First published: Fri Oct 25 2002(Updated: )
IPSEC implementations including (1) FreeS/WAN and (2) KAME do not properly calculate the length of authentication data, which allows remote attackers to cause a denial of service (kernel panic) via spoofed, short Encapsulating Security Payload (ESP) packets, which result in integer signedness errors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Farmers Wife | =1.9.1 | |
Farmers Wife | =1.9.2 | |
Farmers Wife | =1.9 | |
Farmers Wife | =1.9.6 | |
Farmers Wife | =1.9.4 | |
Farmers Wife | =1.9.3 | |
Farmers Wife | =1.9.5 | |
NetBSD current | =1.5.3 | |
NetBSD current | =1.5 | |
FreeBSD Kernel | =4.6-stable | |
FreeBSD Kernel | =4.6-release | |
NetBSD current | =1.5 | |
NetBSD current | =1.6-beta | |
NetBSD current | =1.5.1 | |
NetBSD current | =1.5 | |
NetBSD current | =1.5.2 | |
Apple macOS Server | =10.2 | |
FreeBSD Kernel | =4.6 | |
Apple iOS and macOS | =10.2 | |
global technology associates gnat box firmware | =3.3 | |
nec ix2010 | ||
NEC IX1011 | ||
nec bluefire ix1035 router | ||
global technology associates gnat box firmware | =3.1 | |
global technology associates gnat box firmware | =3.2 | |
NEC IX1010 | ||
nec ix1020 | ||
NEC IX1050 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0666 is classified as a high severity vulnerability due to its potential to cause kernel panics, resulting in denial of service.
To fix CVE-2002-0666, update the affected IPSEC implementations to the latest stable version that addresses this vulnerability.
CVE-2002-0666 affects multiple versions of FreeS/WAN, NetBSD, and FreeBSD, specifically versions 1.9.x of FreeS/WAN and various versions of NetBSD and FreeBSD.
Users running vulnerable versions of FreeS/WAN, NetBSD, and FreeBSD are at risk from CVE-2002-0666.
CVE-2002-0666 allows remote attackers to exploit integer signedness errors by sending spoofed short Encapsulating Security Payload packets.