CVE Vulnerabilities

CVE-2000-0916

Published: Dec 19, 2000 | Modified: Sep 05, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

FreeBSD 4.1.1 and earlier, and possibly other BSD-based OSes, uses an insufficient random number generator to generate initial TCP sequence numbers (ISN), which allows remote attackers to spoof TCP connections.

Affected Software

Name Vendor Start Version End Version
Freebsd Freebsd 2.0 2.0
Freebsd Freebsd 3.0 3.0
Freebsd Freebsd 4.0 4.0
Freebsd Freebsd 4.1 4.1
Freebsd Freebsd 4.1.1 4.1.1

References