CVE-2012-2387: Debian Devotee

Medium severity, CVSS 5.0. EPSS: 1.4% chance of exploitation in the next 30 days.

devotee 0.1 patch 2 uses a 32-bit seed for generating 48-bit random numbers, which makes it easier for remote attackers to obtain the secret monikers via a brute force attack.

Affected products

  • Debian Devotee: version 0.1 only

Published 2012-08-20. Last modified 2026-06-16.