MEDIUM · 6.8

CVE-2008-1148

A certain pseudo-random number generator (PRNG) algorithm that uses ADD with 0 random hops (aka "Algorithm A0"), as used in OpenBSD 3.5 through 4.2 and NetBSD 1.6.2 through 4.0, allows remote attacker...

Vulnerability Description

A certain pseudo-random number generator (PRNG) algorithm that uses ADD with 0 random hops (aka "Algorithm A0"), as used in OpenBSD 3.5 through 4.2 and NetBSD 1.6.2 through 4.0, allows remote attackers to guess sensitive values such as (1) DNS transaction IDs or (2) IP fragmentation IDs by observing a sequence of previously generated values. NOTE: this issue can be leveraged for attacks such as DNS cache poisoning, injection into TCP packets, and OS fingerprinting.

CVSS Score

6.8

MEDIUM

AV:N/AC:M/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
AppleMac Os X10.0
AppleMac Os X Server10.0
DragonflybsdDragonflybsd1.0
FreebsdFreebsd4.4
NetbsdNetbsd1.6.2
OpenbsdOpenbsd2.6
CosmicperlDirectory Pro10.0.3
DarwinDarwin1.0
NavisionFinancials Server3.0

References

FAQ

What is CVE-2008-1148?

CVE-2008-1148 is a vulnerability with a CVSS score of 6.8 (MEDIUM). A certain pseudo-random number generator (PRNG) algorithm that uses ADD with 0 random hops (aka "Algorithm A0"), as used in OpenBSD 3.5 through 4.2 and NetBSD 1.6.2 through 4.0, allows remote attacker...

How severe is CVE-2008-1148?

CVE-2008-1148 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2008-1148?

Check the references section above for vendor advisories and patch information. Affected products include: Apple Mac Os X, Apple Mac Os X Server, Dragonflybsd Dragonflybsd, Freebsd Freebsd, Netbsd Netbsd.