newsbot
13-02-2008, 07:03 PM
A serious weakness has been discovered in OpenBSD's PRNG, which allows an attacker to predict the next transaction ID (typically up to 8-10 guesses) given a series of consecutive 12-15 transaction IDs.
http://www.securiteam.com/securityreviews/5PP0H0UNGW.html
http://www.securiteam.com/securityreviews/5PP0H0UNGW.html