First published: Tue Dec 19 2000(Updated: )
The IPSEC implementation in OpenBSD 2.7 does not properly handle empty AH/ESP packets, which allows remote attackers to cause a denial of service.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenBSD | =2.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0962 is classified as a denial of service vulnerability.
To resolve CVE-2000-0962, upgrade to a later version of OpenBSD that does not contain the vulnerability.
CVE-2000-0962 specifically impacts OpenBSD version 2.7.
CVE-2000-0962 can be exploited by attackers sending specially crafted empty AH/ESP packets.
No specific patch for CVE-2000-0962 is available; upgrading to a secure version of OpenBSD is the recommended action.