Freebsd 7.1 and prior [Medium]

By Security Team on Wednesday, November 26th, 2008 in Security Notifications | Related Software Packages:

Affects:

  • Freebsd 7.1 and prior [Medium]

Description

The arc4random function in the kernel in FreeBSD 6.3 through 7.1 does not have a proper entropy source for a short time period immediately after boot, which makes it easier for attackers to predict the function’s return values and conduct certain attacks against the GEOM framework and various network protocols, related to the Yarrow random number generator.

If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.

CVE Identifier: CVE-2008-5162
Severity: Medium

National Vulnerabilities Database

NIST National Vulnerabilities Database

Security Team

We'll keep you safe. Trust us, that's our job. Even though, contrary to what our Avatar might imply, we're not all linebackers. In fact, some of us are quite petite. And others of us wear high heeled boots. Red. Wondering whether we also know what we're talking about? C'mon -have you read any of these security posts?

Comments are closed.

© 2010 OpenLogic, Inc. | Licensing | Privacy Policy | Terms of Use