PT-2008-2740 · Openbsd · Openbsd

Publicado

2008-03-04

·

Atualizado

2017-08-08

·

CVE-2008-1146

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions OpenBSD versions 2.8 through 4.2
Description A pseudo-random number generator (PRNG) algorithm, known as "Algorithm X3", is used in OpenBSD. This algorithm allows remote attackers to guess sensitive values, such as DNS transaction IDs, by observing a sequence of previously generated values. This issue can be leveraged for attacks like DNS cache poisoning against OpenBSD's modification of BIND.
Recommendations For OpenBSD versions 2.8 through 4.2, consider updating to a version that uses a more secure PRNG algorithm to prevent attackers from guessing sensitive values.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2008-1146

Produtos afetados

Openbsd