CVE-2002-0666: Medium severity Frees Wan Frees Wan vulnerability
IPSEC implementations including (1) FreeS/WAN and (2) KAME do not properly calculate the length of authentication data, which allows remote attackers to cause a denial of service (kernel panic) via spoofed, short Encapsulating Security Payload (ESP) packets, which result in integer signedness errors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2002-0666?
CVE-2002-0666 is classified as a high severity vulnerability due to its potential to cause kernel panics, resulting in denial of service.
How do I fix CVE-2002-0666?
To fix CVE-2002-0666, update the affected IPSEC implementations to the latest stable version that addresses this vulnerability.
Which software versions are affected by CVE-2002-0666?
CVE-2002-0666 affects multiple versions of FreeS/WAN, NetBSD, and FreeBSD, specifically versions 1.9.x of FreeS/WAN and various versions of NetBSD and FreeBSD.
Who is at risk from CVE-2002-0666?
Users running vulnerable versions of FreeS/WAN, NetBSD, and FreeBSD are at risk from CVE-2002-0666.
What type of attacks does CVE-2002-0666 allow?
CVE-2002-0666 allows remote attackers to exploit integer signedness errors by sending spoofed short Encapsulating Security Payload packets.