First published: Thu May 06 2004(Updated: )
racoon before 20040407b allows remote attackers to cause a denial of service (infinite loop and dropped connections) via an IKE message with a malformed Generic Payload Header containing invalid (1) "Security Association Next Payload" and (2) "RESERVED" fields.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
KAME Racoon | <=2004-04-07a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0392 is classified as a denial of service vulnerability that can lead to dropped connections.
To address CVE-2004-0392, upgrade to a version of KAME racoon released after 2004-04-07a that contains the necessary security patches.
The vulnerability in CVE-2004-0392 is triggered by the arrival of an IKE message containing a malformed Generic Payload Header.
KAME racoon versions prior to 2004-04-07a are affected by CVE-2004-0392.
Exploitation of CVE-2004-0392 can cause an infinite loop leading to a denial of service, impacting service availability.