Vulnerability CVE-2002-0666


Published: 2002-11-04   Modified: 2012-02-12

Description:
IPSEC implementations including (1) FreeS/WAN and (2) KAME do not properly calculate the length of authentication data, which allows remote attackers to cause a denial of service (kernel panic) via spoofed, short Encapsulating Security Payload (ESP) packets, which result in integer signedness errors.

CVSS2 => (AV:N/AC:L/Au:N/C:N/I:N/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
None
Partial
Affected software
Netbsd -> Netbsd 
NEC -> Bluefire ix1035 router 
NEC -> Ix1010 
NEC -> Ix1011 
NEC -> Ix1020 
NEC -> Ix1050 
NEC -> Ix2010 
Global technology associates -> Gnat box firmware 
Frees wan -> Frees wan 
Freebsd -> Freebsd 
Apple -> Mac os x 
Apple -> Mac os x server 

 References:
http://www.kb.cert.org/vuls/id/459371
http://www.securityfocus.com/bid/6011
http://www.iss.net/security_center/static/10411.php
http://www.debian.org/security/2002/dsa-201
http://razor.bindview.com/publish/advisories/adv_ipsec.html
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2002-016.txt.asc

Copyright 2022, cxsecurity.com

 

Back to Top