Vulnerability Description
FreeBSD 4.1.1 and earlier, and possibly other BSD-based OSes, uses an insufficient random number generator to generate initial TCP sequence numbers (ISN), which allows remote attackers to spoof TCP connections.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Freebsd | Freebsd | 2.0 |
References
- ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:52.tcp-iss.ascPatchVendor Advisory
- http://www.securityfocus.com/bid/1766PatchVendor Advisory
- ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:52.tcp-iss.ascPatchVendor Advisory
- http://www.securityfocus.com/bid/1766PatchVendor Advisory
FAQ
What is CVE-2000-0916?
CVE-2000-0916 is a vulnerability with a CVSS score of 7.5 (HIGH). FreeBSD 4.1.1 and earlier, and possibly other BSD-based OSes, uses an insufficient random number generator to generate initial TCP sequence numbers (ISN), which allows remote attackers to spoof TCP co...
How severe is CVE-2000-0916?
CVE-2000-0916 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2000-0916?
Check the references section above for vendor advisories and patch information. Affected products include: Freebsd Freebsd.