CVE Vulnerabilities

CVE-2003-1230

Published: Dec 31, 2003 | Modified: Jul 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

The implementation of SYN cookies (syncookies) in FreeBSD 4.5 through 5.0-RELEASE-p3 uses only 32-bit internal keys when generating syncookies, which makes it easier for remote attackers to conduct brute force ISN guessing attacks and spoof legitimate traffic.

Affected Software

Name Vendor Start Version End Version
Freebsd Freebsd 4.5-release (including) 4.5-release (including)
Freebsd Freebsd 4.6-release (including) 4.6-release (including)
Freebsd Freebsd 4.7-release (including) 4.7-release (including)
Freebsd Freebsd 4.7-stable (including) 4.7-stable (including)
Freebsd Freebsd 5.0-release (including) 5.0-release (including)

References