CVE

Id
2485  
CVE No.
CVE-2000-0916  
Status
Candidate  
Description
FreeBSD 4.1.1 and earlier, and possibly other BSD-based OSes, uses an insufficient random number generator to generate initial TCP sequence numbers (ISN), which allows remote attackers to spoof TCP connections.  
Phase
Proposed (20001129)  
Votes
ACCEPT(2) Cole, Mell | MODIFY(1) Frech | REVIEWING(1) Christey  
Comments
Frech> XF:tcp-seq-predict(139) | Christey> Abstraction issue: CVE-1999-0077 is for TCP sequence | prediction as a general problem; but here we have a specific | implementation flaw.