Random number bug blights FreeBSD
The devil's in the detail
Posted in Software & Security, 30th November 2007 15:07 GMT
Free whitepaper – Managing desktop software for fun and profit
The FreeBSD project pushed out a brace of updates on Thursday to guard against a pair of potentially serious security vulnerabilities.
First up is an update that patches a bug in the GNU tar archiving utility that created a mechanism for hackers to overwrite files on a vulnerable system.
The bug, which stems from insufficient checking, affects an alternative utility that does much the same job as the more widely used bsdtar archiving tool. Bsdtar has been the default archiving utility since FreeBSD 5.3.
More seriously, security researchers have discovered that it's possible for attackers to access the internal state tracking used in the pseudo-random number generators, random and urandom, bundled with FreeBSD.
The flaw is akin to the bugs in pseudo-random generators within Windows XP and 2000 and has much the same effect. As such, the bug enables hackers to determine "random numbers" that underpin the security of encryption functions, such as SSL transactions.
Hackers are likely to need local access to vulnerable systems, so attacks based on the cryptographic weakness are far from straightforward. An update from the FreeBSD project is designed to secure systems against possible attack.
FreeBSD, well regarded as a stable OS, is most commonly used as a web server platform. Fixing the pseudo-random generator bug involves a system reboot, which could be an issue in some hosting environments.
More information on the update can be found in an advisory from the FreeBSD Project here. ®
The Register Agile Data Center Summit
New storage architectures make SSDs more cost-effective
Dell PowerEdge R710 solution with VMware ESX vs. Dell PowerEdge 2850 solution

Sign up, sign up for The Register IT security newsletter
Microsoft's Windows 7 price gamble - and why it's flawed
Managing Desktop Software for fun and profit
Intel's flash new SSDs hit by bugs