Vulnerabilities > CVE-2008-1146

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL

Summary

A certain pseudo-random number generator (PRNG) algorithm that uses XOR and 3-bit random hops (aka "Algorithm X3"), as used in OpenBSD 2.8 through 4.2, allows remote attackers to guess sensitive values such as DNS transaction IDs by observing a sequence of previously generated values. NOTE: this issue can be leveraged for attacks such as DNS cache poisoning against OpenBSD's modification of BIND.

Vulnerable Configurations

Part Description Count
OS
Apple
83
OS
Dragonflybsd
4
OS
Freebsd
74
OS
Netbsd
16
OS
Openbsd
17
Application
Cosmicperl
1
Application
Darwin
2
Application
Navision
1