Files
CVEs-PoC/2011/CVE-2011-4121.md
T
2024-05-26 14:27:05 +02:00

19 lines
907 B
Markdown

### [CVE-2011-4121](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4121)
![](https://img.shields.io/static/v1?label=Product&message=OpenSSL%20extension%20of%20Ruby%20(Git%20trunk)&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3D%20versions%20after%202011-09-01%20up%20to%202011-11-03%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=Other&color=brighgreen)
### Description
The OpenSSL extension of Ruby (Git trunk) versions after 2011-09-01 up to 2011-11-03 always generated an exponent value of '1' to be used for private RSA key generation. A remote attacker could use this flaw to bypass or corrupt integrity of services, depending on strong private RSA keys generation mechanism.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/ARPSyndicate/cvemon
- https://github.com/chnzzh/OpenSSL-CVE-lib