CyberSec.Space Logo
Back to CVE Browser

CVE-2008-1147

MEDIUM
6.8
CVSS Severity Score
EPSS Score0.0660%
EPSS Percentile34.74th
PublishedMar 4, 2008
Last ModifiedApr 23, 2026

Vulnerability Description

A certain pseudo-random number generator (PRNG) algorithm that uses XOR and 2-bit random hops (aka "Algorithm X2"), as used in OpenBSD 2.6 through 3.4, Mac OS X 10 through 10.5.1, FreeBSD 4.4 through 7.0, and DragonFlyBSD 1.0 through 1.10.1, allows remote attackers to guess sensitive values such as IP fragmentation IDs by observing a sequence of previously generated values. NOTE: this issue can be leveraged for attacks such as injection into TCP packets and OS fingerprinting.

Affected Platforms (CPE)

πŸ“¦
Cosmicperl

Directory Pro

= 10.0.3
πŸ“¦
Darwin

Darwin

= 1.0
πŸ“¦
Darwin

Darwin

= 9.1
πŸ“¦
Navision

Financials Server

= 3.0

References & Advisories

Related Vulnerabilities