CVE-2004-0218: Medium severity OpenBSD OpenBSD vulnerability
Published Mar 25, 2004
·Updated
isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service (infinite loop) via an ISAKMP packet with a zero-length payload, as demonstrated by the Striker ISAKMP Protocol Test Suite.
Affected Software
1 affected component
OpenBSD OpenBSD<=3.4
Remediation
Patch Available
Event History
Mar 25, 2004
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0218?
CVE-2004-0218 is classified as a denial of service vulnerability.
2
How do I fix CVE-2004-0218?
To fix CVE-2004-0218, upgrade to OpenBSD version 3.5 or later.
3
What software is affected by CVE-2004-0218?
CVE-2004-0218 affects OpenBSD versions 3.4 and earlier.
4
What type of attack does CVE-2004-0218 enable?
CVE-2004-0218 allows remote attackers to cause a denial of service through an infinite loop.
5
What is required to exploit CVE-2004-0218?
Exploiting CVE-2004-0218 requires sending an ISAKMP packet with a zero-length payload.