset time,
name - from user register)
Consequence:
IEX leading to ATN (Authentication Fault)
BF Description
Inadequate entropy sources (date/time and user name) mixing using
concatenation allow generation of passwords that do not satisfy
the non-inferable randomness requirement (time known from password reset time, name -
from user register), which may be exploited for IEX (of password), leading to
ATN
Analysis
Source Code
Code With Bug |
Code With Fix |
Source Code Not Available
|
|
Source Code Not Available
|
|