CVE-2004-0392: Medium severity KAME Racoon vulnerability
racoon before 20040407b allows remote attackers to cause a denial of service (infinite loop and dropped connections) via an IKE message with a malformed Generic Payload Header containing invalid (1) "Security Association Next Payload" and (2) "RESERVED" fields.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0392?
CVE-2004-0392 is classified as a denial of service vulnerability that can lead to dropped connections.
How do I fix CVE-2004-0392?
To address CVE-2004-0392, upgrade to a version of KAME racoon released after 2004-04-07a that contains the necessary security patches.
What specific conditions trigger the vulnerability in CVE-2004-0392?
The vulnerability in CVE-2004-0392 is triggered by the arrival of an IKE message containing a malformed Generic Payload Header.
Which versions of KAME racoon are affected by CVE-2004-0392?
KAME racoon versions prior to 2004-04-07a are affected by CVE-2004-0392.
What happens if my system is exploited through CVE-2004-0392?
Exploitation of CVE-2004-0392 can cause an infinite loop leading to a denial of service, impacting service availability.