| |||||||||||||
| Test ID: | 1.3.6.1.4.1.25623.1.0.59932 |
| Category: | FreeBSD Local Security Checks |
| Title: | FreeBSD Security Advisory (FreeBSD-SA-07:09.random.asc) |
| Summary: | FreeBSD Security Advisory (FreeBSD-SA-07:09.random.asc) |
| Description: | The remote host is missing an update to the system as announced in the referenced advisory FreeBSD-SA-07:09.random.asc The random(4) and urandom(4) devices return an endless supply of pseudo-random bytes when read. Cryptographic algorithms often depend on the secrecy of these pseudo-random values for security. Under certain circumstances, a bug in the internal state tracking on the random(4) and urandom(4) devices can be exploited to allow replaying of data distributed during subsequent reads. Solution: Upgrade your system to the appropriate stable release or security branch dated after the correction date http://www.securityspace.com/smysecure/catid.html?in=FreeBSD-SA-07:09.random.asc |
| Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2007-6150 FreeBSD Security Advisory: FreeBSD-SA-07:09 http://security.FreeBSD.org/advisories/FreeBSD-SA-07:09.random.asc BugTraq ID: 26642 http://www.securityfocus.com/bid/26642 http://www.vupen.com/english/advisories/2007/4053 http://osvdb.org/39600 http://www.securitytracker.com/id?1019022 http://secunia.com/advisories/27879 XForce ISS Database: freebsd-sysdevrandom-information-disclosure(38764) http://xforce.iss.net/xforce/xfdb/38764 |
| Copyright | Copyright (c) 2007 E-Soft Inc. http://www.securityspace.com |
| This is only one of 32582 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |
|