FreeBSD Insecure Random Number Generator Information Disclosure Weakness
BID:26642
Info
FreeBSD Insecure Random Number Generator Information Disclosure Weakness
| Bugtraq ID: | 26642 |
| Class: | Design Error |
| CVE: |
CVE-2007-6150 |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 29 2007 12:00AM |
| Updated: | Nov 30 2007 03:03PM |
| Credit: | Robert Woolley is credited with the discovery of this vulnerability. |
| Vulnerable: |
FreeBSD FreeBSD 6.0 .x FreeBSD FreeBSD 6.0 -STABLE FreeBSD FreeBSD 6.0 -RELEASE FreeBSD FreeBSD 5.5 -STABLE FreeBSD FreeBSD 5.5 -RELEASE FreeBSD FreeBSD 7.0 BETA4 FreeBSD FreeBSD 6.3 FreeBSD FreeBSD 6.2 -STABLE FreeBSD FreeBSD 6.2 FreeBSD FreeBSD 6.1 -STABLE FreeBSD FreeBSD 6.1 -RELEASE-p10 FreeBSD FreeBSD 6.1 -RELEASE FreeBSD FreeBSD 6.0 -RELEASE-p5 |
| Not Vulnerable: | |
Discussion
FreeBSD Insecure Random Number Generator Information Disclosure Weakness
FreeBSD is prone to an information-disclosure weakness that stems from a flaw in the 'random(4)' and 'urandom(4)' pseudo-random number generators.
An attacker can exploit this issue to access fragments of previously read random values. Information obtained may aid in further attacks.
FreeBSD is prone to an information-disclosure weakness that stems from a flaw in the 'random(4)' and 'urandom(4)' pseudo-random number generators.
An attacker can exploit this issue to access fragments of previously read random values. Information obtained may aid in further attacks.
Exploit / POC
FreeBSD Insecure Random Number Generator Information Disclosure Weakness
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
FreeBSD Insecure Random Number Generator Information Disclosure Weakness
Solution:
The vendor released an advisory along with fixes to address this issue. Please see the references for more information.
FreeBSD FreeBSD 6.1 -STABLE
FreeBSD FreeBSD 6.1 -RELEASE
FreeBSD FreeBSD 6.2 -STABLE
FreeBSD FreeBSD 6.2
FreeBSD FreeBSD 6.1 -RELEASE-p10
FreeBSD FreeBSD 5.5 -STABLE
FreeBSD FreeBSD 5.5 -RELEASE
Solution:
The vendor released an advisory along with fixes to address this issue. Please see the references for more information.
FreeBSD FreeBSD 6.1 -STABLE
-
FreeBSD random.patch
http://security.freebsd.org/patches/SA-07:09/random.patch
FreeBSD FreeBSD 6.1 -RELEASE
-
FreeBSD random.patch
http://security.freebsd.org/patches/SA-07:09/random.patch
FreeBSD FreeBSD 6.2 -STABLE
-
FreeBSD random.patch
http://security.freebsd.org/patches/SA-07:09/random.patch
FreeBSD FreeBSD 6.2
-
FreeBSD random.patch
http://security.freebsd.org/patches/SA-07:09/random.patch
FreeBSD FreeBSD 6.1 -RELEASE-p10
-
FreeBSD random.patch
http://security.freebsd.org/patches/SA-07:09/random.patch
FreeBSD FreeBSD 5.5 -STABLE
-
FreeBSD random.patch
http://security.freebsd.org/patches/SA-07:09/random.patch
FreeBSD FreeBSD 5.5 -RELEASE
-
FreeBSD random.patch
http://security.freebsd.org/patches/SA-07:09/random.patch
References
FreeBSD Insecure Random Number Generator Information Disclosure Weakness
References:
References:
- FreeBSD Homepage (FreeBSD)
- FreeBSD Security Information (FreeBSD)