Predictable Random Values in std::random_device Class

Predictable Random Values in std::random_device Class

CVE-2015-5276 · MEDIUM Severity

AV:N/AC:L/AU:N/C:P/I:N/A:N

The std::random_device class in libstdc++ in the GNU Compiler Collection (aka GCC) before 4.9.4 does not properly handle short reads from blocking sources, which makes it easier for context-dependent attackers to predict the random values via unspecified vectors.

Learn more about our Web Application Penetration Testing UK.