Ruby Improper Input Validation Vulnerability - CVE-2011-2705 - Vulnerability Database

Ruby Improper Input Validation Vulnerability - CVE-2011-2705

Medium
Reference: CVE-2011-2705
Title: Ruby Improper Input Validation Vulnerability
Overview:

The SecureRandom.random_bytes function in lib/securerandom.rb in Ruby before 1.8.7-p352 and 1.9.x before 1.9.2-p290 relies on PID values for initialization which makes it easier for context-dependent attackers to predict the result string by leveraging knowledge of random strings obtained in an earlier process with the same PID.