CVE-2002-0666 Information

Description

IPSEC implementations including (1) FreeS/WAN and (2) KAME do not properly calculate the length of authentication data which allows remote attackers to cause a denial of service (kernel panic) via spoofed short Encapsulating Security Payload (ESP) packets which result in integer signedness errors.

Reference

ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2002-016.txt.asc http://razor.bindview.com/publish/advisories/adv_ipsec.html http://www.debian.org/security/2002/dsa-201 http://www.iss.net/security_center/static/10411.php http://www.kb.cert.org/vuls/id/459371 http://www.securityfocus.com/bid/6011

Share on: