CNCVE编号:CNCVE-20000916 CVE编号:CAN-2000-0916 安全级别:高 漏洞中文描述: FreeBSD 4.1.1版本以及更早期的版本和一些其他基于BSD的操作系统, 使用了一种并不充分的随机数字产生器来生成TCP的初始序列号(ISN,initial TCP sequence numbers),这使得远程攻击者可以进行TCP连接欺骗。 漏洞英文描述: FreeBSD 4.1.1 and earlier, and possibly other BSD-based OSes, uses an insufficient random number generator to generate initial TCP sequence numbers (ISN), which allows remote attackers to spoof TCP connections. 漏洞参考: FREEBSD:FreeBSD-SA-00:52 | ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:52.tcp-iss.asc | BID:1766 | URL:http://www.securityfocus.com/bid/1766 系统类型:其他 漏洞类型:设计错误