First published: Wed Dec 31 2003(Updated: )
The implementation of SYN cookies (syncookies) in FreeBSD 4.5 through 5.0-RELEASE-p3 uses only 32-bit internal keys when generating syncookies, which makes it easier for remote attackers to conduct brute force ISN guessing attacks and spoof legitimate traffic.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
FreeBSD FreeBSD | =4.5-release | |
FreeBSD FreeBSD | =4.6-release | |
FreeBSD FreeBSD | =4.7-release | |
FreeBSD FreeBSD | =4.7-stable | |
FreeBSD FreeBSD | =5.0-release | |
FreeBSD FreeBSD | =5.0-release | |
FreeBSD FreeBSD | =4.6-release | |
FreeBSD FreeBSD | =4.7-stable | |
FreeBSD FreeBSD | =4.5-release | |
FreeBSD FreeBSD | =4.7-release |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.