CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2008-1147

MEDIUM
6.8
CVSS Severity Score
EPSS Score0.0660%
EPSS Percentile34.74th
Published2008年3月4日
Last Modified2026年4月23日

Vulnerability Description

A certain pseudo-random number generator (PRNG) algorithm that uses XOR and 2-bit random hops (aka "Algorithm X2"), as used in OpenBSD 2.6 through 3.4, Mac OS X 10 through 10.5.1, FreeBSD 4.4 through 7.0, and DragonFlyBSD 1.0 through 1.10.1, allows remote attackers to guess sensitive values such as IP fragmentation IDs by observing a sequence of previously generated values. NOTE: this issue can be leveraged for attacks such as injection into TCP packets and OS fingerprinting.

Affected Platforms (CPE)

📦
Cosmicperl

Directory Pro

= 10.0.3
📦
Darwin

Darwin

= 1.0
📦
Darwin

Darwin

= 9.1
📦
Navision

Financials Server

= 3.0

References & Advisories

相關漏洞威脅