CVE Vulnerabilities

CVE-2003-1230

Published: Dec 31, 2003 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The implementation of SYN cookies (syncookies) in FreeBSD 4.5 through 5.0-RELEASE-p3 uses only 32-bit internal keys when generating syncookies, which makes it easier for remote attackers to conduct brute force ISN guessing attacks and spoof legitimate traffic.

Affected Software

NameVendorStart VersionEnd Version
FreebsdFreebsd4.5-release (including)4.5-release (including)
FreebsdFreebsd4.6-release (including)4.6-release (including)
FreebsdFreebsd4.7-release (including)4.7-release (including)
FreebsdFreebsd4.7-stable (including)4.7-stable (including)
FreebsdFreebsd5.0-release (including)5.0-release (including)

References