Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2008-5162 | First vendor Publication | 2008-11-26 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H | |||
---|---|---|---|
Overall CVSS Score | 7 | ||
Base Score | 7 | Environmental Score | 7 |
impact SubScore | 5.9 | Temporal Score | 7 |
Exploitabality Sub Score | 1 | ||
Attack Vector | Local | Attack Complexity | High |
Privileges Required | Low | User Interaction | None |
Scope | Unchanged | Confidentiality Impact | High |
Integrity Impact | High | Availability Impact | High |
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:L/AC:M/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 6.9 | Attack Range | Local |
Cvss Impact Score | 10 | Attack Complexity | Medium |
Cvss Expoit Score | 3.4 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
The arc4random function in the kernel in FreeBSD 6.3 through 7.1 does not have a proper entropy source for a short time period immediately after boot, which makes it easier for attackers to predict the function's return values and conduct certain attacks against the GEOM framework and various network protocols, related to the Yarrow random number generator. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5162 |
CAPEC : Common Attack Pattern Enumeration & Classification
Id | Name |
---|---|
CAPEC-59 | Session Credential Falsification through Prediction |
CAPEC-112 | Brute Force |
CAPEC-281 | Analytic Attacks |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-330 | Use of Insufficiently Random Values |
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2009-04-09 | Name : Mandriva Update for ruby MDVSA-2008:029 (ruby) File : nvt/gb_mandriva_MDVSA_2008_029.nasl |
2008-11-24 | Name : FreeBSD Security Advisory (FreeBSD-SA-08:11.arc4random.asc) File : nvt/freebsdsa_arc4random.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
50137 | FreeBSD arc4random() Function Entropy Source Weakness |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:12:54 |
|
2024-11-28 12:17:03 |
|
2024-08-02 12:10:11 |
|
2024-08-02 01:02:52 |
|
2024-02-14 21:28:19 |
|
2024-02-02 01:09:44 |
|
2024-02-01 12:02:50 |
|
2023-09-05 12:09:05 |
|
2023-09-05 01:02:41 |
|
2023-09-02 12:09:12 |
|
2023-09-02 01:02:42 |
|
2023-08-12 12:10:48 |
|
2023-08-12 01:02:42 |
|
2023-08-11 12:09:14 |
|
2023-08-11 01:02:48 |
|
2023-08-06 12:08:51 |
|
2023-08-06 01:02:43 |
|
2023-08-04 12:08:56 |
|
2023-08-04 01:02:46 |
|
2023-07-14 12:08:55 |
|
2023-07-14 01:02:44 |
|
2023-03-29 01:10:10 |
|
2023-03-28 12:02:50 |
|
2022-10-11 12:07:55 |
|
2022-10-11 01:02:33 |
|
2021-05-04 12:08:23 |
|
2021-04-22 01:08:45 |
|
2020-05-23 00:22:36 |
|
2019-03-19 12:02:56 |
|
2016-06-28 17:21:10 |
|
2016-04-26 18:02:50 |
|
2013-05-11 00:30:54 |
|