The "internal state tracking" code for the random and urandom devices in FreeBSD 5.5, 6.1 through 6.3, and 7.0 beta 4 allows local users to obtain portions of previously-accessed random values, which could be leveraged to bypass protection mechanisms that rely on secrecy of those values.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/26642 | vdb entry |
http://security.FreeBSD.org/advisories/FreeBSD-SA-07:09.random.asc | patch vendor advisory |
http://www.securitytracker.com/id?1019022 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/38764 | vdb entry |
http://secunia.com/advisories/27879 | third party advisory vendor advisory |
http://osvdb.org/39600 | vdb entry |
http://www.vupen.com/english/advisories/2007/4053 | vdb entry |