Subject: Re: FreeBSD Security Advisory: FreeBSD-SA-00:52.tcp-iss (fwd)
To: None <abs@purplei.com>
From: None <itojun@iijlab.net>
List: tech-net
Date: 10/09/2000 07:18:17
> Would this be relevant for NetBSD?
>>Topic: TCP uses weak initial sequence numbers
yes, partially.
- (1) if you have rnd(4) configured to the kernel config file, and
(2) your sys/netinet/tcp_subr.c is after 1.30 (1997/10),
you are okay. this means that, for official releases, 1.3 and
higher is okay.
- otherwise, you are affected by the issue.
i think we should do an advisory, as many of architectures shipped
with rnd(4) disabled in GENERIC configuration file, for 1.3 and 1.4.
i'll try to cook up a draft.
itojun