CVE-2000-0916 Information

Description

FreeBSD 4.1.1 and earlier and possibly other BSD-based OSes uses an insufficient random number generator to generate initial TCP sequence numbers (ISN) which allows remote attackers to spoof TCP connections.

Reference

ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:52.tcp-iss.asc http://www.securityfocus.com/bid/1766

Share on: