IBM Corporation Information for VU#498440
Multiple TCP/IP implementations may use statistically predictable initial sequence numbers
- Vendor Information Help Date Notified: 08 Mar 2001
- Statement Date: 12 Apr 2001
- Date Updated: 19 Apr 2001
We have studied the document written by Guardent regarding vulnerabilities
caused by statistical analysis of random increments, that may allow a
malicious user to predict the next sequence of chosen TCP connections.
IBM's AIX operating system should not be vulnerable as we have implemented
RFC 1948 in our source coding. According to Guardent, we do not expect an
exploit described in the document to affect our AIX OS because we employ
We are not aware of further vendor information regarding this vulnerability.
The CERT/CC has no additional comments at this time.
If you have feedback, comments, or additional information about this vulnerability, please send us email.