← Back

CVE-2008-5162

nvd nist
Published: Nov 26, 2008Modified: Apr 23, 2026

JSON object

Loading...
7.0
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.0 / Impact: 5.9
Source: NVD

Description

The arc4random function in the kernel in FreeBSD 6.3 through 7.1 does not have a proper entropy source for a short time period immediately after boot, which makes it easier for attackers to predict the function's return values and conduct certain attacks against the GEOM framework and various network protocols, related to the Yarrow random number generator.

Affected (30)

Products: Freebsd: Freebsd
1 product
Freebsd
Configuration A
30 vulnerable
Vulnerable SoftwareAffected Versions
Freebsd
From 6.4 to 7.0
Version 6.3
Version 6.3 p1
Version 6.3 p2
Version 6.3 p3
Version 6.3 p4
Version 6.3 p5
Version 7.0
Version 7.0 p1
Version 7.0 p3
Version 7.0 p4
Version 7.0 p5
Version 7.1
Version 7.1 p10
Version 7.1 p12
Version 7.1 p13
Version 7.1 p14
Version 7.1 p15
Version 7.1 p16
Version 7.1 p1
Version 7.1 p2
Version 7.1 p3
Version 7.1 p4
Version 7.1 p5
Version 7.1 p6
Version 7.1 p7
Version 7.1 p8
Version 7.1 p9
Version 7.1 rc1
Version 7.1 rc2

References (10)

Source: secteam@freebsd.org
Broken Link
Source: secteam@freebsd.org
Broken Link
Source: secteam@freebsd.org
Broken LinkThird Party AdvisoryVDB Entry
Source: secteam@freebsd.org
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry

Timeline

No history available yet.