Mageia 2024-0304: tgt Security Advisory Updates
Summary
tgt (aka Linux target framework) before 1.0.93 attempts to achieve
entropy by calling rand without srand. The PRNG seed is always 1, and
thus the sequence of challenges is always identical. (CVE-2024-45751)
References
- https://bugs.mageia.org/show_bug.cgi?id=33545
- https://www.openwall.com/lists/oss-security/2024/09/07/2
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-45751
Resolution
MGASA-2024-0304 - Updated tgt packages fix security vulnerability
SRPMS
- 9/core/tgt-1.0.85-1.1.mga9