The Channel logo


By | John Leyden 30th November 2007 15:07

Random number bug blights FreeBSD

The devil's in the detail

The FreeBSD project pushed out a brace of updates on Thursday to guard against a pair of potentially serious security vulnerabilities.

First up is an update that patches a bug in the GNU tar archiving utility that created a mechanism for hackers to overwrite files on a vulnerable system.

The bug, which stems from insufficient checking, affects an alternative utility that does much the same job as the more widely used bsdtar archiving tool. Bsdtar has been the default archiving utility since FreeBSD 5.3.

More seriously, security researchers have discovered that it's possible for attackers to access the internal state tracking used in the pseudo-random number generators, random and urandom, bundled with FreeBSD.

The flaw is akin to the bugs in pseudo-random generators within Windows XP and 2000 and has much the same effect. As such, the bug enables hackers to determine "random numbers" that underpin the security of encryption functions, such as SSL transactions.

Hackers are likely to need local access to vulnerable systems, so attacks based on the cryptographic weakness are far from straightforward. An update from the FreeBSD project is designed to secure systems against possible attack.

FreeBSD, well regarded as a stable OS, is most commonly used as a web server platform. Fixing the pseudo-random generator bug involves a system reboot, which could be an issue in some hosting environments.

More information on the update can be found in an advisory from the FreeBSD Project here. ®

comment icon Read 29 comments on this article alert Send corrections


Frank Jennings

What do you do? Use manual typwriters or live in a Scottish croft? Our man advises
A rusty petrol pump at an abandoned gas station. Pic by Silvia B. Jakiello via shutterstock

Trevor Pott

Among other things, Active Directory needs an overhaul
Baby looks taken aback/shocked/affronted. Photo by Shutterstock

Kat Hall

Plans for 2 million FTTP connections in next four years 'not enough'
Microsoft CEO Satya Nadella


League of gentlemen poster - Tubbs and Edward at the local shop. Copyright BBC
One reselling man tells his tale of woe